Cyber Liability Insurance

Cyber coverage that pays for the response, not just the lawsuit

Ransomware, wire fraud, and stolen customer data — with a 24/7 incident response team you can call at 2 a.m.

Cyber liability covers the cost of a data breach, ransomware attack, or funds-transfer fraud, and it is now one of the most-claimed policies in the small business market. Attackers do not target companies by size — they scan for unpatched systems and reused passwords, and a fifteen-person firm with a payroll file is a completely viable target. The average incident for a small business runs well into six figures once forensics, legal notification, and downtime are counted.

The most valuable feature of a modern cyber policy is the response team. When you call the hotline, you get a breach coach, a forensics firm, and a negotiator who have handled hundreds of these events. They contain the incident, determine what data was actually exposed, manage the notification requirements in every state where your customers live, and deal with the extortion demand if there is one. Trying to assemble that team yourself, mid-incident, at retail rates, is how a bad week becomes a bad quarter.

Coverage splits into two halves. First-party covers your own losses — forensics, data restoration, ransom payments, lost income during downtime, and notification costs. Third-party covers claims from others — customers whose data was exposed, regulators imposing penalties, and payment card networks assessing fines. A cheap policy usually cuts the first-party side, which is exactly where the money goes. We show you both columns when we quote.

What's covered

  • Incident response and forensics. 24/7 breach hotline, investigators to determine scope, and legal counsel to guide the response.
  • Ransomware and extortion. Negotiation, ransom payment where lawful and approved, and the cost of restoring systems and data.
  • Business interruption. Lost income and extra expense while systems are down, including dependent outages at a vendor.
  • Notification and monitoring. Legally required notices to affected individuals plus credit monitoring and a call center.
  • Liability and regulatory defense. Lawsuits from affected customers, regulatory investigations, and PCI fines and assessments.
  • Funds transfer and social engineering fraud. Money wired to a criminal after a spoofed vendor or executive request, subject to a sublimit.

What it doesn't cover

  • Upgrading your systems. The policy restores what you had; it does not fund the security improvements you should have made.
  • Known vulnerabilities left unpatched. Carriers may deny a claim tied to a critical patch you were warned about and ignored.
  • Bodily injury and property damage. Physical harm remains a general liability matter.
  • Lost or reduced future revenue. Reputational decline beyond the covered interruption period is generally not indemnified.
  • Misrepresented controls. Claiming MFA on the application when it is not actually deployed can void the policy.

How claims actually play out

The Friday ransomware

A distributor's file server and backups were encrypted after a credential-stuffing attack on a remote access account. Order processing stopped completely; the demand was $340,000 in crypto.

Outcome: The response team restored from an offline backup instead of paying. The claim totaled $214,000 across forensics, restoration, and eleven days of interruption — and the carrier required MFA at renewal.

The vendor invoice that wasn't

A controller received an emailed banking change from a longtime supplier and wired $88,000. The email came from a lookalike domain registered nine days earlier.

Outcome: Social engineering fraud coverage paid $75,000 after the sublimit and deductible, and the firm implemented callback verification on all banking changes.

The stolen laptop

An unencrypted laptop with a client spreadsheet of roughly 6,200 records was stolen from a car. Notification obligations spanned nine states.

Outcome: The policy funded $63,000 in legal review, notification, and two years of credit monitoring, and defended a class claim that was dismissed the following year.

What drives your price

Records stored
Volume and sensitivity of the personal, health, and payment data you hold is the primary rating factor.
Security controls
Multifactor authentication, endpoint detection, offline backups, and email filtering can cut premium sharply — some carriers will not quote without MFA.
Industry and regulation
Healthcare, finance, and education carry heavier notification and regulatory exposure.
Revenue and dependency
Larger revenue means larger interruption values, and heavy reliance on one platform adds dependent business interruption exposure.
Prior incidents
A previous breach is not disqualifying, but carriers want to see what changed afterward.

Cyber Liability questions

Ready to price cyber liability?

One application, shopped to up to 10 A-rated carriers. A licensed agent presents the options side by side — usually within one business day.

Get an Instant Quote 1-866-964-6660

Mon – Fri, 8:00am – 6:00pm CT