Arranging cyber insurance starts with assessing the company’s risk profile

Author: Lauri Treima Time: 01.08.2026

Arranging cyber insurance starts with assessing the company’s risk profile

Cyber insurance helps limit a company’s financial losses after a cyberattack, computer fraud or a data security breach has occurred. Insurance coverage may include the restoration of data and IT systems, malware removal, the involvement of external experts, losses resulting from unauthorised payments, and third-party claims. Business interruption losses may also be included as additional coverage.

Insurance coverage is not identical for every company. The potential scale of a loss depends on the company’s industry, turnover, IT environment, the nature of the data it processes, its dependence on digital services and the security measures already in place. The company’s risk profile is therefore assessed before an offer is prepared. This assessment is used to determine the insured risks, sum insured, deductible, additional coverage and insurance premium.

Cyber insurance is arranged in four stages

1. Submitting a request for an offer

The process begins by completing the form on the Primend cyber insurance website. The company provides its name, registration number and contact details, together with an overview of its existing cybersecurity solutions and the reason for requesting an offer.

The website form is an initial contact form rather than a final insurance application. Based on the information submitted, the Primend team contacts the company and explains the next steps required to prepare an individual offer.

2. Completing the cyber risk questionnaire

The insurer requires more detailed information than is collected through the initial contact form. The company therefore completes a cyber risk questionnaire, which is the principal document used to prepare an individual offer.

The questionnaire covers the company’s industry, turnover, countries of operation, and the number of employees and IT users. The company must also indicate whether it is subject to the requirements of the NIS2 Directive or the DORA Regulation.

The company’s technical environment must also be described, including whether it uses cloud solutions, on-premises servers or both, and whether it processes personal, financial or sensitive data. The questionnaire also covers the use of firewalls, antivirus solutions, regular updates, multifactor authentication, access controls and data backups.

The organisational controls section addresses employee cybersecurity training, internal security rules, payment-detail verification and the use of the four-eyes principle when approving payments. The company must also disclose any cyber incidents that have occurred during the previous three years and any known material IT security weaknesses.

The company’s representative confirms the accuracy of the submitted information by signing the questionnaire. The information must be complete and accurate, as incorrect or incomplete information may affect the amount of compensation or give the insurer grounds to decline the claim.

Before entering into the contract, the company must also review the insurance product information document, the cyber insurance terms and conditions, and the insurance agent information document. The customer does not complete these documents. They explain the scope of coverage, exclusions, the policyholder’s obligations, and the respective roles of the insurer and the intermediary.

3. Assessing the risk profile

The insurer analyses the information provided in the questionnaire and assesses the company’s potential loss exposure and the adequacy of its existing controls. Where necessary, the insurer may request additional documents, data or explanations.

The assessment considers both technical and organisational controls. The insurance terms require the company to use a firewall and antivirus software, update its systems regularly, create data backups, store backups separately from its primary systems, train employees, and verify the legitimacy of transactions and the accuracy of payment details.

If a material security measure is missing and its absence is directly connected to the loss, this may affect the payment of compensation. The insurer may also reduce or decline compensation if the company has provided incomplete information or has not taken reasonable measures to prevent or limit the loss.

4. Preparing the individual offer and policy

Once the risk profile has been assessed, an individual offer is prepared for the company. The insurance policy specifies:

  • the insured risks;
  • the sum insured;
  • the deductible;
  • selected additional coverage;
  • the territorial scope of coverage;
  • the insurance premium and payment terms.

Coverage begins on the date and at the time specified in the policy, provided that the premium or its first instalment has been paid in accordance with the insurance contract.

The sum insured should reflect the company’s potential total loss

Primend cyber insurance does not have a single maximum sum insured that applies to every company. The sum is agreed individually and recorded in the insurance policy together with the deductible, insured risks, additional coverage and territorial scope.

The sum insured should reflect the company’s potential total loss, not only the cost of restoring its IT systems. The financial impact may include external expert fees, data restoration, equipment repair or replacement, direct losses resulting from fraud, legal expenses, third-party claims and business interruption.

If the policy includes additional business interruption coverage, the insurance may cover a reduction in gross profit, continuing fixed costs, lost rental income, and reasonable expenses required to restore operations and manage crisis communication. This coverage applies only if it has been specifically included in the policy and the business interruption was caused directly by an insured cyber risk.

Claims paid during the insurance period reduce the remaining sum insured. If the full sum allocated to a specific risk has been paid, coverage for that risk ends.

Primend helps assess the company’s readiness

Primend helps the company collect the technical information required to complete the cyber risk questionnaire and assess whether the controls relevant to insurance are in place.

If the assessment identifies gaps in access protection, data backups, security monitoring, system updates or employee cybersecurity awareness, Primend can help address these areas. Primend’s services include information security management, security monitoring, Microsoft 365 backup, automated 24/7 security monitoring through Primend Shield, and employee cybersecurity awareness development.

The cooperation model between Primend and Compensa connects the company’s technical cybersecurity measures with its insurable financial exposure. Primend supports the company in assessing its technical readiness and compiling the required information. The insurer assesses the risk and determines the final terms of the insurance coverage.

The insurer is Compensa Vienna Insurance Group ADB Latvian Branch. The insurance intermediary is Primend SIA. Primend OÜ in Estonia and UAB Primend in Lithuania perform administrative functions related to document processing, customer support and complaint handling.

To begin the assessment of your company’s risk profile and request an offer, submit an enquiry through the Primend cyber insurance website.

Contact us