Cyber insurance
Small businesses are attacked because they're easier, not because they're valuable. A single ransomware event or a spoofed invoice can cost more than a fire — and New York law requires you to notify affected customers. This is the policy that pays for the response.
What cyber insurance covers
First party — your own costs
- Incident response — forensic IT, legal counsel, a breach coach, often via the carrier's 24/7 hotline.
- Ransomware and extortion — negotiation, and payment where lawful and necessary.
- Data restoration — rebuilding systems and recovering data.
- Business interruption — lost income while systems are down.
- Notification and credit monitoring — the notices the SHIELD Act requires, and monitoring where it's appropriate or required.
- Funds transfer fraud / social engineering — money sent to a criminal because of a deceptive email.
Third party — claims against you
- Lawsuits from customers or partners whose data you held.
- Regulatory investigations and fines where insurable.
- PCI fines and assessments if card data is compromised.
- Media liability for content on your website or social channels.
The phone number on the policy
When systems are locked at 6 a.m. on a Monday, the value of cyber insurance is having a breach team on call who have done this hundreds of times. For most small businesses, that response service matters more than the limit.
What it costs and what drives it
For a small business with basic controls in place, cyber cover typically runs from a few hundred to a couple of thousand dollars a year for $1 million in limits. Revenue, the volume and type of data you hold, your industry, and — above all — your security controls set the price. MFA, backups and endpoint protection are the three things every carrier asks about.
Who needs it most
- Anyone taking card payments or storing customer records — retail, restaurants, salons.
- Professional and financial services holding client data — often required by clients; pairs with E&O.
- Medical, dental and allied-health practices — HIPAA obligations on top of SHIELD.
- Contractors and trucking firms — invoice fraud and email compromise are rife in industries with large payments and thin admin.
What I need to quote
- Annual revenue and number of employees.
- What data you hold and roughly how many records.
- Whether you have MFA on email and remote access, backups (and where), and endpoint protection.
- Any prior incidents.
Request a quote — cyber can often be added to a BOP or professional liability package, or written standalone with broader cover.
- SHIELD Act (NY Attorney General) — reasonable safeguards, breach notification
Common questions
Short answers to what people ask before they call.
I'm a small shop. Am I really a target?
Yes. Most attacks are automated and indiscriminate — phishing emails, credential stuffing, scanning for unpatched systems. A restaurant's point-of-sale, a contractor's email, a salon's booking system are all targets. Small businesses are hit far more often than large ones, precisely because they have less protection.
What does New York's SHIELD Act require?
Any business holding New Yorkers' private information must have reasonable safeguards and, after a breach, must notify affected people — generally within 30 days — plus the Attorney General, Department of State and State Police. Notification, any credit monitoring you offer, and legal advice have real costs — which cyber insurance is designed to pay.
Does cyber insurance cover funds-transfer fraud?
It can, if the policy includes social engineering or funds transfer fraud cover — a spoofed email convincing your bookkeeper to pay a fake invoice is among the most common and costly cyber losses for small businesses. Check the sub-limit; it's often lower than the main limit.
What do carriers require before they'll write it?
Increasingly: multi-factor authentication on email and remote access, offline or immutable backups, and endpoint protection. Businesses without MFA are hard to insure at all. I'll tell you what a given carrier wants before you apply.
Let's talk it through
A phone call or a message is all it takes. The first conversation is just a conversation.