[nonimo]
EN
Download

Cyber insurance in Ireland: what it covers and how to compare

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Your renewal pack lands, or a client asks you to evidence cyber cover before it will sign, and you go looking for what cyber insurance in Ireland actually does. What you find is broker landing pages that list the same nine bullet points, and a layer of comparison sites offering to rank plans they do not name.

So I went and read the documents instead. On 16 September 2026 I opened every public Irish cyber document I could find: three full policy wordings published for the Republic of Ireland, an Irish proposal form, an Irish product factsheet, three insurer services sheets, one wording that turned out to be a scan, and the commercial insurance pages of two of the most familiar names in Irish general insurance.

Two things are worth knowing before the detail. The first is that a cyber policy here is two halves, your own costs and your liability to others, and the interesting part of each is what it refuses to promise.

The second is that Ireland is not the United Kingdom, and the difference is an Act of 2019 that treats a company turning over €3 million or less as a consumer. That changes what happens if you answer a question on the form wrong, and it is not what the form you sign will tell you. If the form is already in front of you, the questions about AI on it have their own guide.

What it costs a year, before anything else

There is no Irish rate card, but one insurer publishes where it thinks the bands sit and a broker publishes an estimate. Between the two you can place yourself before you read another word. The caveats, which matter more than the numbers themselves, come further down.

BusinessWhat is actually publishedOur estimate, a year
Small, in AIG’s own wordsan annual CyberEdge premium of €899 or less is what AIG treats as small for its services programme. AIG, IRL0566AR 0525 v1€400 to €900
A smaller Irish SME, in a broker’s estimate€1,500 to €3,000 a year. LHK Group, 22 May 2026€900 to €3,000
Midsize, in AIG’s own words€900 to €4,999 is AIG’s tier II, and €5,000 or more its tier III. Same sheets, 0525 v1€3,000 to €5,000

The middle column is quoted from the source named in it, and the last column is our own estimate: not a quote, and not an insurer’s figure.

Where it comes from: it places the published prices on the three bands that two independent European sources draw in the same place, Amrae’s LUCY study of 20,996 policies for 2025 (average premiums of €645, €1,600 and €5,000 by company size) and AIG’s own Irish service tiers (€899 or less, €900 to €4,999, €5,000 or more). Your premium comes out of your proposal form, not out of this table.

What cyber insurance covers in Ireland, in the words of the policies

Every Irish wording I could read splits the same way. One set of insuring clauses pays your costs. Another set pays what you owe somebody else. Brokers call these “first party” and “third party”, and none of the three Irish broker pages I read explained which of the two a given bullet point belonged to.

the halfwhat it paysthe clause names to look for
First partyyour own costsincident response, legal and regulatory costs, digital data recovery, business interruption, extortion
Third partywhat you owe othersprivacy and network security liability, media liability, regulatory proceedings, payment card penalties

Sources: the insuring clauses of the CFC and Travelers Republic of Ireland wordings, and the Chubb Cyber ERM coverage synopsis.

The two current wordings, and the ones quoted most below, are the Travelers International CyberRisk Insurance for Ireland, reference TRV2742 08.25, and the CFC Cyber Proactive Response Republic of Ireland document, version 4.0, dated June 2025. Both are published on the policy documents page of an Irish broker, which is the only reason a member of the public can read either.

The half that covers your own costs, and the panel you have to use

The CFC wording opens with incident response costs: the 24/7 line, a claims manager to coordinate, initial advice including threat intelligence, and initial remote support. Then legal and regulatory costs, data restoration, business interruption, extortion, and remediation after a breach.

That last one is unusual enough to name. After a covered incident CFC will pay for an information security risk assessment, a gap analysis, an information security document set and an awareness training session, all of it framed as mitigating the next incident rather than fixing this one.

What none of the broker pages mentions is the string attached. Under the CFC conditions, costs you pay to outside firms in the window where you do not need the insurer’s consent have to be with a company on its approved claims panel. You do not simply call your own forensics people and send the bill.

The half that covers others, and the fine nobody will promise

The liability clauses are where the careful language lives. Travelers covers regulatory fines and penalties, and then defines them as civil fines and civil monetary penalties imposed in a regulatory proceeding, “but only to the extent they are insurable”. CFC reaches the same place from the other side, excluding fines, penalties and civil or criminal sanctions “unless insurable by law”.

Read that twice. It defers to the law instead of giving you cover, and it is the first sentence I would look for if I were comparing two Irish quotes. Whether a fine from the Data Protection Commission is insurable at Irish law is the question a small firm is actually buying the policy to answer, and the policy sends the question back.

Here is the measurement that makes the point. I searched both wordings for GDPR, for General Data Protection, for Data Protection Commission and for DPC. All four return zero hits in both documents, while control searches for regulatory fines, insurable, privacy breach and Ireland return hits in each. The Irish regulator that would impose the fine is not named anywhere in either policy.

