SMART INSURANCE FOR THE REAL WORLD

Transportation

Light Auto, Medium Auto, Long Haul, Tow Trucks, Sand & Gravel, Intermodal, Cargo and more.

More Info

Business

Business Owner's Policy, Workers' Compensation, Cyber, Real Estate, Restaurants, Retail, and more.

More Info

Contractors

General Liability, Builder's Risk, Tools, Professional Liability, Tools & Equipment, Bond's and more.

More Info

Personal

Auto, Home, Motorcycle, RVs, ATVs Boats, Classic Car, Renters, Condominiums' and more.

More Info

Cyber Insurance

Cyber Insurance for Businesses

Protect Your Business When a Digital Problem Becomes a Business Problem

Cyber insurance may help businesses respond to data breaches, ransomware, hacked email accounts, stolen information, system shutdowns, electronic fraud, and other qualifying cyber incidents.

Cyber risk reaches far beyond the computer. A serious incident can affect customers, employees, vendors, payments, daily operations, legal responsibilities, and the reputation of the business. A cyber policy may provide access to specialized professionals when quick decisions matter.

Coverage for Digital Events and Their Business Costs

What Can Cyber Insurance Help Cover?

Cyber insurance is designed to help businesses respond to certain computer, network, privacy, data, and electronic-fraud incidents. Depending on the policy, it may address expenses paid directly by the business as well as claims brought by customers, employees, vendors, regulators, or other affected parties.

Cyber Investigation

May help pay specialized professionals to determine what happened, how systems were accessed, what information was affected, and what steps may be needed to contain the incident.

Data & System Recovery

May help restore qualifying data, remove malicious software, rebuild affected systems, and return computer operations to an appropriate working condition.

Privacy Response & Notification

May help with qualifying legal guidance, customer notices, mailing, call-center services, credit monitoring, identity protection, and other response expenses.

Business Interruption

Cyber business-interruption coverage may help replace qualifying income lost when a covered network or computer-system interruption prevents normal operations.

Two Sides of Cyber Protection

Your Business Costs vs. Claims Against Your Business

First-Party Coverage

Costs Experienced by Your Business

Forensic investigation
Data and system restoration
Customer notification
Cyber business interruption
Crisis-management expenses

Third-Party Coverage

Claims Made Against Your Business

Customer privacy claims
Qualifying legal-defense expenses
Covered settlements or judgments
Regulatory investigations
Certain vendor or business-partner claims

Examples From Everyday Business Technology

When Might a Business Use Cyber Insurance?

Coverage depends on the policy, cause of loss, security controls, notification timing, limits, deductibles, sublimits, and endorsements.

Ransomware Locks the Systems

Employees cannot access important files or applications and an attacker demands payment to restore access or prevent information from being released.

Customer Data Is Stolen

A hacker accesses personal information belonging to customers, employees, applicants, vendors, or other individuals.

A Fake Email Steals Credentials

An employee responds to a phishing message and a criminal gains access to company email, payment, cloud-storage, or other accounts.

Money Is Sent to a Criminal

Fraudulent instructions appear to come from an owner, executive, vendor, customer, or employee and cause money to be sent to the wrong account.

A Vendor Is Hacked

A cloud provider, payroll company, software vendor, payment processor, or other important outside provider experiences a cyber event that affects the business.

The Business Cannot Operate

A qualifying cyber event disrupts billing, scheduling, communication, sales, production, payment processing, or customer service.

Cyber Policies Are Not All the Same

Important Coverage Options to Review

Ransomware & Cyber Extortion

May provide access to specialists and help with certain qualifying response expenses involving cyber threats, extortion, or ransomware.

Social Engineering

Certain policies may provide limited protection for qualifying losses caused by fraudulent instructions, impersonation, or deceptive payment requests.

Network & Privacy Liability

May help defend qualifying claims alleging that the business failed to protect information or prevent unauthorized access to systems.

Dependent Business Interruption

Certain policies may respond when a qualifying cyber event involving an approved outside technology provider disrupts the insured business.

Regulatory Response

May help with certain covered regulatory inquiries, investigations, legal expenses, and fines or penalties when insurable by law.

Sublimits Matter

Electronic fraud, ransomware, social engineering, notification, business interruption, and other protections may have separate limits or requirements.

