Does Cyber Insurance Cover Insider Threats?

Some cyber policies cover certain insider-caused breaches, but intentional misconduct and stolen-money losses may be excluded or handled under crime coverage.

An insider threat involves someone with authorized access who misuses it, whether by taking information, sabotaging systems, or helping an outside attacker. Cyber liability wording may cover claims arising from a security or privacy failure while excluding some dishonest or intentional acts. In the AIG specimen, exclusions depend on who acted and what others knew; that illustrates why the precise wording matters and should not be generalized to other forms.

Check whether employees, contractors, and temporary workers count as insured persons, and whether the form preserves defense for innocent insureds. Read the dishonest-acts exclusion, any severability clause, and crime coverage for employee theft or computer fraud. Separate the response expense for a data incident from the value of money or property taken. Confirm reporting obligations and cooperate with the insurer’s investigation.

Providers That List This Coverage

Sources

  1. Cyber Insurance. Federal Trade Commission; What Should Your Cyber Insurance Policy Cover; First-Party Coverage; Third-Party Coverage. Accessed 2026-09-25.
  2. CyberEdge specimen policy. AIG; General Terms §§4–6, PDF pp.3–6; Security and Privacy §§1–3, PDF pp.11, 14–18; Event Management §§1–2, PDF pp.19–20. Accessed 2026-09-25.
  3. Cyber insurance coverage & products. Chubb; Cyber insurance coverage; First party coverage; Third-party liability coverage; Cyber crime (by endorsement); Products and services. Accessed 2026-09-25.

Updated . Answers describe typical policies, not your coverage; your policy wording decides what is covered. See the editorial policy or contact Spot with a correction and supporting source.

Let Spot Handle the Insurance Legwork.

Get help buying coverage and managing renewals, with less paperwork for your team. Start with a free consultation.

Talk to Spot