The one page document you are entitled to and have probably never seen

There is a third document in this story, and it is the shortest. Regulation 34(6) of the Insurance Distribution Regulations requires a “standardised insurance product information document” for a non-life product. Regulation 34(9) says what has to be in it.

Four of the required items are the ones a comparison actually turns on: “a summary of the excluded risks”, “the main exclusions specifying where claims cannot be made”, “the obligations at the commencement of the contract” and “the obligations during the term of the contract”.

Those last two are the continuing conditions, the MFA and the backups, on one page, in the manufacturer’s own words. Ask for it by name on every quote and most of the work below is done for you.

The second clock of 72 hours, which is not the regulator’s

The 72 hours in Article 33 of the GDPR is the most familiar clock in this area. Less well known is that the CFC wording has 72 hours of its own, doing something completely different.

the clockwhat it countswhat happens at the end
Article 33 GDPRfrom becoming aware of the breachyou should have notified the DPC. Covered in our guide to the first hour
CFC conditionsfrom you discovering the cyber eventcosts need the claims manager’s prior written consent

Sources: CFC Cyber Proactive Response v4.0, Republic of Ireland, conditions; Article 33 of the GDPR.

They start at slightly different moments and they end in completely different places. If the policy’s spending window closes on the same afternoon you are drafting the notification, you want to know that in advance, not in the middle of it.

Ireland is not the United Kingdom, and the difference is an Act of 2019

British cyber insurance content is excellent and it is everywhere, and on this point it will get you into trouble. The United Kingdom runs on the Insurance Act 2015 and its duty of fair presentation. Ireland does not.

A company under €3 million turnover is a consumer here

The Consumer Insurance Contracts Act 2019 takes its definition of consumer from section 2(1) of the Financial Services and Pensions Ombudsman Act 2017. That definition covers, among others, a natural person not acting in the course of business, and a sole trader, partnership or charity under €3 million of annual turnover.

Then it goes further, in a part that rarely gets quoted. It also covers “an incorporated body that had an annual turnover in its previous financial year of €3 million or less”, provided it is not part of a group above that figure.

So a limited company is a consumer for insurance purposes in Ireland if it is small enough. Most solicitors’ firms, accountancy practices, clinics and agencies in the State are inside that line, and nothing in the paperwork will draw it to their attention. These are exactly the organisations that buy cyber cover because a client asked for it.

Section 8 ended the duty to volunteer information

Section 8(1) says the duties it creates “replace, at the pre-contractual stage of a contract of insurance, the principle of utmost good faith (uberrima fides) and any duty of disclosure of a consumer (including any duty on the consumer to volunteer information)”.

Section 8(2) then draws the line: the duty “is confined to providing responses to questions asked by the insurer, and the consumer shall not be under any duty to volunteer any information over and above that required by such questions”. Section 8(3) puts the matching obligation on the insurer, which “shall be under a duty to ask specific questions, on paper or on another durable medium, and shall not use general questions”.

Three more subsections matter when a claim goes wrong. Section 8(5)(b) says an ambiguous question is read in the way most favourable to you. Section 8(6) lets the insurer use its remedies only where the non-disclosure was “an effective cause” of it writing the risk on those terms. And section 8(10)(a) deems the insurer to have waived the point entirely where it “fails to investigate an absent or obviously incomplete answer”.

The declaration on an Irish form that asks for the opposite

Chubb publishes a short cyber proposal form on its Irish site. The reference code is ROI0268-MD 09/22, it asks for annual turnover in euro, and above the signature line it says this:

“I/we declare that I/we have made a fair presentation of the risk, by disclosing all material matters which I/we know or ought to know or, failing that, by giving the Insurer sufficient information to put a prudent insurer on notice that it needs to make further enquiries in order to reveal material circumstances.”

That is a duty to volunteer, and it is the British standard. I am not going to tell you the clause is void, because that is a decision for a court and section 26 of the 2019 Act is discretionary anyway. What I will tell you is that the sentence and section 8(2) point in opposite directions, and that if you are under €3 million the statute is on your side of the argument.

the questionwhat the Irish Act sayswhat a form in the British style assumes
Must you volunteer?No, if you are a consumer. Section 8(2)Yes. Fair presentation
Who has to ask precisely?The insurer. Section 8(3), no general questionsYou, to anticipate
Ambiguous wording?Read in your favour. Section 8(5)(b)Argued both ways
A question only half answered?Waived, if the insurer did not investigate. Section 8(10)(a)Held against you

Source: Consumer Insurance Contracts Act 2019, sections 8 and 26, irishstatutebook.ie.

There is a practical version of all this. Keep the completed form. Section 10(1) obliges the insurer to give you a copy on paper or another durable medium within a reasonable time of concluding the contract, and the copy is what any later argument will turn on. What to write in the AI section of it is set out in a guide to those questions.

