forumNew topic

Should we get cyber insurance — is the cost less than potential cyber attack losses, or is it a waste of money?

SSultan T***Member
Job title
Social media manager
Sector
Insurance
Organization type
8-person team
Joined
Nov 2024
Message
19
#1

Cyber insurance policies are starting to be offered. Providers say 'we cover hacker attacks, data breaches, and system downtime costs.' But premiums are high: 3-5 thousand lira/year for small companies (50 people). Is it necessary if the budget is limited?

I understand the coverage parts: forensic, customer notification, police support, business interruption. But there are exceptions (internal negligence, policy violations are excluded). Is it really worth it?

If I don't have insurance initially and experience 1-2 attacks, what do I lose? What is the average cost of a cyber attack (in Turkey)? Can they cancel the policy as premiums increase (after 2-3 attacks)?

ZZafer Ö***Member
Job title
Production planning
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Apr 2023
Message
247
Most Helpful#2

To compare insurance policies: AIG, Beazley, Chubb (major carriers). If you hire a broker (e.g. Willis Towers Watson), they'll give recommendations.

RRamazan G***Expert
Job title
Secretary
Sector
Leather
Organization type
20-person company
Joined
Apr 2022
Message
92

Doki · Mobile app · 2025

#3

Im in the same situation thats why Im asking. When making a decision first look at what data you have on hand.

Hope this helps.

OOya G***Member
Job title
Production Manager
Sector
Catering
Organization type
300-person organization
Joined
Oct 2023
Message
66
#4

Absolutely. If I were to add anything: When you try to change everything at once, nothing settles.

HHasan A***Expert
Job title
Customer service representative
Sector
Accounting & advisory
Organization type
family business
Joined
Nov 2025
Message
102
#5

We got stuck at the same point for a while. Processes without records never improve because you don't know what to fix.

The harder it is to reverse a decision the slower you should make it. If you have questions, write them; Ill answer as best I can.

HHakan C***Member
Job title
Supply chain manager
Sector
IT services
Organization type
two-branch business
Joined
Mar 2023
Message
295
#6

Generally correct, but one part is missing. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Taking notes for two weeks yields better results than a six-month estimate. Proven by experience.

HHatice Ö***Member
Job title
Production Manager
Sector
Retail
Organization type
regional distributor
Joined
May 2022
Message
240

Doki · Log management setup · 2025

#7

We need to make a distinction here. If 2FA is on, a stolen password alone is useless.

Of course, it varies if your situation is different.

İİlknur Y***MemberCommunity member
Joined
Sep 2025
Message
2
#8

The opposite happened to me, that's why I'm writing. People defend habits, not processes. Resistance comes from there.

Proven by experience.

MMert K***MemberCommunity member
Joined
Jul 2025
Message
365
#9

Just a heads-up. If permission and scope aren't in writing, don't start that test.

If you have questions, write them; I'll answer as best I can.

MMerve B***New memberCommunity member
Joined
Aug 2026
Message
247
#10

Correct. Don't rely on a single measure; go layer by layer.

Proven by experience.

DDoki ekibiDoki team
Job title
Official account
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
310
#11

Sorry, but this doesn't apply in every case. The answer varies greatly by industry; there is no one-size-fits-all rule.

The answer varies greatly by industry; there is no one-size-fits-all rule. If you have questions, write them; I'll answer as best I can.

KKader Ş***ExpertCommunity member
Joined
Mar 2024
Message
67
#12

I went through the same thing. Processes without records never improve, because you don't know what to fix.

PPolat Y***ExpertCommunity member
Joined
May 2023
Message
54
#13

Let me summarize the topic, since several different answers were given. Most incidents start with a leaked password, not a vulnerability.

Most incidents start with a leaked password, not a vulnerability. Hope this helps.

AAslıhanMember
Job title
Fashion manufacturer
Joined
Apr 2024
Message
102
#14

If you're going this route, sort this out first. The harder it is to reverse a decision, the slower you should make it.

Hope this helps.

AAslı Y***New memberCommunity member
Joined
Sep 2026
Message
304
#15

here's how it went for us. if the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

good luck with that.

HHakan B***Expert
Job title
Human Resources Specialist
Sector
Plastic
Organization type
early-stage startup
Joined
Jan 2026
Message
409
#16

Saved. Just because everyone does it doesn't mean it's right.

Good luck with that.

FFerhat A***ExpertCommunity member
Joined
Mar 2026
Message
124
#17

Let me share my experience. The harder it is to reverse a decision, the slower you should make it.

If 2FA is on, a stolen password alone is useless. This is my opinion, I'm not claiming it's absolute truth.

MMert E***MemberCommunity member
Joined
Sep 2024
Message
28
#18

saved. forgottn test environments are more often the entry point than live systems.

having backups acessible on the same network and with the same identity makes them part of the target then anyway thats all sorry if I went on too long.

DDoruk U***Member
Job title
Technical service technician
Sector
Cosmetics
Organization type
two-branch business
Joined
Aug 2025
Message
137
#19

Thanks a lot, I'll try it today.

MMerve T***ExpertCommunity member
Joined
Feb 2024
Message
13
#20

I'll try it.

Reply