Printable discussion aid

Cyber Policy Review Question List

A useful policy discussion starts with realistic scenarios and follows them through triggers, costs, duties, limits and exclusions. The questions below are prompts for qualified insurance and legal review, not a substitute for it.

Covered-event language

Which definitions would respond to ransomware, business email compromise, accidental disclosure, vendor outage, system failure or privacy allegations?

First-party costs

How are forensics, counsel, restoration, notification, crisis communications, extortion response and business interruption addressed?

Third-party claims

How are privacy claims, customer demands, regulatory proceedings, contract disputes and defense costs treated?

Limits and erosion

What are the overall limit, annual aggregate and category sublimits? Do defense costs reduce the available limit?

Retention and waiting periods

Which deductibles, retentions, coinsurance or time waiting periods apply to each coverage part?

Notice and consent

Who must receive notice, how quickly, and which response actions or vendors require prior consent?

Vendor and dependent interruption

Does coverage respond when a cloud, payment, software or managed-service provider causes interruption or data exposure?

Prior acts and known circumstances

What retroactive dates, continuity terms, prior-knowledge exclusions or application representations matter?

Contract and Tech E&O boundary

Could customer promises, indemnities or service-performance allegations fall outside the cyber form?

Claim evidence

What financial, technical, legal and operational support would be expected for the most important scenarios?

Reminder: Adapt the template to the actual policy, contracts, facts, jurisdiction and professional instructions. Do not use a generic checklist to delay notice or urgent response.