One subsection of the Act waited six years

The Act did not arrive in one piece, and one subsection arrived this year. Section 18(4) was commenced on 13 May 2026 by S.I. No. 203 of 2026, signed by the Minister for Finance, Simon Harris, on 12 May. It had been sitting uncommenced since the Act passed in December 2019.

what commencedwhenincludes
most of the Act1 September 2020sections 15 to 17, 19 to 27
the disclosure regime1 September 2021sections 8, 9, 12 and 14(1) to (5)
section 18(4)13 May 2026the narrowed exclusion for criminal or intentional acts

Source: Consumer Insurance Contracts Act 2019 commencement table, irishstatutebook.ie, updated to 14 September 2026.

What section 18(4) does is stop an exclusion for loss or damage to property caused by a criminal or intentional act from reaching people who did not commit, abet or consent to it. Whether the loss a cyber policy pays to you counts as property for that purpose is not settled, and I am not going to pretend it is. The date and the direction are what is certain.

The MFA condition, and why it behaves differently in Ireland

Cyber policies are full of conditions you have to keep satisfying: multifactor authentication stays on, backups stay offline, patches get applied. Some of them are controls your IT provider runs rather than you. What happens when one of them lapses is decided by statute rather than by the policy, and in Ireland the statute is the 2019 Act.

Section 19 of the 2019 Act replaced the whole law of insurance warranties for a consumer contract, and it did three separate things. Two of them are good news for a small firm that let a control lapse, and the third stops an insurer building the old rule back in by another name.

Section 19 turned warranties into suspensive conditions

Section 19(4) takes any term “that imposes a continuing restrictive condition on the consumer during the course of the contract” and treats it as suspensive, so that “if the breach has been remedied by the time a loss has occurred, the insurer shall (in the absence of any other defence to the claim) be obliged to pay”.

The breach that had nothing to do with the loss

Section 19(5) is the one to write down. It says subsection (4) “does not suspend the liability of the insurer if the fact that the breach has occurred has not increased, in the circumstances concerned, the risk of a loss that has occurred”.

the clause in your policywhat section 19 does to it, for a consumer
a basis of contract clauseinvalid. Section 19(3)
a condition you must keep satisfyingsuspensive, and cover returns once you remedy it. Section 19(4)
a lapse unrelated to the loss that happenedno suspension at all. Section 19(5)

Source: Consumer Insurance Contracts Act 2019, section 19, irishstatutebook.ie.

In plain terms: if MFA was off on a dormant admin account in a branch office, and the loss came through an invoice fraud that had nothing to do with that account, the statute says the lapse does not suspend your cover.

Britain has a comparable provision at section 11 of the Insurance Act 2015, headed “Terms not relevant to the actual loss”, so this is not an Irish invention and I am not going to sell it as one.

What is Irish is who it reaches. Section 19 protects a consumer as the 2019 Act defines one, which is a company under €3 million and not only a person. That is the line worth checking before you accept a wording written for another market.

What an Irish insurer asks before it quotes

The Chubb Irish short form is four pages, and it is the clearest public statement of what an underwriter wants an Irish SME to have. There are eight numbered questions. Four of them are about controls, one is about your history, and the rest are about who you are.

Read it before you need it. Several of the things it asks for cost nothing but an afternoon, including the one that is not a technical control at all: a written rule your staff have read. On the CSO’s numbers, voluntary security training reached 33.2% of Irish enterprises in 2024. Compulsory training reached 24.6%, and 34.7% wrote it into the contract of employment.

The four controls, and the one question about your past

what it asksthe form’s own wordswhere it sits
Remote access“is Multi-Factor Authentication required for all remote network access capability?”question 1a, before anything else on the form
Backups“immutable or Write Once Read Many (WORM) protections”, offline or cut off from the network, privileged accounts, MFAquestion 5, with five ways to answer it
EndpointsEDR, XDR or MDR among six options, or “none of the protections listed”question 6
Email“phishing simulations or other training for employees on at least an annual basis”question 7, the only one about people
Historyany incident, breach or complaint in the last three yearsquestion 8, the only one about the past

Source: Chubb Cyber Enterprise Risk Management Short Proposal Form, ROI0268-MD 09/22, chubb.com.

Notice what each of those questions gives you back. A quote is a free audit. If you cannot tick the backup line, you have learned what to fix this quarter for less than the price of a consultant, and the same reasoning applies to the written rules the form asks you to attach, which is what our policy template is for.

What “none of the protections listed” costs you

Three of the questions offer that option as a tick box, and taking it is not a refusal. The form says so itself: completing it “does not bind Chubb, or the prospective insured, to conclude an insurance policy”, and “further information, including a full proposal form, may be required”. A gap is an invitation to more questions. The flattering answer, by contrast, is the one that costs you the claim.

