For the breach, the ransom, and the wire transfer that was not real

Small businesses get targeted because they are easier to reach than large ones. The attacks that hit hardest are rarely sophisticated — a ransomware infection that locks your systems, an email that convinced someone to wire money to the wrong account, or a stolen laptop with customer records on it.

Walker Insurance Agency writes cyber liability for businesses across Mobile and Baldwin County.

Cyber coverage splits in two. First-party pays your own costs after an incident. Third-party pays claims brought against you by customers or partners whose information was exposed. Most small business losses land on the first-party side, which is the part owners tend to think about least.

What Cyber Liability Covers

First-party — your costs

Forensic investigation — Determining what happened, what was accessed, and whether the intruder is still in your systems.

Data restoration and system repair — Rebuilding what was encrypted, corrupted, or destroyed.

Business interruption — Lost income while your systems are down, which for most businesses is the largest number on the list.

Breach notification — Notifying affected individuals as required by law, plus credit monitoring. This cost lands whether or not anyone ever sues.

Ransom payments — Extortion demands, subject to policy terms and often a sublimit.

Funds transfer fraud — Money sent to a fraudulent account. Almost always a sublimit rather than the full policy limit, and worth checking the number.

Public relations and legal counsel — Managing the fallout and meeting your obligations.

Third-party — claims against you

Privacy liability — Claims from customers, employees, or partners whose data was exposed.

Regulatory response — Fines, penalties, and the cost of responding to a regulator, where insurable.

Media liability — Claims arising from your website and digital content.

What This Means for Businesses Here

Funds transfer fraud is the loss we see most. Business email compromise — someone impersonating a vendor, a customer, or an executive to redirect a payment — hits small businesses constantly. Construction is a particular target, because draw payments are large, scheduled, and easy to research. A fraudulent change-of-banking-details email sent at the right moment in a project costs real money and is rarely recoverable.

Alabama requires breach notification. State law requires notifying affected individuals after a breach involving covered personal information, subject to the statute’s terms. Insurance licensees carry additional data security obligations. Notification costs money before a single claim is filed.

The sublimit is where policies differ most. Two cyber policies with the same headline limit can have very different funds transfer fraud and ransomware sublimits. That number, not the top-line limit, is what most small business claims actually run against. We read it before you buy.

Carriers now ask about your controls. Multi-factor authentication, offline backups, and employee training affect both eligibility and pricing. Some carriers will not write a business without MFA on email. If you are not there yet, tell us and we will point you at what matters most.

Contracts increasingly require it. Larger customers, municipalities, and general contractors now ask vendors to carry cyber coverage at specified limits. If you are being asked, send us the requirement.

Any business with email has the exposure. You do not need to store credit cards. A business with an email account, a bank account, and a computer has everything an attacker needs.

What Affects Your Cost

Annual revenue, industry and the type of data you hold, number of records, your security controls, particularly multi-factor authentication and backups, employee training, claims and incident history, the limits and sublimits you select, whether you accept electronic payments, and vendor and contract requirements.

Frequently Asked Questions

What does cyber liability insurance cover?

First-party costs — forensic investigation, data restoration, breach notification, credit monitoring, legal counsel, public relations, business interruption, and sometimes ransom payments. Third-party liability — claims from customers, partners, or regulators after their information was exposed.

Does my general liability policy cover a data breach?

Generally no. Most general liability policies exclude or severely limit data-related claims. Cyber coverage exists because that gap is real.

Does Alabama have a data breach notification law?

Yes. Alabama requires businesses to notify affected individuals after a breach involving covered personal information, subject to the statute’s terms. Insurance licensees have additional data security obligations. Notification costs money whether or not anyone sues, which is part of why coverage matters for small businesses.

Is funds transfer fraud covered?

Sometimes, and often at a sublimit well below the policy’s main limit. Business email compromise — a fraudulent email redirecting a payment — is one of the most frequent losses. Ask specifically about the sublimit rather than assuming the full limit applies.

Do small businesses really need cyber coverage?

Attackers target small businesses precisely because their defenses are lighter. Any business that stores customer information, takes electronic payments, or relies on email and computer systems to operate has the exposure. Contracts increasingly require it too.

Would You Know Who to Call at 2 a.m.?

Send us your current cyber policy if you have one. We will check the sublimits, tell you what your controls qualify you for, and show you what a different carrier would charge for broader terms.