Skip to content

Cyber Liability Insurance

The most likely six-figure loss for a small business today isn't a fire. It's a spoofed email and a wire that can't be recalled. We shop cyber across 50+ carriers and read the sublimits, because the headline number never tells the whole story.

Get a Quote
Framing crew at work on a residential build

The short answer

What is cyber liability insurance?

Cyber liability insurance covers the costs of a hack, data breach, or funds-transfer fraud: forensics, legal counsel, customer notification, recovered systems, and often the stolen funds themselves. It also covers your liability when customer or employee data is exposed.


What it covers

What this policy is typically built to handle.

  • Funds transfer fraud from spoofed emails and social engineering, on most forms
  • Ransomware response, including negotiation and recovery costs
  • Breach response: forensics, legal counsel, public relations
  • Notification costs for customers and regulators
  • Liability when customer or employee data gets exposed
  • Business income lost to a covered cyber event

Who needs it

Who usually carries it.

  • Businesses holding customer data, payment information, or employee records
  • Companies that move money by wire or approve payments over email
  • Professional firms with confidential client files
  • Retail and healthcare operations handling volumes of sensitive data
  • Any business where days of system downtime means real lost revenue

What it does not cover

  • Losses from security controls you said you had but didn't. Wrong application answers can void a claim.
  • Social engineering and wire fraud are often capped at sublimits well below the headline policy limit.
  • Prior known incidents, meaning breaches you knew about before the policy started.
  • Bodily injury and physical property damage, which generally belong to other policies.
  • Future lost profits and the value of stolen intellectual property, commonly excluded.
  • Exact terms vary widely by carrier. Cyber forms differ more than almost any other line, which is exactly why we compare them for you.

A scenario worth reading

The invoice that wasn't

Picture a construction company's bookkeeper getting what looks like a routine email from a regular subcontractor: please send future payments to a new bank account. The address is nearly identical to the real one and the invoice formatting matches exactly. She processes the next payment. The funds land in a fraudulent account and move within hours. Three days later, the real subcontractor calls about his overdue payment.

How coverage responds

A cyber policy with social engineering coverage is built for this. It covers the fraudulent transfer loss, the forensic work to figure out how the email was compromised, and the notification costs for exposed contacts. Without the policy, the full wire and the cleanup come straight out of the business.

Get a Quote

An illustrative example, not a real claim. Every claim is decided by the insurance company under the terms of the actual policy.

Pricing

What affects your cost.

No two businesses price the same. The only way to know your number is to quote it, and the quoting part is our job.

  • Volume and sensitivity of the data you hold
  • Revenue and the scale of payments moving through the business
  • Security controls: multi-factor authentication, endpoint protection, tested backups
  • Industry and regulatory exposure
  • Prior incidents and claims

Questions

Questions we hear a lot.

Sublimits. A policy with a $1M headline limit may cap social engineering losses at $100K or less, and wire fraud is exactly the loss small businesses take. Ransomware payments and downtime from a vendor's outage often carry their own caps too. We read those numbers on every quote before you do, because the headline limit is not the story. The sublimits are.

A lot. No multi-factor authentication on email and remote access can mean a declination, a higher rate, or worst of all, a denied claim if the application answer was wrong. Answer the security questions accurately, always. If you're missing a control, turning on MFA is usually a same-week fix that changes which markets will offer you terms. We'll tell you which boxes to check off before we go to market.

Depends on the form. Better policies extend to incidents at vendors and cloud providers you depend on. Narrower ones don't. If your operations lean on a handful of outside platforms, that extension is worth insisting on, and it's one of the things we push for when we place the policy.

Some BOPs bolt on a small cyber endorsement, often capped in the tens of thousands. A real incident, with forensics, lawyers, notifications, and lost funds, runs past that fast. Treat the endorsement as a starting point, not coverage. We can quote standalone cyber alongside your BOP renewal so you see what real coverage costs before deciding.

Quote request

Get your Cyber Liability Insurance quote.

Tell us once. A licensed agent shops it across the 50+ insurance companies we work with and comes back with real options, not a form letter.

What happens next

  1. Fill this out. It takes a few minutes, not an afternoon
  2. A licensed agent shops your file across the 50+ insurance companies we work with
  3. Quotes come back, on average, within 24 hours²

Submitting this form does not purchase insurance. No coverage is bound until confirmed in writing by a licensed agent.

Disclosures

  1. Sinai Coverage LLC is an independent insurance agency, not an insurer. Coverage is provided by the insurance companies your policy is placed with. Headquartered in Sunny Isles Beach, Florida. Serving all 50 states.
  2. Average across recent quote requests. Complex risks and certain coverage lines can take longer.
Get a QuoteCall