Cyber Liability Insurance for Small Businesses
Cyber insurance pays for the two sides of a digital incident: your own costs to recover (forensics, restoring systems, notifying customers, lost income) and your liability to others whose data or money was exposed.
Small businesses are not too small to be targeted. Automated attacks do not check your revenue first, and a single spoofed invoice email can move five figures out of your account before anyone notices.
What it covers
- Breach response: forensics, legal counsel, customer notification, and credit monitoring
- Ransomware and extortion, including negotiation and recovery costs
- Business interruption while your systems are down
- Liability and regulatory defense when customer or employee data is exposed
- Social engineering and funds transfer fraud, usually by endorsement with a sublimit
What it does not cover
- Losses from known, unpatched vulnerabilities in some forms
- Upgrades to your systems beyond restoring what you had
- Acts of war, in wording that varies by carrier
- Fraud losses above the social engineering sublimit
Who needs it
Any business that stores customer or employee data, takes payments, relies on email to approve payments, or cannot operate when its computers are down. That describes almost every business.
What drives the price
- Revenue and number of records held
- Multi-factor authentication on email and remote access
- Backups that are tested and kept offline
- Industry (healthcare and financial services price higher)
- Prior incidents
Where owners get caught: a wire fraud sublimit of almost nothing
The most common small business cyber loss is not a hack. It is a convincing email that gets someone to wire money or change a vendor's bank details. Many cyber policies cover this only through a social engineering endorsement with a low sublimit, and some exclude it entirely. We look at that line first, because it is the one most likely to be tested.
Cyber Liability: common questions
Does my general liability or BOP cover a data breach?
Generally no. Standard BOP and GL forms exclude or sharply limit electronic data losses. Some BOPs offer a small cyber endorsement, but it is rarely enough for a real incident.
What security controls do cyber insurers require?
Expect questions about multi-factor authentication, endpoint protection, backups, and employee training. Answering yes when a control is not in place can void coverage, so the application deserves real attention.
How much cyber coverage does a small business need?
Limits commonly start at $1 million. The right number depends on how many records you hold, how long you could operate without your systems, and what your client contracts require.
Cyber Liability in practice
Illustrative stories of businesses that needed it, and what else their review turned up.
A Small Law Firm's Trust Account and the Email That Almost Emptied It
A four-attorney firm handling real estate closings assumed its malpractice policy covered a stolen wire. The review found that malpractice, cyber, and crime coverage each covered a different piece, and the firm had only one of them.
CyberE&OBOPRetailAn Online Store Had Insurance for Its Warehouse and None for Its Website
A direct-to-consumer outdoor gear brand made nearly all its sales online. Its insurance protected the warehouse shelves, but not the store that actually made money, and not the products it imported.
CyberPropertyGLHealthcareThe Dental Practice That Was Insured for Everything Except Its Patient Records
A three-dentist practice had malpractice, a solid office policy, and no cyber coverage, while holding years of patient records, insurance details, and payment data. Here is what a review turned up.
CyberBOPEPLITechnologyWhen a Managed IT Provider Gets Breached, Every Client Gets Breached
An MSP supporting forty small businesses had a cyber policy sized for its own office. The review found that its real exposure was a single compromised tool that touches every client at once.
CyberE&OUmbrellaProfessional servicesA CPA Firm Bought E&O for Tax Mistakes. The Bigger Risk Was a Fake Email.
A twelve-person accounting firm had professional liability for errors in its work. The review found a claims-made trap in its switch of carriers, and a wire fraud exposure its E&O policy was never designed to cover.
E&OCyberEPLIRetailA Kirkland Boutique, a December Inventory, and a Policy Written for March
A women's clothing boutique had a business owners policy that looked fine on paper. The review found an inventory limit set for the slowest month of the year and no protection for the card data running through its register.
BOPGLCyberUsually written alongside
Professional Liability (E&O)
Claims that your advice, work, or service cost a client money. Excluded from every BOP and GL policy.
Learn moreBusiness Owners Policy
Property, liability, and lost income bundled into one policy. The right starting point for most small businesses.
Learn moreDirectors & Officers
Personal protection for founders, directors, and officers when management decisions are challenged.
Learn morePart of the programs we build for professional services, technology & startups and retail & shops.
Not sure your cyber liability coverage fits?
Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.