Coverage
Cyber & Data Breach
Breach response and recovery when client data is compromised.
Pays for notification, credit monitoring, forensic investigation, and client data recovery after a breach or ransomware event.
What's included
- $250k first-party coverage
- 24/7 incident response line
- PII and PHI ready
Who needs it
Anyone holding client records — pretty much everyone.
Quick qualifier
LiveGet My Rates
We shop up to 25 A-rated carriers and email your best options, usually within minutes.
Why cyber liability became a professional-office essential
Professional firms concentrate exactly what attackers monetize: client financial data, SSNs and tax documents, credentials to client systems, and wire-payment workflows. Cyber liability responds when that goes wrong — covering third-party claims from clients whose data you exposed, regulatory proceedings under state breach laws, and (through its first-party side, covered in depth here) your own response costs: forensics, notification, credit monitoring, ransom negotiation, and business interruption.
The claims we see most in professional offices aren’t exotic: business email compromise that redirects a client’s wire, a stolen laptop with client files, ransomware that locks the practice during its busiest season, and vendor-portal credentials phished from staff. Every state now has breach-notification law, and clients’ contracts increasingly require cyber limits alongside E&O — $1M is the emerging floor for data-touching professional vendors.
How cyber and E&O fit together
When a client suffers loss involving both your professional work and a security event — a breached bookkeeping platform, a hacked website you built, a compromised advisor portal — the claim straddles E&O and cyber. Buying both from coordinated forms (ideally the same carrier, or with a broker managing the seam) prevents each policy from pointing at the other. Technology professionals should buy the combined tech E&O/cyber forms built for exactly this; other professions should ensure their cyber includes third-party coverage, not just first-party response.
Frequently asked questions
My firm is tiny. Do attackers really target us?
Small professional firms are targeted precisely because they hold high-value data with lighter defenses — tax preparers and law offices are perennial phishing targets, and business email compromise doesn’t care about headcount. Claims data consistently shows small-business incidents clustering in professional services.
What does cyber insurance require from us?
Underwriting now expects baseline controls: multi-factor authentication on email and remote access, backups, and basic endpoint protection. Firms missing MFA increasingly can’t buy coverage at all — so the application process itself functions as a security checklist worth completing.
Does cyber cover wire-transfer fraud?
Funds-transfer fraud and social-engineering coverage exists but is often sublimited or optional — and it’s the single most likely loss for many professional offices. Confirm the sublimit, and pair coverage with callback verification procedures; carriers may require both.
Is cyber required by law?
No state mandates cyber insurance, but every state mandates breach response — notification duties, timelines, and in some states regulator notice. The insurance funds what the law requires you to do. Client contracts, meanwhile, are making cyber limits a standard vendor requirement.
Deep dive: first-party cyber coverage · tech firms: tech E&O · get quotes.