Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. CISOs can obtain insurance for liability tied to their role, but protection is usually assembled from policies with different purposes—not assumed from a company’s cyber policy alone. AIG, for example, publishes a product called CISO Side A Liability Insurance. Whether it is available or fits a particular CISO depends on jurisdiction, underwriting and the actual policy wording.

What CISO liability insurance can cover

“Professional liability insurance” is an umbrella description, not a guarantee that one policy covers every claim connected to cybersecurity leadership. The main categories address different alleged harms:

Coverage What it generally addresses Key distinction
CISO Side A AIG describes its CISO Side A Liability Insurance as designed for alleged acts by corporate data officers and data departments in management and professional capacities. Side A is a form of directors-and-officers (D&O) protection for insured individuals when the company cannot indemnify them, subject to the policy terms.
D&O Defense costs, awards and settlements arising from an actual or alleged wrongful act by directors or officers. Travelers describes potential claims against an organization’s board and/or officers. Whether a CISO qualifies as an insured officer, and which claims are covered, depend on the policy’s definitions and exclusions.
Cyber Costs associated with a cyber event or breach, which may include forensic investigation, legal expenses and regulatory defense. This is how Travelers describes its CyberRisk coverage. Cyber coverage addresses incident-related costs; it is not automatically personal liability protection for an individual CISO.
Professional liability or E&O Errors, omissions or negligence in professional services. ARC describes miscellaneous professional liability as covering errors and omissions in professional services provided to others for a fee; Zurich also describes professional and technology-service exposures. Coverage depends on the services insured and the wording of the policy. It is particularly relevant to consultants who provide services to clients.

These categories can overlap in a claim, but they are not interchangeable. Aon’s July 25, 2024 webinar on CISO liability specifically addresses how D&O and cyber policies may work together and where D&O coverage may be limited.

Does an employer’s cyber policy protect the CISO personally?

Not necessarily. A cyber policy may pay covered expenses arising from a cyber incident without providing the CISO with personal defense or indemnity for every lawsuit alleging a wrongful management decision. Conversely, a D&O policy may address allegations against an officer without functioning as the company’s breach-response policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For an employed CISO, ask the company or its broker to confirm whether the policy expressly includes the CISO as an insured person, in which capacities, and for which claim types. Also ask whether Side A protection applies if the company cannot indemnify the individual. Do not rely on a policy’s title or a general statement that the company “has cyber insurance.”

What independent CISOs and vCISOs should consider

An independent CISO or vCISO who provides security services to clients for a fee should evaluate professional liability or errors-and-omissions coverage, including technology E&O where appropriate. The central question is whether the policy covers the actual contracted services and allegations that could arise from them—not simply whether it is marketed to technology businesses.

Markel says its E&O coverage serves consultants and service organizations, while CFC lists professional liability and technology E&O products. Those product categories do not establish that a particular program is available in a given location or covers a particular engagement; the quotation and policy form must be checked.

How to assess a policy or coordinated insurance program

Ask a licensed commercial insurance broker to review the policy forms and proposed coverage together. These are the material questions to resolve before relying on a policy:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Who is insured, and in what capacity? Check whether the CISO is named or included in the definition of insured persons, and whether the role is covered as an officer, employee, consultant or professional-services provider.
  • Which coverage is being offered? Identify whether it is Side A, entity-inclusive D&O, cyber, E&O, or a coordinated combination. Confirm how the policies allocate a claim that implicates more than one layer.
  • How are defense costs handled? Review whether costs are advanced, whether they reduce the available limit, and who may select or approve defense counsel.
  • What claims and investigations are addressed? Ask specifically about regulatory investigations, shareholder claims and other allegations relevant to the insured role; do not assume their treatment from a product description.
  • What exclusions and severability terms apply? Review exclusions, insured-versus-insured wording, and whether one insured person’s knowledge or conduct can affect another’s coverage.
  • How do timing and reporting rules work? Check prior-acts treatment, claims-made requirements, reporting deadlines and any applicable notice provisions.
  • What are the financial and geographic limits? Confirm limits, retentions, territory and any differences between the proposed coverage and the company’s existing policies.

Product pages explain broad insurance categories; only the policy language and a broker’s jurisdiction-specific quotation establish the actual protection. AIG notes that its products may not be available in all jurisdictions and are subject to the policy language.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Availability, limits and price

The existence of AIG’s named CISO Side A product shows that CISO-specific coverage is offered, but it does not mean every CISO can buy it directly or qualify. Availability and scope vary with country, underwriting, employer structure, policy form and exclusions. The sources cited here do not establish a generally applicable premium, recommended limit or CISO claim-frequency figure, so those should not be inferred without a broker’s quote for the relevant jurisdiction and risk.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.