Open plan business office with desks and monitors, empty, in early evening light

Cyber liability insurance for businesses that handle data

A phishing email tricks an accounts payable staffer into wiring $47,000 to a fraudulent account. A ransomware attack encrypts a medical practice's entire patient record system, and the attackers want $85,000 to restore access. A retailer's point-of-sale system is quietly breached for six weeks, and 12,000 customer card numbers are exfiltrated before anyone notices.

Talk to an expert

Get a quote

Continue

Core coverage

What cyber liability insurance covers

Cyber policies divide into two tracks. First-party coverage responds to your direct costs after an incident. Third-party coverage responds to claims made against you by others. Understanding the split is the key to buying the right limits.

01First party

Forensic investigation. How they got in, and how long they were there.

A specialist firm identifies how the attacker got in, what they accessed, and how long they were in your system. Ransomware detected on an internal server, and the forensic team traces entry to a phishing email.

02First party

Breach notification. Telling the people whose data it was.

Mass notification campaigns, call centre staffing, and credit monitoring for affected individuals. 10,000 customer records exposed, and state law requires notification within 30 days.

03First party

Ransomware and cyber extortion.

Ransom payment, professional negotiators, and data restoration costs. Attackers encrypt patient records and demand $85,000 for a decryption key.

04First party

Business income loss.

Revenue lost while systems are offline due to a cyber event. An e-commerce site is offline for five days following a breach, against a daily revenue loss of $12,000.

05Third party

Privacy liability.

Defence and settlement of lawsuits from individuals whose data was compromised. A class action filed after 50,000 customer records were exposed in a data breach.

06Third party

Regulatory defence and fines.

Legal defence for regulatory investigations, and the applicable fines and penalties. A HIPAA investigation after a PHI breach, where fines for willful neglect reach $1.5 million annually.

07Third party

Network security liability.

Claims brought when your own compromised systems are used to attack somebody else, plus media liability for defamation or copyright arising from digital content.

Cyber and technology errors and omissions are different policies, and a business that sells software or technical advice usually needs both. Our brokers place them together rather than leaving the seam between them for a claim to find, and read the professional liability wording against your client contracts at the same time as the cyber schedule, alongside the wider business insurance stack where more than one policy is in play.

Who is buying

Four businesses, four different cyber policies

Any business that stores, transmits or processes data carries cyber exposure. Some industries carry it harder than others. Pick the closest match and we will tell you how an underwriter reads it.

Healthcare providers and medical practices

PHI triggers HIPAA's mandatory breach reporting and significant regulatory penalties. Healthcare operators face some of the highest per-record breach costs of any sector.

What underwriters askRecord counts, how PHI is stored, and whether you host or outsource your EHR
The claim that shows upRansomware on patient records, PHI exposure, and the HIPAA investigation that follows
Endorsements it needsRegulatory defence sized to the record count, and a named breach response panel
Watch forHIPAA willful neglect fines reach $1.5 million annually, and the fine sits outside your notification costs rather than inside them.Talk to a broker about this

Professional services firms, manufacturers running connected OT and IoT, and small businesses all carry this exposure too. 43% of all cyberattacks target small businesses, in part because security controls are thinnest there. Size is not a defence.

Laptop open on an otherwise tidy office desk in warm morning light

What actually triggers a cyber claim

A cyber policy responds to the incident and to its consequences. It does not respond to the quality of the product or the advice you sold. That line is where businesses discover they bought one policy and needed two.

Some examples of where the line falls:

Covered: Attackers encrypt your systems and you pay a forensic firm, a negotiator and a notification vendor. First-party cover responds.

Not covered: Your software has a defect that costs a client money. That is technology errors and omissions, not cyber.

Covered: A regulator opens an investigation after customer records are exposed and you need defence counsel. Third-party cover responds.

Not covered: An employee deliberately steals data and sells it. Intentional illegal acts are not insurable.

Timing matters as much as the trigger. A cyber policy is written on a claims-made basis with a retroactive date, so a breach that began before that date can fall outside the policy even though you discovered it inside the period. That is why retroactive date continuity matters more than price when you move carrier, and it is worth understanding how a claims-made policy responds before you switch on the strength of a quote alone.

