Cyber Insurance for Washington and Idaho Small Businesses: The Complete Guide

Cyber insurance pays the costs of a data breach, ransomware attack, or fraudulent wire transfer: forensic investigation, notifying customers, legal defense, lost income while systems are down, and claims from people whose data was exposed. Most business owners policies and general liability policies do not. Washington gives businesses 30 days to notify affected residents; Idaho requires notice without unreasonable delay.

By Trella Commercial · Updated October 3, 2026

The short version

  • Cyber insurance has two halves: first-party coverage for your own costs (investigation, notification, ransomware, lost income) and third-party coverage for claims and regulatory actions brought against you.
  • In Washington, 74% of the data breaches reported to the Attorney General from July 2023 to July 2026 were cyberattacks, and 58% of those were ransomware. The median breach affected 1,888 Washingtonians. See the full analysis.
  • Your general liability policy almost certainly excludes data breaches, and a business owners policy usually offers little or nothing.
  • Washington law requires notice to affected residents within 30 days of discovering a breach, and to the Attorney General when more than 500 Washington residents are affected. Idaho requires notice "in the most expedient time possible and without unreasonable delay."
  • The application asks about your security controls, especially multifactor authentication and backups. Your answers become part of the policy, so they have to be accurate.

Why it matters for small businesses in Washington

Trella Commercial analyzed every data breach notice filed with the Washington Attorney General: 1,675 notices as of October 2026. The headline is that breaches are common, mostly criminal, and mostly not headline events.

  • Most breaches are attacks. 74% of the 705 notices filed from July 2023 to July 2026 were cyberattacks. Ransomware was 58% of those attacks.
  • Businesses are the largest group. Businesses filed 42% of recent notices, ahead of health care at 24%.
  • Most breaches are small. The median breach affected 1,888 Washington residents, and 69% affected 5,000 or fewer. Washington only requires a filing with the Attorney General above 500 residents, so the many smaller breaches never appear in this data at all.
  • Deadlines are routinely missed. For breaches discovered since March 2020, only 17% of notices reached the Attorney General within 30 days. The median was 78 days.
  • The exposed data is the expensive kind. 63% of notices involved Social Security numbers and 37% involved medical information.

The full methodology and charts are in Washington Data Breaches by Industry, 2015 to 2026.

What cyber insurance covers

A cyber policy is a bundle of coverage parts, each with its own limit. Not every policy includes every part, and some are only available by endorsement, so the declarations page matters more than the policy name. Each part is explained in detail in what cyber insurance covers.

Coverage partWhat it pays forExample
Breach responseForensic investigators, a breach attorney (often called a breach coach), customer notification, call centers, credit monitoring, and public relationsMalware is found on the server holding client files
Cyber extortionNegotiation and, where lawful and approved by the insurer, a ransom payment (ransomware guide)Files are encrypted with a ransom demand
Business interruptionLost net income and extra expense while your systems are down (business interruption guide)Your scheduling and billing system is offline for a week
Data restorationRebuilding or restoring data and softwareBackups have to be restored and reconfigured
Funds transfer and social engineering fraudMoney sent because of a fake or altered payment instruction, usually under a sublimitAn employee pays a "vendor" invoice with new bank details
Privacy and network security liabilityDefense and settlements when customers, patients, or clients sue over exposed dataPatients sue after their records are exposed
Regulatory defense and penaltiesResponding to regulators and, where insurable by law, fines and penaltiesA state Attorney General investigates the breach
Payment card (PCI) assessmentsFines and assessments from card brands after a card data breachA point-of-sale breach exposes card numbers
Media liabilityClaims of defamation or copyright infringement from your website and online contentA photo on your site draws an infringement claim

What cyber insurance usually does not cover

  • Incidents you knew about before the policy started
  • Bodily injury and physical property damage
  • Widespread failures of outside infrastructure, such as a regional power or internet outage
  • Upgrading your systems beyond what you had before the incident (betterment)
  • Losses tied to security controls you said you had on the application but did not
  • Acts of war, under exclusions whose wording varies a great deal by insurer

Funds transfer fraud deserves its own check (full guide to wire fraud coverage). Many policies cover it only under a social engineering endorsement with a low sublimit, and some exclude it. If your business sends or receives large payments, ask exactly what the policy pays and when. More on the exclusions and conditions that deny claims: what cyber insurance does not cover.

Does your business owners policy or general liability already cover a breach?

Usually not. Most current general liability forms exclude claims arising from access to or disclosure of confidential or personal information. The full explanation, including the court cases behind it, is in does a BOP or general liability policy cover a data breach? Some business owners policies add a small data breach endorsement, but its limits tend to be low and it rarely includes ransomware, business interruption from a cyber event, or funds transfer fraud.

PolicyBreach response costsLawsuits over exposed dataRansomwareWire fraud
General liabilityGenerally excludedGenerally excludedNoNo
Business owners policySometimes, under a small endorsementSometimes, limitedRarelyRarely
Crime policyNoNoNoSometimes, depending on the insuring agreements
Cyber policyYesYesYesOften, under an endorsement and sublimit

A professional liability or tech errors and omissions policy covers mistakes in your professional services, which is a different risk. Technology companies often need both, sometimes combined on one form. See cyber vs tech E&O vs crime insurance.

Washington and Idaho breach notice laws

If a breach exposes personal information, state law decides who you must tell and how fast. These requirements apply whether or not you have insurance. A cyber policy's breach response coverage pays for complying with them.

