Skip to main content

Cyber liability insurance explained for small and mid-sized businesses

August 3rd, 2026

6 min. read

By Mark Rodgers

Cyber liability insurance explained for small and mid-sized businesses
16:11

Commercial Insurance 101: Cyber Liability

Written by Mark Rodgers, President and Founder, Trailstone Insurance Group

The most common cyber loss for small businesses is not what most owners picture. It is not a hooded figure breaking through a firewall. It is an employee clicking a fake email and wiring real money to the wrong account. And here is the kicker: most base cyber policies do not fully cover that scenario unless you specifically ask for it.

Today we will walk through what a cyber liability policy actually covers, the coverage gap almost every business has, and the specific endorsement to look for on your own policy. This is part 7 of our Commercial Insurance 101 series, and there is an accompanying video on our YouTube channel if you would rather watch.

 

Here's the Short Answer

Cyber liability insurance protects businesses from data breaches, ransomware, business interruption from a cyber event, third-party legal claims, regulatory fines where insurable, and the cost of notifying affected parties. Most modern policies also include a breach response service that connects you with attorneys, forensic investigators, and PR specialists when something happens. The most common cyber loss for small businesses today is social engineering fraud, also called fraudulent funds transfer, which usually requires a specific endorsement to be fully covered. Carriers also expect basic cyber hygiene, including multi-factor authentication, regular backups, and employee training. Without those in place, claims can be reduced or denied.

What Cyber Liability Actually Covers

Let's break down what a cyber policy really protects. A modern cyber liability policy responds to several distinct exposures:

  • Data breaches. Events involving customer, employee, or financial records.
  • Ransomware and extortion. Attacks where access to your systems or data is held hostage.
  • Business interruption. Lost revenue from a cyber event that shuts down your operations.
  • Legal defense and settlements. Claims from third parties affected by a breach.
  • Regulatory fines and penalties. Where they are legally insurable in your jurisdiction.
  • Notification and credit monitoring. The cost of informing affected parties and providing credit monitoring services.

On top of that, most modern policies include a breach response service. That means the moment something happens, you are connected with attorneys, forensic investigators, and PR specialists who handle the response. For a small business that has never been through a breach, that breach response team is often the most valuable part of the policy.

The Coverage Gap Almost Everyone Has

Here is the part that matters most. The most common cyber loss for small businesses today is not a hacker stealing customer data. It is something called social engineering fraud, also called fraudulent funds transfer. That is when an employee gets tricked, usually through a fake email that looks like it is from you or a vendor, into wiring money or changing payment information.

And here is the kicker. Most base cyber policies exclude social engineering fraud or only cover it with a small sub-limit. To get full coverage, you usually need a specific endorsement called Social Engineering Fraud or Fraudulent Instruction coverage.

So the most common loss is the one most policies do not fully cover, unless you specifically ask for it. This is one of those quiet gaps we look for in every commercial review. The endorsement is often inexpensive relative to the exposure, but only if it is on the policy before the loss happens, not after.

What Cyber Liability Does Not Cover

Let's be clear about the exclusions, because they catch business owners off guard. Knowing the exclusions is just as important as knowing the coverage.

Common Cyber Liability Exclusions

Exclusion Why It Matters
Intentional fraud by an owner or executive Not insurable under any policy
Poor cyber hygiene Claims can be reduced or denied if MFA, backups, and basic protections are missing
War or state-sponsored cyber attacks Usually excluded unless a specific endorsement is added
Utility and internet outages Excluded if not caused by a direct cyber attack on your systems
Future profits or stock value loss Generally not covered beyond direct first-party costs
Pre-existing incidents Anything that happened before the policy started is excluded

That second one matters more than the others. Carriers expect you to have basic protections in place: multi-factor authentication, regular backups, antivirus, and employee training. If you do not, your claim may be reduced or denied. So your cyber policy and your cyber hygiene work together, not separately.

A Real Question From a Business Owner

Marco, who owns a small accounting firm, asked: "One of my staff wired $48,000 to what looked like a vendor's new bank account. It was fake. Will my cyber policy cover this?"

Marco, this is exactly the social engineering fraud scenario we just talked about, and it happens to small firms every single week. Whether you are covered depends on three things:

  • Do you have a cyber policy at all? Many small businesses still do not.
  • Does it include a social engineering or fraudulent instruction endorsement? Without that endorsement, this loss is often excluded entirely.
  • What is the sub-limit on that endorsement? Many small business policies cap social engineering at $25,000 or $50,000, which sometimes covers the loss and sometimes does not.

The fix going forward is to confirm that endorsement is on your policy, raise the sub-limit if your business handles larger transactions, and put a verbal verification process in place for any payment instruction that arrives by email. The phone call to verify takes 2 minutes. The fraudulent wire takes 2 years to recover from, if you recover at all.

