Cyber Insurance in South Africa: What Insurers Check
Cyber insurance in South Africa has hardened. Insurers now check your actual security controls before quoting, and paying the premium is no longer enough to guarantee a payout. If you want cover in 2026, you need multi-factor authentication, endpoint protection, working backups, and a written incident response plan. This guide explains what insurers check, why applications get declined, and how to position your business for both cover and claims.
Two things changed the market. First, claims volume: ransomware and business email compromise hit South African businesses of every size, and insurers paid out. Second, regulation: POPIA made data protection a legal duty, so a breach now carries regulatory consequences alongside the financial ones. The result is an insurance market that asks harder questions than it did three years ago. The Information Regulator has also grown more active in enforcement, which insurers track closely when pricing risk.
What insurers actually check before quoting
Application forms have shifted from box-ticking to evidence. Expect questions on these five areas, and expect follow-ups:
- Multi-factor authentication: on email, VPN, and administrative accounts. This is the single most common decline reason for SMEs. If MFA is not on, many insurers stop reading.
- Endpoint protection: managed antivirus or EDR on every laptop and server, with patching cadence documented. “We update when Windows prompts” is not an answer that gets coverage.
- Backups: the 3-2-1 pattern, meaning three copies, two media, one offline or offsite, with restore tests. Insurers increasingly ask for the date of your last successful restore test.
- Email security: filtering, DMARC implementation, and staff training on payment-change fraud, because business email compromise claims dominate South African loss statistics.
- Incident response: a written plan with named owners. Some policies now require an incident response retainer before they will quote.
Underwriters verify rather than trust. Larger risks can expect a security questionnaire validated by scan data or a third-party assessment. Misrepresenting controls on an application is worse than admitting gaps, because a false answer gives the insurer grounds to repudiate the claim after an incident.
What cyber insurance covers, and what it does not
A typical South African cyber policy bundles first-party and third-party cover. First-party means your own costs: incident response and forensics, data recovery, business interruption while systems are down, extortion negotiation costs, and notification expenses including regulator fines where insurable by law. Third-party means other people’s costs: claims from customers whose data leaked, defence costs, and settlements.
Common exclusions catch buyers off guard. Losses from unpatched, unsupported systems are often excluded. Prior known incidents that were never remediated are excluded. Some policies exclude state-backed attacks, and most exclude deliberate acts by insiders in senior positions. Read the exclusions section before the cover section, because the exclusions tell you what you are really buying. For the underlying security practices that keep claims low, our POPIA compliance checklist overlaps heavily with what insurers want to see.
Why claims get declined
Claims are declined for three main reasons, and all three are avoidable:
Control drift. You had MFA when you signed, someone removed it from a service account, and the attacker came in through that account. Policies increasingly require controls to be maintained throughout the policy period, not just demonstrated at application. This is the decline reason nobody argues with, because the policy language is explicit.
Late notification. Most policies require you to notify the insurer within days of discovering an incident, often 48 to 72 hours, and to use their panel providers. Calling your own IT company first and the insurer second is a claim risk. Put the insurer’s emergency number in your incident response plan, next to the POPIA 72-hour notification deadline we covered in the breach notification guide.
Misrepresentation. The application said “backups tested quarterly” and the last test was two years ago. Insurers investigate controls after an incident, and the gap between claimed and actual is where repudiation lives.
How much does cyber insurance cost in South Africa?
Indicative 2026 numbers for a small business with 10 to 50 staff and modest data holdings: R50,000 to R150,000 in annual premium for R1 million to R5 million in cover. Mid-sized businesses with more sensitive data pay more per rand of cover, and businesses with strong, verifiable controls pay less for the same limit. The range is wide because the controls are what move the number, which is the point worth taking to your board: security spend lowers your premium and your claim risk at the same time.
Premiums have also grown with the risk. Global reinsurance data reported by Marsh shows cyber rates rising through the mid-2020s before stabilising, and South African pricing follows global trends with a lag. Budget for annual increases rather than flat renewals.
Should your business buy cyber insurance?
Insurance transfers financial risk, it does not reduce technical risk. Both matter. My view, having assessed enough South African SMEs to see the pattern: buy the cover once your fundamentals are solid, because insurance on weak fundamentals is expensive and fragile at claim time. If MFA and backups and incident response are not yet in place, fix those first, then apply, and the same improvements that made you secure will make you cheaper to insure. If you want a view on where your business stands before approaching insurers, that is precisely what an ongoing security assessment process is for.
FAQ: cyber insurance in South Africa
What do cyber insurers check in South Africa?
Multi-factor authentication on email and admin accounts, managed endpoint protection with documented patching, tested backups held offline, email security including DMARC, and a written incident response plan. Larger risks also face security scans or third-party validation. Weak answers on MFA or backups commonly cause outright declines. Insurers verify controls at application and again after any incident.
How much does cyber insurance cost per year?
Small businesses typically pay R50,000 to R150,000 annually for R1-5 million in cover, scaling up with headcount, data sensitivity, and revenue. Verifiable security controls reduce premium, so businesses with strong MFA, backups, and incident response pay less for the same limits. Expect annual premium increases while global cyber claims stay high.
Does POPIA affect cyber insurance?
Yes, in both directions. Insurers ask about POPIA compliance because the law creates breach notification duties and regulator exposure that drive claims. A documented POPIA programme, including the 72-hour notification process, improves your application. Conversely, ignoring POPIA obligations weakens your position at claim time, since regulators and insurers both read the same incident timeline.
Can a cyber insurance claim be rejected?
Yes, commonly for three reasons: the security controls claimed on the application were not actually in place, the insurer was notified late or a non-panel provider was used first, or the loss fell under an exclusion such as unpatched unsupported systems. All three are avoidable with honest applications, a response plan that names the insurer, and maintained controls throughout the policy period.
Is cyber insurance worth it for an SME?
Yes, once fundamentals are in place. A single ransomware event can cost more than most SMEs carry in reserve, and insurance covers response, recovery, and liability that would otherwise come off the balance sheet. But insurance on weak security is poor value, because claims get declined exactly when needed. Fundamentals first, cover second.
Conclusion: insurable is just secure with paperwork
The controls insurers want are the controls that prevent incidents in the first place. That is not a coincidence, and it is good news for buyers: the work you do to qualify for cover is the same work that makes claims unlikely. Get MFA everywhere, test your backups, write the incident response plan, then buy the cover with confidence. Get in touch if you want a security posture review before your next renewal.







