By Felix Kong|Licensed Insurance Agent
Looper Insurance Agency Limited (GA1034)
Published: 2026-08-24|Last updated: 2026-08-24
Cyber insurance covers the financial loss and third-party liability a business faces after a hacking incident, a ransomware attack, a social engineering fraud or a data breach. In Hong Kong, any company holding customer personal data falls under the Personal Data (Privacy) Ordinance (Cap. 486, "PDPO"), and a single breach can trigger notification, investigation and compensation exposure. Cyber cover is not compulsory here — but it is one of the few policies that genuinely funds your recovery rather than simply reimbursing a physical asset. Looper Insurance Agency Limited (GA1034), a licensed Hong Kong insurance agency, compares cyber insurance options for local SMEs across multiple insurers.
Table of Contents
One fake email, three days of downtime
Why attackers target small businesses
What actually costs money in a cyber claim
Three routes to cover in Hong Kong
The claims-made trap
Personal and family cyber plans
Five questions to ask before you buy
FAQ
1. One Fake Email, Three Days of Downtime
A trading client told us about this last month. A staff member received a WhatsApp message from "the boss" instructing a payment to a new supplier. Something felt slightly off — but the tone, the way she was addressed, even the boss's usual turn of phrase were all exactly right. So she paid. The money left the account. The next day it emerged that the boss had never sent anything.
This is not a film plot. It happens in Hong Kong every day. The industry name for it is business email compromise (BEC); where the attacker impersonates a superior, a family member or a supplier to induce a voluntary transfer, it is classified as social engineering fraud. The distinction matters, because the two are treated very differently inside a policy.
2. Why Attackers Target Small Businesses
Most owners ask the same question: "We're a small company — why would a hacker bother with us?"
The reality is the opposite. Attackers prefer smaller businesses, for a simple reason. A large corporate has an IT department, a firewall and someone paid to watch the logs. A small company may have one NAS, one shared password and a Windows machine that will be updated "tomorrow". Low cost of attack, high hit rate.
Cyber risk research published by international insurers indicates that more than half of all cyber attacks are aimed at small and medium-sized enterprises, and that SMEs — with limited internal resources — are far less able to recover on their own. When a large corporate is breached, it makes the news, pays, and carries on. When a small business is breached, it can be the end of the business. That asymmetry is precisely why cyber insurance exists in the SME market.
Underwriters look at the basics: firewall and anti-virus, regular patching, tiered user permissions, whether you collect and store customer credit card or financial data, and any prior data-protection claims. Answer those well and both your premium and your chance of acceptance improve materially.
3. What Actually Costs Money in a Cyber Claim
Most people assume a cyber incident comes down to a single decision: pay the ransom or don't. In practice the money is spent afterwards:
Business interruption. Systems are locked, so you cannot ship, invoice or collect. The loss accrues by the day.
Forensic investigation and data restoration. You need IT forensic specialists to establish how the attacker got in, how deep they went, whether a backdoor remains — and then to rebuild the data.
Privacy liability. Customer data that leaves your systems can be pursued by those customers, and the Privacy Commissioner for Personal Data (PCPD) may open an investigation.
Notification and crisis management. Contacting every affected customer, handling the press, instructing lawyers.
Cyber insurance is not really about how much ransom was paid. It is about what the whole recovery costs. Corporate cyber policies are built in two halves: first-party loss (business interruption, data and system restoration, incident response and forensics, cyber extortion) and third-party liability (privacy and confidentiality liability, network security liability, online media liability), plus regulatory investigation costs and crisis public relations. None of these sit inside a standard office policy or a general business package.
4. Three Routes to Cover in Hong Kong
4.1 Entry-level SME plans (tabled products)
Off-the-shelf products that bind quickly without extended underwriting. They suit most Hong Kong SMEs:
Limits of roughly HKD 2,000,000 to HKD 4,000,000
Annual premium from HKD 5,000 (smaller companies, lower limit)
Premium is banded by the company's total annual revenue — higher revenue, higher premium
Note: cyber extortion cover is often an optional add-on, not automatically included, and its limit usually sits inside the main policy limit rather than on top of it
Above HKD 4,000,000 of limit, or where annual revenue exceeds HKD 50,000,000, the risk moves to bespoke underwriting
Typical premium structure for tabled SME plans:
Total annual revenue (HKD) | Limit HKD 2,000,000 | Limit HKD 4,000,000 |
|---|---|---|
Under 10 million | approx. 5,000 | approx. 7,000 |
10m – 14.99m | approx. 8,000 | approx. 12,500 |
15m – 19.99m | approx. 11,000 | approx. 18,000 |
20m – 50m | approx. 19,000 | approx. 30,000 |
(Indicative market levels for tabled SME plans. Add the Insurance Authority premium levy of 0.1%. All figures HKD; actual premium is set by the insurer's quotation.)
4.2 Bespoke corporate programmes
For larger, higher-risk or multi-jurisdictional businesses. Limits and structure are built to the risk, and market capacity runs high — programmes of up to US$100,000,000 in total capacity are available. These placements normally include a 24/7 incident response hotline, which matters more than it sounds: what you do in the first 48 hours usually determines how the claim ends.
4.3 Technology company packages
If you build software, run a fintech, operate cloud services or work in AI, the market offers combined packages that bundle Professional Indemnity, Cyber, Media Liability and Products Liability into one placement. That avoids buying four separate policies — and avoids the grey areas that open up between them.
Which route fits?
