Cyber Liability Insurance
The Breach Is Expensive. Telling Everyone About It Is Usually Worse.
Most small businesses assume a cyber claim means ransomware. More often it is the cost of notifying every customer whose data was in your system, and the lawsuits that follow. Premier Group Insurance shops more than 25 carriers to find a policy that answers the losses you are actually likely to have.
What Cyber Liability Covers
Cyber policies split into two halves. First-party pays your costs. Third-party pays for what other people come after you for. Most businesses need both, and a lot of cheap policies are thin on one side
First Party: Your Own Costs
Third-Party: What Others Claim Against You
The Loss You Are Most Likely to Have
Ransomware gets the headlines. The loss that actually shows up at small businesses is quieter than that. Someone in accounting gets an email that looks like it came from a vendor you use, or from the owner, asking to update banking details or push a wire through before end of day. The money goes out. It does not come back.
Here is the part worth reading twice. A lot of base cyber policies do not cover that. It gets treated as social engineering or funds transfer fraud, and it is frequently excluded or capped at a fraction of your policy limit unless someone specifically added it. The most likely loss and the least reliably covered loss are often the same event.
It is not exotic to fix. Most carriers offer social engineering coverage by endorsement, and it is usually inexpensive. But it has to be asked for, and an online quote form is not going to ask for you. This is the single most common gap we find when we review a cyber policy a business already owns.
When we quote cyber, we ask how payments get approved at your business and who is authorized to move money. That question shapes the policy more than your firewall does.
Who Needs Cyber Liability?
The test is not whether you are a technology business. It is whether you hold information about other people or move money electronically. That is nearly everyone.
Businesses Being Asked for It by Contract
Professional services firms, agencies, IT and managed service providers, and anyone bidding on enterprise or government work. Client security questionnaires and vendor agreements now routinely specify a cyber limit, and this is the fastest growing reason businesses call us about it.
Businesses Holding Sensitive Records
Medical and wellness practices, med spas, accountants and bookkeepers, property managers, and anyone holding health information, financial records, or employee files. Notification obligations are driven by the number of records you hold, which means a small business with a long customer list can face a large notification bill.
Businesses That Move Money
Contractors paying subs, businesses running payroll, anyone approving wires or ACH transfers. If someone at your company can send money based on an email, you have the exposure described in the section above, whether or not you have a single customer record on file.
Why Carrier Choice Matters on Cyber
Cyber is the least standardized commercial policy on the market. Two policies with the same limit and a similar price can differ enormously in what they include, what they sub-limit, and how much they expect you to have in place before they will pay.
Underwriting has also tightened. Many carriers now require multi-factor authentication, offsite backups, or specific controls as a condition of coverage, and answering a question wrong on the application can affect a claim later. Getting those answers right is part of the placement, not paperwork to rush through.
Because we shop across more than 25 carriers, we can compare what each one actually includes rather than handing you the one policy a single-carrier agent has to sell. On a line this unstandardized, that difference is worth more than it is anywhere else.
How It Works
1. Tell Us How You Operate
What records you hold, roughly how many, how payments get approved, and what security you already have in place. If a contract specifies a cyber limit, send that too.
2. We Shop 25+ Carriers
We compare what each policy actually includes, confirm social engineering is addressed, and check that the controls you have satisfy each carrier’s requirements.
3. You Choose
We walk through the limits, the sub-limits, and the exclusions that matter, so you know what the policy does before you need it to do it.
Frequently Asked Questions
Does my Business Owners Policy Include Cyber?
No. A standard BOP bundles property, general liability, and business income. Cyber is written separately, though many carriers will add a limited amount by endorsement. Limited is the word to pay attention to, because those endorsements are often small enough that they would not cover a real notification event.
We Are Small And we do Not Store Credit Cards. Do we Still Need It?
Probably, yes. Notification obligations attach to personal information, not just payment data, so customer names with email addresses can be enough to trigger them. And if anyone at your business can move money based on an email, that exposure exists regardless of what you store.
How Much Does Cyber Liability Insurance Cost?
It depends on your revenue, your industry, how many records you hold, and what security controls you have. Businesses with multi-factor authentication and tested backups price better, sometimes substantially. There is no useful average across different businesses.
Does Cyber Cover an Employee Wiring Money to a Scammer?
Not always, and this is the most important question on this page. It is usually treated as social engineering or funds transfer fraud and is frequently excluded or heavily sub-limited unless it was specifically endorsed. Ask us to confirm it is on your policy, or send us the one you have and we will check.
Our Client is Requiring Cyber Coverage Before They Will Sign. What do we Need?
Send us the contract or the security questionnaire. Those documents usually specify a limit and sometimes name required coverages, and we will build the quote to satisfy the language rather than guessing at it.
Do we Need Cyber if we Already Carry Professional Liability?
They cover different things. Professional liability answers a claim that your work or advice caused a client a financial loss. Cyber answers a breach, a ransomware event, and the notification and lawsuits that follow. For professional services firms the two are usually written together, and carriers often price the pair better than either alone.
Get a Cyber Liability Quote in About 5 Minutes
Tell us what you do, roughly how many customer records you hold, and how payments get approved at your business. If a client contract is driving this, send that along. We will shop across our carrier network and come back with options. No commitment required