33.2%voluntary ICT security training
24.6%compulsory
34.7%written into the contract of employment
Irish enterprises, 2024. CSO, Information Society Statistics Enterprises 2024, released 14 February 2025. Categories overlap

The training line is the one where an Irish firm can most cheaply say yes, and the national picture says three quarters do not. That is a gap a quote will find and an afternoon will close.

What the Irish market actually sells, and who is behind it

Copying British content goes badly wrong here. The names on the shelf are not the same, and neither is the way you buy.

Two household names that do not list a cyber product

Aviva Ireland’s commercial insurance index lists nine products on 16 September 2026, from farm to apartment blocks. Cyber is not among them. Allianz Ireland’s business insurance page returns zero matches for the word cyber and says, twice, that “our commercial products are not available on a Direct basis”.

That is not a criticism of either company, and neither statement means the cover is unavailable through them. What the two pages do tell you is the route. Allianz says its commercial products are not sold direct, Aviva does not list cyber at all, and there is no Irish equivalent of the direct online cyber purchase that British content assumes.

productthe public Irish documentwho carries itbuy direct?
Travelers International CyberRiskfull wording, TRV2742 08.25Travelers Insurance DAC, Dublin 2, authorised by the Central Bankno, broker
CFC Cyber Proactive Responsefull wording, v4.0, 06/25CFC as coverholder, insurer named on your certificateno, broker
CFC Cyber Private Enterprisefull wording, 06/24CFC Underwriting Limited, regulated by the FCAno, broker
Chubb Cyber ERMfactsheet and short proposal formChubb European Group SE, registered in Ireland No. 904967broker, with online quoting for eligible small risks
AIG CyberEdgeservices sheets only, IRL0566AR 0525AIG Europe S.A., Ireland branchno, broker
HSB Cyberwording published, 06/22, but as a scannot readable in the scannot readable
Aviva Ireland, Allianz Irelandno cyber product listednot applicablenot listed

Sources: the documents named, read 16 September 2026; mig.ie policy documents page; chubb.com ie-en; aig.ie; aviva.ie; allianz.ie.

Two things fall out of that table. Every route goes through an intermediary, and the entity whose balance sheet is behind the policy is not always the name printed at the top of it.

Broker, coverholder, insurer: three names, one policy

The CFC wording describes CFC as “the Coverholder identified on your Policy Certificate”. A coverholder writes business on somebody else’s paper, which means the entity that actually owes you money is on the certificate and not in the forty pages you were sent. Ask which insurer that is, and ask it before you bind rather than after.

Three names on one policy is normal here and no cause for alarm on its own; it only becomes a problem when nobody can tell you which of the three answers a given question, so put the name of each on the file before you sign.

What Irish cyber policies say about AI, in their own words

Here is a thing I expected to find and did not. Of the three Irish broker pages I read, none mentions artificial intelligence at all, and the only match on one of them was the AI inside the words EMAIL US.

The contracts are ahead of the marketing: two of the wordings name it, and one gives it a clause of its own. This is a different question from the one an underwriter puts to you, which has its own guide.

The Travelers clause that removes an argument

Clause 1.23 of the Irish Travelers wording is headed Artificial Intelligence and reads in full:

“With respect to any Security Breach or, under the Cyber Crime Insuring Clauses, any fraudulent instruction or entry or change of data, no coverage under this Policy will be excluded solely because such Security Breach, fraudulent instruction, or entry or change of data is made or facilitated through the use of artificial intelligence, deepfake, or similar technology.”

That clause adds no cover, but it closes off a defence before anyone has to argue about it, which is worth more than it looks.

CFC, one year apart

CFC’s June 2025 Republic of Ireland wording names AI three times. Its definition of a cyber event includes “an attack that utilises artificial intelligence (AI)”, and both halves of the media liability clause reach content “created, in whole or in part, by artificial intelligence programmes”.

The June 2024 CFC wording for the same market, published by the same broker, does not contain the string artificial once. I checked it with the spacing stripped out, because PDF extraction breaks words apart, and with a control word to prove the search was working.

20.2%
of Irish enterprises used AI technologies in 2025, and 17.2% of small ones. CSO, Information Society Statistics Enterprises 2025, released 6 February 2026
documentdatewhat it says about AI
Travelers, Ireland, TRV274208/25a clause headed Artificial Intelligence, confirming cover is not excluded
CFC Cyber Proactive Response, ROI06/25AI attacks inside the definition of cyber event; AI content inside media liability
CFC Cyber Private Enterprise, ROI06/24nothing. Zero occurrences of artificial
Chubb Cyber ERM factsheet, Ireland09/21nothing
AIG CyberEdge services, Ireland05/25nothing
Aviva Ireland, Allianz Ireland pagesread 16/09/26no cyber product listed

Sources: each document as cited above, read and searched on 16 September 2026.

Read down that last column and the pattern is a market catching up in the space of about a year, with the newest wordings doing the work and the older documents silent.

