Cyber & Privacy Liability

Cyber coverage for firms that move money and hold data.

The realistic exposure for most small and mid-sized businesses is not a sophisticated breach. It is a wire fraud triggered by a convincing email, and whether that is covered depends on wording most policies handle differently.

CA #6015336Admitted · Specialist · E&SFree review
Santa Barbara cityscape

Scope

What this coverage does — and where it fails.

Property managers, escrow-adjacent businesses, medical and professional practices, and anyone who initiates transfers on behalf of clients carry more of this exposure than they think.

What a properly built program includes

  • Network security and privacy liability to third parties
  • Breach response: forensics, notification, credit monitoring, and public relations
  • Business interruption and system failure from a cyber event
  • Ransomware and cyber extortion, subject to carrier protocols
  • Social engineering and funds transfer fraud — where the form includes it
  • Regulatory defense and fines where insurable by law

What we read for

  • Social engineering excluded or heavily sublimited — the most likely loss
  • Funds transfer fraud confused with crime coverage; they are different triggers
  • Business interruption waiting periods measured in days
  • Ransomware sublimits and coinsurance well below the policy limit
  • Requirements for multi-factor authentication that void coverage if not maintained
  • Vendor and cloud outages excluded when your operations depend on them

Detail

What actually decides the outcome.

01

Social engineering is the claim that actually happens

An employee receives convincing instructions to change wire details and follows them. Many cyber forms sublimit this heavily or push it to a crime policy. For any business that moves client funds, this is the first coverage to confirm, not the last.

02

Warranties in the application can void the coverage

Carriers increasingly ask whether you have multi-factor authentication, offline backups, and endpoint detection, and answering yes creates a condition. If it lapses, the claim is exposed. Answer accurately, and tell us when your controls change.

03

Business interruption is measured in hours you cannot bill

Systems-down cover usually carries a waiting period before it responds. For a practice that bills hourly, that waiting period is the coverage decision.

Send the declarations page.

Free, confidential, and no obligation — with a written summary either way.

Start a coverage review

Start here

Request a review of this coverage.

Tell us what you are insuring and where it stands. If there is a non-renewal notice or an escrow deadline, say so — those move to the front of the line.

FREE · CONFIDENTIAL · NO OBLIGATION

Prefer to talk? Call or text (305) 990-2753 or email team@haymakersre.com

FAQ

Common questions.

01

We are small. Are we really a target?

Targeting is largely automated and indifferent to size, and small firms typically have fewer controls. The more relevant question is what a week without systems, or a misdirected client wire, would cost you.

02

Is cyber included in my general liability policy?

Almost never in any meaningful way. General liability forms typically exclude electronic data and privacy exposures outright. A small endorsement occasionally appears, but the limits are not intended to respond to a real event.

03

Does cyber insurance pay a ransom?

Many forms cover extortion payments subject to sublimits, carrier approval, and legal restrictions on payments to sanctioned parties. The more valuable part of the coverage is usually the incident response team the carrier brings, not the payment itself.

Related lines

Other coverage we place.