Cyber insurance has gone from a nice-to-have to a baseline coverage for California businesses, and the reason is simple: the losses are frequent, expensive, and largely uncovered by the policies most owners already carry. A ransomware event, a fraudulent wire transfer, or a data breach exposing customer information can run from tens of thousands to millions of dollars — and your general liability, property, and crime policies were mostly not designed to pay for it.
This guide explains what cyber insurance actually covers, the specific exposures that drive California claims (including the state's uniquely aggressive privacy law), what carriers now require before they'll even quote you, and how to read the sublimits and exclusions that separate a policy that protects you from one that only looks like it does.
Why Your Existing Policies Don't Cover Cyber
Owners are often surprised that a cyber loss falls through their existing program:
- General liability covers bodily injury and physical property damage — and most CGL policies now carry explicit exclusions for data and electronic events ("silent cyber" has largely been endorsed out of standard policies).
- Commercial property covers physical damage to tangible property; data is generally not "tangible property," and a ransomware lockout isn't physical damage.
- Crime / fidelity policies cover certain theft and employee dishonesty, but often exclude or sublimit social-engineering and voluntary-transfer wire fraud — the exact way most business email compromise losses happen.
Cyber insurance exists precisely to fill this gap, and it's built in two halves: first-party (your losses) and third-party (your liability to others).
First-Party Coverage — Your Own Losses
First-party coverage pays for the direct costs your business absorbs after an incident:
- Incident response and forensics — the breach coach (privacy attorney), forensic investigators, and the team that figures out what happened and stops it. This is usually the first and most valuable thing a policy delivers.
- Data restoration — the cost to recover or recreate data and systems corrupted or encrypted in an attack.
- Business interruption — lost income and extra expense while your systems are down, including from an attack on a vendor you depend on (contingent/dependent business interruption).
- Cyber extortion / ransomware — ransom negotiation and, where legally permissible, payment, plus the cost of recovery. Almost always sublimited (see below).
- Digital asset / bricking — restoring or replacing data and, in some forms, hardware rendered useless by an attack.
- Reputational harm — some policies cover income lost to reputational damage following a publicized event.
Social Engineering and Funds-Transfer Fraud
The single most common cyber claim for small and mid-size businesses isn't exotic malware — it's business email compromise (BEC): an attacker impersonates an executive or vendor and tricks an employee into wiring money or changing payment details. Coverage for this — variously called social engineering fraud, funds-transfer fraud, or invoice manipulation — is frequently offered only by endorsement and at a lower sublimit than the policy aggregate. If your business moves money, this is a coverage to insist on and size deliberately.
Third-Party Coverage — Your Liability to Others
Third-party coverage responds when others are harmed by a breach of data you held:
- Breach notification — the cost of notifying affected individuals (required by California law), credit monitoring, and call-center support.
- Privacy and network security liability — defense and damages when customers, employees, or partners sue over a breach.
- Regulatory defense and penalties — the cost of responding to regulators (including the California Privacy Protection Agency and the Attorney General) and, where insurable, fines.
- Media / content liability — claims like defamation or IP infringement arising from your online content.
- PCI fines and assessments — penalties from card networks after a payment-card breach, if you take cards.
The California Factor — CCPA, CPRA, and the Private Right of Action
California has the most consequential state privacy regime in the country, and it directly shapes cyber exposure for any business that holds Californians' personal information.
Under the California Consumer Privacy Act (CCPA), as expanded by the California Privacy Rights Act (CPRA), consumers have a private right of action when certain personal information is breached as a result of a business's failure to maintain reasonable security. Statutory damages run from $100 to $750 per consumer per incident (or actual damages, if greater) — which means a breach affecting tens of thousands of records can generate a class action with staggering exposure, entirely apart from regulatory action.
On top of that, California's breach-notification law (Civil Code §1798.82) requires notifying affected residents when their personal information is compromised. Cyber insurance is built to fund both sides of this: the notification obligation and the liability that follows.
In most states the biggest cyber question is "what will the attack cost us to fix?" In California, you have to add "and what will our own customers be able to recover from us afterward?" The CCPA private right of action is why the third-party side of a cyber policy matters so much here.
What Carriers Now Require Before They'll Quote
After years of heavy ransomware losses, cyber underwriting tightened dramatically. Most carriers now require a set of baseline controls just to offer terms — and stronger controls to earn better pricing. The common ones:
- Multi-factor authentication (MFA) — on email, remote access (VPN/RDP), and privileged/admin accounts. This is the near-universal gate; no MFA often means no quote.
