Is your situation covered?
| Scenario | Typical verdict | Why |
|---|---|---|
| Ransomware encrypts your servers | Depends on wording | Cyber policy pays ransom, forensics, restoration. GL and BOP usually don't. |
| Employee wires $80k to a spoofed vendor | Depends on wording | Social engineering fraud endorsement required — not automatic on crime policies. |
| Customer PII stolen in a breach | Depends on wording | Cyber policy pays notification, credit monitoring, regulatory fines. |
| Business income lost during system outage | Depends on wording | Cyber business interruption endorsement; standard BI needs physical damage. |
| Lawsuit from a customer whose card was breached | Depends on wording | Cyber liability, not general liability. GL excludes electronic data. |
General industry patterns. Your actual cover lives in your policy wording — PolicyPal reads it for you.
The short answer
Standard business insurance (GL, BOP) does not cover cyber events — the ISO CG 21 06 endorsement explicitly excludes electronic data and access. You need a standalone cyber liability policy or a cyber endorsement on your BOP. Coverage splits into first-party (your losses: ransom, forensics, restoration, business income) and third-party (claims against you: breach lawsuits, regulatory fines).
What's usually missing from small-business cyber policies
Sub-limits on ransomware payouts, exclusions for war and nation-state actors, coinsurance on business interruption, and no coverage for social engineering fraud unless specifically endorsed. Read the schedule of coverages, not just the limit.
What PolicyPal checks
Upload your BOP or standalone cyber policy and we flag: ransomware sub-limits, waiting period for BI, social engineering coverage, PCI fine coverage, retroactive date, and whether MFA/backup warranties could void a claim.
Common claim issues
Cyber claims fail more often on warranty and hygiene requirements than on the incident itself.
- MFA warranty breached — no MFA on admin accounts
- Backups not tested or offline as required
- Late notification (many cyber policies require 24–72 hours)
- Paying ransom before insurer approval voids reimbursement
Frequently asked
- How much cyber coverage does a small business need?
- Baseline $1M / $1M is common for firms under $10M revenue. Regulated industries (healthcare, finance, legal) often need $3M–$5M.
- Does cyber cover ransomware payments?
- Yes if you have cyber extortion coverage — but sanctions rules require insurer approval before payment.
- Is wire fraud covered?
- Only with a social engineering fraud endorsement — it's not automatic on cyber or crime policies.
- What is a retroactive date?
- The earliest date a discovered breach is covered. A new policy with today's retro date won't pay for a breach that started six months ago.
- Do I need cyber if I use cloud providers?
- Yes — cloud vendor contracts cap their liability. Your data, notification, and customer suits are still your responsibility.
- Does GL cover cyber lawsuits?
- No — the ISO CG 21 06 exclusion removes electronic data claims from general liability. Cyber liability is the correct policy.
Your policy is the only source of truth
Stop guessing. Check your actual policy.
Generic answers don't pay claims. PolicyPal reads your policy wording in seconds and tells you, in one sentence, whether you're covered.