Tabled SME plan | Bespoke corporate | Technology package | |
|---|---|---|---|
Best for | General SMEs, retail, trading, professional firms | Large, high-risk, multi-jurisdiction | Software / fintech / cloud / AI |
Limit | HKD 2,000,000 – 4,000,000 | Flexible, very high available | Structured to the risk |
Annual premium | From HKD 5,000 | On quotation | On quotation |
Underwriting | Fast, form-based | Proposal form plus questions | Proposal form |
24/7 incident hotline | Usually not included | Yes | Yes |
Cyber extortion | Usually an optional add-on | Generally included (where insurable) | Generally included |
5. The Claims-Made Trap
Most corporate cyber policies are written on a claims-made basis: they respond only to claims first made against you during the policy period.
Two practical consequences:
Anything you already knew about before inception is generally excluded. Do not wait for an incident and then buy cover — the proposal form asks directly whether you are aware of any circumstance that might give rise to a claim, and an inaccurate answer will be contested at claim stage.
Notify the insurer in writing as soon as you become aware of a suspicious circumstance — not when the other side formally comes after you. Delay can prejudice the claim.
This is fundamentally different from the occurrence basis used by fire and household policies. An occurrence policy asks when the event happened; a claims-made policy asks when the claim was brought against you. So if a claims-made policy lapses for a year, incidents from that gap generally have no policy to respond to when someone comes after you later. Before you sign, ask your insurance agent one direct question: is this claims-made or occurrence?
6. Personal and Family Cyber Plans
Cyber risk is not only a corporate problem. Personal and family cyber security plans are available at around HKD 800 a year, covering cyber fraud, social engineering scams, cyber extortion, identity theft and cyberbullying, with an annual limit of about HKD 20,000 per insured person.
Benefit | Limit per incident (HKD) |
|---|---|
Cyber fraud (account, bank card or e-wallet compromise) | 5,000 |
Cyber social engineering (impersonation of family, supplier or authority) | 5,000 |
Cyber extortion threat | 20,000 |
Data or system restoration | 10,000 |
Cyberbullying (monitoring and counselling costs) | 10,000 |
Identity theft resolution costs | 10,000 |
Legal costs and injunction applications | 20,000 |
Annual limit per insured person | 20,000 |
Two features that are easy to miss:
Some plans cover children under 18 free of charge, sharing the parent's annual limit
Insuring several family members together attracts a discount, typically 5% to 10%
Personal plans also carry meaningful exclusions — cryptocurrency losses, investment and romance scams, and activities of a business or professional nature are generally not covered. Read the policy wording before you buy.
To put it plainly: a personal plan protects you and your family; a corporate policy protects the business. They are not interchangeable. An owner holding a personal cyber plan has no cover for a loss suffered by the company.
7. Five Questions to Ask Before You Buy
Is this claims-made or occurrence? (See section 5.)
Is cyber extortion included or an add-on? If it is an add-on, does its limit sit inside the main limit or on top of it?
How is business interruption calculated? When does the waiting period end, and for how long does the cover run?
Are social engineering and fraudulent payment instructions covered? Voluntary transfers are usually treated as cyber crime cover — frequently an extension, not a standard insuring clause.
Is there a 24/7 incident response hotline? Who exactly do you call at 3am?
FAQ
Q: We're a small company and not an IT business — do we really need cyber insurance?
A: If you hold customer personal data (names, phone numbers, addresses, payment details) or your operations depend on computer systems, you have exposure. SMEs are the preferred target precisely because their defences are weaker. Entry-level tabled plans start at around HKD 5,000 a year for a HKD 2,000,000 limit, which is affordable for most Hong Kong SMEs.
Q: A fake email from "the boss" told staff to pay a supplier. Is that covered?
A: It depends on the policy. That kind of voluntary transfer is not a classic hacking loss; it falls under social engineering fraud or cyber crime cover, which many cyber policies offer only as an optional extension. Ask about this benefit by name before binding — never assume it is automatic.
Q: Is the ransom itself insured?
A: Corporate policies generally include cyber extortion cover, but on tabled SME plans it is often an optional add-on, and its limit forms part of the overall policy limit rather than sitting on top of it. Some jurisdictions also restrict ransom payments. Actual recoverability is governed by the policy wording.
Q: What does it cost, and how is the premium calculated?
A: Tabled SME plans are banded by total annual revenue. A company with revenue under HKD 10 million taking a HKD 2,000,000 limit pays around HKD 5,000 a year; a company with revenue of HKD 20–50 million taking a HKD 4,000,000 limit pays around HKD 30,000. The Insurance Authority premium levy of 0.1% is added. Revenue above HKD 50 million, or limits above HKD 4,000,000, move to bespoke quotation.
Q: Is cyber insurance compulsory in Hong Kong?
A: No. There is no statutory requirement for a Hong Kong business to buy cyber insurance — it is a voluntary class. However, if you hold personal data you carry security obligations under the Personal Data (Privacy) Ordinance (Cap. 486), and the cost of notification, investigation, remediation and civil claims after a breach falls on you.
The Bottom Line
Cyber insurance will not stop you being hacked, any more than fire insurance stops a fire. What it decides is this: on the day it happens, are you scrambling alone, or do you have money and a team behind you to clean it up?
How much cover does a business your size, in your industry, actually need? We can work that out with you.
Related Articles
Free Quote
Looper Insurance Agency Limited (GA1034) provides free insurance quotations and comparisons.
Phone: 2633 6813
Email: cs@looperin.com
Website: www.looperin.com
Disclaimer: This article is for reference only and does not constitute insurance advice. Premiums and limits quoted reflect general market levels; actual coverage, limits, deductibles and exclusions are subject to policy terms and conditions. For professional insurance advice, please contact a licensed insurance agent.
Conclusion
Lorem ipsum

Felix Kong
CEO
繼續閱讀




