Rapid Risk PartnersInsurance Services LLC

Home/Commercial lines/Cyber and privacy

Cyber and
privacy

A workstation with multiple screens

The cheap policy and the real policy look identical on a certificate. They behave nothing alike at two in the morning when everything is encrypted.

Controls decide eligibility now

Multifactor authentication, offline backups, and endpoint detection are no longer discounts. Without them, most markets will not quote at all.

What the policy covers

The pieces, and what each one is actually for.

First party

Breach response

Forensics, legal counsel, notification, credit monitoring, and public relations. The panel your carrier provides is worth as much as the limit.

First party

Ransomware and extortion

Ransom payment where lawful, negotiation specialists, and the restoration work that follows. Sublimits and coinsurance are common here.

First party

Business interruption and system failure

Lost income from an outage. Confirm whether the trigger requires an attack or also covers your own system failure and your vendor's.

Crime

Funds transfer and social engineering

The claim small businesses actually have. A fraudulent invoice or wire instruction, paid by a real employee following a real process.

Third party

Privacy and network security liability

Suits and regulatory action following a breach, including CCPA exposure and payment card penalties.

Third party

Media liability

Defamation, copyright, and content claims arising from your website, marketing, and social channels.

Read this part

Read these before you bind

Cyber forms are not standardized. Two policies at the same limit can differ by an order of magnitude in what they pay.

  • Waiting period on business interruption. Eight hours and twenty four hours are very different products.
  • Sublimits and coinsurance on ransomware, sometimes as low as ten percent of the policy limit.
  • Warranty language on security controls. Answering yes to multifactor authentication when it is partially deployed can void the coverage.
  • Dependent business interruption, which is what responds when your vendor is the one who goes down.
  • Prior acts and the retroactive date, because dwell time on an intrusion routinely predates the policy by months.

How we place cyber

Work the inputs before working the market.

Step 01

Inventory the data

Records held, payment card volume, health information, and where it lives. Volume of records drives both the notification exposure and the price.

Step 02

Document the controls

MFA, backups, EDR, email filtering, patching cadence, and privileged access. We complete this with you so the application is accurate and defensible.

Step 03

Match limit to notification cost

The limit is not a guess. Cost per record times record count plus forensics and legal gives you a defensible number.

Step 04

Test the response plan

Who calls the carrier hotline, who has authority to engage counsel, and what your first hour looks like. Coverage without a plan burns the retention on confusion.

Where the exposure concentrates

Professional servicesHealthcare and home healthNonprofits with donor dataTechnology and SaaSFinancial servicesRetail and ecommerceManufacturersSchoolsMunicipal contractorsProperty managementCourt reporting and legal supportAny business that wires money

Not on the list is not the same as not placeable. Ask.

Questions we get

Straight answers.

We are small. Are we really a target?

Small businesses are the preferred target precisely because the controls are weaker and the payments are faster. Most of the claims we see are opportunistic and automated, not targeted.

Does our IT provider's insurance cover us?

Their E&O covers their negligence, to their limit, after you prove it. It does not pay your notification costs, your downtime, or your regulatory exposure. Their policy is not a substitute for yours.

What does CCPA exposure actually mean for us?

California's privacy statute allows a private right of action with statutory damages per consumer per incident for certain breaches. For a business holding even modest consumer records, that arithmetic gets serious quickly.

Next step

Send us the submission

Loss runs, current declarations, and five minutes of context. You will hear back the same business day with what we can do and which markets we are approaching.