藝術品保險懶人包

老闆必讀

One Fake Email Stopped the Business for Three Days: Cyber Insurance for Hong Kong SMEs

Read More

藝術品保險懶人包

老闆必讀

One Fake Email Stopped the Business for Three Days: Cyber Insurance for Hong Kong SMEs

Read More

藝術品保險懶人包

老闆必讀

One Fake Email Stopped the Business for Three Days: Cyber Insurance for Hong Kong SMEs

Read More

By Felix Kong|Licensed Insurance Agent
Looper Insurance Agency Limited (GA1034)
Published: 2026-08-24|Last updated: 2026-08-24

Cyber insurance covers the financial loss and third-party liability a business faces after a hacking incident, a ransomware attack, a social engineering fraud or a data breach. In Hong Kong, any company holding customer personal data falls under the Personal Data (Privacy) Ordinance (Cap. 486, "PDPO"), and a single breach can trigger notification, investigation and compensation exposure. Cyber cover is not compulsory here — but it is one of the few policies that genuinely funds your recovery rather than simply reimbursing a physical asset. Looper Insurance Agency Limited (GA1034), a licensed Hong Kong insurance agency, compares cyber insurance options for local SMEs across multiple insurers.

Table of Contents

  1. One fake email, three days of downtime

  2. Why attackers target small businesses

  3. What actually costs money in a cyber claim

  4. Three routes to cover in Hong Kong

  5. The claims-made trap

  6. Personal and family cyber plans

  7. Five questions to ask before you buy

  8. FAQ

1. One Fake Email, Three Days of Downtime

A trading client told us about this last month. A staff member received a WhatsApp message from "the boss" instructing a payment to a new supplier. Something felt slightly off — but the tone, the way she was addressed, even the boss's usual turn of phrase were all exactly right. So she paid. The money left the account. The next day it emerged that the boss had never sent anything.

This is not a film plot. It happens in Hong Kong every day. The industry name for it is business email compromise (BEC); where the attacker impersonates a superior, a family member or a supplier to induce a voluntary transfer, it is classified as social engineering fraud. The distinction matters, because the two are treated very differently inside a policy.

2. Why Attackers Target Small Businesses

Most owners ask the same question: "We're a small company — why would a hacker bother with us?"

The reality is the opposite. Attackers prefer smaller businesses, for a simple reason. A large corporate has an IT department, a firewall and someone paid to watch the logs. A small company may have one NAS, one shared password and a Windows machine that will be updated "tomorrow". Low cost of attack, high hit rate.

Cyber risk research published by international insurers indicates that more than half of all cyber attacks are aimed at small and medium-sized enterprises, and that SMEs — with limited internal resources — are far less able to recover on their own. When a large corporate is breached, it makes the news, pays, and carries on. When a small business is breached, it can be the end of the business. That asymmetry is precisely why cyber insurance exists in the SME market.

Underwriters look at the basics: firewall and anti-virus, regular patching, tiered user permissions, whether you collect and store customer credit card or financial data, and any prior data-protection claims. Answer those well and both your premium and your chance of acceptance improve materially.

3. What Actually Costs Money in a Cyber Claim

Most people assume a cyber incident comes down to a single decision: pay the ransom or don't. In practice the money is spent afterwards:

  • Business interruption. Systems are locked, so you cannot ship, invoice or collect. The loss accrues by the day.

  • Forensic investigation and data restoration. You need IT forensic specialists to establish how the attacker got in, how deep they went, whether a backdoor remains — and then to rebuild the data.

  • Privacy liability. Customer data that leaves your systems can be pursued by those customers, and the Privacy Commissioner for Personal Data (PCPD) may open an investigation.

  • Notification and crisis management. Contacting every affected customer, handling the press, instructing lawyers.

Cyber insurance is not really about how much ransom was paid. It is about what the whole recovery costs. Corporate cyber policies are built in two halves: first-party loss (business interruption, data and system restoration, incident response and forensics, cyber extortion) and third-party liability (privacy and confidentiality liability, network security liability, online media liability), plus regulatory investigation costs and crisis public relations. None of these sit inside a standard office policy or a general business package.

