Breach response
Forensics, legal counsel, notification, credit monitoring, and public relations. The panel your carrier provides is worth as much as the limit.
The cheap policy and the real policy look identical on a certificate. They behave nothing alike at two in the morning when everything is encrypted.
Multifactor authentication, offline backups, and endpoint detection are no longer discounts. Without them, most markets will not quote at all.
What the policy covers
Forensics, legal counsel, notification, credit monitoring, and public relations. The panel your carrier provides is worth as much as the limit.
Ransom payment where lawful, negotiation specialists, and the restoration work that follows. Sublimits and coinsurance are common here.
Lost income from an outage. Confirm whether the trigger requires an attack or also covers your own system failure and your vendor's.
The claim small businesses actually have. A fraudulent invoice or wire instruction, paid by a real employee following a real process.
Suits and regulatory action following a breach, including CCPA exposure and payment card penalties.
Defamation, copyright, and content claims arising from your website, marketing, and social channels.
Read this part
Cyber forms are not standardized. Two policies at the same limit can differ by an order of magnitude in what they pay.
How we place cyber
Records held, payment card volume, health information, and where it lives. Volume of records drives both the notification exposure and the price.
MFA, backups, EDR, email filtering, patching cadence, and privileged access. We complete this with you so the application is accurate and defensible.
The limit is not a guess. Cost per record times record count plus forensics and legal gives you a defensible number.
Who calls the carrier hotline, who has authority to engage counsel, and what your first hour looks like. Coverage without a plan burns the retention on confusion.
Where the exposure concentrates
Not on the list is not the same as not placeable. Ask.
Questions we get
Small businesses are the preferred target precisely because the controls are weaker and the payments are faster. Most of the claims we see are opportunistic and automated, not targeted.
Their E&O covers their negligence, to their limit, after you prove it. It does not pay your notification costs, your downtime, or your regulatory exposure. Their policy is not a substitute for yours.
California's privacy statute allows a private right of action with statutory damages per consumer per incident for certain breaches. For a business holding even modest consumer records, that arithmetic gets serious quickly.
Next step
Loss runs, current declarations, and five minutes of context. You will hear back the same business day with what we can do and which markets we are approaching.