RequirementWashington (RCW 19.255)Idaho (Idaho Code 28-51)
What counts as personal informationName plus Social Security number, driver's license or state ID, financial account number with its access code, full date of birth, health insurance ID, medical information, biometric data, passport, student, or military ID; also a username or email with its passwordName plus Social Security number, driver's license or Idaho ID, or financial account number with its access code
Deadline to notify residentsMost expedient time possible, no more than 30 calendar days after discovery, with limited exceptions such as a law enforcement requestMost expedient time possible and without unreasonable delay; no fixed number of days
Notice to the Attorney GeneralRequired within 30 days when more than 500 Washington residents are notifiedNot required for private businesses (state agencies must notify within 24 hours)
Vendors holding your dataMust notify you immediately after discovering a breachMust notify you immediately if misuse has occurred or is reasonably likely
Encrypted dataNo notice needed unless the encryption key was also compromisedEncrypted data falls outside the definition of a breach
Risk of harmNo notice needed if the breach is not reasonably likely to subject consumers to a risk of harmNotice is required when misuse has occurred or is reasonably likely to occur
EnforcementThe Attorney General enforces under the Consumer Protection Act; injured consumers can sue for damages under the breach lawFines of up to $25,000 per breach for intentionally failing to notify

For the full Washington rules, including what the notice must say and how to deliver it, see Washington data breach notification law.

Two practical consequences. First, when a vendor is breached, the duty to notify your customers usually stays with you as the owner of the data. Second, a Washington business that holds data on Idaho customers, or the reverse, has to follow both states' rules.

Washington's My Health My Data Act

Washington's My Health My Data Act (RCW 19.373) reaches far beyond hospitals and clinics. It covers "consumer health data" collected by businesses that are not subject to HIPAA, such as gyms, wellness studios, and apps, and it took effect for small businesses on June 30, 2024. Violations are treated as unfair or deceptive acts under Washington's Consumer Protection Act. If your business collects health-related information from Washington consumers, check that your cyber policy's privacy liability and regulatory coverage responds to claims under it. More in Washington's My Health My Data Act.

How much coverage you need and what it costs

There is no standard price. Insurers rate each business on:

  • Revenue and industry
  • How many records you hold, and how sensitive they are (health, financial, Social Security numbers)
  • Your security controls, especially multifactor authentication, backups, and endpoint protection
  • Prior incidents and claims
  • The limit and retention (deductible) you choose
  • Coverage for funds transfer fraud and business interruption

More on each factor, and eight ways to lower the premium: what drives the cost of cyber insurance.

To size a limit, work through three numbers: what it would cost to investigate and notify every person whose data you hold, how much income you would lose in a week or two offline, and what your largest payment exposure is. Then check your contracts. Client agreements, leases, and vendor contracts often set a minimum cyber limit (how to read the clause), and that minimum is a floor, not a recommendation. Step-by-step sizing, with a worked example: how much cyber insurance a small business needs.

What the application will ask

Cyber applications have become security questionnaires. Expect questions like these:

  • Is multifactor authentication required for email, remote access, and administrator accounts?
  • Are backups kept offline or otherwise separated from your network, and have you tested restoring them?
  • Do you use endpoint detection and response software on computers and servers?
  • How quickly are critical security patches applied, and do you run any unsupported software?
  • Do employees receive phishing and security awareness training?
  • Before changing a vendor's bank details or sending a large payment, do you confirm by calling a known phone number?

Answer carefully. The application becomes part of the policy, and an inaccurate answer about a control like multifactor authentication can give the insurer grounds to deny a claim. If a control is missing, it is usually better to add it before you apply. Every section of a typical application, with what a strong answer looks like: what a cyber insurance application asks.

If you have an incident

The full hour-by-hour checklist is in what to do in the first 24 hours after a data breach.

  1. Call your insurer's breach hotline or your broker before hiring outside vendors. Many policies require you to use approved vendors, or to get consent before spending money, for costs to be covered.
  2. Preserve evidence. Do not wipe or rebuild systems until forensics says it is safe.
  3. Do not pay a ransom or respond to the attacker without the insurer and its advisors.
  4. Track the clock. In Washington, the 30 days to notify residents runs from discovery of the breach.

Who needs it most

Every business that stores customer data, takes payments, or wires money has some exposure (six questions to decide whether you need a policy). It is highest for:

For the coverage at a glance, see cyber liability insurance.

Common questions

Do small businesses really need cyber insurance?

If the business stores customer or employee data, takes card payments, or sends wire transfers, the exposure exists whether or not it is insured. In Washington, the median breach reported to the Attorney General affected 1,888 residents, and 69% affected 5,000 or fewer, so most reported breaches involve organizations far smaller than the ones in the news.

Does cyber insurance pay ransoms?

Many policies cover ransom payments under cyber extortion coverage, when the payment is lawful and the insurer approves it in advance. The insurer and its advisors usually manage the negotiation, and payments to sanctioned parties are prohibited.

What is the Washington deadline to report a data breach?

RCW 19.255.010 requires notice to affected Washington residents in the most expedient time possible and no more than 30 calendar days after the breach is discovered, with limited exceptions such as a law enforcement request. If more than 500 Washington residents are notified, the Attorney General must also be notified within 30 days.

Does Idaho require businesses to notify the Attorney General after a breach?

No. Idaho Code 28-51-105 requires state agencies to notify the Idaho Attorney General within 24 hours, but private businesses only need to notify affected Idaho residents, without unreasonable delay, when misuse of their information has occurred or is reasonably likely.

Is cyber insurance the same as crime insurance?

No. Crime insurance covers theft of money and property, including employee theft, and some crime policies cover certain fraudulent transfers. Cyber insurance covers breach response, ransomware, system downtime, and liability for exposed data. Businesses that move large payments often need both, coordinated so a wire fraud loss is not caught between them.

Sources

This guide is general information, not legal advice or a policy. Coverage depends on underwriting and the wording of the policy actually issued. Statutes checked October 2026.

Every guide in this series

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.