Does Cyber Insurance Cover Zero-Day Attacks?
A zero-day attack may trigger cyber coverage if it causes a covered event; the label alone does not establish coverage or an exclusion.
A zero-day attack exploits a software flaw before a fix is available or broadly deployed. A policy may respond based on its security-event definition even though the business could not patch the flaw in advance, but the answer depends on the contract and the facts. An endorsement aimed at neglected or known vulnerabilities may treat a newly disclosed flaw differently from an undisclosed one; Chubb describes one company-specific patching endorsement as an example.
Read the policy’s cyberattack and vulnerability definitions, any known-circumstance exclusion, and terms addressing failure to maintain security. Check whether patch timing is measured from public disclosure or notification by the insurer. Review the applicable limits, waiting periods, and incident-response requirements. Ask the carrier to explain the quoted wording for an unknown vulnerability and preserve evidence of when the flaw became known and what steps were taken.
Related Coverage
Providers That List This Coverage
Sources
- Cybersecurity for Small Business. Federal Trade Commission; Govern; Cyber Insurance; Common Cyberattacks: Phishing, Ransomware, Business Email Imposters; Vendor Security. Accessed 2026-09-25.
- CyberEdge specimen policy. AIG; General Terms §§4–6, PDF pp.3–6; Security and Privacy §§1–3, PDF pp.11, 14–18; Event Management §§1–2, PDF pp.19–20. Accessed 2026-09-25.
- Cyber insurance coverage & products. Chubb; Cyber insurance coverage; First party coverage; Third-party liability coverage; Cyber crime (by endorsement); Products and services. Accessed 2026-09-25.





