The short version
- Start with records. Count every person whose sensitive data you hold: customers, patients, clients, and current and former employees. Breach response costs scale with that number.
- Then downtime. Estimate the gross profit you would lose, plus extra expenses, for one to two weeks without your systems.
- Then money movement. Your largest single wire or ACH payment is the floor for social engineering and funds transfer coverage.
- Then contracts. A client or landlord minimum is a floor, not a target.
- Most reported Washington breaches are mid-sized. In Attorney General filings, 40% of breaches affected 1,001 to 5,000 Washington residents and 29% affected 501 to 1,000. Size for the records you actually hold, not for the median.
Step 1: Count the records you hold
Breach response costs (the attorney, forensics, letters, call center, and credit monitoring) rise with the number of people you must notify. Count everyone whose name sits alongside sensitive data in your systems, email, and files:
| Record type | Where it hides | Include it? |
|---|---|---|
| Customer or patient records with birth dates, ID numbers, health, or financial details | Practice management, CRM, booking, accounting software | Yes |
| Current and former employees | Payroll exports, I-9s, W-2s, HR folders | Yes, including former employees |
| Clients' tax, financial, or legal documents | Shared drives, email attachments, scanned files | Yes |
| Card numbers | Only if you store them; hosted payment pages usually mean you do not | Yes, if stored |
| Names and emails only | Newsletter lists | Lower risk, but a username plus password is personal information in Washington |
Then compare your count with what Washington breaches actually look like. Among notices filed with the Attorney General, which only receives breaches affecting more than 500 residents:
| Washington residents affected | Share of notices |
|---|---|
| 501 to 1,000 | 29% |
| 1,001 to 5,000 | 40% |
| 5,001 to 10,000 | 9% |
| 10,001 to 50,000 | 14% |
| More than 50,000 | 8% |
Source: Trella Commercial's analysis of Washington Attorney General breach notices. Breaches under 500 Washington residents are not filed and do not appear here.
To turn the count into dollars, ask your broker or a breach response provider for current per-person notification and monitoring pricing, and add the attorney and forensic costs, which do not shrink much for a small breach.
Step 2: Estimate downtime
Business interruption pays lost net income plus continuing expenses and extra costs while your systems are down from a covered event. A simple worksheet:
| Line | How to estimate |
|---|---|
| Daily gross profit | Revenue per working day minus the costs that stop when you stop |
| Continuing expenses | Payroll you would keep paying, rent, loan payments, software subscriptions |
| Extra expense | Overtime, temporary equipment, outside IT, manual workarounds |
| Days offline | Ransomware recovery often takes days to weeks; use one to two weeks as a starting assumption, longer if your backups are not tested |
| Waiting period | The policy pays only after this many hours; subtract it |
Multiply daily loss by days offline. If you depend on one cloud system, such as scheduling, practice management, or ecommerce, ask whether the policy includes dependent business interruption for that vendor's outages.
Step 3: Find your largest payment exposure
Social engineering and funds transfer fraud coverage is usually a sublimit, often much smaller than the main limit. Size it from:
- Your largest single outgoing payment: a supplier invoice, a payroll run, a property or equipment purchase
- Client funds you move, for example a trust or escrow account
- Customer payments that could be redirected by a fake invoice from your email
If your largest payment is larger than the sublimit offered, ask for more, look at a crime policy to sit alongside, or tighten verification procedures so a fake request cannot get through.
Step 4: Check your contracts
Client agreements, leases, vendor contracts, and grants often set a minimum cyber or technology errors and omissions limit, and sometimes require specific coverages such as privacy liability or regulatory coverage. Read the insurance clause for:
- The minimum limit and whether it is per claim or aggregate
- Required coverage parts, such as privacy liability, network security, or media
- Whether the other party must be an additional insured
- How long coverage must stay in place after the work ends
A contract minimum is the least you can carry, not a measure of your exposure. If Steps 1 to 3 add up to more, the higher number wins.
Step 5: Put the number together
| Component | Your estimate |
|---|---|
| Breach response for your record count (Step 1) | |
| Downtime for one to two weeks (Step 2) | |
| Liability and regulatory defense, if data is exposed | Discuss with your broker; it rises with record count and data type |
| Total first-party and liability exposure | Sum of the above |
| Largest payment exposure (Step 3) | Set the social engineering sublimit from this |
| Contract minimum (Step 4) | The floor |
Compare the total with the limits insurers offer. Small business cyber policies are commonly written at limits such as $1 million, $2 million, or higher, with each coverage part either sharing that aggregate or carrying its own sublimit.
Sublimits, retentions, and the details that change the answer
- Aggregate limit: everything the policy pays in a year. A ransomware event can draw on five coverage parts at once, so the aggregate must cover them together.
- Sublimits to check: social engineering and funds transfer fraud, regulatory fines and penalties, PCI assessments, dependent business interruption, and reputational harm.
- Breach response inside or outside the limit: some policies pay breach response costs in addition to the aggregate; others erode it.
- Retention: a higher retention lowers premium. Pick one you could pay from cash in a bad month.
- Coinsurance: some ransomware coverage makes you share a percentage of the loss.
Example: how the steps play out
Illustrative only. The business is invented, and the figures stand in for your own estimates, not market benchmarks.
A physical therapy clinic with 12 employees holds records for about 6,000 current and former patients, plus 40 current and former employees. It cannot schedule or bill without its practice software, which is hosted by a vendor. Its largest outgoing payment is about $60,000 for equipment.
- Records: about 6,000 people, which puts a breach in the 5,001 to 10,000 band that 9% of Washington notices fall into. The clinic asks its broker for per-person response pricing at that count.
- Downtime: two weeks of lost gross profit plus payroll it would keep paying. Dependent business interruption matters because the practice software is a vendor's.
- Money movement: the social engineering sublimit should be at least $60,000, and the clinic adds a call-back rule for payment changes.
- Contracts: a hospital referral agreement requires $1 million of cyber coverage.
- Data type: some patient data is HIPAA data; its website and marketing data may fall under Washington's My Health My Data Act, so privacy liability wording matters.
The clinic ends up comparing $1 million and $2 million quotes, with the response, downtime, and privacy exposure, not the contract minimum, deciding between them.