The short version
- Cyber insurance has two halves: first-party coverage for your own costs (investigation, notification, ransomware, lost income) and third-party coverage for claims and regulatory actions brought against you.
- In Washington, 74% of the data breaches reported to the Attorney General from July 2023 to July 2026 were cyberattacks, and 58% of those were ransomware. The median breach affected 1,888 Washingtonians. See the full analysis.
- Your general liability policy almost certainly excludes data breaches, and a business owners policy usually offers little or nothing.
- Washington law requires notice to affected residents within 30 days of discovering a breach, and to the Attorney General when more than 500 Washington residents are affected. Idaho requires notice "in the most expedient time possible and without unreasonable delay."
- The application asks about your security controls, especially multifactor authentication and backups. Your answers become part of the policy, so they have to be accurate.
Why it matters for small businesses in Washington
Trella Commercial analyzed every data breach notice filed with the Washington Attorney General: 1,675 notices as of October 2026. The headline is that breaches are common, mostly criminal, and mostly not headline events.
- Most breaches are attacks. 74% of the 705 notices filed from July 2023 to July 2026 were cyberattacks. Ransomware was 58% of those attacks.
- Businesses are the largest group. Businesses filed 42% of recent notices, ahead of health care at 24%.
- Most breaches are small. The median breach affected 1,888 Washington residents, and 69% affected 5,000 or fewer. Washington only requires a filing with the Attorney General above 500 residents, so the many smaller breaches never appear in this data at all.
- Deadlines are routinely missed. For breaches discovered since March 2020, only 17% of notices reached the Attorney General within 30 days. The median was 78 days.
- The exposed data is the expensive kind. 63% of notices involved Social Security numbers and 37% involved medical information.
The full methodology and charts are in Washington Data Breaches by Industry, 2015 to 2026.
What cyber insurance covers
A cyber policy is a bundle of coverage parts, each with its own limit. Not every policy includes every part, and some are only available by endorsement, so the declarations page matters more than the policy name. Each part is explained in detail in what cyber insurance covers.
| Coverage part | What it pays for | Example |
|---|---|---|
| Breach response | Forensic investigators, a breach attorney (often called a breach coach), customer notification, call centers, credit monitoring, and public relations | Malware is found on the server holding client files |
| Cyber extortion | Negotiation and, where lawful and approved by the insurer, a ransom payment (ransomware guide) | Files are encrypted with a ransom demand |
| Business interruption | Lost net income and extra expense while your systems are down (business interruption guide) | Your scheduling and billing system is offline for a week |
| Data restoration | Rebuilding or restoring data and software | Backups have to be restored and reconfigured |
| Funds transfer and social engineering fraud | Money sent because of a fake or altered payment instruction, usually under a sublimit | An employee pays a "vendor" invoice with new bank details |
| Privacy and network security liability | Defense and settlements when customers, patients, or clients sue over exposed data | Patients sue after their records are exposed |
| Regulatory defense and penalties | Responding to regulators and, where insurable by law, fines and penalties | A state Attorney General investigates the breach |
| Payment card (PCI) assessments | Fines and assessments from card brands after a card data breach | A point-of-sale breach exposes card numbers |
| Media liability | Claims of defamation or copyright infringement from your website and online content | A photo on your site draws an infringement claim |
What cyber insurance usually does not cover
- Incidents you knew about before the policy started
- Bodily injury and physical property damage
- Widespread failures of outside infrastructure, such as a regional power or internet outage
- Upgrading your systems beyond what you had before the incident (betterment)
- Losses tied to security controls you said you had on the application but did not
- Acts of war, under exclusions whose wording varies a great deal by insurer
Funds transfer fraud deserves its own check (full guide to wire fraud coverage). Many policies cover it only under a social engineering endorsement with a low sublimit, and some exclude it. If your business sends or receives large payments, ask exactly what the policy pays and when. More on the exclusions and conditions that deny claims: what cyber insurance does not cover.
Does your business owners policy or general liability already cover a breach?
Usually not. Most current general liability forms exclude claims arising from access to or disclosure of confidential or personal information. The full explanation, including the court cases behind it, is in does a BOP or general liability policy cover a data breach? Some business owners policies add a small data breach endorsement, but its limits tend to be low and it rarely includes ransomware, business interruption from a cyber event, or funds transfer fraud.
| Policy | Breach response costs | Lawsuits over exposed data | Ransomware | Wire fraud |
|---|---|---|---|---|
| General liability | Generally excluded | Generally excluded | No | No |
| Business owners policy | Sometimes, under a small endorsement | Sometimes, limited | Rarely | Rarely |
| Crime policy | No | No | No | Sometimes, depending on the insuring agreements |
| Cyber policy | Yes | Yes | Yes | Often, under an endorsement and sublimit |
A professional liability or tech errors and omissions policy covers mistakes in your professional services, which is a different risk. Technology companies often need both, sometimes combined on one form. See cyber vs tech E&O vs crime insurance.
