A stolen laptop can turn into a much bigger problem than replacing the laptop itself. If it held work files, customer details, saved passwords, or access to company systems, the real worry starts after the device disappears.

So, is a stolen device excluded from cyber insurance? Sometimes. But the answer usually depends on what happened after the theft and what your policy actually defines as a covered cyber event.

Theft Doesn’t Always Mean Automatic Coverage

Cyber insurance is mainly built around digital risks. A policy may respond when stolen equipment leads to a data breach or unauthorized access, but it doesn’t automatically mean the insurer will pay for the physical device.

That distinction matters. Your laptop was stolen. The cost of buying another laptop may fall outside the cyber policy. The expenses caused by someone using information from that laptop could be treated very differently.

And some policies specifically exclude physical property loss. Others include limited coverage for devices when the theft is tied to a covered cyber incident. The wording is what counts.

Read the Device and Property Exclusions

Look closely at the exclusions section. That’s where the annoying little sentence can change the whole answer.

• Physical loss of equipment may be excluded, even though the policy covers the cyber consequences connected to that equipment.

• A stolen phone with company data on it can create a separate issue, especially if the policy requires security controls such as encryption.

• If the device was left unattended in a way the policy considers careless, coverage could become harder to establish, and that wording deserves a careful read.

What Happens After the Theft Matters

Imagine Raj loses his work laptop from his car. Nothing dramatic. He had parked outside a grocery store and noticed the laptop was gone when he got home. The next morning, he stopped reopening the same five tabs to check whether his company accounts had been accessed and instead reported the incident to IT.

That response matters because insurers often care about what you did once you knew there was a problem. Delaying notification can create trouble. So can failing to follow required security steps.

Security Conditions Can Change the Claim

Encryption is a good example. If a policy requires company devices to be encrypted and the stolen laptop wasn’t, the insurer may question coverage for the resulting incident. The same goes for other policy conditions that require reasonable security measures.

Honestly, this is one area where businesses shouldn’t guess. A policy can look broad until you reach the exclusions and conditions buried later in the wording.

What Should You Check?

Start with the definitions. Find out how the policy describes a cyber incident, data breach, computer system, and covered property. Then look for exclusions involving theft or physical loss.

Also check whether the policy covers breach response costs after a device is stolen. That can be more important than the laptop itself if sensitive information was exposed.

If you’re buying cyber insurance now, ask the insurer a blunt question: “If an employee’s encrypted laptop is stolen and company data is exposed, exactly what does this policy pay for?” Get the answer in writing.

A stolen device isn’t automatically excluded from every cyber insurance policy. But assuming it’s covered because you bought cyber insurance is just as risky.

The trick is knowing where the physical loss ends and the cyber loss begins. Insurance wording decides that boundary. And that boundary can get expensive fast.