Three companies—Stoïk, Dattak, and Hiscox—highlight different strategies for cyber insurance in the French market. Each offers services that go beyond traditional coverage limits or annual premiums, aiming to meet the complex needs of businesses dealing with cyber risks. For small and medium-sized enterprises (SMEs), a cyber incident can have serious consequences, such as halted operations, inaccessible customer data, and uncertainty about compromised financial information. In such cases, management must identify affected data, inform partners, and assess financial damage, while IT providers analyze the incident and systems may need to be rebuilt or restored.
Stoïk focuses on a model that combines prevention, insurance, and incident response. Its Stoïk Protect environment includes automated scans for vulnerabilities, cloud configurations, Active Directory, phishing threats, and employee training. The company also provides its own CERT (Computer Emergency Response Team), available around the clock. Stoïk aims to reduce the likelihood of claims by identifying vulnerabilities before they can be exploited, which is especially valuable for SMEs without dedicated cybersecurity teams. However, the tools do not eliminate the need for internal action, as detected vulnerabilities must still be addressed.
Dattak offers a similar structure, combining insurance, a prevention platform, and an incident response team. Its Dattak Defense platform includes scans for exposed services, vulnerabilities, and changes in the attack surface, as well as assessments of cloud and Active Directory configurations. The company also provides incident response through its CERT. Dattak is expanding beyond cyberattacks to include broader technological risk management, covering fraud, computer outages, third-party dependencies, and professional liability. This approach acknowledges that not all computer interruptions are the result of malicious attacks, such as critical SaaS outages or cloud incidents.
Hiscox provides a more simplified approach with its CyberClear Premium product, aimed at start-ups, SMEs, and small businesses with up to 25 million euros in annual turnover. The offering is distributed through brokers using the MyHiscox extranet, with a streamlined process that avoids complex technical questionnaires. It combines cyber insurance with prevention services like Norton Small Business, 24/7 expert assistance, and legal protection. However, the simplicity of access should not be mistaken for the complexity of the risk, as contracts may still include deductibles, exclusions, and sub-limits.
Comparing cyber insurance requires more than just looking at annual premiums. Companies should evaluate what incidents are covered, including ransomware, fake supplier fraud, data theft, computer outages, and cloud provider unavailability. It is important to determine whether business interruption losses are covered, the waiting period before compensation begins, the duration of coverage, and how financial losses are calculated. The response to incidents involving external suppliers, such as AWS or SaaS providers, should also be considered.
In the event of an attack, it is important to know who will intervene—internal CERT, mandated providers, hotlines, or legal experts—and within what timeframe. Intervention costs, such as forensic analysis, system restoration, and legal fees, may reduce the compensation ceiling. Deductibles and the actual amount available after applying sub-limits and exclusions should be considered. Coverage for cyberfraud without direct intrusion, such as fake transfers or presidential fraud, should also be included. Prevention tools like vulnerability scans, phishing simulations, and training should be evaluated, along with who handles the alerts.
For SaaS publishers, ESNs, and hosts, liability towards customers is crucial, as an attack can lead to both company losses and customer claims. Contractual obligations, such as declaration deadlines, complaint filing, minimum security measures, backups, and internal procedures, must be respected to ensure compensation. A thorough comparison of cyber insurance involves testing five realistic scenarios, including ransomware, fake supplier fraud, computer outages, cloud provider unavailability, and data breaches. The choice of insurance depends on the company's existing organization, whether it has a cybersecurity officer, and its specific contractual model. Cyber insurance should be viewed as part of a broader system that includes prevention, IT providers, crisis management, regulatory obligations, and financial capacity.
Cyber Insurance Models in France: Comparing Stoïk, Dattak, and Hiscox Approaches
AI-rewritten from original reportingHow it works
cyber-insurancesmecybersecurityrisk-managementfraud-protectionincident-response