Washington and Idaho breach notice laws
If a breach exposes personal information, state law decides who you must tell and how fast. These requirements apply whether or not you have insurance. A cyber policy's breach response coverage pays for complying with them.
| Requirement | Washington (RCW 19.255) | Idaho (Idaho Code 28-51) |
|---|---|---|
| What counts as personal information | Name plus Social Security number, driver's license or state ID, financial account number with its access code, full date of birth, health insurance ID, medical information, biometric data, passport, student, or military ID; also a username or email with its password | Name plus Social Security number, driver's license or Idaho ID, or financial account number with its access code |
| Deadline to notify residents | Most expedient time possible, no more than 30 calendar days after discovery, with limited exceptions such as a law enforcement request | Most expedient time possible and without unreasonable delay; no fixed number of days |
| Notice to the Attorney General | Required within 30 days when more than 500 Washington residents are notified | Not required for private businesses (state agencies must notify within 24 hours) |
| Vendors holding your data | Must notify you immediately after discovering a breach | Must notify you immediately if misuse has occurred or is reasonably likely |
| Encrypted data | No notice needed unless the encryption key was also compromised | Encrypted data falls outside the definition of a breach |
| Risk of harm | No notice needed if the breach is not reasonably likely to subject consumers to a risk of harm | Notice is required when misuse has occurred or is reasonably likely to occur |
| Enforcement | The Attorney General enforces under the Consumer Protection Act; injured consumers can sue for damages under the breach law | Fines of up to $25,000 per breach for intentionally failing to notify |
For the full Washington rules, including what the notice must say and how to deliver it, see Washington data breach notification law.
Two practical consequences. First, when a vendor is breached, the duty to notify your customers usually stays with you as the owner of the data. Second, a Washington business that holds data on Idaho customers, or the reverse, has to follow both states' rules.
Washington's My Health My Data Act
Washington's My Health My Data Act (RCW 19.373) reaches far beyond hospitals and clinics. It covers "consumer health data" collected by businesses that are not subject to HIPAA, such as gyms, wellness studios, and apps, and it took effect for small businesses on June 30, 2024. Violations are treated as unfair or deceptive acts under Washington's Consumer Protection Act. If your business collects health-related information from Washington consumers, check that your cyber policy's privacy liability and regulatory coverage responds to claims under it. More in Washington's My Health My Data Act.
How much coverage you need and what it costs
There is no standard price. Insurers rate each business on:
- Revenue and industry
- How many records you hold, and how sensitive they are (health, financial, Social Security numbers)
- Your security controls, especially multifactor authentication, backups, and endpoint protection
- Prior incidents and claims
- The limit and retention (deductible) you choose
- Coverage for funds transfer fraud and business interruption
More on each factor, and eight ways to lower the premium: what drives the cost of cyber insurance.
To size a limit, work through three numbers: what it would cost to investigate and notify every person whose data you hold, how much income you would lose in a week or two offline, and what your largest payment exposure is. Then check your contracts. Client agreements, leases, and vendor contracts often set a minimum cyber limit (how to read the clause), and that minimum is a floor, not a recommendation. Step-by-step sizing, with a worked example: how much cyber insurance a small business needs.
What the application will ask
Cyber applications have become security questionnaires. Expect questions like these:
- Is multifactor authentication required for email, remote access, and administrator accounts?
- Are backups kept offline or otherwise separated from your network, and have you tested restoring them?
- Do you use endpoint detection and response software on computers and servers?
- How quickly are critical security patches applied, and do you run any unsupported software?
- Do employees receive phishing and security awareness training?
- Before changing a vendor's bank details or sending a large payment, do you confirm by calling a known phone number?
Answer carefully. The application becomes part of the policy, and an inaccurate answer about a control like multifactor authentication can give the insurer grounds to deny a claim. If a control is missing, it is usually better to add it before you apply. Every section of a typical application, with what a strong answer looks like: what a cyber insurance application asks.
If you have an incident
The full hour-by-hour checklist is in what to do in the first 24 hours after a data breach.
- Call your insurer's breach hotline or your broker before hiring outside vendors. Many policies require you to use approved vendors, or to get consent before spending money, for costs to be covered.
- Preserve evidence. Do not wipe or rebuild systems until forensics says it is safe.
- Do not pay a ransom or respond to the attacker without the insurer and its advisors.
- Track the clock. In Washington, the 30 days to notify residents runs from discovery of the breach.
Who needs it most
Every business that stores customer data, takes payments, or wires money has some exposure (six questions to decide whether you need a policy). It is highest for:
- Health care, dental, and wellness businesses, which hold medical information covered by HIPAA or Washington's My Health My Data Act. See cyber insurance for dental and medical practices and how one dental practice structured its cyber coverage.
- Professional services firms holding client financial and tax records, and anyone with a trust account. See cyber insurance for law and CPA firms, the law firm story, and professional services.
- Technology and IT companies, whose breach can become their clients' breach. See the managed IT provider story and technology companies.
- Retail and ecommerce businesses that handle card data and depend on online sales. See the ecommerce story and retail.
- Real estate brokerages, escrow agents, and property managers, who handle closing funds and deposits. See wire fraud in Washington real estate closings.
For the coverage at a glance, see cyber liability insurance.