What none of the wordings says

Here is the gap, and it is the reason this guide exists. Every AI reference I found is about an attack made with AI, or content made with AI. Not one of the Irish wordings says anything about your own staff putting client information into a chat tool.

What the AI providers do with that text afterwards is at least written down. OpenAI has no single answer on how long it keeps your chats, Google sets out who reads your chats and for how long, and at Anthropic one setting decides between thirty days and five years.

Large enterprises57.7%
Medium28.6%
Small17.2%
Irish enterprises using AI technologies, by size class, 2025. CSO, released 6 February 2026

The CSO puts AI use at 20.2% of all Irish enterprises in 2025, split 57.7% of large, 28.6% of medium and 17.2% of small ones, with 9.3% of all enterprises using it for natural language generation, the category that covers drafting. None of that is addressed by any policy on the Irish shelf.

Whether an accidental disclosure into a tool run by another company is a covered privacy breach under your wording is a question for your broker, in writing. The answer will turn on the definition of a privacy breach, not on anything with AI in the heading. It will also turn on which product you were actually using, and with Microsoft that is a question with several answers.

What cyber insurance costs in Ireland

There is no rate card, and anyone publishing a precise Irish average is guessing. Two numbers are genuinely published, and each comes with a caveat that matters more than the figure itself.

€899
the annual CyberEdge premium at or below which AIG treats an Irish insured as small for its services programme. AIG, IRL0566AR 0525 v1

That €899 is a threshold rather than a price, and it is the closest thing to an insurer telling you what small looks like here. It is also the bottom rung of a published ladder, because AIG produces the same sheet three times.

AIG tierannual CyberEdge premiumservices valued at up to
I, small€899 or lessnot stated
II, midsize€900 to €4,999€8,000
III, large€5,000 or greater€25,000

Source: AIG Cyber Loss Control Services, Ireland, references IRL0566AR, IRL0567AR and IRL0568AR, all 0525 v1, aig.ie.

That ladder is not a rate card either, but it tells you where one underwriter thinks the bands sit. The second number is a broker’s estimate: LHK Group wrote on 22 May 2026 that “smaller Irish SMEs may pay from €1,500 to €3,000 per year”. Putting one insurer’s ladder beside a broker’s estimate is arithmetic rather than evidence, and the arithmetic puts those smaller firms on the second rung rather than the first.

What moves a premium is the form, not the sector

So the controls above are the cheapest lever you have, and a written AI rule is worth an afternoon. Chubb’s Irish factsheet says it applies “no minimum premiums” and that premiums “scale for all sizes of risks based on the scope of coverage and limits”.

That same factsheet carries the reference UK8081-MD 09/21, while the proposal form for the same market carries ROI0268-MD 09/22. One is written for Ireland and the other is a 2021 document served from an Irish address, which is a fair warning about how little material is written specifically for Ireland.

Before you use a comparison site, check the Central Bank register

Four of the queries I ran on the Irish web on 16 September 2026 put sites offering to compare or rank cyber policies into the top ten. Ireland gives you a cheap way to check any of them.

Two regulations give you everything you need, and they are both short.

the regulationwhat it saysthe question it hands you
Reg. 57a person “shall not undertake, or purport to undertake, insurance or reinsurance distribution in the State” unless registered here or in another Member State, and doing so “commits an offence”. Reg. 58 sets up to €500,000 on indictmentunder what registration are you arranging this?
Reg. 34(4)an intermediary advising “on the basis of a fair and personal analysis” must base it “on an analysis of a sufficiently large number of insurance contracts available on the market”how many cyber contracts did you actually look at?

Source: European Union (Insurance Distribution) Regulations 2018, S.I. No. 229 of 2018, irishstatutebook.ie.

Both questions are answerable in a sentence by anyone entitled to your business, and neither is rude. The first one you can check yourself before you even ask it.

The register carries trading names, so the brand is enough

The check takes twenty seconds at registers.centralbank.ie. It matters that the register lists trading names as well as legal ones, because that is the name you see on the website.

what I typedwhat came back
OBFC5168, OBF Insurance Group Limited
Campion InsuranceC9913, Campion Insurances Limited, trading as Bestquote.ie, Campion Insurance, PIB Global
McCarthy InsuranceC30147, Charles Mc Carthy Insurances Limited, with six trading names listed
the five comparison brands in my resultsno rows returned for any of them

Source: Central Bank of Ireland Financial Service Provider Search, run 16 September 2026. A nil result is not proof of anything: a site may be an introducer, or registered in another Member State and listed on that regulator’s register instead.

I am deliberately not naming the five. Run the search yourself on whatever site you are about to hand your turnover figure to, and if nothing comes back, ask them under what registration they are arranging your insurance.

“A fair and personal analysis”, and why you ask for it in writing

Regulation 34 is the half that shapes the conversation rather than policing it. A distributor must specify your “demands and the needs” and may “only propose a contract that is consistent” with them, which is a rule about the advice and not about the paperwork.

