General Insurance

Why Your General Insurance Policy Doesn’t Cover a Data Breach in a Small Business

Document showing data breach exclusion clause in general liability insurance policy with ransomware statistics

Quick Answer

Standard general liability policies exclude data breach coverage. 88% of small business breaches involve ransomware, yet only 17% of small businesses carry cyber insurance. A data breach can cost $3.31 million on average for firms under 500 employees. Without a dedicated cyber policy, businesses face out-of-pocket losses for notification, legal fees, and regulatory fines. Talk to your agent about adding a cyber endorsement to your BOP.

Updated December 2025

Most small business owners think their general liability policy covers a data breach. It doesn’t. Standard CGL policies explicitly exclude electronic data loss. The Federal Trade Commission says these policies don’t cover network attacks, third-party data breaches, or regulatory inquiries. Yet 88% of SMB breaches involve ransomware (Verizon 2025 DBIR). Only 17% of small businesses carry any form of cyber insurance.

That gap leaves you footing the bill for forensic investigators, credit monitoring through Experian, and fines from regulators like the CFPB. Here’s what’s actually in your policy, how to close the gap, and where to look for hidden gotchas like vendor risk and prior-acts exclusions.

Key Takeaways

  • Standard general liability policies exclude electronic data breaches: 88% of SMB breaches involve ransomware, yet only 17% of small businesses carry cyber insurance. Source: Verizon (2025)
  • Small businesses face average breach costs of $3.31 million for organizations with under 500 employees. Source: IBM (via CNIC Solutions, 2025)
  • Only 17% of small businesses carry cyber insurance, despite rising threat levels. Source: Deep Strike Research (2025)
  • ISO CGL forms contain an explicit exclusion: “loss of, damage to, or inability to access electronic data.” Source: NIST (2025)
  • Adding a cyber endorsement to a BOP typically costs between $45 and $320 annually, but response costs exceed this range. Source: SBA (2025)

What Does a General Liability Policy Cover?

CGL policies cover bodily injury and physical property damage. Slips, falls, broken windows. They were never designed for digital data. That’s the gap.

The Federal Trade Commission has long said these policies can’t handle network attacks, data breaches, or regulatory investigations. For a small business that stores customer payment card data or Social Security numbers, a CGL policy is just the wrong tool.

Why ‘All-Risk’ Policies Fall Short

Many owners think a policy labeled “all-risk” covers everything. Not even close. The National Institute of Standards and Technology confirms that CGL forms were never intended for data breach events. Courts agree.

Even a policy sold as full-coverage won’t cover a ransomware demand. A 2025 Sixth Circuit ruling in Georgia denied coverage for a payment-card breach under a CGL policy, citing the ISO exclusion. The business had assumed it was protected. It wasn’t. Carriers like Travelers and Chubb use this exact language.

Did You Know?

Only 17% of small businesses carry cyber insurance, despite 88% of breaches involving ransomware. Source: Verizon (2025)

Does Your Policy Exclude Electronic Data?

The ISO CGL form has a specific exclusion: “loss of, damage to, or inability to access electronic data.” That one sentence voids any data breach claim. It’s absolute.

This language covers ransomware attacks, data corruption, and system lockouts. Courts have consistently upheld it, even when a business suffered huge losses. Insurers like Hiscox and The Hartford rely on this exclusion routinely.

Court Rulings That Back the Insurer

The 2025 Sixth Circuit decision we mentioned? It was a payment-card breach at a retailer. The court found the electronic data exclusion applied. No coverage. That case resonates because many small businesses use card processors like Square or Stripe and assume their liability policy has their back. It doesn’t.

Other courts have applied the same logic. When a breach hits, the insurer points to this exclusion and denies. You can’t argue around it.

By the Numbers

Small businesses face average breach costs of $3.31 million. Source: IBM (2025)

Why Are Small Businesses Targeted?

Attackers know small businesses are soft targets. Limited IT budgets, no dedicated security staff. A 2025 SBA report found only 11% have a formal cyber risk plan. That’s a huge vulnerability.

Even if a breach starts at a vendor, the small business is still on the hook. State laws like CCPA and GDPR impose notification duties regardless of fault. The CFPB has also increased its focus on small business data practices.

The Vendor Risk Most Owners Ignore

A breach at your email provider or cloud storage company can trigger liability for you. Yet standard policies don’t cover that. If your payroll processor leaks employee W-2s, you may face lawsuits. Without cyber liability, those costs are yours.

Check vendor contracts. Require them to carry their own cyber insurance. Carriers like Hiscox offer third-party liability that covers vendor failures, but you have to ask for it.

Pro Tip

Review your vendor contracts for data handling clauses. If a vendor processes customer data, ensure they carry cyber insurance. Ask your agent about adding third-party coverage to your policy.

What Does a Data Breach Cost a Small Business?

A breach is a financial emergency, not a tech headache. IBM’s 2025 study puts the average cost for firms under 500 employees at $3.31 million according to IBM (via CNIC Solutions analysis). That includes forensic work, customer notification, legal fees, and fines.

Notification and credit monitoring: $250,000. Forensic investigation: $180,000. Legal defense: $400,000. CCPA fines: $350,000. Business interruption: $500,000. Total: $1.68 million. That’s for a mid-sized breach. Your checking account at Chase isn’t protected from business fraud by FDIC insurance. That only covers bank deposits, not cyber losses.

Real-World Cost Breakdown (2025 Data)

For a business with 200 employees, this is crippling. No general policy covers it. Without cyber insurance, the owner faces personal liability.

Small Business Data Breach Cost Breakdown (2025)

What Does Cyber Insurance Cover?

