Cyber Liability Insurance
Covers the cost of a data breach, a ransomware demand, or an intrusion into the systems you run the business on. It is also sold as data breach liability and as network security liability. Same policy, three names, depending on who is asking you for it.
The short version
- Cyber liability responds to a breach, a ransomware event, or an intrusion, covering both what you spend to deal with it and what other people claim from you afterwards.
- It is written in two halves. First-party pays your own costs. Third-party answers claims from customers, banks and regulators. Most policies include both, in different amounts.
- General liability almost always excludes it. The usual trigger for buying is a client contract or a vendor security review that names the coverage and a limit.
This page is general information, not insurance advice, and it does not change any policy. Coverage varies by carrier, policy form, and state. See our disclaimer.
What cyber liability is generally intended to cover
Breach response
Generally intended to pay for the work that starts the morning you find out: forensics to establish what happened, legal advice on what you owe whom, notifying the people affected, and credit monitoring where it is offered.
Ransomware and extortion
Generally intended to respond to an extortion demand, including the negotiation and the specialists who handle it. Carriers differ widely on how they treat payment itself, so read that clause.
Business interruption from a system failure
Generally intended to cover income lost while systems are down after a covered event. Some forms extend to a failure at a vendor you depend on rather than only your own systems.
Claims from people whose data was exposed
Generally intended to respond when customers, employees or business partners allege your breach harmed them, including the defence of those claims.
Regulatory exposure
Generally intended to respond to investigations and proceedings after a breach, and to fines and penalties where the law allows them to be insured. Whether a given penalty is insurable is a matter of state law, not carrier preference.
Payment card exposure
Generally intended to respond to assessments from card brands and acquiring banks after card data is taken, where that exposure is included on the form.
What it does not cover
Cyber answers for data and systems. Physical accidents, employee injury and the building belong on other policies.
Someone getting physically hurt
A visitor injured on your premises is bodily injury, which sits with general liability.
general liability→Your employees getting hurt
Employee injury is workers compensation, whatever caused it.
workers’ compensation→Your hardware burning or being stolen
Fire, theft and weather damage to equipment is property coverage. Cyber may pay to replace hardware bricked by an attack, which is a different thing from a fire.
commercial property→A professional mistake that has nothing to do with data
Advice or work a client says cost them money is professional liability.
professional liability→Money taken by your own staff
Employee theft and most funds transfer fraud belong on a crime policy, though some cyber forms add a limited amount back.
crime insurance→Who is going to ask you for it
Cyber is now demanded by contract far more often than by statute.
- A corporate client before signing, usually at a named limit
- A client's vendor security review, alongside questions about multi-factor authentication and backups
- A bank or payment processor where card data is handled
- A lender or investor during diligence
- A state or federal regulator, in sectors with their own breach rules
- A landlord or partner whose systems connect to yours
A contract asking for cyber?
Tell us what your business does and we will point you at the right market for it.
Get a quoteWhat drives the price
Cyber is rated on how much data you hold and how hard you are to get into.
Records held
How many individuals' records you store, and what kind. Health and payment data rate differently from a mailing list.
Revenue
A proxy for how large an interruption would be and how many people a breach would touch.
Your industry
Healthcare, financial services, education and anyone taking card payments sit higher than a business holding little personal data.
Security controls
Multi-factor authentication, offline backups, endpoint detection and staff training all move the price, and some carriers will not quote without multi-factor authentication at all. This is the one rating factor you can change before you apply.
Limits and retention
Higher limits cost more, and cyber retentions are often larger than people expect. Check whether a waiting period applies to business interruption.
Claim history
Prior incidents count, and so do incidents you reported that never became claims.
Coverages you may see on a cyber policy
The insuring agreements below appear on cyber policies in this market, split the way a carrier splits them.
Third party — claims from others
- Multimedia liability
- Security and privacy liability
- Privacy regulatory defence and penalties
- PCI DSS liability
- Bodily injury liability
- Property damage liability
- TCPA defence
First party — your own costs
- Breach event costs
- Post breach remediation costs
- System failure
- Dependent system failure
- Cyber extortion
- Cyber crime
- Bricking loss
- Property damage loss
- Reward expenses
- Court attendance costs
Apply for this coverage
Cyber underwriting turns on what data you hold and what controls sit in front of it. The full application covers records held, payment handling, multi-factor authentication, backups and prior incidents, which is what a carrier needs before it will put up a limit.
Start the cyber application →Frequently asked questions
What is the difference between first-party and third-party cyber coverage?
First-party pays your costs: forensics, notification, lost income, extortion. Third-party answers what other people claim from you: customers whose data was exposed, banks, regulators. A policy that looks cheap is often thin on one half.
Is data breach liability the same as cyber liability?
In practice it is the same market. Data breach liability tends to describe the narrower piece dealing with exposed personal information, while cyber liability covers that plus system failure, extortion and interruption. Contracts use both terms, sometimes interchangeably.
What is network security liability?
The part of a cyber policy answering for a failure of your security that harms someone else, including transmitting malware to a third party or your network being used to attack another. It appears as a named insuring agreement on most forms and is often what a contract is asking for.
Does my general liability policy cover a data breach?
Almost never. General liability forms carry exclusions that remove electronic data and privacy exposures, which is the reason a separate cyber market exists.
Does cyber cover a ransom payment?
Some forms do, some cover only the response around it, and sanctions rules can bar a payment. Treat this as a clause to read rather than an assumption.
We are small. Is this really an exposure?
Ransomware is largely indiscriminate, and small businesses are targeted because their controls are weaker. The more common trigger, though, is commercial: a customer will not sign without it.
Will a carrier quote us without multi-factor authentication?
Often no. Multi-factor authentication on email and remote access has become a condition of entry for many carriers rather than a discount. Putting it in place before applying changes what is available to you.
How much does cyber liability cost?
It depends on the data you hold, your revenue, your industry, the controls you have in place and the limits chosen, so there is no single figure. Request a quote for your own situation.
Other coverages: general liability, professional liability, crime insurance, business owner’s policy.
Get a cyber liability quote
Tell us what your business does and we will point you at the right market for it.
Start my quoteGet the small-business insurance newsletter
Plain-English coverage tips, comparisons, and offers — no spam, unsubscribe anytime.