Cyber risk is not limited to technology companies or large corporations. Any business that uses email, online banking, cloud software, payment systems, employee records, customer information, or connected equipment can experience a costly cyber event.
Small businesses depend on technology
Businesses use technology to process payments, communicate with clients, issue invoices, manage payroll, store contracts, schedule employees, and maintain customer records. When those systems become unavailable or compromised, the loss can affect revenue, reputation, and the ability to serve customers.
A cyber event does not always involve a sophisticated hacker. It may begin with a fraudulent email, reused password, lost laptop, misdirected attachment, dishonest employee, compromised vendor, or an incorrect system setting that exposes information.
A general liability policy may not be enough
Traditional general liability and property policies were not designed to address every data, privacy, ransomware, or technology-related loss. They may exclude electronic data, privacy claims, unauthorized access, cyber extortion, or loss caused by system failure.
A dedicated cyber policy can combine first-party protection for the insured business with third-party liability coverage for claims made by customers, employees, regulators, or other affected parties. The specific coverage still depends on the insuring agreements, definitions, exclusions, conditions, and endorsements.
First-party coverage helps the business respond
First-party cyber coverage may pay certain costs incurred directly by the insured after a covered event. Depending on the policy, this can include forensic investigation, legal guidance, data restoration, system recovery, cyber extortion response, notification, call-center services, credit monitoring, crisis communications, and cyber-related business interruption.
These services can be as important as the insurance limit. A business facing a possible breach may need approved privacy counsel, forensic specialists, negotiators, restoration vendors, and communications support immediately—not after searching for providers during a crisis.
Third-party coverage addresses claims and liability
Third-party cyber coverage may address defense and covered liability arising from alleged privacy or network-security failures. Claims may allege that the business failed to protect information, allowed unauthorized access, transmitted malicious code, or violated a contractual or legal duty.
Coverage may also address certain regulatory investigations or payment-card assessments, subject to insurability, policy wording, and sublimits. Fines, penalties, contractual amounts, and restitution are not automatically covered.
California businesses may have breach-notification duties
The California Attorney General explains that state law requires a business to notify California residents when specified unencrypted personal information was acquired, or is reasonably believed to have been acquired, by an unauthorized person. A business required to notify more than 500 California residents from one breach must also submit a sample notification to the Attorney General.
Whether notice is required—and what it must contain—depends on the facts and applicable law. Cyber policies commonly require prompt notice to the insurer and use of approved counsel and vendors. A business should contact its broker or carrier immediately when an event or suspected event occurs.
Business interruption can be the largest loss
A company may lose revenue while systems are investigated, restored, or rebuilt. Cyber business-interruption coverage can address certain lost income and extra expense caused by a covered security failure or system failure.
Review the waiting period, restoration period, calculation method, sublimit, and whether the policy covers dependent business interruption caused by an outage or cyber event at a key vendor. Some policies distinguish malicious attacks from accidental system failures.
Payment fraud requires careful policy review
Business-email compromise often involves convincing an employee to send money to a fraudulent account or change legitimate payment instructions. Coverage may appear under social engineering, fraudulent instruction, funds-transfer fraud, computer fraud, or a separate crime policy.
These terms are not interchangeable. Review who must send or receive the instruction, whether a callback or verification procedure is required, which accounts qualify, the applicable sublimit and retention, and how cyber and crime policies coordinate.
Vendor incidents can become your problem
A business may outsource email, payroll, payment processing, data storage, point-of-sale systems, or managed technology services, but it may still face operational disruption or customer obligations when a vendor is compromised.
Ask whether the policy covers dependent business interruption, contingent system failure, outsourced-service providers, and breaches involving information held by vendors. Review contracts for indemnification, notification, security, insurance, and limitation-of-liability provisions.
The application becomes part of the risk
Cyber insurers may ask about multifactor authentication, backups, endpoint protection, encryption, patching, remote access, employee training, wire-transfer procedures, and incident-response planning. Answers should be accurate and confirmed with the person responsible for the company’s technology.
Misstatements can create coverage disputes. Preserve the completed application and supporting information, and notify the broker when the company’s security controls, vendors, data, revenue, or operations materially change.
Insurance works best with basic cybersecurity
Insurance transfers part of the financial risk but cannot prevent an attack. The Cybersecurity and Infrastructure Security Agency recommends practical measures for small businesses, including multifactor authentication, software updates, phishing awareness, and tested backups. The Federal Trade Commission also recommends employee training and an incident-response plan.
Businesses should limit access to sensitive information, verify payment changes through a known contact method, keep offline or isolated backups, test restoration, update software promptly, document vendors, and create a response plan that identifies who to call.
Questions to ask at renewal
Review what information and systems the business uses, how long operations could continue without them, which vendors are critical, and the largest plausible payment or ransomware loss. Then compare the proposal’s limits, sublimits, waiting periods, retentions, exclusions, reporting duties, and incident-response services.
A small endorsement attached to another policy may provide useful protection, but it should not be assumed equivalent to a broader standalone cyber policy. The appropriate structure depends on the company’s revenue, data, operations, contracts, security controls, and tolerance for interruption.