Commercial · Cyber Liability · WA · ID · OR · AZ
Cyber insurance for the businesses actually targeted.
Small businesses are the easy marks — and general liability doesn't touch a data breach. Cyber covers the ransomware payment, the breach-response bill, the lawsuit, and the downtime. Increasingly, your lease or client contract requires it.
What it covers
First-party and third-party, together.
Cyber liability responds to both sides of an incident: your own costs (first-party) and what you owe others (third-party). It's the coverage general liability specifically doesn't provide — and the one small businesses need most, because they're targeted precisely for having weaker defenses.
Ransomware & extortion
Covers extortion payments, negotiation, and recovery when your systems are locked or data is held hostage.
Get a quoteBreach response
Forensics, legal, customer notification, and credit monitoring — the immediate, expensive first-party costs.
Get a quoteBusiness interruption
Lost income when a cyber event or outage takes your operation offline.
Get a quoteThird-party liability
Claims and lawsuits from customers or partners whose data was exposed in your breach.
Get a quoteRegulatory defense
Defense and fines tied to breach-notification laws, including Washington's requirements.
Get a quoteSocial engineering
Wire-fraud and phishing loss — often a sublimit, and one we make sure is actually there.
Get a quote· A market of A+ insurance companies
Who needs it
Any business that holds data or takes payments.
If you store customer information, take card payments, use cloud software, or are contractually required to carry cyber — you have the exposure. Tech firms, healthcare, professional services, and retail are common targets, but any small business with a laptop and a customer list qualifies.
What drives your price
- Annual revenue and records held
- Your industry and data sensitivity
- Security controls (MFA, backups, EDR)
- Prior incidents and claims
- Coverage limits and retention
- Dependence on third-party vendors
First-party vs. third-party cyber coverage
| Type | What it pays for | Example |
|---|---|---|
| First-party | Your own incident costs | Ransomware, forensics, notification, downtime |
| Third-party | What you owe others | Customer lawsuits, regulatory fines |
| General liability | Neither — cyber is excluded | A breach is not a GL claim |
Common mistakes we fix
- Assuming general liability covers a data breach — it doesn't.
- No multi-factor authentication, which now drives declines and higher rates.
- Ignoring the social-engineering/wire-fraud sublimit until a fraudulent transfer happens.
- Under-limiting relative to the records you hold and the contracts you sign.
Go deeper
Related reading
Questions clients ask
Quick answers, no jargon.
Prefer to talk it through? A licensed advisor picks up: 206 · 363 · 1110.
- Both first-party costs (ransomware, breach response, forensics, customer notification, business interruption) and third-party liability (lawsuits and regulatory action from a breach). It's built for exactly what general liability excludes.
- No. General liability covers physical injury and property damage, not data. A breach — and the notification costs, lawsuits, and downtime it triggers — needs cyber liability.
- It depends on your revenue, the data you hold, your security controls, and the limits you choose. Businesses with MFA and solid backups qualify for better rates — we help you present well and shop A+ carriers.
- Not by state law generally, but it's increasingly required by leases, client contracts, and vendors — and Washington's data-breach notification law creates real costs a policy helps cover.
- It covers extortion payments, negotiation, and the cost of restoring systems and data after an attack locks you out. It's often the single most valuable part of a small-business cyber policy.
- Yes. Using cloud tools doesn't remove your responsibility for the customer data you hold, and a vendor outage or your own compromised credentials can still trigger a costly incident.