- Endpoint detection and response (EDR) — modern endpoint security beyond legacy antivirus.
- Secure, tested backups — offline or immutable backups you have actually restored from, so ransomware doesn't force a payment.
- Email filtering and security awareness training — to blunt phishing and BEC.
- Patch management and end-of-life system removal, and often network segmentation and a documented incident-response plan.
These controls aren't just underwriting hoops — they're the same measures that prevent most losses. Improving them is the most reliable way to both lower premium and reduce the chance you ever file a claim.
Reading the Fine Print — Sublimits, Coinsurance, and Exclusions
Two cyber policies with the same headline limit can offer wildly different protection. The details that matter:
- Ransomware / cyber extortion sublimits and coinsurance — many policies now cap ransomware at a fraction of the aggregate and require you to share a percentage of the loss (coinsurance). Know these numbers before you need them.
- Social engineering sublimit — as noted, funds-transfer fraud is frequently sublimited well below the policy aggregate.
- Dependent/contingent business interruption — whether the policy covers downtime caused by an outage at a vendor or cloud provider, and any waiting period before it pays.
- Waiting period / retention — business interruption typically has an hourly waiting period; the deductible (retention) can be substantial.
- Exclusions to check — war/hostile-act and "widespread event" exclusions (in the wake of state-sponsored attacks), prior known incidents, unencrypted-device or unpatched-system conditions, and betterment/upgrade costs.
How Much Coverage — and What It Costs
The right limit depends on how much sensitive data you hold, how much revenue depends on your systems, and how much money you move. A professional-services firm with a small client database has a very different exposure than a healthcare provider, an e-commerce retailer, or a business that wires large sums. Rather than anchoring on a round number, size the limit to a realistic worst case: a full breach-notification event for your record count, plus a multi-week business interruption, plus defense of a resulting claim. Premiums for small and mid-size businesses have stabilized after years of increases, and strong security controls are the biggest factor in getting a competitive quote.
Building Your Cyber Program — A Practical Checklist
- Deploy the controls carriers require — MFA everywhere, EDR, tested offline/immutable backups, email filtering, and training — before you shop.
- Buy both halves — first-party (your costs) and third-party (your liability); don't assume one includes the other.
- Add social-engineering / funds-transfer fraud by endorsement and size the sublimit to how much money you move.
- Confirm ransomware sublimits and coinsurance and whether dependent business interruption is included.
- Size the limit to a real worst case — breach notification for your record count plus extended downtime plus defense.
- Answer the application as a warranty — accurately, because it affects whether a claim gets paid.
- Know your incident-response resources — most policies include a breach hotline and pre-approved vendors; know how to reach them before an incident.
Frequently Asked Questions
Does my general liability or property policy already cover cyber?
Almost never in a meaningful way. Standard CGL now typically excludes data and electronic events, and property policies cover physical damage, not encrypted or stolen data or lost income from an outage. Cyber insurance exists specifically to fill that gap.
Is cyber insurance only for tech companies?
No. Any business that holds customer or employee data, takes payments, relies on computers to operate, or moves money by wire has a cyber exposure. Contractors, medical and dental practices, retailers, professional-services firms, and manufacturers all file cyber claims — often for wire fraud or ransomware rather than a classic data breach.
Why does California make cyber liability worse?
The CCPA/CPRA gives consumers a private right of action with statutory damages of $100–$750 per consumer per incident for breaches caused by inadequate security, plus a strict breach-notification requirement. That turns a breach into potential class-action exposure on top of the cost of fixing the incident — which is exactly what the third-party side of a cyber policy is designed to cover.
Will I get denied a quote if I don't have MFA?
Very likely. Multi-factor authentication on email, remote access, and admin accounts is now a near-universal minimum for cyber carriers. If you don't have it yet, that's the first thing to implement — it improves both your insurability and your actual security.
Sources & Further Reading
- California Attorney General — CCPA — the California Consumer Privacy Act, consumer rights, and the data-breach private right of action.
- California Privacy Protection Agency — CPRA rulemaking and enforcement.
- CISA — StopRansomware — federal guidance on ransomware defense, multi-factor authentication, and backups.
Talk to Bollinsure
Bollinsure is an independent California broker that places cyber insurance across a broad market of carriers — matching your coverage to how much data you hold, how much you depend on your systems, and how much money you move, while making sure the ransomware, social-engineering, and business-interruption terms actually fit your risk. We'll help you get the security controls in place to qualify for strong terms and read the sublimits so there are no surprises at claim time. See our cyber insurance overview or request a review.