Cyber Insurance That Protects
When a breach hits, our policies cover the costs that pile up: forensics, legal fees, lost revenue, and the response team to get you back online.
Complete Cyber Protection
Our policies cover both sides of a cyber incident: your direct costs (first-party) and the liabilities from affected customers and regulators (third-party).
New to this? Start with our primer, What is cyber insurance?
First-Party Costs
-
Business Interruption
Lost income and extra expenses while systems are down
-
Data Recovery
Forensic investigation and system restoration costs
-
Breach Notification
Legal-compliant customer and regulatory notifications
-
Crisis Management
PR support to protect your reputation
-
Extortion Payments
Ransomware and cyber extortion coverage
-
System Failure
Downtime and data restoration when the cause isn't an attack — a system failure or an employee error, like a database wiped by mistake
Third-Party Liabilities
-
Regulatory Fines
HIPAA, PCI-DSS, and other compliance penalties
-
Customer Lawsuits
Defense costs and damages from privacy claims
-
Credit Monitoring
Identity theft protection for affected individuals
-
Legal Defense
Experienced cyber liability attorneys
-
Media Liability
Website content and social media claims
Coverages that are often limited or excluded
Cyber policies vary widely in what they include. The coverages below are among the most consequential in a claim, and also among the most likely to be limited or excluded, particularly when cyber is added as an endorsement to a business owner's policy rather than written as a standalone policy. They are worth confirming before you buy, and we compare the market to make sure they are there.
Funds-transfer fraud & social engineering
When staff are tricked into wiring money to a criminal, or a vendor's "new banking details" turn out to be a fraudster. A bank generally will not reimburse an authorized transfer, but this coverage responds.
Invoice manipulation
A real invoice cloned with a changed routing number, sent from inside a trusted inbox. It covers the loss when a client pays the wrong account, along with the dispute over which party is responsible.
Dependent business interruption
Lost income when a vendor or supplier you rely on is breached and cannot deliver. The CrowdStrike and CDK Global outages affected thousands of businesses at once.
Bricking
The cost to replace hardware an attack has left unusable. It is frequently excluded and can be a significant expense.
Contingent bodily injury & property damage
When a cyber event causes physical injury or property damage, not only lost data. Standard policies often exclude it.
Loss of tangible property
When social engineering reroutes a shipment of goods rather than a payment. Many crime forms cover funds only.
The Threat is Real and Growing
Cyber attacks aren't just a "big business" problem. Small and medium businesses are prime targets because they often have weaker defenses but valuable data.
lost to email and wire fraud
in 2024 (FBI Internet Crime Report)
median wire-fraud loss
per business (FBI IC3)
total cybercrime losses in 2024
up 33% from 2023 (FBI IC3)
Coverage in Depth
Responding to a breach and staying compliant are two of the areas a cyber policy touches most. These guides break down what's involved and where coverage steps in.
Data Breach Checklist
A step-by-step checklist for the first hours and days after a breach, and how a policy funds forensics, notification, and recovery.
Read the checklist →Compliance Guide
HIPAA, PCI-DSS, SOC 2, CMMC, GDPR, and state privacy laws, what non-compliance costs, and how a policy covers regulatory defense and fines where insurable.
Read the guide →Cyber Insurance Questions & Answers
What does cyber insurance cover?
Cyber insurance covers both first-party costs (business interruption, data recovery, notification costs, forensics) and third-party liabilities (lawsuits, regulatory fines, credit monitoring). It also provides access to expert incident response teams.
How much cyber insurance coverage do I need?
Coverage needs vary by industry and business size. Most small businesses start with $1M in coverage, while larger companies or those in regulated industries may need $5M-$10M+. We assess your specific risk profile to recommend appropriate limits.
Does cyber insurance cover ransomware?
Yes, cyber insurance typically covers ransomware attacks including ransom payments (where legally permitted), business interruption losses, data recovery costs, and incident response expenses.
Will cyber insurance cover social engineering attacks?
Many policies now include social engineering coverage for business email compromise and fraudulent transfer scams. However, coverage varies by insurer and may require specific endorsements.
Do I need cyber insurance if I don't store customer data?
Yes. Even businesses without customer data face cyber risks from ransomware, business email compromise, and system downtime. Cyber insurance also covers your own business records and financial information.
What if an employee accidentally deletes our data or takes us offline — no hacker involved?
That's a first-party loss, and it's covered where your policy includes system failure coverage. The first-party side responds to downtime and data restoration when the cause is a system failure or human error — an employee wiping a database by mistake, including one using an AI tool — not just a malicious attack. We make sure that coverage is in the policy, since not every cyber policy includes it.
Get coverage that fits your business
Get a quote built around your industry and risk profile. Takes about 10 minutes to get started.
