Breach response, ransomware, business interruption, and privacy liability for businesses of every size — placed through the specialty and wholesale markets that compete for cyber risk. We tell you in plain English what carriers require, then shop it so you don’t have to.
Standard business policies were written for bodily injury and damaged property — not stolen data, locked-up systems, or a wire sent to a fraudster. Cyber is its own line, sold through its own markets, priced on your security controls. We work those markets daily, know which carriers fit which risk, and turn one short application into competing quotes.
A modern cyber policy has two sides — first-party coverage that pays your own costs after an incident, and third-party liability when others come after you. Plus the crime-style endorsements where many of today’s losses actually happen.
The first-party core: a 24/7 breach hotline, forensics to find out what happened, breach counsel, legally required notification letters to affected individuals, credit monitoring, and PR. State notification laws make much of this mandatory — the policy pays for it and hands you the response team.
Covers extortion demands, professional negotiators, and the cost of restoring systems after an attack that encrypts your data. Carriers pair it with the controls that stop it — MFA, endpoint detection, tested offline backups — which is exactly what underwriters ask about on the application.
When an attack takes your systems down, this replaces the income you lose during the outage and pays the extra expense of operating around it, plus the cost of recreating or restoring data. Contingent coverage can extend to outages at the cloud and software vendors you depend on.
The third-party side: defense and damages when customers, patients, employees, or business partners sue over a breach of their data — or claim malware spread from your network to theirs. For most businesses this is the coverage a client contract is actually asking for.
Defense costs for investigations by state attorneys general, the FTC, or HHS after a breach, plus fines and penalties where law allows them to be insured. PCI coverage handles the assessments card brands levy when payment card data is compromised — a common gap for anyone who takes cards.
Endorsements for where small-business dollars actually leave: an employee tricked into wiring money to a fraudster, funds transferred out of your accounts by an intruder, invoice manipulation, and “bricking” — hardware rendered useless by an attack. Usually sublimited, so the numbers deserve a close read.
Cyber is the line businesses most often buy blind: unfamiliar coverages, security questionnaires, sublimits buried in endorsements. Our job is to translate, shop, and structure it right the first time.
Most buyers stall out on carrier questionnaires. We start with one short supplemental application, take it to the specialty and wholesale cyber markets we work with daily, and bring back competing quotes — so you compare real options instead of filling out the same form five times.
Carriers now price on your controls: multi-factor authentication, endpoint detection (EDR), tested backups, patching. We tell you exactly what a carrier wants to see, what it changes in your premium, and the cheapest path to “yes” — before the application ever goes out.
Premium jumped at renewal? Carrier walked away after an incident? That is a placement problem, not a dead end. Wholesale cyber markets exist for exactly these risks, and we know which ones will look at a claim history or a control gap and still quote.
Cyber policies are claims-made, sublimited, and full of conditions. A licensed advisor walks you through the retroactive date, the social-engineering sublimit, and the callback requirements — the fine print that decides whether a six-figure loss is covered or excluded.
All 50 states have data breach notification laws — but deadlines, definitions of personal information, and regulator reporting differ in every one, and a growing list of states adds full privacy statutes on top. Pick your state for the specifics, or request a quote and we’ll handle the mapping.
Operating in a state or territory not listed? Request a quote — we place cyber coverage nationwide.
A straightforward path — whether it’s your first cyber policy or your fifth renewal.
Industry, revenue, the data you hold, and the basics of your security setup — MFA, backups, endpoint protection. One short application; if a control is missing, we tell you before it costs you a quote.
We take your application to the specialty and wholesale carriers that compete for your class and size, then translate the results — limits, retentions, sublimits, and retroactive dates — into a plain-English comparison.
Pick the program that fits, we bind, and you get your policy and certificates — including the evidence of cyber coverage a client contract or vendor agreement is asking for.
One short application tells you what the market will offer, what carriers will require, and what it costs. No obligation.