So there is a precise question to ask a broker, and “are you independent” is the wrong one. Ask instead: are you advising me on the basis of a fair and personal analysis, and how many cyber contracts did you look at? Either answer is useful, and it goes in the email rather than the phone call, for a reason that applies to every AI and data question too: a written answer survives the person who gave it.

What actually goes wrong in Ireland, according to the regulator

The Data Protection Commission publishes its own numbers, and they do not describe the world the marketing describes.

6,521
breach notifications received by the DPC in 2025. Half arose from correspondence being sent to the wrong recipient. DPC Annual Report 2025

The DPC’s key numbers for 2025 record 6,521 breach notifications and 16,160 new cases, the latter a 45% increase on 2024. They also record €530,773,000 in administrative fines, of which €530 million was one decision against TikTok Technology Limited. The line that should change how you read a cyber quote is the one beside the notification figure: “Half of all notifications arose as a result of correspondence being sent to the wrong recipient.”

That is not hacking. It is an email to the wrong Murphy, an attachment with the previous client still in it, a letter in the wrong envelope. The CSO’s survey puts it from the other side. In 2024 some 11.5% of Irish enterprises lost ICT services temporarily, 2.1% had data destroyed or corrupted, and only 1.5% had confidential data disclosed.

11.5%had ICT services temporarily unavailable
2.1%had data destroyed or corrupted
1.5%had confidential data disclosed
Irish enterprises in 2024. CSO, ICT Security, released 14 February 2025

So when you compare two cyber quotes, weigh the clauses that respond to a mistake made by your own staff at least as heavily as the ones about ransomware, because that is the claim the national statistics say you are most likely to make. The related question of whether a disclosure is a reportable breach at all is a separate guide and a separate clock.

NIS2, and where it reaches a small firm first

One more piece of Irish context, because brokers are starting to raise it. On 8 July 2026 the European Commission referred Ireland, along with Spain, France and the Netherlands, to the Court of Justice for failing to notify complete transposition of the NIS2 Directive, with a request for a lump sum and daily penalties.

Ireland’s own NCSC still states that the 17 October 2024 deadline “has not been met” and that the registration and incident reporting portals are unavailable. Most SMEs are out of scope of NIS2 anyway, and where it will reach you first is through a larger customer’s supplier questionnaire, which is where the AI questions on a questionnaire come in.

The checklist: how to compare cyber policies in Ireland

Copy this, take it to both quotes, and fill it in from the documents rather than from the summary email. Nothing in it requires you to buy anything, and there is no email gate on it. Our other guides cover the AI side of the same questions.

Ten points, and a line at the end for the answer you could not get.

Who the insurer is, and the documents you are owed

  1. Who is the insurer Not the broker, and not the brand on the wording. The entity that owes you money is named on the certificate, and a coverholder is not it. Ask: which insurer, and is it on the Central Bank register or the register of its home Member State?
  2. The two documents you are owed Ask for the full policy wording and the Insurance Product Information Document, before you bind. Regulation 34(6) of S.I. No. 229 of 2018 requires the IPID for a non-life product, and 34(9) says it must set out the main exclusions and the obligations during the term of the contract. A quote summary is not either of them.

Your status under the 2019 Act, and what you sign

  1. Your status under the 2019 act Turnover in the last financial year: ________ At or under €3 million, and not in a larger group, and you are a consumer under the Consumer Insurance Contracts Act 2019. Say so in writing when you return the proposal form.
  2. The disclosure declaration Read the sentence above the signature. If it asks you to volunteer all material matters, ask the broker to reconcile it with section 8(2). Keep the completed form: section 10(1) says you are entitled to a copy.
  3. The continuing conditions List every condition you must keep satisfying: MFA, backups, patching, logging. Ask which ones the insurer treats as conditions precedent, and note that section 19(4) of the 2019 Act makes a continuing restrictive condition suspensive for a consumer.

Fines, the response panel and the human error

  1. The regulatory fine clause Both Irish wordings say fines are covered only so far as insurable at law, and neither names the DPC. Ask, in writing: on your reading, is a Data Protection Commission fine payable under this policy, and on what basis?
  2. The response panel and the clock Who must you call first, and how long may you spend before you need written consent? Check whether your own IT provider and solicitor are allowed on the job at all.
  3. What it does for a human error Half of Irish breach notifications are correspondence sent to the wrong recipient. Ask which insuring clause responds to that, with the clause number, not a reassurance.

AI, and the limits under the headline limit

  1. AI, asked properly Two questions, not one. Is an attack made using AI covered? And is an accidental disclosure by our own staff into an AI tool run by another company a covered privacy breach?
  2. Limits, sublimits and retentions The headline limit is the least useful number. Write down the sublimit for extortion, for business interruption and for regulatory response, and the retention that applies to each.

