Business Insurance

Cyber liability for when the systems go down.

The cost of a breach is rarely the hacking. It is the notification, the forensics, the downtime and the lawyers afterwards.

Cyber cover is one of the few policies where the first-party costs — what the incident does to you — usually exceed the third-party liability. A ransomware event closes a business for days, requires specialist forensics, triggers notification obligations under Texas law, and only then produces claims from the people whose data was exposed.

First-party and third-party are different halves

First-party cover pays your own costs: incident response, forensic investigation, data restoration, business interruption while systems are down, and any ransom payment where the policy permits it. This is the half most businesses actually claim on.

Third-party cover responds to claims from others — customers whose data was exposed, regulators, payment card networks. Both halves matter, but a policy weighted only toward liability leaves you funding the response yourself.

Texas notification obligations

Texas requires businesses to notify individuals whose sensitive personal information was compromised, and to do so without unreasonable delay. Where a breach affects a large number of Texans, the Attorney General must also be notified.

Notification is not cheap. Identifying who was affected, producing and sending notices, and standing up credit monitoring costs real money before a single claim is made against you. That is precisely what breach response cover is for.

Social engineering is often excluded

The most common loss small businesses actually suffer is not a sophisticated intrusion. It is an employee wiring money after a convincing email. That is social engineering or funds transfer fraud, and many cyber policies exclude it or apply a sub-limit far below the main limit.

If you make payments on emailed instructions — and almost every business does — check this specifically. It is usually available as an endorsement and it is the cover most likely to be used.

What it covers

The parts of a cyber liability insurance policy


Breach response

Forensics, legal advice and incident management from the first hours.

Notification costs

Identifying affected people, notifying them, and credit monitoring where offered.

Ransomware

Extortion response, negotiation and recovery, subject to the policy terms.

Business interruption

Income lost while systems are unavailable after an incident.

Third-party liability

Claims from customers, regulators and payment networks after a breach.

Funds transfer fraud

Money sent on fraudulent instruction — frequently excluded or sub-limited, so check it.

Working with us

What we do differently


We are an independent agency, so we place your cyber liability insurance across several carriers rather than fitting you to one company's product. That means a genuine comparison, and someone to call who is not a call centre.

  • Check the sub-limit for social engineering and funds transfer fraud specifically
  • Confirm business interruption is included, not just liability
  • Ask what the waiting period is before interruption cover starts paying
  • Know who you call in the first hour — most policies provide a response line
A business team working at their computers in a Dallas office
Common questions

Cyber Liability Insurance, answered


Does my general liability policy cover a data breach?

Almost certainly not. General liability responds to bodily injury and physical property damage. Data is neither, and most policies now carry explicit electronic data exclusions. Cyber cover is a separate policy.

What are my notification obligations in Texas?

Texas requires notification to individuals whose sensitive personal information was compromised, without unreasonable delay, and notification to the Attorney General where a breach affects a large number of Texans. The cost of doing this is a common first-party claim.

Is a ransom payment covered?

Many policies include extortion cover, subject to their own conditions and to sanctions law. What matters as much is the response support — negotiation, forensics and recovery — because paying is rarely the whole answer.

We are small. Do we really need this?

Small businesses are targeted precisely because their controls are lighter. The most common loss is not a sophisticated attack but an employee wiring funds on a fake instruction, which is a cover worth having regardless of size.

Does it cover our downtime?

Cyber business interruption covers income lost while systems are unavailable, usually after a short waiting period. Check both the waiting period and the indemnity period, as they vary considerably between forms.

Ready for a cyber liability insurance quote?

Answer a few questions and one of our agents will come back to you.

No obligation. We will never sell your information. Prefer to talk? Call (817) 540-2947.

Ready for peace of mind?

Let us protect what matters most.