Data Breach
The situation: We found out that customer data, including names and payment information, was exposed in a hack of our small business's systems. I don't know what I'm required to do or whether any of our insurance covers this.
Quick Answer
A data breach involving customer information is typically the kind of event cyber insurance is designed to address, often covering costs like customer notification, credit monitoring, legal fees, and sometimes regulatory fines depending on your policy and state law. A standard general liability or business owners policy usually does not cover this well, since data breaches are generally treated as a specialized risk requiring their own coverage.
What Happened
A small online retailer discovered that a vulnerability in their e-commerce platform had allowed an outside party to access a database containing customer names, email addresses, and partial payment card information. The owner had purchased a standalone cyber insurance policy the previous year after a conversation with their insurance agent about growing online sales. The policy's breach response coverage paid for a forensic investigation to determine the scope of the breach, legal counsel to advise on notification requirements, and the cost of notifying affected customers and offering credit monitoring. Without that policy, those costs would have come directly out of the business's own funds.
Likely Relevant Policies
- Cyber Insurance
- Business Owners Policy (BOP)
- Errors & Omissions (E&O)
Potential Coverages
Cyber Insurance (Breach Response) High likelihood
This coverage typically pays for the immediate costs of responding to a breach, including forensic investigation, legal guidance, and customer notification.
Cyber Insurance (Liability) Medium likelihood
If affected customers or regulators pursue claims related to the breach, cyber liability coverage may help pay for legal defense and settlements, depending on the policy.
Errors & Omissions (E&O) Possible likelihood
If the breach stemmed from a failure in a service the business provided to clients, such as mishandling data on their behalf, E&O coverage might apply alongside or instead of cyber coverage depending on the circumstances.
General Liability Low likelihood
Standard general liability policies are typically built around bodily injury and property damage, not data breaches, so this coverage usually doesn't respond to a cyber incident on its own.
Possible Exclusions
- Breaches resulting from known, unpatched vulnerabilities the business failed to address after being notified
- Losses from an employee's intentional or fraudulent conduct, depending on policy wording
- Regulatory fines in jurisdictions where insurance is not permitted to cover such penalties
- Breaches involving systems or vendors excluded from the policy's defined scope
Questions That Determine Coverage
- Do you carry a standalone cyber insurance policy, or only a general business policy?
- What type of data was exposed, and how many people are affected?
- Was the vulnerability known and unaddressed before the breach occurred?
- What are your state's specific data breach notification requirements?
- Did the breach originate from your own systems or a third-party vendor?
- Does your policy cover regulatory investigations and potential fines?
Recommended Immediate Actions
- Work with IT or a security professional to contain the breach and stop further data exposure.
- Preserve logs and evidence for a forensic investigation rather than deleting anything.
- Contact your cyber insurer promptly, since many policies require early notification to access response services.
- Consult legal counsel about notification obligations under applicable state and federal law.
- Prepare to notify affected customers within required time frames once the scope is understood.
- Avoid public statements about the breach's cause or scope until the investigation is further along.
Documents to Collect
- System and access logs from around the time of the breach
- Forensic investigation report once completed
- List of affected individuals and the type of data exposed
- Legal counsel's guidance on notification requirements
- Cyber insurance policy declarations page
- Communications sent to affected customers and any regulators
Common Claim Process
After notifying the insurer, most cyber policies provide access to a panel of pre-approved vendors, including forensic investigators and breach response attorneys, who assess the scope of the incident and determine notification obligations. The insurer typically covers costs like the investigation, legal guidance, required notifications, and credit monitoring for affected individuals, up to the policy's limits. If lawsuits or regulatory action follow, cyber liability coverage may provide a legal defense and pay covered settlements. The process can take weeks to months depending on the breach's complexity and how many people are affected.
Potential Outcomes
- Breach response costs covered, including forensic investigation, notification, and credit monitoring.
- Legal defense and settlement costs covered under cyber liability if customers or regulators pursue claims.
- Partial coverage if some costs fall outside the policy's defined scope or sublimits.
- Claim denied or reduced if the business knowingly ignored a security vulnerability before the breach.
- Increased cyber insurance premium or new security requirements at renewal following a claim.
Risk Prevention Tips
- Keep software, plugins, and payment systems updated with current security patches.
- Limit the amount of sensitive customer data you store to only what's necessary.
- Use encryption and strong access controls for systems holding customer information.
- Have an incident response plan in place before a breach happens, not after.
- Review whether your business needs standalone cyber insurance rather than assuming a general policy covers this risk.
Frequently Asked Questions
Does general business insurance cover a data breach?
Usually not well. Standard general liability or business owners policies are typically built around physical injury and property damage, so a data breach generally requires a separate cyber insurance policy to be properly covered.
What does cyber insurance typically pay for after a breach?
It often covers costs like forensic investigation, legal counsel, customer notification, credit monitoring, and sometimes liability claims or regulatory defense, depending on the specific policy.
Am I legally required to notify customers after a data breach?
Most states have their own data breach notification laws with specific timelines and requirements, so this is worth confirming with legal counsel rather than assuming a single national standard applies.
Can insurance cover fines from a data breach?
Some cyber policies include coverage for regulatory fines and penalties, though this varies by policy and by jurisdiction, since some places don't allow insurance to cover certain types of fines at all.
Do small businesses really need cyber insurance?
Any business that stores customer data, processes payments, or relies on digital systems carries some breach risk, so it's worth evaluating cyber insurance rather than assuming that only large companies need it.
Related Terms
Related Scenarios
Related Tools
- Coverage Builder
- Insurance Needs Assessment
See the full list of live tools on the Tools page.
Explore the rest of the Small Business scenarios.
Browse Small Business scenarios →Educational information, not advice: Coverage depends on the policy wording, endorsements, exclusions, limits, deductibles and applicable state laws. This information is educational only and is not legal or insurance advice.