4. Three Routes to Cover in Hong Kong

4.1 Entry-level SME plans (tabled products)

Off-the-shelf products that bind quickly without extended underwriting. They suit most Hong Kong SMEs:

  • Limits of roughly HKD 2,000,000 to HKD 4,000,000

  • Annual premium from HKD 5,000 (smaller companies, lower limit)

  • Premium is banded by the company's total annual revenue — higher revenue, higher premium

  • Note: cyber extortion cover is often an optional add-on, not automatically included, and its limit usually sits inside the main policy limit rather than on top of it

  • Above HKD 4,000,000 of limit, or where annual revenue exceeds HKD 50,000,000, the risk moves to bespoke underwriting

Typical premium structure for tabled SME plans:

Total annual revenue (HKD)

Limit HKD 2,000,000

Limit HKD 4,000,000

Under 10 million

approx. 5,000

approx. 7,000

10m – 14.99m

approx. 8,000

approx. 12,500

15m – 19.99m

approx. 11,000

approx. 18,000

20m – 50m

approx. 19,000

approx. 30,000

(Indicative market levels for tabled SME plans. Add the Insurance Authority premium levy of 0.1%. All figures HKD; actual premium is set by the insurer's quotation.)

4.2 Bespoke corporate programmes

For larger, higher-risk or multi-jurisdictional businesses. Limits and structure are built to the risk, and market capacity runs high — programmes of up to US$100,000,000 in total capacity are available. These placements normally include a 24/7 incident response hotline, which matters more than it sounds: what you do in the first 48 hours usually determines how the claim ends.

4.3 Technology company packages

If you build software, run a fintech, operate cloud services or work in AI, the market offers combined packages that bundle Professional Indemnity, Cyber, Media Liability and Products Liability into one placement. That avoids buying four separate policies — and avoids the grey areas that open up between them.

Which route fits?


Tabled SME plan

Bespoke corporate

Technology package

Best for

General SMEs, retail, trading, professional firms

Large, high-risk, multi-jurisdiction

Software / fintech / cloud / AI

Limit

HKD 2,000,000 – 4,000,000

Flexible, very high available

Structured to the risk

Annual premium

From HKD 5,000

On quotation

On quotation

Underwriting

Fast, form-based

Proposal form plus questions

Proposal form

24/7 incident hotline

Usually not included

Yes

Yes

Cyber extortion

Usually an optional add-on

Generally included (where insurable)

Generally included

5. The Claims-Made Trap

Most corporate cyber policies are written on a claims-made basis: they respond only to claims first made against you during the policy period.

Two practical consequences:

  1. Anything you already knew about before inception is generally excluded. Do not wait for an incident and then buy cover — the proposal form asks directly whether you are aware of any circumstance that might give rise to a claim, and an inaccurate answer will be contested at claim stage.

  2. Notify the insurer in writing as soon as you become aware of a suspicious circumstance — not when the other side formally comes after you. Delay can prejudice the claim.

This is fundamentally different from the occurrence basis used by fire and household policies. An occurrence policy asks when the event happened; a claims-made policy asks when the claim was brought against you. So if a claims-made policy lapses for a year, incidents from that gap generally have no policy to respond to when someone comes after you later. Before you sign, ask your insurance agent one direct question: is this claims-made or occurrence?

6. Personal and Family Cyber Plans

Cyber risk is not only a corporate problem. Personal and family cyber security plans are available at around HKD 800 a year, covering cyber fraud, social engineering scams, cyber extortion, identity theft and cyberbullying, with an annual limit of about HKD 20,000 per insured person.

Benefit

Limit per incident (HKD)

Cyber fraud (account, bank card or e-wallet compromise)

5,000

Cyber social engineering (impersonation of family, supplier or authority)

5,000

Cyber extortion threat

20,000

Data or system restoration

10,000

Cyberbullying (monitoring and counselling costs)

10,000

Identity theft resolution costs

10,000

Legal costs and injunction applications

20,000

Annual limit per insured person

20,000

Two features that are easy to miss:

  • Some plans cover children under 18 free of charge, sharing the parent's annual limit

  • Insuring several family members together attracts a discount, typically 5% to 10%

Personal plans also carry meaningful exclusions — cryptocurrency losses, investment and romance scams, and activities of a business or professional nature are generally not covered. Read the policy wording before you buy.

