Policy summary
Cyber liability
Claim
Supplier invoice · wire
Response
Incident · day one
Cyber insurance.
Helps you recover from a bad email. It responds when an invoice gets swapped, the scheduling system gets locked, or customer data in the phone gets out.
Funds transfer fraud, the fake invoice you paid
Ransomware response, recovery, and the lost days
Customer data notification and the claim that may follow
Prefer to talk? Call +1 802-GOT-RIZA · Sun to Sat, 8am to 8pm ET
Markets we place through.
Cyber coverage is built to answer three things.
One inbox, three bad days. Here is how they show up on a real week.
Invoice fraud
If the payment goes to the wrong account.
A supplier’s email is spoofed. Your bookkeeper pays the fake invoice.
Funds transfer fraud coverage helps recover or replace the money.
You keep the supplier.
Claim
Supplier invoice · wire
Ransomware
If the scheduling system gets locked.
Monday morning, nobody can see the route or the invoices.
After a covered event, the policy pays for the response, the recovery, and the lost days.
You do not negotiate alone.
Incident
Scheduling system locked
Customer data
If the customer list gets out.
A phone with the customer app is lost, or the CRM is breached.
Notification, credit monitoring, and the lawsuit that may follow.
We read the notification rules for your state before you need them.
Timeline
Customer data exposure
Also in the policy.
Less famous. Still decides what the bad week costs.
Placing the policy is half the job.
We stay for the other half. Four things that happen when a broker is on the account.
Meet the cyber clause.
Keep the contract.
Contract cyber requirements matched before you sign
Systems and vendors updated as you add them
One number to call the day it happens
One broker on the phone with the response team
Meet the cyber clause.
Keep the contract.
Contract cyber requirements matched before you sign
Systems and vendors updated as you add them
One number to call the day it happens
One broker on the phone with the response team
Add a system or a vendor.
Keep the policy current.
New software and vendors added as you adopt them
MFA and backups confirmed at each change
Records count updated as the customer list grows
One account record, not a new application
Call one number.
We stay on it.
Response team engaged the day it happens
Bank and carrier notified the same morning
Notification questions answered in plain words
We chase status so you do not have to
Renewal is a comparison,
not a rubber stamp.
This year’s controls go into one submission
Every market we place through gets a look
Sublimits compared side by side
Stay or switch, your call
What changes the price.
Five things that move a cyber quote. Published averages are not your price.
How much money moves through the inbox and how many customers are in the system.
On email and remote access. Most carriers ask first.
Offline or tested. The difference between a bad day and a bad month.
Who holds your data and how you pay your bills.
Carriers price on history and on what changed since.
Where cyber coverage stops.
These usually come next. Each has its own policy and its own page.
The job
AnchorWhere most contracts start and most claims land.
Plans & advice
If you designIf you design or advise, this is where those claims go. Not general liability.
The shutdown
Time basedIf a covered loss closes the doors, this helps carry payroll and rent until they reopen.
The bundle
If eligibleThe basics in one policy for businesses that fit the carrier’s rules.
A better renewal starts with the policy you already have.
Already insured? Send it once. We compare it with today’s options.
Send
Compare
Choose
Plain answers before the next job.
The questions worth settling before the next invoice.
Why would a contractor need cyber insurance?
A contractor would carry cyber insurance for the same reason an office would: the money and the customer list both live in the inbox. A plumbing shop pays suppliers by wire, runs dispatch and invoicing in the cloud, and keeps customer names, addresses, and card details in a phone app. A spoofed supplier email that changes the bank details on one invoice can cost more than a van. Ransomware on the scheduling system stops the routes on a Monday. What changes the answer is how much money moves through email and how many customers are in the system, so we ask about both before sizing the policy.
Does it cover a fake invoice we paid?
A fake invoice you paid can be covered, under the part of the policy called funds transfer fraud or social engineering. It responds when someone impersonates a supplier or a manager and your own staff sends the money in good faith. A bookkeeper who pays a spoofed invoice with new bank details is the textbook case. This coverage almost always carries a sublimit lower than the rest of the policy, and some carriers leave it off unless asked. What changes the answer is that sublimit and whether the policy includes it at all, which is why we ask for the number before you bind rather than after the wire.
Does it cover ransomware?
Ransomware is covered by most cyber policies, and it is the loss carriers think about most. The policy pays for the response team, the forensics, the recovery of systems and data, and the days the business could not operate while the scheduling and invoicing were locked. Where the law allows and the carrier agrees, it can also cover a negotiated payment. What changes the answer is your backups and whether multi-factor authentication is on email and remote access, since carriers price on both and some will not quote without them. A tested offline backup turns a bad month into a bad day.
What do carriers require before they quote?
What carriers require before they quote a cyber policy is a short list of controls, and most will not move without them. Multi-factor authentication on email and any remote access is first. Backups that are kept offline or tested come next. Many also ask about endpoint protection, how you verify a change to a vendor’s bank details, and whether anyone has had an incident before. A shop that turns on MFA the week before applying usually qualifies. What changes the answer is the carrier and the size of the business, so we check the controls with you before the application goes in, not after a decline.
Does my general liability policy cover any of this?
Your general liability policy generally covers none of this. GL responds to bodily injury and property damage to other people, and most forms now exclude data breaches, electronic data, and loss of money outright. A customer whose card details leaked from your app is not injured in the way GL means, and a wire you sent to a thief is not property damage. Some business owner’s policies add a small cyber endorsement, usually with a modest limit. What changes the answer is that endorsement, because a shop that relies on it should read the limit, and a firm that handles real money is better served by a standalone cyber policy.
What happens the day something goes wrong?
The day something goes wrong, you call one number and the carrier’s response team takes over. The policy includes a breach coach, a lawyer who runs the response, plus forensics to find out what happened and how far it went. If money moved, the bank is notified the same day. If customer data is out, the team handles the notifications and credit monitoring the state rules require. Your broker is on the same call and stays on it. What changes the answer is how fast you call, because the notification clock starts at discovery and the recovery is cheaper the earlier the team is engaged.
Ready to compare your cyber options?
Tell us about the business, or send your current policy.
Prefer to talk? Call +1 802-GOT-RIZA · Sun to Sat, 8am to 8pm ET