The gaps

What cyber liability insurance does not cover

Cyber policies are specific. Assuming your existing coverage fills these gaps is how businesses end up uninsured at the worst possible moment. Eight that matter on a cyber schedule.

Technology errors and omissions

WHAT YOU NEED

Tech E&O or professional liability. A claim about the product or the advice you sold is a different policy.

Nation-state attacks

WHAT YOU NEED

The war exclusion. Wordings vary widely and some are broad enough to catch a criminal attack attributed to a state. Discuss it before binding, not after.

Security hygiene failures

WHAT YOU NEED

Multi-factor authentication, patching and staff training are conditions now rather than discounts. A control you said you had and did not is a coverage argument.

Prior known breaches

WHAT YOU NEED

Anything you knew about before inception. Check retroactive date continuity every time you move carrier.

Bodily injury and property damage

WHAT YOU NEED

General liability. A cyber policy does not respond to somebody being hurt or to physical damage.

Intentional illegal acts

WHAT YOU NEED

Nothing covers this, by anyone, at any price. It is the one exclusion on this list with no endorsement behind it.

Upgrades and betterment

WHAT YOU NEED

The cost of rebuilding a system better than it was. The policy restores you to where you were, not to where you wish you had been.

Contractual penalties you agreed to

WHAT YOU NEED

Service credits and liquidated damages you signed up for are a commercial promise, not an insured loss.

The war exclusion and the social engineering sub-limit are the two that most often separate a policy that responds from one that argues. Both are readable at quote stage and expensive to discover later. Speak to our team about which wording your business actually needs, and ask about cover for employee injury at the same time if you are carrying staff.

Two tracks

The loss splits in two, and the sub-limit sits on the half people forget

Cyber cover is bought as one policy and used as two. Almost every buying mistake on this page comes from sizing one track and assuming the other followed.

Network switch with patch cables running into it, photographed close up

Your own recovery costs

Forensic investigation, notification, credit monitoring, ransom and negotiators, lost income while systems are down, and crisis PR. This half is spent in the first weeks and it is spent whether or not anybody ever sues you. Forensic investigation alone runs $50,000 to $200,000, and notification runs $3 to $5 per record.

Stack of legal documents and bound volumes on a desk

What you owe everyone else

Privacy lawsuits from the individuals whose data was exposed, regulatory defence and fines, network security liability when your systems are used to attack somebody else, and media liability. This half arrives months later and can run into the millions before a single settlement is reached.

Close up of a printed policy schedule with a magnifier resting on the fine print

The sub-limit on the half people forget

Social engineering losses, which means wire fraud and increasingly deepfake instruction, are usually written under a sub-limit rather than the policy limit. Some carriers cap it at $100,000 on a $2 million policy. It is the single most common gap between the cover a business thinks it bought and the cover it has.

None of this is unusual and none of it is hidden. It is written in the schedule, and reading the schedule is the job. Our brokers compare sub-limits, war exclusion language and retroactive dates across every quote before you see them, and check the certificate wording your contracts ask for when a client wants proof of cover.

Speak to our team

Endorsement check

Tick what your business actually handles

Each line below is something an underwriter will ask about, and each one changes the schedule. Nothing here is a quote and nothing here is priced. It shows which parts of a cyber policy your business actually has to negotiate.

What your schedule has to carry

Tick what applies and the cover it implies appears here.

Take this to your renewal. A broker can tell you in one call which of these your current schedule already answers, and at what sub-limit.

Speak to our team

Cost

What drives the cost of cyber liability insurance

There is no flat answer, and any number quoted without seeing your controls is a guess dressed up as a price. Cyber premiums stabilised through 2024 and 2025 after the ransomware spike and the market is more competitive now, but underwriters are scrutinising controls far more closely than they used to. Six inputs move a cyber premium more than anything else.

01

Record count and data type

How many records you hold and what kind. Health and card data price differently from a mailing list, because the notification obligation and the regulator behind it are different.

Effect on premium
02

Security controls

Multi-factor authentication, endpoint detection, offline backups and a documented incident response plan. This is the input a business can actually change, and it is the one underwriters look at first.

Effect on premium
03

Industry and regulatory exposure

Healthcare, finance and retail carry mandatory reporting regimes and named penalties. The regulator is part of the rate.