To put it plainly: a personal plan protects you and your family; a corporate policy protects the business. They are not interchangeable. An owner holding a personal cyber plan has no cover for a loss suffered by the company.

7. Five Questions to Ask Before You Buy

  1. Is this claims-made or occurrence? (See section 5.)

  2. Is cyber extortion included or an add-on? If it is an add-on, does its limit sit inside the main limit or on top of it?

  3. How is business interruption calculated? When does the waiting period end, and for how long does the cover run?

  4. Are social engineering and fraudulent payment instructions covered? Voluntary transfers are usually treated as cyber crime cover — frequently an extension, not a standard insuring clause.

  5. Is there a 24/7 incident response hotline? Who exactly do you call at 3am?

FAQ

Q: We're a small company and not an IT business — do we really need cyber insurance?

A: If you hold customer personal data (names, phone numbers, addresses, payment details) or your operations depend on computer systems, you have exposure. SMEs are the preferred target precisely because their defences are weaker. Entry-level tabled plans start at around HKD 5,000 a year for a HKD 2,000,000 limit, which is affordable for most Hong Kong SMEs.

Q: A fake email from "the boss" told staff to pay a supplier. Is that covered?

A: It depends on the policy. That kind of voluntary transfer is not a classic hacking loss; it falls under social engineering fraud or cyber crime cover, which many cyber policies offer only as an optional extension. Ask about this benefit by name before binding — never assume it is automatic.

Q: Is the ransom itself insured?

A: Corporate policies generally include cyber extortion cover, but on tabled SME plans it is often an optional add-on, and its limit forms part of the overall policy limit rather than sitting on top of it. Some jurisdictions also restrict ransom payments. Actual recoverability is governed by the policy wording.

Q: What does it cost, and how is the premium calculated?

A: Tabled SME plans are banded by total annual revenue. A company with revenue under HKD 10 million taking a HKD 2,000,000 limit pays around HKD 5,000 a year; a company with revenue of HKD 20–50 million taking a HKD 4,000,000 limit pays around HKD 30,000. The Insurance Authority premium levy of 0.1% is added. Revenue above HKD 50 million, or limits above HKD 4,000,000, move to bespoke quotation.

Q: Is cyber insurance compulsory in Hong Kong?

A: No. There is no statutory requirement for a Hong Kong business to buy cyber insurance — it is a voluntary class. However, if you hold personal data you carry security obligations under the Personal Data (Privacy) Ordinance (Cap. 486), and the cost of notification, investigation, remediation and civil claims after a breach falls on you.

The Bottom Line

Cyber insurance will not stop you being hacked, any more than fire insurance stops a fire. What it decides is this: on the day it happens, are you scrambling alone, or do you have money and a team behind you to clean it up?

How much cover does a business your size, in your industry, actually need? We can work that out with you.

Related Articles

Free Quote

Looper Insurance Agency Limited (GA1034) provides free insurance quotations and comparisons.
Phone: 2633 6813
Email: cs@looperin.com
Website: www.looperin.com

Disclaimer: This article is for reference only and does not constitute insurance advice. Premiums and limits quoted reflect general market levels; actual coverage, limits, deductibles and exclusions are subject to policy terms and conditions. For professional insurance advice, please contact a licensed insurance agent.

Conclusion

Lorem ipsum

Felix Kong

Felix Kong

CEO

仲用緊十年前嘅方式買保險?

Looper 幫你格價,專家幫你把關。試過就知分別。

No credit card required.

仲用緊十年前嘅方式買保險?

Looper 幫你格價,專家幫你把關。試過就知分別。

No credit card required.

仲用緊十年前嘅方式買保險?

Looper 幫你格價,專家幫你把關。試過就知分別。

No credit card required.