The question I could not get answered: _______________ Broker: _____________ Date: _____________

point, and what to askwhere it isquote Aquote B
1. The insurer that owes you moneycertificate
2. Full wording and IPID, before you bindfrom the broker
3. Your status: turnover at or under €3 million, no larger groupyour accounts
4. The declaration, against section 8(2)proposal form, above the signature
5. The conditions: MFA, backups, patching, loggingwording and IPID

Points 1 to 5 of the checklist, with a column for each quote. The second column is where the sections above say the answer is found.

point, and what to askwhere it isquote Aquote B
6. Is a DPC fine payable, in writingwording, fines clause
7. Who you call, and when consent is neededwording, conditions
8. Human error: the insuring clause, by numberwording, insuring clauses
9. AI attacks, and staff disclosures into an AI toolwording, definitions
10. Sublimits and retentionsschedule

Points 6 to 10.

The tenth point is where most comparisons fall over. Two quotes with the same headline limit can differ by a factor of ten on the sublimit that will actually pay, and the sublimits live in the schedule rather than in the wording.

What a tool can do here, and what no tool can do, including ours

We make software that hides identifying information in text before it goes into an AI tool, and it runs on the machine rather than in a service.

It touches point 9 of the checklist and nothing else on the list. If your people draft with an AI tool, taking the names and the numbers out before the text leaves the building is a data minimisation measure you can describe to an underwriter. It is not a control an underwriter asks about. Nothing in the Chubb Irish form, and nothing in any wording I read, gives you a better answer because you run one.

The engine on an Irish file note, and what it missed

The run below was made on 16 September 2026 with invented values:

in   Claimant: Niamh Ni Bhraonain, PPS No. 1234567FA,
     of 14 Cloonlara Rise, Athlone N37 XK52.
out  Claimant: [PERSON_1], [PERSON_2]. [REFERENCE_1],
     of [ADDRESS_1], Athlone [ADDRESS_2].

in   Invoice from Kearnley Traders Ltd, VAT IE6388047V.
out  Invoice from [COMPANY_1], VAT [REFERENCE_1].

in   Sorcha Dhroighnean called about the file.
out  Sorcha Dhroighnean called about the file.

The third line is the one to look at. A bare Irish name with no title or announcing phrase in front of it comes out untouched. Put Senator or Claimant in front of the same name and it is masked. The first line has the opposite fault: the words PPS No were themselves masked as a name, which is the kind of mistake you get from a system designed to err on the side of hiding.

what is in the textwhat the engine did with it
PPS number, Irish VAT numbermasked, and shown to you for review
IBAN, email addressmasked without asking
Eircode, street addressmasked
a bare name with no title in front of itnothing

Source: the run above, on the engine published in the product demo, 16 September 2026.

The difference between the first two rows is deliberate. A PPS number is found by the name beside it and then flagged rather than cleaned in silence, because the check character on its own is too weak a test and would flag innocent references by accident. The same weakness is why a PPS number with nothing beside it is left as it is.

By default nothing is blocked, none of this is data loss prevention, and nothing here makes a policy respond that would not otherwise have responded. What it can do is make a truthful answer to a supplier questionnaire slightly easier to write, and that is the whole claim.

If you buy nothing at all, do these five things

  1. Find out whether you are a consumer. Last year’s turnover, against €3 million, plus the group test. It takes one look at the accounts and it changes which law protects you.
  2. Ask for the wording and the IPID on every quote. Both, in writing, before you bind. A broker who will not send them has told you something.
  3. Run the two names through the register. The insurer and whoever is arranging it, at registers.centralbank.ie. Twenty seconds.
  4. Fix the backup question first. It is the control the Irish proposal form asks about in the most detail, with five ways to answer it, and it is the cheapest of the four to improve.
  5. Write down what your staff may put into an AI tool. One page, dated, signed. It is the document the questionnaire asks you to attach, and a template is here.

And keep the completed proposal form. Of everything in this guide, that is the piece of paper most likely to decide an argument, and section 10(1) of the 2019 Act says you are entitled to it.


Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account, and your client’s details never leave your machine.

Sources

Consumer Insurance Contracts Act 2019 (No. 53 of 2019), Irish Statute Book. Sections 8, 9, 10, 19 and 26, quoted above. Commencement dates from the Act’s commencement table, updated to 14 September 2026.

Financial Services and Pensions Ombudsman Act 2017, section 2 for the €3 million consumer definition and section 60 for the €250,000 compensation limit and the obligation to comply.

European Union (Insurance Distribution) Regulations 2018 (S.I. No. 229 of 2018), Irish Statute Book. Regulation 34 on demands and needs, on fair and personal analysis, and at 34(6) and 34(9) on the insurance product information document; Regulations 57 and 58 on registration and penalties.

Central Bank of Ireland, Financial Service Provider Search, registers.centralbank.ie. Register rows and nil results quoted above were run on 16 September 2026.

