3 minute readBusiness
Cyber coverage pays for the costs of a data breach or attack: forensics, notification, credit monitoring, legal defense, regulatory response, business interruption, and in some forms ransomware and funds-transfer fraud. Any business handling payment or personal data has this exposure, regardless of size.
What you need to know
First-party vs. third-party
First-party covers your own response and lost income; third-party covers claims from affected customers or partners.
Social engineering is often separate
Wire-fraud and funds-transfer coverage is frequently a sub-limit or endorsement, not automatic.
Controls affect eligibility
Carriers increasingly require multi-factor authentication and backups to offer meaningful limits.
Common mistakes
- Setting property and income limits from rounded-down guesses instead of real numbers.
- Skipping hired and non-owned auto because the business owns no vehicles.
- Signing contracts that require limits or wording the policy does not provide.
- Letting subcontractor certificates lapse, which shows up at audit.
- Treating insurance as a one-time purchase while the business keeps changing.
When to talk to an agent
Talk to an agent before signing a lease or a major contract, when you hire your first employee, when revenue or payroll changes materially, and any time you add a service, location or vehicle.
Frequently asked
This article is general information, not a policy or a promise of coverage. What your policy pays depends on its specific terms, limits and exclusions. Ask us to review your actual policy before making a decision.