
A ransomware encrypts the billing server on a Friday night, the IT team is on reduced standby, and the backup provider takes 48 hours to restore a partial backup. In the meantime, customer orders are no longer going out, the phone line is overwhelmed, and the professional multi-risk insurance does not foresee any coverage for this type of disaster.
This scenario is increasingly common in companies of all sizes, including those that thought they had “enough IT security” in-house.
Evidence Required by Cyber Insurers: What Really Blocks Compensation
Most executives imagine that cyber risk insurance works like auto insurance: you report the incident, and you wait for the payout. The reality on the ground is very different. Insurers have tightened their requirements in recent years, and without detailed material evidence, compensation may be denied.
Specifically, at the time of the claim, we are asked to provide a precise inventory of affected assets, timestamped incident logs, certificates of staff training in cybersecurity, and proof that software patches were deployed before the attack. If backup tests have not been documented, the insurer may invoke “gross negligence” to reduce or cancel coverage.
Even before comparing contracts, it is essential to understand the benefits of cyber risk insurance in relation to what each policy requires as technical prerequisites. A cheap contract with broad exclusions costs more than a rigorous contract that actually compensates.
- Maintain an up-to-date register of suppliers and subcontractors with access to the information system, including their levels of authorization
- Document each backup restoration test (date, tested scope, result) to prove that the recovery plan works
- Keep evidence of the deployment of security updates on critical workstations and servers
- Archive materials and certificates of cybersecurity training provided to employees, even short sessions

NIS2 Directive and Personal Responsibility of Executives
There is a lot of talk about GDPR compliance, but the NIS2 directive changes the game on a specific point. Article 20 of NIS2 requires governing bodies to personally approve cyber risk management measures, oversee their implementation, and undergo appropriate training.
This is not symbolic. For entities classified as significant, executives can be temporarily suspended from their duties in case of a breach. Cybersecurity is no longer a topic delegated to the IT department: it is a governance obligation that personally engages the executive.
This personal responsibility enhances the value of cyber insurance that also covers the liability of executives. Traditional D&O insurance policies do not always include this aspect. It is essential to verify that the contract explicitly covers administrative sanctions and defense costs related to breaches of cybersecurity obligations.
Transposition into French Law: Anticipating Despite Delays
The French transposition of NIS2 is delayed, but obligations are coming. Waiting for the publication of the national text to act means preparing your compliance evidence in an emergency, exactly the scenario that insurers penalize. Anticipating NIS2 compliance directly improves insurance conditions, as insurers are already incorporating these criteria into their underwriting questionnaires.
Cyber Insurance and the Supply Chain: A Common Blind Spot
NIS2 also imposes responsibility on the supply chain. If a subcontractor suffers a cyberattack and it impacts your business, you must be able to demonstrate that you had assessed their security level. Feedback on this point varies by sector, but the trend is clear: clients increasingly require cyber insurance certificates from their providers.
Cyber insurance is becoming a commercial criterion, not just financial protection. Some tenders already include a clause requiring minimum cyber coverage from the provider. Not being insured can mean losing a contract, even before suffering an attack.
What a Cyber Contract Really Covers Regarding Subcontracting
A good cyber insurance contract covers business interruption losses caused by an IT failure at a contractually bound supplier. It covers the costs of notifying clients if personal data has been processed by the compromised subcontractor. However, if no formal contract binds the two parties, coverage is often excluded.

Costs of a Cyberattack Without Insurance: Direct and Indirect Losses
According to the Asterès firm, 385,000 successful cyberattacks targeted French organizations in 2022, with a total estimated cost of 2 billion euros. These figures aggregate direct losses (ransom, system restoration, equipment replacement) and often underestimated indirect costs.
Indirect costs represent the heaviest burden: business interruption for several days, loss of customers who do not return after a data breach, legal fees related to complaints, and reputational damage that no communication campaign can quickly repair. An uninsured company absorbs all these losses on its cash flow.
- Crisis management costs: forensic experts, crisis communication, dedicated hotline for affected clients
- Business losses during the period of unavailability of the IT system
- Liability towards third parties whose data has been compromised
- Administrative sanctions (CNIL, and soon NIS2) that can reach significant amounts depending on the size of the company
IT protection (firewall, antivirus, training) reduces the likelihood of an attack. Cyber insurance covers the financial consequences when protection fails. The two work together, not one instead of the other. Even a well-protected system remains exposed to successful attacks, and that is precisely what makes insurance coverage necessary for any company that relies on its information system daily.