Effect on premium
04

Revenue and dependency

Revenue sets the business interruption exposure, and how much of it depends on systems being up sets how fast that exposure accrues.

Effect on premium
05

Claims and incident history

Prior incidents, and whether the findings were remediated. A closed-out incident with evidence reads very differently from an open one.

Effect on premium
06

Limits and sub-limits

The policy limit, and separately the social engineering, regulatory and dependent business interruption sub-limits underneath it. Each one is priced.

Effect on premium

Three marks is an input that moves a cyber premium more than the others here. It is a relative weighting drawn from how underwriters behave, not a rate, and not a quote.

What that adds up to in practice

Most small businesses carry $1 million in cyber limits. That sounds like a lot until you stack it: forensic investigation at $50,000 to $200,000, notification for 10,000 records at $3 to $5 each, regulatory defence, income loss during downtime, and third-party liability if clients sue. A mid-sized breach can consume a $1 million policy before the class action is filed. Cyber business interruption is also a distinct trigger from property business interruption, and the limits need to reflect the actual exposure under each. Our brokers work through that calculation as part of every submission.

Talk to an expert

Process

How a placement works

We understand your business first, then take it to the carriers who want to write it. An advisor walks you through the options and what they cost. No two files are the same, so what follows is the shape of a placement rather than a script.

  1. Loss runs and a payroll schedule spread on a desk beside a calculator and laptop

    We understand the business first

    What you do, where, with how many people, and what your contracts oblige you to carry. Those answers decide which markets will look at the file at all, and how much of the rest of this applies to you.

  2. Brokerage desk with a monitor in morning light

    We match it to the carriers who want to write it

    One set of information goes to underwriters with genuine appetite for your work rather than whoever happened to quote last renewal. An advisor talks you through what comes back and what it costs.

  3. Stamped certificate on a clipboard with a pen and a magnifier

    After bind, certificates checked against the wording the contract asks for

    A main contractor wants proof before your crew can start, and this is how COIs get issued here. We read the certificate request against your contract so it asks the carrier for the wording that contract needs rather than a generic form that usually fails review.

No federal law mandates it, but contracts increasingly do. Client agreements, vendor onboarding and data processing terms routinely require it at a stated limit, and some state regulators expect it of licensed firms. In practice it is required by whoever you want to do business with rather than by statute.

First-party responds to your own costs after an incident: forensics, notification, ransom, lost income. Third-party responds to claims made against you by other people: privacy lawsuits, regulatory action, network security liability. Most policies carry both, at different limits, and sizing one does not size the other.

Usually, but under a sub-limit rather than the full policy limit. Social engineering and funds transfer fraud cover is where wire fraud and deepfake instruction sit, and some carriers cap it at $100,000 on a $2 million policy. Read the sub-limit before you rely on it.

Cyber extortion cover typically pays the ransom, the professional negotiator and the data restoration costs. Whether a payment can lawfully be made is a separate question, and sanctions screening is part of the claims process.

Yes. Outsourcing the systems does not outsource the liability to the people whose data you hold. It also adds a dependency, because an outage inside your provider's network can stop your business. Dependent business interruption cover is what answers that.

It depends entirely on the war exclusion wording, which varies widely between carriers. Some are narrow and some are broad enough to catch a criminal attack later attributed to a state. This is a wording to compare before binding rather than after.

Start from your record count for the notification floor, then add forensics, income loss and third-party liability on top. Most small businesses carry $1 million, and a mid-sized breach can use that up before a class action is filed. The right answer depends on your data and on how much of your revenue stops when systems do.

They change what carriers will offer and on what terms. Multi-factor authentication, endpoint detection, offline backups and a documented incident response plan are conditions of cover with most markets now rather than optional extras. We will tell you which controls the underwriters looking at your file are actually asking about.

Get started

Ready to place cyber coverage?

We submit across admitted and E&S markets to find the right coverage at the right price. If your current policy has gaps in its social engineering sub-limit or its war exclusion language, we will find them before a claim does.

  • Sub-limits compared before you see them
  • 100+ carrier portals
  • Admitted and E&S markets
Glass facade of a modern commercial office building in daylight
Export Design
Download files for your developer
General
WordPress Builders