The short version
- General liability was written for injuries and property damage, not data. Electronic data is not "tangible property" under the standard form, so a data loss is not property damage.
- The data breach exclusion: in 2014, the Insurance Services Office (ISO), which drafts the standard forms most insurers use, released endorsements excluding claims arising from access to or disclosure of confidential or personal information. They are now widely used.
- The personal injury argument mostly lost. Before those exclusions, some businesses argued that a breach was a "publication" violating privacy. Courts split, and the exclusion was written to close the question.
- Business owners policies may add a little. Some include or offer a data breach or "cyber" endorsement, usually with a low limit and narrow coverage.
- What is almost never covered by either: ransomware, your lost income from a cyber event, wire fraud, and regulatory penalties.
What each policy does and does not do
| Cyber loss | General liability | Business owners policy | Cyber policy |
|---|---|---|---|
| Forensics, breach attorney, notification | No | Sometimes, under a small endorsement | Yes |
| Customers sue over exposed data | Usually excluded | Sometimes, limited | Yes |
| Ransomware negotiation and payment | No | Rarely | Usually |
| Lost income while systems are down | No | Rarely; property business income needs physical damage | Yes, after a waiting period |
| Restoring data and software | No | Small built-in limits are common | Yes |
| Employee tricked into wiring money | No | Rarely | Often, under a sublimit |
| Attorney General investigation | No | Rarely | Usually |
| Card brand (PCI) assessments | No | Rarely | Often |
Why general liability does not cover a breach
Electronic data is not property
The standard general liability form covers "property damage," and defines it in terms of tangible property. The current form states that electronic data is not tangible property. So when a hacker corrupts or steals data, there is no property damage for coverage to attach to.
The 2014 data breach exclusions
Some policyholders tried a second route: the "personal and advertising injury" part of general liability, which covers "oral or written publication, in any manner, of material that violates a person's right of privacy." If hackers expose customer records, is that a publication?
Courts disagreed:
| Case | What happened | Result |
|---|---|---|
| Zurich American Insurance Co. v. Sony (New York trial court, 2014) | Hackers stole personal information of millions of PlayStation users, and Sony faced dozens of class actions | No duty to defend: the "publication" was by the hackers, not by Sony. The parties settled during the appeal. |
| Travelers v. Portal Healthcare Solutions (U.S. Court of Appeals, Fourth Circuit, 2016) | Patient records sat on an unsecured server, viewable online for months | Duty to defend: making the records available online was a publication under the policy. |
ISO responded by releasing endorsements in 2014 (forms CG 21 06, CG 21 07, and CG 21 08) that exclude injury or damage arising out of any access to or disclosure of confidential or personal information. They expressly exclude notification costs, credit monitoring, forensics, and public relations, the very costs a breach creates. Most insurers now attach one of these or their own version, so the Portal Healthcare argument rarely helps a business today.
What a business owners policy may add
A business owners policy (BOP) combines property and general liability, so it starts with the same data breach gaps. Some BOPs add:
- Small built-in limits for restoring electronic data and for interruption of computer operations
- An optional data breach endorsement for notification and response costs, usually with a modest limit
- A "cyber" endorsement that bundles a few first-party costs, sometimes with limited liability coverage
These can help with a small, simple incident. They rarely include ransomware, cyber business interruption, funds transfer fraud, or regulatory defense, and their limits are often far below what a breach notice to a few thousand people costs to handle. They also tend to share limits with other parts of the BOP.
How to check your own policy
- Find the general liability exclusions schedule on your declarations page or forms list. Look for CG 21 06, CG 21 07, CG 21 08, or a company form titled something like "Access or Disclosure of Confidential or Personal Information."
- Search the BOP forms list for "data compromise," "data breach," "cyber," "electronic data," or "computer operations." If you find one, note its limit, what it covers, and whether liability is included.
- Check for funds transfer or social engineering coverage anywhere in your program, including a crime policy. If it is missing everywhere, a fake invoice is uninsured.
- Look at business income wording. Property business income usually requires direct physical loss or damage, which a ransomware attack does not cause.
- Compare the limits to a realistic incident: notifying every customer and employee whose data you hold, plus a week or two offline.
A broker can do this in one pass. It is part of a free policy review.
When the BOP endorsement might be enough, and when it is not
| Situation | BOP endorsement | Standalone cyber |
|---|---|---|
| Very little customer data, no card storage, payments through a processor | May be a reasonable start | Still worth pricing |
| You hold Social Security numbers, health information, or financial records | Usually too small | Recommended |
| Your business stops if systems go down | Will not cover lost income from a cyber event | Recommended |
| You send or receive large payments by wire or ACH | Usually no fraud coverage | Recommended, with social engineering |
| A client or landlord contract requires cyber coverage | Rarely satisfies the requirement | Usually required |
| You collect health-related data from Washington consumers | Unlikely to address privacy law claims | Recommended; see the My Health My Data Act |