If your business takes card payments, stores customer information, books appointments online, or relies on email to move money, you have cyber exposure. Small businesses are frequent targets because their defenses are thinner.
Most general liability and property policies exclude or sharply limit cyber events. A dedicated cyber policy combines first-party coverage for your own costs with third-party coverage if customers or regulators come after you.
What Cyber Liability typically covers
- Breach response. Forensic investigation, legal counsel, customer notification, call centers, and credit monitoring after a data breach.
- Ransomware and extortion. Expert negotiation, restoration costs, and — where permitted — extortion payments.
- Business interruption. Lost income and extra expense when a cyber event shuts down your systems.
- Data restoration. Costs to recover or recreate damaged data and software.
- Privacy and network liability. Defense and damages if customers, partners, or regulators claim you failed to protect their data.
- Social engineering / funds transfer fraud. Losses from fraudulent payment instructions — often sublimited or added by endorsement, so ask specifically.
A front-desk employee opens a fake invoice email and ransomware locks a clinic’s scheduling system for four days. Cyber coverage pays for the incident response team, data restoration, patient notifications, and the income lost while the office ran on paper.
Businesses that commonly carry Cyber Liability
- Retailers and restaurants that take card payments
- Medical, dental, and professional offices with client records
- Businesses that store customer data or run online booking
- Any business that pays invoices or payroll by wire or ACH
- E-commerce sellers
- Companies whose clients require cyber coverage in contracts
What it usually does not cover
- Known prior incidents. Events that started before the policy began are excluded.
- Missing required security controls. Many carriers require multi-factor authentication, backups, and patching; misrepresenting them can jeopardize a claim.
- Bodily injury and physical property damage. Those remain with GL and property policies.
- Upgrades (betterment). Improving your systems beyond their pre-loss state is usually not covered.
- War and infrastructure failure. Widespread infrastructure outages and acts of war are commonly excluded.
- Low funds-transfer limits. Wire-fraud coverage may be sublimited well below the main limit.
Independent means we compare — not just quote one company
We shop cyber coverage through our carrier and wholesale partners when it is available for your class and state. Applications focus on your security controls, so having answers about MFA, backups, and employee training ready speeds things up.
Tips before you buy
- Turn on multi-factor authentication for email, banking, and remote access — it is often required to qualify.
- Keep offline or immutable backups and test restores.
- Use a call-back procedure to verify any change to payment instructions.
- Ask whether a cyber endorsement on your BOP is enough or a stand-alone policy makes more sense.
Coverage that pairs with Cyber Liability
Professional Liability / E&O
Claims that your advice, service, or professional mistake cost a client money.
Learn moreBusiness Owners Policy (BOP)
Liability + property + business income in one package for eligible small businesses.
Learn moreGeneral Liability
Third-party injury, property damage, and advertising injury claims — plus defense costs.
Learn morePopular with: Professional & Medical Offices · Retail & Boutiques · Restaurants & Food Service · All commercial coverage
Cyber Liability questions
Is cyber insurance worth it for a small business?
If you store customer data, take payments, or rely on email and cloud software, a single incident can cost far more than a year of premium. A short conversation about your setup will tell you whether a small endorsement or a full policy makes sense.
Does my BOP include cyber?
Some BOPs offer a small data-breach endorsement with modest limits. It is a start, but it may not include ransomware, business interruption, or liability. Compare it with a stand-alone policy.
Does cyber insurance pay ransoms?
Some policies cover extortion payments where legally permitted, along with expert negotiators. Many also focus on restoring systems without paying.
What security steps do carriers require?
Common requirements include multi-factor authentication, regular backups, endpoint protection, software updates, and employee phishing training.
Is wire fraud covered?
Often only by specific social engineering or funds-transfer coverage, frequently at a lower limit. Ask for it by name.
We cover your assets
Let’s build the right commercial program
Tell us about your business once. We shop multiple carriers, explain the trade-offs in plain English, and handle certificates, audits, and renewals after you bind.
Educational only — not a policy, quote, or coverage guarantee. Coverage, eligibility, and carrier availability vary by state, class of business, and underwriting. Policy language controls. Talk with a licensed Asshield agent about your situation.