Dedicated cyber coverage pays for first-party response and third-party liability. First-party includes forensic costs, notification, credit monitoring, and business interruption. Third-party covers customer lawsuits and regulatory fines.

A standalone policy or BOP endorsement covers both. Carriers like Chubb and AIG offer standalone policies that cover PCI DSS fines and credit monitoring through Experian.

How Add-Ons Work on a BOP

For a 50-employee shop, adding a cyber rider to your BOP through carriers like The Hartford typically costs $320 a year. That covers forensic teams and notification costs. Meanwhile, a breach can easily top $1 million.

But these endorsements have limits. Many cap ransomware payments at $50,000, and insurers increasingly require proof of multi-factor authentication before binding coverage. If your security is outdated, you may not qualify or will pay higher premiums. For a micro-business that rarely handles digital client data, the annual premium may be hard to justify. Cyber insurance delivers the most value when customer information or online operations are central to how you earn revenue.

Comparison of Cyber Coverage Options (2025)
Policy Type Annual Cost (Avg) First-Party Coverage Third-Party Liability
General Liability (No Cyber) $200–$500 No No
General Liability + Cyber Rider $320–$600 Yes Optional
Standalone Cyber Policy $1,200–$3,500 Yes Yes

“Commercial general liability policies are generally not intended to cover data breach events. Businesses should be aware of coverage gaps.” — National Institute of Standards and Technology, 2025

— National Institute of Standards and Technology

How an Accounting Firm Survived a Ransomware Attack

A 42-person accounting firm in Indiana experienced a ransomware attack in March 2025. The attacker encrypted client tax records and demanded $150,000 in Bitcoin. The firm had no cyber coverage at the time.

They paid $180,000 in forensic investigation fees. Then $250,000 to notify 3,100 clients. Legal fees for potential class action lawsuits totaled $400,000. The IRS imposed a $200,000 penalty for delayed reporting. In total, the firm spent over $1 million out of pocket.

After the incident, they reviewed their insurance and added a cyber endorsement. The annual cost? $320. The coverage now protects them against similar threats. Their agent advised them to also consider how delivery drivers should stack auto insurance to avoid costly coverage gaps, especially if they transport sensitive documents.

Your Action Plan to Close the Gap

Here’s how to close the gap proactively:

  1. Review your policy’s exclusions section. Look for “loss of electronic data,” “inability to access data,” or “cyber incident.”
  2. Ask your agent about adding a cyber endorsement to your BOP. Confirm it includes both first-party and third-party liability.
  3. Check your vendor contracts. Require vendors handling customer data to carry cyber insurance.
  4. Train your staff on phishing and ransomware prevention. A 2025 SBA study found that 80% of breaches involve human error.
  5. Update your risk assessment annually. A business that’s growing rapidly may need higher limits.

For small business owners with home-based operations, it’s also worth understanding how to adjust homeowners insurance home to cover business equipment and data. Many assume their standard policy covers it, only to find out it doesn’t.

Frequently Asked Questions

Does my general liability policy cover a ransomware attack?

No. Standard policies exclude electronic data loss. Ransomware attacks are explicitly not covered.

How much does cyber coverage cost for a small business?

Annual premiums range from $45 to $320 for a rider. Standalone policies cost $1,200–$3,500. A business with 50 employees pays ~$320/year for a BOP with cyber add-on.

Why do only 17% of small businesses have cyber insurance?

Many underestimate the risk. Others believe their general policy covers cyber incidents. This gap leaves most SMBs vulnerable.

What does a cyber endorsement cover?

It covers forensic investigation, customer notification, credit monitoring, legal defense, and business interruption. Third-party liability requires a separate endorsement.

Can a breach at a vendor void my coverage?

Not directly, but it can trigger liability. Your policy may still exclude data breaches, even if caused by a third party. Always verify coverage.

Do state laws like CCPA affect my coverage?

Yes. CCPA fines can reach $7,500 per violation. General policies do not cover regulatory penalties. Cyber insurance does.

How do I audit my current policy for gaps?

Check the exclusions section for “electronic data,” “loss of data,” or “inability to access data.” Ask your agent about adding a cyber rider. Review vendor contracts for data handling clauses.

Is there a guide to help determine if I need cyber coverage?

Yes. For example, the liability only full coverage: breakeven guide helps you compare costs and risks across coverage types. It’s useful for small business owners weighing policy options.

Can I stack multiple term life insurance policies?

Yes, if you’re a high-risk applicant or need higher coverage. The stacking multiple term life insurance strategy can help cover estate needs. It’s a path many miss.

What should I do if my business has a data breach?

Act fast. Notify your insurer immediately. Use a term life insurance payout process: gather documentation, file a claim, and follow up. While not directly related, knowing how to file a claim efficiently helps in any crisis.

How can I compare term life insurance quotes without being misled?

Use tools like how to compare term life insurance quotes without getting misled. These guides help avoid inflated rates and hidden fees, just as you need clarity when choosing cyber coverage.

What does the term life insurance medical exam actually test for?

It checks for major health risks like heart disease, diabetes, and smoking. A term life insurance medical exam can affect your premium. But it’s also a reminder: proactive risk management, whether for health or data, pays off.

AR

Alex Rivera

Staff Writer

Alex Rivera is a Cybersecurity & Emerging Risks Insurance Expert with 9 years of focused experience in cyber insurance, data privacy, insurtech, and climate-related risks. They stay current with rapidly changing technology and the new threats it creates for both individuals and organizations. With a background in IT security before entering insurance, Alex brings a unique technical perspective to coverage discussions. They write for Smart Insurance 101 to help readers understand modern risks that traditional insurance often overlooks and to make these complex topics feel manageable.