The short version
- The question is exposure, not size. A three-person bookkeeping firm holding hundreds of tax returns has more cyber exposure than a twenty-person landscaping crew that takes checks.
- Small businesses are in the data. Businesses filed 757 of the 1,675 breach notices in Washington Attorney General records. Retailers alone filed 148, professional services firms 57, legal practices 35, and construction companies 20.
- Your other policies probably do not help. General liability and business owners policies usually exclude data breaches; see why.
- The legal duties apply either way. Washington's breach law requires notice within 30 days whether or not you are insured.
- Six yes-or-no questions below will tell you whether you need a policy and roughly how much attention it deserves.
Six questions that decide it
| Question | If yes | Why it matters |
|---|---|---|
| Do you store names with Social Security numbers, birth dates, driver's license numbers, financial accounts, or health information? | Strong need | These are the data elements that trigger Washington and Idaho breach notice laws |
| Would your business stop if your computers, phones, or software went down for a week? | Strong need | Lost income from a cyber event is not covered by property policies |
| Does anyone send wires or ACH payments, or change vendor bank details? | Strong need, with social engineering coverage | Business email compromise is one of the largest sources of business fraud losses |
| Do you take card payments or store card numbers? | Need | Card brands can assess fines and costs after a card breach |
| Does a client, landlord, or partner contract require cyber coverage? | Required | Without it you are in breach of the contract |
| Do you collect health-related information from Washington consumers? | Need, with careful privacy wording | Washington's My Health My Data Act creates privacy claims risk |
If you answered yes to any of the first three, a cyber policy is worth buying. If you answered no to all six, your exposure is small, and a modest policy or a business owners policy endorsement may be a reasonable starting point.
What the Washington data shows about businesses like yours
Trella Commercial analyzed every breach notice filed with the Washington Attorney General, which receives a notice when a breach affects more than 500 Washington residents. Smaller breaches are never filed, so these counts understate how often small businesses are hit.
| Business type in the notices | Notices filed, 2015 to 2026 |
|---|---|
| Retail | 148 |
| Hospitality | 57 |
| Professional services | 57 |
| Software | 42 |
| Legal | 35 |
| Construction | 20 |
| Clothing | 20 |
Among business filers, 73% of breaches were cyberattacks, and businesses filed 231 ransomware notices, more than any other sector. The median breach in the whole dataset affected 1,888 Washington residents, and 69% affected 5,000 or fewer. Many of these are ordinary companies, not household names, whose customers or employees had to be told their information was exposed. See the full analysis.
The costs a small business carries without a policy
None of these depend on the size of the business, and all of them land at once:
- A breach attorney to determine what the law requires and draft the notices
- Forensic investigators to find how the attacker got in, what was taken, and whether they are gone
- Notification to every affected person, and to the Attorney General above 500 Washington residents, within 30 days
- Credit monitoring and a call center, commonly offered to affected people
- Restoring systems and data, often with outside IT help working nights and weekends
- Lost income while you cannot schedule, bill, ship, or take payments
- Lawsuits and regulatory inquiries from people whose data was exposed
- Money lost to fraud, if a fake invoice or payment change got through
A cyber policy is built around exactly this list. See what cyber insurance covers.
When a small policy, or none, can be reasonable
- Very little data: you keep no customer records beyond names and emails, and no employee records beyond what your payroll provider holds.
- No electronic payments: card payments run through a processor's hosted page, and you do not send or receive wires.
- You can work on paper: an outage would be an inconvenience, not a shutdown.
Even then, check your vendors. If your payroll, booking, or practice software provider is breached, the duty to notify your customers or employees usually stays with you. A small policy, or a business owners policy data breach endorsement, can cover that response.
Common objections
| Objection | The reality |
|---|---|
| "We're too small to be a target." | Most attacks are automated: phishing emails and scans for weak passwords hit thousands of businesses at once. Washington's records include hundreds of ordinary businesses. |
| "Our IT person has it handled." | Good security lowers the odds and the premium. It does not pay for notification, lawyers, lost income, or lawsuits when something gets through. |
| "Our data is in the cloud, so it's their problem." | Cloud providers secure their platform; you are generally responsible for your accounts, passwords, and data. A stolen login is your breach. |
| "We'd just pay out of pocket." | Run the list above for a breach of every customer and employee record you hold, plus a week offline. Then decide. |
| "Our general liability covers it." | Usually not. Most general liability policies exclude data breaches outright. |
Next steps
- Answer the six questions above honestly.
- List the data you hold and how many people it covers.
- Note how long you could operate without your systems.
- Check every contract for cyber insurance requirements.
- Size a limit with our guide to how much cyber insurance a small business needs.