Cyber insurance coverage review

Email, Cloud Systems, Payments & Customer Data

Your Business May Have More Cyber Exposure Than You Realize

A company does not need to be a technology business to have cyber risk. Everyday email, payroll, banking, cloud software, payment processing, employee records, and customer information can all create exposure.

Build the Policy Around the Technology You Actually Use

What Should a Business Review Before Buying Cyber Insurance?

Cyber applications may ask detailed questions about customer information, employee data, payment activity, cloud systems, outside vendors, multi-factor authentication, backups, employee training, remote access, prior incidents, and other security practices.

Multi-Factor Authentication

Insurers may review whether important email, administrator, cloud, remote-access, and financial accounts use additional authentication beyond a password.

Data Backups

Applications may ask how frequently important data is backed up and whether backup copies are separated or protected from the main network.

Employee Training

Security-awareness and phishing training may help reduce the chance that employees respond to fraudulent emails or reveal sensitive credentials.

Software Updates

Insurers may ask about patching procedures, supported software, operating systems, endpoint protection, and vulnerability management.

Outside Technology Vendors

Cloud platforms, software providers, payroll companies, payment processors, and IT firms can create important dependencies that should be disclosed.

Incident-Response Plan

A documented plan can help employees understand whom to contact, what systems to protect, and how to respond when a potential cyber event is discovered.

A Real-Looking Email Can Cause a Real Financial Loss

Business Email Fraud & Fake Payment Instructions

Criminals may impersonate an owner, executive, employee, vendor, customer, or financial institution to convince someone to send money, change banking information, reveal credentials, or disclose sensitive information.

Fake Vendor Instructions

A criminal changes bank information on an invoice or requests that future payments go to a fraudulent account.

Fake Executive Request

An email or text appears to come from a company leader requesting an urgent wire transfer, gift cards, payroll change, or confidential information.

Verify Through Another Method

Businesses can reduce exposure by requiring employees to verify unusual payment requests and bank-account changes using known contact information.

Your Data and Systems May Be Somewhere Else

Cyber Events Involving Outside Vendors

Cloud & Software Providers

Email, customer management, accounting, file storage, scheduling, and other cloud systems may contain important business information.

Payroll & HR Providers

Outside providers may hold employee identification, tax, payroll, direct-deposit, benefits, and other sensitive information.

Payment Companies

Payment processors, banks, billing systems, and point-of-sale platforms may be critical to receiving and sending money.

Managed Technology Providers

Outside IT firms may have high-level access to networks, computers, passwords, security tools, backups, and administrative systems.

Use the Policy Early

What Should a Business Do After a Cyber Incident?

Cyber policies may require prompt notice and may provide access to approved attorneys, forensic investigators, negotiators, restoration firms, and other response professionals.

1

Report the Incident

Contact the cyber insurer’s incident hotline or claims contact as soon as reasonably possible.

2

Limit Additional Damage

Follow professional guidance for affected devices, passwords, remote access, backups, and compromised accounts.

3

Preserve Evidence

Keep suspicious emails, payment instructions, account records, device information, logs, messages, and other relevant evidence.

4

Coordinate the Response

Work with approved professionals to investigate, restore operations, review notification duties, and document qualifying expenses.

Cyber Insurance Learning Center

Understand the Coverage Before an Incident

Explore practical guides about ransomware, data breaches, response costs, cyber extortion, privacy obligations, and business interruption.

Cyber Extortion

How Does Ransomware Coverage Work?

Learn about cyber investigation, specialist response, negotiation, system restoration, data recovery, business interruption, and important policy requirements.

Explore Ransomware Coverage →

How Does Ransomware Coverage Work?

Privacy Response

What Happens After a Data Breach?

Review investigation, legal guidance, customer notices, credit monitoring, communication, regulatory response, and other expenses that may follow a qualifying data breach.

Open the Data Breach Guide →

What Happens After a Data Breach?

Adding Software, Vendors, Employees, or Online Payments?

Technology Changes Can Change Your Cyber Exposure

New cloud systems, remote access, online payments, additional customer records, new employees, outside vendors, or major contracts can affect cyber insurance limits, security requirements, and available coverage.

Cyber Insurance Questions

Cyber Insurance FAQs

Clear answers about data breaches, ransomware, electronic fraud, customer information, vendors, business interruption, employee mistakes, security requirements, and cyber insurance.