Three Things You Can Actually Do This Week

If you take three things from this post, take these.

1. Confirm Your Social Engineering Coverage

Ask whether your cyber policy includes social engineering fraud coverage, and what the sub-limit is. If it is not there, add it. If the sub-limit is too low for the size of transactions your business handles, raise it.

2. Confirm Your Cyber Hygiene Basics

Multi-factor authentication on email and financial systems, regular backups, antivirus, and a written employee training process. Carriers reward these with lower premiums and stronger coverage, and the absence of them can reduce or deny a claim.

3. Do Not Assume Your IT Vendor's Insurance Protects You

Their policy protects them. You need your own. This is one of the most common assumptions we hear, and it is wrong every time. The IT vendor's coverage responds to claims against the vendor, not claims against your business.

How Trailstone Approaches Cyber Liability

Cyber is one of the policies where the fine print matters most, and where being independent makes the biggest difference. Two policies with the same headline price can have wildly different sub-limits, exclusions, and breach response services. This is exactly the kind of comparison our Commercial TRAC review is built for. TRAC stands for Trailstone Risk Assessment and Comparison, and on the cyber side it means we pull each carrier's actual policy language side by side, not just the premium. We compare your social engineering coverage, your business interruption sub-limits, your ransomware terms, and the quality of your breach response team. Then we lay out which carrier actually fits your business, with a written summary of where the gaps are and what it would cost to close them. We revisit it every renewal because cyber threats and carrier appetites change faster than almost any other line of insurance.

Frequently Asked Questions About Cyber Liability Insurance

What does cyber liability insurance cover?

A modern cyber liability policy covers data breaches, ransomware and extortion, business interruption from a cyber event, third-party legal defense and settlements, regulatory fines where insurable, and the cost of notifying affected parties. Most policies also include a breach response service with attorneys, forensic investigators, and PR specialists.

What is social engineering fraud?

Social engineering fraud, sometimes called fraudulent funds transfer or fraudulent instruction, is when an employee is tricked through a fake email or call into wiring money, changing payment information, or releasing sensitive data. It is the most common cyber loss for small businesses today.

Does my cyber policy cover wire fraud?

Most base cyber policies exclude social engineering and wire fraud, or only cover it with a small sub-limit. To get full coverage, you typically need a specific endorsement called Social Engineering Fraud or Fraudulent Instruction coverage. Always check whether the endorsement is on your policy and what the sub-limit is.

Do small businesses really need cyber insurance?

Yes. Small businesses are targeted at high rates because attackers know defenses are usually thinner and verification habits less consistent. Many client and vendor contracts now require proof of cyber coverage before they will work with you, regardless of company size.

What is a breach response service?

A breach response service is a team included with most modern cyber policies that handles the immediate response to a cyber event. It typically includes attorneys, forensic investigators, and PR specialists. For a business that has never been through a breach, this team is often the most valuable part of the policy.

What basic cyber protections do carriers expect?

Carriers typically expect multi-factor authentication on email and financial systems, regular backups, antivirus, and an employee training process. Without these, your premium is usually higher and your claim may be reduced or denied. Cyber hygiene and cyber insurance work together, not separately.

Does my IT vendor's insurance protect my business?

No. Your IT vendor's policy protects them, not you. Their coverage responds to claims against the vendor. Your business needs its own cyber liability policy to respond to losses you suffer directly.

How often should I review my cyber policy?

Every renewal, at minimum. Cyber threats and carrier appetites shift faster than almost any other line of insurance. Endorsements that were uncommon 2 years ago are standard today, and sub-limits that fit your business last year may not fit the volume you handle now.

What to Do Next: Your Cyber Liability Checklist

  • Confirm whether your business carries cyber liability coverage as a standalone policy or as a BOP endorsement.
  • Check whether social engineering or fraudulent instruction is included, and what the sub-limit is.
  • Confirm multi-factor authentication is on email and financial systems, including any vendor portals.
  • Confirm regular backups, antivirus, and employee training are documented.
  • Put a verbal verification process in place for any payment instruction or banking change that arrives by email.
  • Pull your declarations page and review your breach response provisions, your business interruption sub-limits, and your ransomware terms.
  • Ask for a written summary of your cyber policy's coverage, exclusions, and the endorsements your business should consider.

Schedule a Complimentary Cyber Insurance Review

If you would like a complimentary review of your cyber liability policy, including a look at your social engineering coverage and your breach response provisions, we are happy to help. Visit www.trailstoneinsurance.com or give us a call. Trailstone will provide a complimentary review of your insurance and a written summary you can keep for your records.

Next up in the Commercial Insurance 101 series: Employment Practices Liability, also called EPLI, which protects you from one of the fastest-growing types of business lawsuits and one that does not need a customer or an injury to happen.

Written by Mark Rodgers, President and Founder, Trailstone Insurance Group