As businesses moved online, a gap opened that traditional policies were never written to cover: the cost of a data breach or cyberattack. Cyber liability insurance fills it, and for any business that holds customer data or depends on its systems, it has moved from optional to essential.
Cyber policies typically cover first-party losses, the costs the business itself incurs after an incident: investigating and containing a breach, notifying affected customers, credit monitoring, restoring data and systems, business interruption from downtime, and, in many policies, ransomware-related costs. These direct costs alone can be severe, and they are exactly what a general liability policy will not pay.
Policies also generally cover third-party liability: claims by customers, partners, or regulators harmed by a breach, including defense costs and regulatory fines where insurable. Because a single breach can trigger both the business's own recovery costs and a wave of outside claims, cyber coverage is built to respond on both fronts.
Cyber is a fast-evolving line. Insurers increasingly require baseline security controls, multi-factor authentication, backups, employee training, as a condition of coverage, and terms change as threats do. Getting cyber insurance now often means demonstrating that you take security seriously, which is a reasonable expectation and a useful discipline.
The one risk your other policies wrote out.
This is general information, not personalized insurance advice. Coverage terms, definitions, and availability vary by policy and provider.