← All field notes
Cyber

What Is Cyber Liability Insurance?

Cyber liability insurance covers what happens after a data breach or cyberattack — the response, the legal fallout, the recovery, and the liability to people whose data was exposed. It exists because a breach isn't one cost; it's a cascade of them, and almost none are covered by the general liability or property policies a business already carries. For any business holding customer data, cyber is the policy that turns a potentially business-ending incident into a managed claim.

What cyber insurance covers

A cyber policy generally splits into two sides:

First-party coverage — your own costs to respond and recover:

  • Breach response — forensics to find out what happened, and the immediate handling.
  • Notification — the legally required process of informing affected individuals.
  • Credit monitoring for those affected.
  • Business interruption — lost income while systems are down from an incident.
  • Data restoration — rebuilding corrupted or lost data.
  • Cyber extortion / ransomware — response costs for ransomware events.

Third-party coverage — your liability to others:

  • Legal defense and settlements from lawsuits by affected customers or partners.
  • Regulatory fines and penalties where insurable.
  • Liability for failing to protect data.

What does cyber insurance cover, in detail.

Why your other policies don't cover this

Owners often assume their general liability or property policy has them covered. It generally doesn't. General liability covers physical bodily injury and property damage — not data breaches. Property insurance covers physical assets, and data usually isn't treated as physical property. The result is a gap: the breach happens, the bills arrive, and the existing policies decline. Cyber was created specifically to fill that gap. What general liability doesn't cover.

The analogy

Think of cyber insurance like the difference between fire insurance and a fire suppression and cleanup service. Your other policies might rebuild a physical building, but a cyberattack doesn't burn down a building — it floods your operations with a different kind of damage: locked systems, exposed customer data, legal notifications, downtime, and angry clients. Cyber insurance is the policy built for that fire — it funds the people who put it out (forensics, response) and clean up after (notification, restoration, liability), because the standard policies were written for bricks, not bytes. Cyber insurance vs general liability.

Who needs it

The honest answer is broader than people expect: almost any business that holds customer data, processes payments, relies on computer systems to operate, or stores sensitive information. That's most modern businesses, not just tech companies. The myth that cyber is a "big company problem" is exactly why small businesses are frequent targets — their defenses are thinner. Does your small business need cyber?

What cyber insurance doesn't do

Cyber insurance pays for the fallout — it doesn't prevent the attack. Strong security practices reduce the chance of a breach (and increasingly affect whether you can even get coverage), while the policy absorbs the cost when prevention fails. The two work together: security lowers the odds, insurance covers the consequences. Cybersecurity best practices.

Frequently asked questions

  • The costs of a data breach or cyberattack — including breach response and forensics, customer notification, credit monitoring, business interruption, data restoration, ransomware response, and third-party liability like legal defense and settlements.
  • Generally no. General liability covers physical injury and property damage, not data breaches. Cyber liability exists specifically to fill that gap. GL vs cyber.
  • Often yes. Small businesses are frequent targets precisely because their defenses are thinner, and a breach's costs — notification, legal, downtime — can be severe relative to their size. Does your small business need cyber?
  • First-party covers your own response and recovery costs; third-party covers your liability to others affected by the breach, like customers who sue. Most policies include both.
  • No — it covers the financial fallout. Security practices reduce the likelihood of an attack and increasingly affect eligibility for coverage; insurance absorbs the cost when an attack succeeds. Cybersecurity best practices.

Put it into practice

Bring us your current policy.

We'll mark up the gaps this article describes, line by line, no charge, no commitment.