Business

Cyber liability, without the fear-mongering.

Most cyber-insurance marketing sells fear. Here’s the calmer version: for a small business, the most common losses aren’t movie-plot hacks — they’re a bookkeeper wiring money to a convincing fake invoice, a locked-up computer system before a busy weekend, or a lost laptop that turns into a legal notification duty. Cyber policies exist for exactly those Tuesdays.

What these policies actually respond to

  • Funds-transfer fraud and social engineering — someone impersonates a vendor, a client, or you, and money moves. For small businesses this is consistently among the most frequent and painful losses.
  • Ransomware and system recovery — the response team, forensics, restoration, and the income lost while systems are down (cyber business interruption).
  • Breach response duties — California law requires notifying affected individuals when certain personal data is exposed. Policies fund the lawyers, notification, and credit monitoring that duty triggers.
  • Third-party claims — when clients or partners say your incident became their problem.

The sublimit surprise

The number on the front of a cyber policy is rarely the number that pays a social-engineering loss. Funds-transfer fraud and social engineering are commonly sublimited — sometimes to a small fraction of the headline limit — and sometimes require specific verification procedures to have been followed for coverage to apply at all. If a policy was bought for the wire-fraud scenario, the sublimit page is the page that matters. This is the single most useful thing to check on a cyber policy you already own.

Who genuinely needs it

  • Businesses that hold client data — even "just" names, emails, and payment details.
  • Businesses that move money on instructions — escrow-adjacent, bookkeeping, property management, anyone whose inbox can trigger a wire.
  • Businesses whose contracts or clients require it — increasingly standard in vendor agreements.
  • Businesses that would lose real revenue from a week of downtime.

A cash-only sole proprietor with no client data and no systems dependence has a genuinely weaker case — and an honest review should say so.

The eligibility flip side

Basic security hygiene — multi-factor authentication, backups, updated systems — is now both a pricing lever and, at some carriers, an eligibility requirement. The applications ask; the answers become part of the record. The practical upshot: turning on MFA is often the highest-return "insurance" step a small business can take, because it improves both the risk and the terms available for it.

General information, reviewed July 2026. Breach-notification duties: California Civil Code §1798.82 (see the California Attorney General’s guidance). Every cyber form differs; the issued policy’s terms control. This page is not insurance or legal advice.

Own a cyber policy and never checked the sublimits? Check my coverage — free