Liability insurance · CYBER LIABILITY

Cyber Liability Insurance (Cyber Insurance)

A comprehensive cyber policy covering third-party liability arising from cyber incidents such as hacking, ransomware, DDoS and insider leaks, together with incident-response costs and business-interruption loss.

Cyber Liability Insurance

From a licensed insurance broker

N2N Insurance Brokerage does not represent any single insurer — it independently represents the client as an FSS-registered broker (Reg. No. 2026-012201). We compare the wordings, rates and service of AIG · Chubb · DB · Hyundai · KB · Meritz to propose the cover and price best suited to your risk. Each insurer's full wording is provided at application and binding.

Overview

Cyber liability insurance covers a cyber incident affecting a company’s IT systems and data — comprehensively insuring both the resulting third-party liability and the company’s own incident response and recovery costs (First-Party Loss).

It responds to a wide range of cyber incidents — hacking, malware, ransomware, DDoS, phishing, insider leaks and human error.

Key features

  • 01
    1st-Party / 3rd-Party combined

    Third-party liability (external claims) and the company’s own response costs (forensics, recovery, business-interruption loss) are covered under a single policy.

  • 02
    24-hour breach-response service

    On notification, you are connected to cyber-forensic, legal and PR specialists for immediate response.

  • 03
    Ransomware / extortion cover

    Cover for ransom payment, negotiation and recovery costs (subject to compliance with applicable sanctions law).

  • 04
    Business-interruption (BI) cover

    Cover for lost revenue and fixed costs during system downtime caused by a cyber incident.

Who needs it

  • 01
    Online platforms & e-commerce

    Online malls, O2O and fintech that process large volumes of payment and personal data.

  • 02
    Large manufacturers & distributors

    Sectors where OT/ICS connectivity means ransomware can halt production lines.

  • 03
    Finance, healthcare & public institutions

    Sectors handling large volumes of sensitive data, where an incident brings high reputational and class-action risk.

Main losses covered — third-party liability

  • Damages to data subjects for a personal-data breach
  • Liability where a network-security incident damages a third party’s systems
  • Liability for defamation or copyright infringement (digital content)
  • Regulatory-investigation and class-action defence costs

First-party loss

  • Investigation and forensic costs, and recovery costs (data restoration and system rebuild)
  • Cyber business-interruption (BI) loss — lost revenue and fixed costs
  • Ransomware ransom and negotiation costs (subject to sanctions compliance)
  • Crisis-management PR and reputation-recovery costs
  • Customer-notification costs and call-centre operating costs

Endorsements (additional cover)

  • Endorsement extending cover to (unintentional) system failure
  • Cover for outsourcing / supply-chain cyber incidents
  • Social-engineering funds-transfer cover
  • Computer Fraud / Funds Transfer Fraud

Losses not covered (main exclusions)

  • The insured’s wilful unlawful acts
  • War and state-sponsored cyber attacks (a Cyber War Exclusion may apply)
  • Previously known vulnerabilities or incidents
  • Intellectual-property or patent infringement (general clause)
  • Bodily injury or property damage (separate CGL)
  • Contract-performance guarantee liability

Conditions & process

Policy period1 year (Claims-Made basis)
PaymentSingle (annual) payment
InsurersAIG · Chubb · DB · Meritz · Hyundai
ChannelIndividual consultation with our broker (010-5755-6465)
Turnaround5–10 business days (security review)

What we need to quote

  • IT security framework (ISMS, ISO 27001, firewall, IPS, etc.)
  • Status of MFA, EDR and backup systems
  • Annual revenue and volume of data held
  • Cyber-incident history over the past 5 years
  • Desired limits (aggregate / sub-limits)

Other notes

  • For cyber insurance the underwriting stage (Security Questionnaire) is critical — cover may be declined if the security level is insufficient
  • Ransomware cover applies subject to compliance with international sanctions law such as OFAC
  • On becoming aware of an incident, you must immediately contact the insurer and specialists (IR team)

Withdrawal / quality assurance / pre-contract disclosure

  • The application may be withdrawn within 15 days of receiving the policy (excluding professional financial consumers)
  • Cancellable within 3 months for breach of the duty to explain material matters or a missing handwritten signature
  • Breach of the duty of disclosure may lead to cancellation or reduction of the claim
Depositor-protected product

Points to note

Please check the basics of the policy when you apply.

  • When applying for the policy, please confirm the product name, policy period, premium-payment period and the insured , and be sure to receive and check the policy wording.
  • Before concluding the contract, please read the product description and policy wording.
  • If you cancel an existing policy to take out a new one, acceptance may be declined, the premium may rise and the cover may differ — please take note.
  • Payment of the claim may be restricted by exclusions and payment-limitation grounds.

Nullity of the contract

If the insured event has already occurred at the time the contract is made, the contract is void. However, where the contract is void due to the company's intent or negligence, or where the company knew or could have known of the nullity before acceptance yet did not refund the premium, the company refunds the premium with interest at the policy-loan rate published by the Korea Insurance Development Institute, compounded annually, for the period from the day after payment to the day of refund.