Travelers, International CyberRisk Insurance, Republic of Ireland, reference TRV2742 08.25, published policy document. Clause 1.23 on artificial intelligence, definition 7.69 on regulatory fines, and the Travelers Insurance DAC regulatory statement.

CFC, Cyber Proactive Response, Republic of Ireland, version 4.0, June 2025, published policy document. Definition 13 on cyber events, insuring clause 7 on media liability, exclusion 18 on uninsurable fines, and the 72 hour condition.

CFC, Cyber Private Enterprise, Republic of Ireland, June 2024, published policy document. Used as the comparison point: zero occurrences of artificial.

Chubb, Cyber Enterprise Risk Management Short Proposal Form, ROI0268-MD 09/22, chubb.com. The control questions and the fair presentation declaration.

Chubb, Cyber Enterprise Risk Management factsheet, Ireland, UK8081-MD 09/21, chubb.com. No minimum premiums, online quoting for eligible small risks, and the Chubb European Group SE Irish registration.

AIG, Cyber Loss Control Services, Ireland, three sheets, all 0525 v1: small businesses (IRL0566AR, the €899 threshold), midsize (IRL0567AR, €900 to €4,999) and large (IRL0568AR, €5,000 or greater).

Aviva Ireland commercial insurance index, aviva.ie, and Allianz Ireland business insurance, allianz.ie, both read 16 September 2026. Neither lists a cyber product; the Allianz page states that commercial products are not available on a direct basis.

LHK Group, Cyber Insurance for SMEs in Ireland, lhkgroup.ie, published 22 May 2026. The €1,500 to €3,000 broker estimate.

Data Protection Commission, Annual Report 2025, dataprotection.ie. The 6,521 breach notifications, the wrong recipient finding, the 16,160 new cases and the €530,773,000 in fines.

Central Statistics Office, Information Society Statistics Enterprises, ICT Security 2024, released 14 February 2025, for the training and incident percentages, and Artificial Intelligence 2025, released 6 February 2026, for the 20.2% and the size class breakdown.

Insurance Act 2015 (United Kingdom), section 11, legislation.gov.uk. Used only to say that the Irish rule in section 19(5) has a British counterpart.

European Commission, Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice, 8 July 2026, and Ireland’s NCSC, NIS2 page, for the missed transposition deadline and the unavailable portals.

Common questions

What does cyber insurance cover in Ireland?

Two halves. Your own costs after an incident, meaning response, legal advice, data restoration, lost income and extortion. And your liability to other people, meaning claims, defence costs and regulatory fines where those are insurable at law. The Irish wordings I read all split it that way.

How much does cyber insurance cost for a small business in Ireland?

Nobody publishes a rate card. The two sourced Irish figures are AIG treating an annual CyberEdge premium of €899 or less as small, in a May 2025 document, and the broker LHK Group writing on 22 May 2026 that smaller Irish SMEs may pay €1,500 to €3,000 a year.

Is my company a consumer under the Consumer Insurance Contracts Act 2019?

Quite possibly. The Act borrows the definition in section 2(1) of the Financial Services and Pensions Ombudsman Act 2017, which includes an incorporated body with turnover of €3 million or less in its previous financial year, provided it is not in a group above that figure.

Do Irish cyber policies mention artificial intelligence?

Two of the ones I read do. The Travelers Republic of Ireland wording has a clause headed Artificial Intelligence, and the CFC Cyber Proactive Response wording names AI in its definition of a cyber event and in its media liability clause. Neither addresses staff putting data into a chat tool.

Do I need multifactor authentication to get cyber insurance in Ireland?

It is asked, early. Chubb's Irish short proposal form asks whether multifactor authentication is required for all remote network access, and then asks separately whether backups are protected by it. A no is not automatically a refusal, but it is priced.

Does cyber insurance cover a GDPR fine in Ireland?

Both wordings I read defer to the law rather than answer. Travelers covers regulatory fines and penalties but only to the extent they are insurable. CFC excludes fines unless insurable by law. Neither names the GDPR or the Data Protection Commission, so ask your broker to answer it in writing.

What happens if I answer a cyber proposal form wrong in Ireland?

For a consumer, section 9 of the Consumer Insurance Contracts Act 2019 sets proportionate remedies. An innocent misrepresentation means the insurer must pay the claim. A negligent one gets a compensatory and proportionate response. A fraudulent one lets the insurer avoid the contract.

Can I complain if an Irish insurer refuses a cyber claim?

Yes, and it is free. The Financial Services and Pensions Ombudsman can direct compensation of up to €250,000 under section 60(5) of the Financial Services and Pensions Ombudsman Act 2017, and section 60(8) requires the provider to comply with the direction.

How do I check whether a comparison website can legally sell me insurance?

Search the name on the Central Bank of Ireland's register at registers.centralbank.ie. Regulation 57 of S.I. No. 229 of 2018 makes it an offence to undertake insurance distribution in the State without being registered here or in another Member State.