Demo

Greene Insurance is a fictional company. This site is an integration fixture — no coverage is sold, no license is held, and every phone number, address, and license identifier on it is a placeholder.How this site was built

Commercial lines

Cyber Liability

Breach response, ransomware, and the liability that follows a data loss.

What it covers

  • Breach response and notification costs
  • Ransomware and cyber extortion
  • Business interruption from a network event
  • Funds transfer fraud and social engineering (sublimit)

What people get wrong

Most carriers now require MFA on email and remote access to bind. Answering the application wrong is grounds for rescission.

What cyber actually pays for, and why the application is a warranty

A cyber policy has two halves. First-party coverage pays your costs: forensics to work out what happened, legal counsel to determine your notification obligations, notifying affected individuals, credit monitoring, restoring data and systems, extortion payments where lawful, and the income lost while you were down. Third-party coverage pays what you owe other people — the lawsuits, the regulatory proceedings, and the contractual liabilities that follow a breach of someone else's data.

For businesses under a few hundred employees, the loss that actually happens is rarely dramatic. It is a spoofed email that convinces someone to change wire instructions, a compromised mailbox that quietly invoices your customer list, or ransomware delivered through remote access that was never patched. Those sit under funds transfer fraud and social engineering coverage, which almost always carry a sublimit well below the policy limit and often require a call-back verification procedure to be in place before they will pay. Read that sublimit — it is the number that matters, not the headline limit.

Underwriting has hardened around controls. Multi-factor authentication on email and remote access, offline or immutable backups that have actually been tested, endpoint detection, and separation of administrative accounts are now near-universal requirements to bind. The application answers function as warranties: if you attest to MFA and a breach investigation shows it was not enabled, the carrier can rescind the policy and pay nothing. Answer the application literally, and if a control is partial, say so and let us find a carrier that will write it as it is.

Business interruption on a cyber policy has a waiting period measured in hours rather than days, and it pays from the end of that period. When you buy, look at how the policy handles an outage at a vendor rather than at you — dependent business interruption — because for most small firms the systems that would stop the business are somebody else's. And confirm the carrier provides a 24/7 incident response line with a panel of counsel and forensics; on day one that access is worth more than the limit.