Losses not covered

The specific losses not covered (exclusions) are set out in each insurer's policy wording and product description; on this page, see the “Cover” tab(or the “Losses not covered” section) for the main exclusions. For other cover-specific grounds on which claims are not paid, please refer to the policy wording.

Cover start date

The company provides cover, in accordance with the policy, from the time it accepts the application and receives the first premium. Where the company accepts the application after receiving the first premium with it, cover also begins from the time the first premium was received.

Policyholder's handwritten signature

The application must be completed by the policyholder, and the policyholder and the insured must sign it by hand. Failure to sign by hand may result in disadvantages regarding the validity of the contract. On an internet cyber-mall, an electronic signature may be used instead.

Right to be informed and have the product explained

The policyholder has the right to be given and have explained the information needed about the product they wish to buy.

Duty to explain

The insurer and N2N Insurance Brokerage must explain the important matters of the product to ordinary financial consumers.

Duty of disclosure before the contract

When applying, the policyholder, the insured or their agent must disclose truthfully the facts they know regarding the questions in the application (including the questionnaire). Otherwise the claim may be declined or the contract cancelled. Where insurance is taken out by telephone or other means of communication, the duty is performed by answering the seller's questions, which are recorded, without a separate written questionnaire, so answers must be given with particular care.

Duty of disclosure after the contract

If, after the contract is made, any of the following arises in respect of the subject-matter insured, the policyholder or the insured must notify the company in writing without delay and obtain endorsement on the policy.

  • When intending to take out, or learning of, a contract with another insurer covering the same risk as this contract
  • When transferring the subject-matter insured
  • When altering, rebuilding or extending the subject-matter insured or the building housing it
  • When moving the subject-matter insured to another location
  • When the risk is, or is found to have been, materially changed

Withdrawal of the application

  • The policyholder may withdraw the application within 15 daysof receiving the policy, in which case the premium paid is refunded. However, a contract more than 30 days after application (45 days where a policyholder aged 65+ contracted by telephone) cannot be withdrawn.
  • In addition, a medical-examination contract, a contract with a cover period of 90 days or less, guarantee insurance, statutory compulsory insurance, liability insurance under the Automobile Accident Compensation Act, or a commercial-insurance contract concluded by a professional financial consumer cannot be withdrawn.

Quality-assurance scheme

  • If, after application, the policyholder did not receive the policy wording and their copy of the application, was not given an explanation of the important contents of the wording, or did not sign the application by hand, they may cancel the contract within 3 monthsof the contract being formed.
  • In that case the premium already paid is refunded to the policyholder, with interest at the policy-loan rate compounded annually for the period the premium was held.

Why the surrender value may be less than the premiums paid, or nil

The surrender value is the amount paid if the contract is cancelled early. Unlike bank savings, insurance combines risk protection and savings: part of the premium is paid out as claims to other policyholders who suffer accidents, and part covers the insurer's operating expenses, so the surrender value on early cancellation may be less than the premiums paid, or nil.

Depositor protection

  • This policy is protected under the Depositor Protection Act, such that the surrender value (or the maturity benefit) plus other payments is protected up to “KRW 100 million per person” (aggregated with the insurer's other protected products).
  • Separately, the aggregate accident-claim amount of that insurer's protected products is “KRW 100 million per person” protected.
  • (However, a policy whose policyholder and premium payer is a corporation is not protected.)

Tax benefit (protection-type insurance)

Under Article 59-4(1) of the Income Tax Act (special tax credit), for protection-type insurance taken out by an employee only, a tax credit of 12% of the premium paid (capped at KRW 1 million per year) is available. Tax matters may change with amendment or repeal of the relevant tax law.

Personal-data protection

Except as provided by law, the insurer and N2N Insurance Brokerage do not collect, use, inspect or provide personal data related to this contract — for its conclusion, maintenance and claim payment — without the consent of the policyholder, the insured or the beneficiary. However, for those purposes the insurer may, with the consent of the policyholder and the insured and in accordance with law, provide personal data to other insurers and insurance-related bodies.

Solicitation-order and reporting centre

  • Providing special benefits in connection with concluding an insurance contract is punishable under the Insurance Business Act.
  • Financial Supervisory Service: 1332 (no area code) / mobile (02)1332 / “Report a solicitation-order violation” at http://fss.or.kr
  • General Insurance Association of Korea: 1332 (no area code) / mobile (02)1332 / “Solicitation-order Violation Report Centre” at http://knia.or.kr

FSS Insurance Fraud Prevention Centre

  • Insurance crime, under Article 8 of the Special Act on the Prevention of Insurance Fraud, is punishable by up to 10 years' imprisonment or a fine of up to KRW 50 million, and abetting insurance crime is subject to the same punishment.
  • Tel: 1332 (no area code) / mobile (02)1332 / Web: http://insucop.fss.or.kr or “Insurance Fraud Prevention Centre” at http://fss.or.kr

Insurance consultation and dispute mediation

  • For consultation or any complaint or dispute about insurance, contact the insurer's customer call centre for prompt handling. If you object to the outcome, you may apply for dispute mediation to the Financial Supervisory Service and the Korea Consumer Agency.
  • FSS Financial Consumer Protection Centre: 1332 (no area code) / http://fss.or.kr
  • Korea Consumer Agency Consumer Counselling Centre: 1372 (no area code) / http://www.kca.go.kr

Notice

The above is a summary and excerpt of the policy wording; for grounds on which claims are not paid and other details, please refer to the policy wording and product description.