What does cyber insurance cover?

Cyber insurance may help with qualifying expenses involving data breaches, cyberattacks, ransomware, forensic investigations, system restoration, legal services, customer notification, business interruption, liability claims, and regulatory response.

Does a small business need cyber insurance?

A small business may have cyber exposure whenever it uses email, computers, online banking, electronic payments, cloud services, customer records, employee information, remote access, or other technology that could be attacked or interrupted.

Do I need cyber insurance if I do not sell products online?

Possibly. Cyber risk can come from email, payroll, banking, employee records, customer information, cloud software, payment systems, remote access, vendors, and other everyday business technology.

Does general liability insurance cover a data breach?

General liability insurance should not automatically be assumed to provide the specialized first-party and third-party protection available under a cyber policy. The actual policies and exclusions should be reviewed.

Does cyber insurance cover ransomware?

Certain cyber policies may cover qualifying ransomware-response expenses, investigation, negotiation, system restoration, data recovery, and business interruption. Security requirements, limits, exclusions, and policy terms vary.

Will cyber insurance pay a ransom?

Coverage may be available under certain policies, but payment is not automatic. Policy terms, legal restrictions, insurer approval, specialist recommendations, sanctions considerations, and the facts of the incident must be reviewed.

Does cyber insurance cover stolen money?

Certain electronic-fraud or social-engineering losses may be covered, but these protections commonly have separate limits, deductibles, verification requirements, exclusions, and other conditions.

What is social-engineering fraud?

Social engineering generally involves a criminal manipulating an employee into sending money, changing payment details, revealing credentials, sharing sensitive information, or taking another harmful action.

Does cyber insurance cover lost business income?

Cyber business-interruption coverage may help replace qualifying income lost during a covered network or system interruption, subject to applicable waiting periods, limits, definitions, and calculation methods.

What happens if one of my technology vendors is hacked?

Certain cyber policies may respond to qualifying incidents involving approved outside providers that hold data or support important business systems. Vendor definitions and dependent business-interruption coverage should be reviewed carefully.

Does cyber insurance cover employee mistakes?

Certain accidental events, such as sending information to the wrong person, losing a device, clicking a malicious link, or exposing credentials, may be covered depending on the circumstances and policy terms.

What should I do first after discovering a cyber incident?

Contact the cyber insurer’s incident hotline or claims contact promptly. Follow professional instructions, preserve evidence, limit further damage, and review policy requirements before hiring outside vendors or making significant payments.

Why does the cyber application ask about multi-factor authentication?

Multi-factor authentication adds another verification step beyond a password and may reduce unauthorized account access. Insurance companies may consider it an important underwriting and security control.

Why does the application ask about backups?

Backups may help a business restore information after ransomware, accidental deletion, system failure, or another qualifying incident. Insurers may review backup frequency, protection, testing, and whether copies are isolated from the main network.

Can customers require my business to carry cyber insurance?

Yes. Customers, lenders, landlords, government entities, vendors, and larger organizations may require cyber insurance or minimum limits before entering into a business agreement.

What information is needed for a cyber insurance quote?

Information may include business type, annual revenue, number of employees, customer and employee records, payment methods, cloud systems, technology vendors, security controls, backups, employee training, prior incidents, requested limits, and contractual requirements.

How much cyber insurance does a business need?

Appropriate limits may depend on annual revenue, number and type of stored records, dependence on technology, payment activity, customer contracts, interruption exposure, industry requirements, and vendor dependencies.

Are all cyber policies the same?

No. Definitions, ransomware coverage, social-engineering limits, business-interruption protection, dependent-provider coverage, notification services, security requirements, deductibles, waiting periods, and exclusions can vary significantly.

What affects the cost of cyber insurance?

Pricing may depend on business type, annual revenue, employee count, information stored, payment activity, security controls, backups, vendors, prior incidents, requested limits, deductibles, sublimits, and selected coverage.

Cyber insurance options

Data. Systems. Payments. Operations.

Cyber Coverage Built Around the Way Your Business Uses Technology

Best Formula Insurance can help review your customer information, employee records, computer systems, cloud providers, payment activity, outside vendors, contracts, security controls, cyber limits, and available cyber insurance options.