Do Small Businesses Need Cyber Insurance?

Most small businesses that store customer or employee data, take card payments, rely on computers to operate, or send money electronically do need cyber insurance. Washington breach records show attacks hitting retailers, restaurants, professional firms, and contractors, not just large companies. A business with almost no data and no electronic payments may reasonably carry less.

By Trella Commercial · Updated October 4, 2026

The short version

  • The question is exposure, not size. A three-person bookkeeping firm holding hundreds of tax returns has more cyber exposure than a twenty-person landscaping crew that takes checks.
  • Small businesses are in the data. Businesses filed 757 of the 1,675 breach notices in Washington Attorney General records. Retailers alone filed 148, professional services firms 57, legal practices 35, and construction companies 20.
  • Your other policies probably do not help. General liability and business owners policies usually exclude data breaches; see why.
  • The legal duties apply either way. Washington's breach law requires notice within 30 days whether or not you are insured.
  • Six yes-or-no questions below will tell you whether you need a policy and roughly how much attention it deserves.

Six questions that decide it

QuestionIf yesWhy it matters
Do you store names with Social Security numbers, birth dates, driver's license numbers, financial accounts, or health information?Strong needThese are the data elements that trigger Washington and Idaho breach notice laws
Would your business stop if your computers, phones, or software went down for a week?Strong needLost income from a cyber event is not covered by property policies
Does anyone send wires or ACH payments, or change vendor bank details?Strong need, with social engineering coverageBusiness email compromise is one of the largest sources of business fraud losses
Do you take card payments or store card numbers?NeedCard brands can assess fines and costs after a card breach
Does a client, landlord, or partner contract require cyber coverage?RequiredWithout it you are in breach of the contract
Do you collect health-related information from Washington consumers?Need, with careful privacy wordingWashington's My Health My Data Act creates privacy claims risk

If you answered yes to any of the first three, a cyber policy is worth buying. If you answered no to all six, your exposure is small, and a modest policy or a business owners policy endorsement may be a reasonable starting point.

What the Washington data shows about businesses like yours

Trella Commercial analyzed every breach notice filed with the Washington Attorney General, which receives a notice when a breach affects more than 500 Washington residents. Smaller breaches are never filed, so these counts understate how often small businesses are hit.

Business type in the noticesNotices filed, 2015 to 2026
Retail148
Hospitality57
Professional services57
Software42
Legal35
Construction20
Clothing20

Among business filers, 73% of breaches were cyberattacks, and businesses filed 231 ransomware notices, more than any other sector. The median breach in the whole dataset affected 1,888 Washington residents, and 69% affected 5,000 or fewer. Many of these are ordinary companies, not household names, whose customers or employees had to be told their information was exposed. See the full analysis.

The costs a small business carries without a policy

None of these depend on the size of the business, and all of them land at once:

  1. A breach attorney to determine what the law requires and draft the notices
  2. Forensic investigators to find how the attacker got in, what was taken, and whether they are gone
  3. Notification to every affected person, and to the Attorney General above 500 Washington residents, within 30 days
  4. Credit monitoring and a call center, commonly offered to affected people
  5. Restoring systems and data, often with outside IT help working nights and weekends
  6. Lost income while you cannot schedule, bill, ship, or take payments
  7. Lawsuits and regulatory inquiries from people whose data was exposed
  8. Money lost to fraud, if a fake invoice or payment change got through

A cyber policy is built around exactly this list. See what cyber insurance covers.

When a small policy, or none, can be reasonable

  • Very little data: you keep no customer records beyond names and emails, and no employee records beyond what your payroll provider holds.
  • No electronic payments: card payments run through a processor's hosted page, and you do not send or receive wires.
  • You can work on paper: an outage would be an inconvenience, not a shutdown.

Even then, check your vendors. If your payroll, booking, or practice software provider is breached, the duty to notify your customers or employees usually stays with you. A small policy, or a business owners policy data breach endorsement, can cover that response.

Common objections

ObjectionThe reality
"We're too small to be a target."Most attacks are automated: phishing emails and scans for weak passwords hit thousands of businesses at once. Washington's records include hundreds of ordinary businesses.
"Our IT person has it handled."Good security lowers the odds and the premium. It does not pay for notification, lawyers, lost income, or lawsuits when something gets through.
"Our data is in the cloud, so it's their problem."Cloud providers secure their platform; you are generally responsible for your accounts, passwords, and data. A stolen login is your breach.
"We'd just pay out of pocket."Run the list above for a breach of every customer and employee record you hold, plus a week offline. Then decide.
"Our general liability covers it."Usually not. Most general liability policies exclude data breaches outright.

Next steps

  1. Answer the six questions above honestly.
  2. List the data you hold and how many people it covers.
  3. Note how long you could operate without your systems.
  4. Check every contract for cyber insurance requirements.
  5. Size a limit with our guide to how much cyber insurance a small business needs.

Common questions

Is cyber insurance worth it for a small business?

For a business that holds sensitive customer or employee data, depends on its systems to operate, or sends money electronically, usually yes. One breach can require a breach attorney, forensics, notification within 30 days in Washington, lost income, and defense against lawsuits, costs that general liability policies typically exclude.

Are small businesses really targeted by hackers?

Small businesses are hit regularly, often by automated phishing and password attacks rather than targeted hacking. Washington Attorney General records include 757 business breach notices, including 148 from retailers and 57 from professional services firms, and only breaches affecting more than 500 Washington residents are filed.

Is cyber insurance required by law?

No Washington or Idaho law requires businesses to buy cyber insurance. Breach notification laws apply whether or not you are insured, and many client, vendor, and lease contracts require cyber coverage as a condition of doing business.

What is the minimum cyber insurance a small business should have?

There is no legal minimum. The right limit depends on how many records you hold, how long you could operate offline, your largest payment exposure, and any contract requirements. Our sizing guide walks through each.

Can a business owners policy endorsement replace cyber insurance?

For a business with very little data and no electronic payments, a BOP data breach endorsement can be a reasonable start. It usually does not include ransomware, lost income from a cyber event, wire fraud, or regulatory defense.

Sources

This page is general information, not a recommendation for any specific business. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.