
You do not have to sell software to be holding the thing they want.
Cyber cover for businesses whose product is not technology — restaurants, retail, clinics, gyms, salons and trades. Card payments, the customer database, the mailing list and the loyalty program are the exposure, and none of them are covered by a property or general liability policy.
Tell us the situation.
One licensed human replies the same business day — not five agents, not an auto-responder. If the policy you have is already the right one, we will tell you.
We use this to quote and service your insurance, and we do not sell it or pass it to lead networks. Privacy policy.
What business cyber businesses actually need.
Card payments and the POS
A breach of the point-of-sale or payment path — forensics, card-brand assessments, reissuing costs and the PCI fines that follow.
Without it — The card networks bill you for their side of it, and that assessment is not a claim any other policy recognizes.
Customer database and records
Notifying everyone whose details you held, credit monitoring, and the regulator’s questions afterwards.
Without it — Notification cost scales with the size of the list, and arrives before anybody knows how the breach happened.
Mailing lists and loyalty programs
The marketing list, the rewards accounts and the app logins — including points stolen and spent from customer accounts.
Without it — A loyalty balance is money as far as the customer is concerned, and refunding it is not covered by anything else.
Ransomware and lockout
Negotiation, restoring systems, and the income lost while the tills, bookings or scheduling are down.
Without it — A business that cannot take payment is closed, whether or not the doors are open.
Funds transfer and social engineering
Money sent because somebody convincingly pretended to be a supplier, a landlord or the owner.
Without it — The commonest cyber loss for a small business is not a hack at all — it is an invoice that looked right, and crime cover often excludes it when the transfer was authorized.
Vendor and processor breach
An incident at the booking platform, payroll provider or processor that holds your customers’ data.
Without it — Your customers hold you responsible for a list you outsourced, and their contract with you is the one that matters.
Where business cyber shows up.
- Restaurant
The POS, the customer database and the loyalty program are what gets taken — and card-brand assessments land on you whoever was at fault.
- Professional Services
Client records are the asset. A breach means notification costs, regulators and a business that cannot operate.
- Convenience Stores
Card terminals and loyalty systems put payment data in a small business with no security staff.
- Juice & Smoothie Bars
Loyalty balances and stored cards are exactly what an attack is looking for.
- Nonprofits
A donor database is exactly the list an attacker wants, and notifying it is the cost that follows.
- Delivery Restaurants
Taking orders online means holding addresses and payment data for everyone who ever ordered.
- Social Services Nonprofits
A breach of a shelter or counselling client list is a safety incident as well as a notification cost.
- Associations & Membership Organizations
A membership list is exactly the data an attacker wants, and members expect it to be protected.
- Thrift Stores & Charity Retail
Card data in a small retail operation with no security staff is the standard target.
- Medical Spas
Notification duty follows the data, not whether you call yourself a medical practice.
- Estheticians
Treatment records with photographs are among the most sensitive data a small business holds.
- Laser Hair Removal & Energy Devices
Identifiable clinical photographs are exactly the data a notification duty attaches to.
What business cyber operators ask us.
We do not sell software. Why would we need cyber at all?
Because the exposure is the data and the money, not the product. If you take card payments, hold a customer list, run a booking system, email a promotion or operate a loyalty scheme, you are holding exactly what an automated attack is looking for — and none of that requires you to be a technology business. The relevant question is not whether you are a target but whether you could fund a forensic investigation and a notification exercise out of cash while the tills are down.
Is this the same policy a software company buys?
No, and buying theirs would be paying for something you cannot claim on. A technology company also buys technology errors and omissions, which covers their software or service failing a customer. You do not have that exposure, so you should not be quoted it. What you need is the breach-response half — the forensics, the notification, the card-brand assessments, the business interruption — sized to the number of records you hold and the volume you process.
Our card processor says we are covered. Are we?
They mean their systems are compliant, not that your liability is insured. Read what the merchant agreement actually says about assessments: after a breach the card brands recover their costs from the acquiring bank, and the acquirer recovers from the merchant. That flows down to you regardless of who was at fault for the intrusion, and it is a contractual liability rather than damages — which is why a general liability policy does not touch it and why the coverage has to be named.
Does our general liability cover a data breach?
No. Modern general liability carries an explicit electronic data exclusion, and even the older forms required bodily injury or physical property damage, which a breach is not. The gap is deliberate on the insurer’s side rather than an oversight, and it has been widening for a decade.
How much does it cost for a small business?
For a single-location restaurant, shop, clinic or studio it commonly lands in the high three to low four figures a year, and it is one of the cheapest lines relative to what it pays for — a notification exercise across a few thousand customer records will exceed the premium many times over. Price is driven by records held, card volume and revenue, not headcount, so a small business with a long customer list rates higher than a bigger one with none.
Not ready to talk? The guides answer the questions this page raises in more depth. Already insured with us and need a certificate or a policy change? Ask the service team rather than starting a quote — it is faster and it goes to the people whose job it is. We also write home and auto, which is usually cheaper alongside the business policy than apart from it.