About N2N Insurance Brokerage

  • N2N Insurance Brokerageis an insurance broker registered under Article 89 of the Insurance Business Act; it does not represent any single insurer but advises and intermediates on the side of the client (policyholder) (FSS Reg. No. 2026-012201 · Business Reg. No. 611-23-02374).
  • This site compares the wordings and rates of multiple insurers; application and acceptance follow each insurer's policy wording.

When you need cyber liability insurance

Common risk patterns in digital operations — a five-scenario self-check

🛒

Online platforms processing large volumes of payment and personal data

Online malls, O2O and fintech handle large volumes of payment and personal data, so a hacking or data-breach incident can cause large losses.

🏭

Manufacturers and distributors whose OT/ICS systems are linked to production lines

When ransomware halts production or logistics systems, the loss extends beyond data leakage to business-interruption loss.

🏥

Institutions processing large volumes of sensitive data — finance, healthcare, public sector

For institutions handling sensitive data, an incident raises both reputational damage and class-action risk.

💻

Any business exposed to external attacks such as ransomware and phishing

Cyber incidents — hacking, malware, DDoS, phishing, insider leaks — occur across every industry.

⏱️

When you need an immediate incident-response capability

With a cyber incident, the forensic, legal and PR response in the first few hours determines the scale of the loss.

A dispute pattern seen in the field

After a cyber incident a company often thinks of itself as “the victim,” but the actual loss arises in two directions. One is third-party liability for damage suffered by customers, business partners and others (3rd Party) — damages for personal-data breaches, regulatory-investigation and class-action defence costs, and so on. The other is loss the company bears directly (1st Party) — forensics and data-recovery costs, and business-interruption loss during downtime. Cyber liability insurance is typically designed to cover both risks under a single policy. Note too that even coverable items such as ransomware ransom come with conditions — for example compliance with applicable sanctions law — so the policy terms must be understood as well.

Source: (standard insurance-textbook scenario)

Three things easily missed when buying cyber liability insurance

The wording and structure points decision-makers most often overlook

  • 1

    Third-party liability and first-party loss are different covers

    Cyber risk splits into third-party liability (3rd Party) and the company’s own recovery and business-interruption loss (1st Party). Check that the policy covers both.

  • 2

    The scope and basis of business-interruption (BI) cover

    Lost revenue and fixed costs during system downtime fall under business-interruption (BI) cover. Check the wording for when cover starts and on what basis it is calculated.

  • 3

    Ransomware ransom cover is conditional

    Ransom and negotiation costs can be covered, but conditions apply — such as compliance with applicable sanctions law. Confirm exactly whether and on what terms it is covered.

Frequently asked questions

The questions asked most when considering cyber liability insurance

What incidents does cyber liability insurance cover?

It responds to a wide range of cyber incidents affecting IT systems and data — hacking, malware, ransomware, DDoS, phishing, insider leaks and human error. It covers both third-party liability and the company’s own incident-response and recovery loss.

How do third-party liability and first-party loss differ?

Third-party liability (3rd Party) is responsibility to outsiders — damages for personal-data breaches, regulatory-investigation and class-action defence costs. First-party loss (1st Party) is loss the company bears directly — forensics and recovery costs, business-interruption (BI) loss. Cyber liability insurance generally covers both areas together.

Is business-interruption loss covered too?

Lost revenue and fixed costs during downtime caused by a cyber incident fall under business-interruption (BI) cover. When cover starts and how it is calculated vary by wording, so this should be checked.

Is ransomware ransom covered?

Ransom and negotiation costs can be covered, but conditions apply — such as compliance with applicable sanctions law. Confirm exactly whether and on what terms in the wording.

How does it differ from privacy / data-breach liability insurance?

Cyber liability insurance covers cyber incidents broadly (hacking, ransomware, BI and more), while privacy / data-breach liability insurance is specialised in personal-data breaches and focused on meeting statutory duties. The two are often designed together.

How is the premium calculated?

The insurer calculates it based on industry, the volume and sensitivity of data processed, revenue, security level, the limit and cover structure, and past incident history. The exact premium and terms are confirmed after underwriting by insurers such as AIG, Chubb, DB, Hyundai, KB and Meritz.

Hanwook Seong, insurance broker

🏢 Operated by an independent insurance brokerage

n2nib.comis operated by N2N Insurance Brokerage (a registered insurance broker under Article 89 of the Insurance Business Act · FSS Reg. No. 2026-012201 · Business Reg. No. 611-23-02374). The wording, cover and exclusion information on this page is excerpted and summarised from the official product materials of member insurers AIG · Chubb · DB · Hyundai · KB · Meritz. Our brokerage fee is paid by the insurer and is not charged to the policyholder (Article 98 of the Insurance Business Act — prohibition of special benefits).