Cyber & data

The loss that arrives through the network.

Cyber coverage can respond to ransomware, payment fraud, data breaches, and business interruption. We match the policy to the risks your business has today.

What this covers

First-party loss, third-party liability, and the response.

Cyber policies split into money you lose, money you owe others, and the specialists who show up on day one.

Ransomware & extortion

Negotiation, forensic investigation, restoration, and — where lawful and unavoidable — the ransom itself. The recovery cost usually exceeds the demand. Sub-limits and coinsurance on this coverage are common and worth reading closely.

Business interruption & system failure

Lost income while systems are down, including in many policies an outage at a vendor you depend on. Waiting periods here are measured in hours, and the difference between an eight-hour and a twenty-four-hour retention is substantial for an operating business.

Funds-transfer & social engineering fraud

The most common loss we actually see. An email that appears to come from an executive or a known vendor redirects a payment. Many policies cover this only by endorsement and at a lower sub-limit, so it must be requested specifically rather than assumed.

Privacy liability & regulatory

Claims from customers or employees whose data was exposed, plus regulatory investigations and fines where insurable. Notification obligations are set by state law and trigger faster than most businesses expect.

Breach response

The practical value on day one: a breach coach, forensics, legal counsel, notification services, and credit monitoring. Most small businesses have no plan for the first forty-eight hours, and this is the coverage that supplies one.

The controls carriers now require

Multi-factor authentication, offline or immutable backups, endpoint detection, email filtering, and employee training. These are increasingly conditions of coverage rather than discounts — and a misstatement on the application can jeopardize a claim.

Typically included

What a usable cyber policy carries.

Coverage differs more between cyber carriers than in almost any other line.

Ransomware and extortionBusiness interruption with a short waiting periodDependent business interruptionFunds-transfer fraud endorsementSocial engineering coveragePrivacy and network security liabilityRegulatory defenseBreach response servicesData restorationNot sure? Ask us
Where policies fall short

Where cyber programs fall down.

Almost always in the sub-limits rather than the headline number.

01

Relying on the small endorsement inside a BOP

A modest cyber add-on is useful as a first layer and inadequate for a genuine ransomware event. The limit is frequently a fraction of what recovery costs.

02

No social engineering coverage

The most frequent loss is often the one excluded. Funds-transfer fraud commonly requires a specific endorsement and carries its own lower sub-limit.

03

Application answers that do not match reality

Cyber applications ask direct questions about MFA, backups, and training. Answering aspirationally rather than accurately can void coverage precisely when it is needed.

04

A waiting period longer than the outage

If business interruption does not begin until twenty-four hours in, a twelve-hour outage that cost real money produces no recovery.

Common questions

Cyber questions from owners.

Usually beginning with whether they are a target at all.

We are small. Are we really a target?

Small businesses are targeted precisely because their controls are lighter and their ability to pay is real. Most attacks are automated and opportunistic rather than chosen. If you hold customer data, move money, or depend on systems to operate, the exposure exists.

Does our general liability policy cover a data breach?

Generally no. Most general liability forms exclude electronic data and cyber events explicitly. This is a standalone coverage for a reason.

What do carriers require before they will quote?

Multi-factor authentication on email and remote access is close to universal now, along with tested backups kept offline or immutable, endpoint detection, and documented employee training. These have shifted from discounts to prerequisites over the last several years.

If an employee wires money to a fraudster, are we covered?

Only if the policy includes social engineering or funds-transfer fraud coverage — often an endorsement with its own sub-limit rather than part of the base form. It is the first thing we check on any policy someone already holds.

Our review

What we review on a cyber policy.

Every sub-limit, not just the aggregate
Social engineering and funds-transfer coverage
Business interruption waiting period
Dependent business interruption for vendors
Ransomware coinsurance provisions
Breach response panel and whether you may choose counsel
Application answers against actual controls
Retroactive date and prior-acts coverage

Two questions tell us most of what we need.

What data do you hold, and how does money leave the business? Start there and we will size the rest.

Learn moreCall us