Goldbridge Insurance Services
The claim most businesses actually have is not a Hollywood hack. It is a wire sent to the wrong account, or a laptop full of customer records. California law puts a price on both.
A bookkeeper gets an email from a vendor with updated banking details. The formatting is right, the signature block is right, the thread it’s replying to is real. She updates the record and wires $180,000 on Thursday. The real vendor calls the following week asking where the money is.
That is the cyber claim small and mid-size businesses actually have. Not ransomware on the evening news. A convincing email and a payment that left the building.
Whether your policy pays that claim, and how much of it, comes down to a number buried in your schedule of coverages that most policyholders have never looked at.
A cyber policy is not one limit. It is a stack of separate coverages, and several of them carry their own cap well below the headline number.
Funds transfer fraud and social engineering are usually the most restricted of the group. It is common to see a $1,000,000 cyber policy carrying a funds transfer fraud sublimit of $100,000 or $250,000. The business thinks it has a million dollars of protection. Against the loss it is most likely to suffer, it has a fraction of that.
The same structure shows up elsewhere. Ransomware is frequently sublimited. Business interruption usually carries a waiting period before anything accrues, often around twelve hours. Breach notification costs are sublimited on lower-premium policies, which matters because notification is a fixed, unavoidable cost the moment a breach is confirmed.
Carriers do this for a reason. These are high-frequency, high-severity categories, and sublimiting them is how a broad policy stays affordable. The problem is not that sublimits exist. The problem is that nobody explains them at binding, so the business finds out during the claim.
The practical takeaway: find your funds transfer fraud and social engineering sublimits and compare them to the largest payment your business could plausibly send in error. If the sublimit is smaller, ask what it costs to raise it. On many policies it is a modest premium change.
Most states have breach notification laws. California’s are older, stricter, and paired with a private right of action that turns a security incident into arithmetic.
Under California Civil Code section 1798.82, a business that owns or licenses computerized personal information about California residents has to disclose a breach of unencrypted personal information to those residents. The disclosure has to be made within 30 calendar days of discovery or notification of the breach, subject to narrow delays for law enforcement or to determine scope.
The notice itself is prescribed. It has to be titled “Notice of Data Breach” and organized under set headings: What Happened, What Information Was Involved, What We Are Doing, What You Can Do, and For More Information. It has to identify the types of information involved, give the date or date range, describe the incident, and where Social Security or ID numbers were exposed, provide credit reporting agency contacts.
If the breach affects more than 500 California residents in a single incident, a sample copy of the notice has to be submitted electronically to the Attorney General within 15 calendar days of notifying consumers.
None of that is free. Forensics, legal review, notification production and mailing, a call center, credit monitoring. For a mid-size breach those costs land in six figures before anyone files a lawsuit.
California Civil Code section 1798.150, part of the CCPA, gives consumers a private right of action when their nonencrypted and nonredacted personal information is subject to unauthorized access, exfiltration, theft or disclosure because the business failed to maintain reasonable security.
Damages are statutory: not less than $100 and not greater than $750 per consumer per incident, or actual damages, whichever is greater. Those figures adjust for inflation, and as of January 1, 2025 the range sits at roughly $107 to $799.
Do that math on a customer list. Five thousand affected California residents at the statutory floor is half a million dollars before anyone proves a single dollar of actual harm. At the top of the range it is several million.
Two limits are worth knowing. The cause of action reaches only nonencrypted, nonredacted personal information, so encryption genuinely matters. And a consumer seeking statutory damages must give 30 days’ written notice first; if the business cures the violation in that window and confirms it in writing, statutory damages are off the table. Fixing your security after the fact does not count as curing that breach.
Cyber is best understood as two halves.
These are the reasons a cyber claim fails, and most of them are avoidable at placement.
| Issue | What it means for you |
|---|---|
| Sublimit exhausted | Covered, but only to the sublimit. The most common form of a partially paid claim. |
| Security warranty breached | Many applications ask whether you have multi-factor authentication, offline backups and endpoint detection. Answering yes and not having it can void coverage. Answer accurately. |
| Unencrypted device | Some policies restrict coverage for data on unencrypted laptops and drives. California’s statutes also key on encryption. |
| Prior known circumstances | An incident you knew about before binding is typically excluded. Disclose it. |
| War and state-sponsored attack | These exclusions have tightened significantly across the market. Worth reading rather than assuming. |
| Voluntary parting | Some crime forms argue a wire you authorized, even under deception, is not covered theft. This is precisely why social engineering coverage has to be explicit. |
Cyber underwriting tightened sharply after the ransomware years, and the questions are no longer cosmetic. Expect to be asked about:
That wire verification procedure is worth dwelling on. A written rule that any change to banking details gets confirmed by phone to a number already on file, not a number in the email, prevents the single most common loss on this page. It costs nothing and underwriters ask about it.
Anyone holding personal information or moving money, which is nearly everyone. Where it matters most:
No. Commercial general liability responds to bodily injury and property damage. Data is not tangible property under most forms, and cyber events are excluded on current GL wording.
Attackers select by ease, not by size. Business email compromise in particular is aimed squarely at small firms with no verification procedure and someone authorized to send money.
Crime policies address theft of money and securities, including employee dishonesty. Cyber addresses data, systems and the liability that follows a breach. Social engineering losses sit on the seam, which is why the wording on both needs checking rather than assuming one picks it up.
Usually yes, where payment is lawful, subject to the extortion sublimit. Recovery and downtime costs typically exceed the ransom anyway.
California’s notification duty keys on unencrypted personal information, and the CCPA private right of action reaches nonencrypted, nonredacted data. Encryption is genuinely one of the highest-value controls you can implement, though whether it removes a specific obligation depends on the facts.
Start with record count, because notification and statutory damages scale with it, then look at the largest single payment your business could send by mistake. Those two numbers drive the answer more than revenue does.
Often, where insurable by law. Insurability of penalties varies, so this is a wording question.
Cyber works alongside the rest of your program. Businesses that get this right usually also carry employment practices liability for employee claims and general liability for the physical side, and law firms add professional liability on top. Our business insurance overview lays out how the pieces fit.
Send us your cyber declarations page. We will tell you what your funds transfer fraud and social engineering sublimits actually are, whether contingent business interruption is on there, and what it would cost to fix the gaps. Ten minutes of our time, and we will tell you if it’s already built correctly.
Request a Review Call (888) 590-2667
Or start here. Tell us what you carry now and we will reply the same business day with exactly what we need.
This page is general information about how cyber liability coverage is typically structured and about California statutory obligations. It is not legal advice and it is not a description of any specific policy. Coverage is determined solely by the terms, conditions and exclusions of the policy you hold, and statutory requirements and dollar thresholds change over time. Verify current requirements with qualified counsel.