(562) 395-5011

Does General Liability Insurance Cover Cyber Incidents?

Find out whether commercial general liability insurance covers cyber incidents for businesses in Santa Fe Springs and Los Angeles County, and what separate cyber coverage you may need.

Coverage BasicsUpdated August 31, 202613 min read
Business owner reviewing cyber insurance coverage alongside CGL policy in Los Angeles County

For businesses in Santa Fe Springs and throughout Los Angeles County, standard commercial general liability (CGL) insurance provides little to no meaningful protection against cyber incidents -- data breaches, ransomware attacks, phishing fraud, and other digital threats are either explicitly excluded from most CGL policies or fall into coverage gaps that leave your business exposed.

Most small businesses assume their CGL handles it. It doesn't -- and the exclusions have been getting broader, not narrower, with every ISO policy update.

IT team reviewing cyber liability insurance coverage for a Los Angeles County small business

Why CGL Was Not Designed for Cyber Risk

Commercial general liability insurance was designed in an era when business risks were primarily physical -- slip and falls, property damage, advertising in printed materials. The ISO CGL form was standardized before the internet became a core business infrastructure component.

Over the past decade, insurance carriers have responded to the explosive growth of cyber claims by adding explicit cyber exclusions to standard CGL policies. The ISO introduced a formal cyber exclusion endorsement (ISO CG 21 06) that many carriers now attach to CGL policies, specifically excluding:

  • Claims arising from unauthorized access to computer systems
  • Data breaches and disclosure of personal information
  • Denial of service attacks
  • Transmission of malware or ransomware
  • Failure to protect electronic data

Even policies without an explicit cyber endorsement often fail to respond to cyber claims because the standard CGL coverage triggers (bodily injury and property damage to tangible property) do not naturally fit cyber losses.

What Happens When CGL Is Tested Against Cyber Claims

The legal history of CGL cyber coverage is instructive. Courts across the U.S. have reached inconsistent conclusions about whether CGL covers cyber losses, but the trend in California is increasingly toward exclusion:

Cyber Claim TypeCGL Coverage?Why
Customer data stolen from your serversGenerally noData is intangible property under most CGL definitions
A customer's system infected by malware from your networkSometimesProperty damage to third-party systems may trigger CGL
Ransomware payment demandedNoNot a covered liability claim type
Business email compromise fraudNoNot bodily injury or property damage
Defamation posted by a hacker on your websitePossiblyPersonal/advertising injury may apply in limited circumstances
Regulatory fines for data breachNoFines and penalties are excluded from CGL

The Insurance Information Institute advises that businesses relying on CGL to cover cyber incidents are taking significant uninsured risk.

The California Data Breach Landscape

California has some of the strictest data privacy laws in the United States, including:

  • California Consumer Privacy Act (CCPA) -- requires businesses to disclose data breaches and provides consumers the right to sue for certain violations
  • California Privacy Rights Act (CPRA) -- expanded CCPA with a new enforcement agency
  • California data breach notification law -- requires notification to affected individuals and the state Attorney General within specific timeframes

Los Angeles County businesses that handle customer personal information -- names, addresses, email addresses, payment card data, health information -- face significant statutory obligations and potential civil claims if a breach occurs.

The California Attorney General's office has actively enforced these laws, and private lawsuits under the CCPA have become common. A significant breach affecting California residents can generate both regulatory penalties and class action litigation that CGL will not cover.

Small business owner in Los Angeles County reviewing cyber liability policy to fill gaps in CGL coverage

What Cyber Liability Insurance Covers

A standalone cyber liability policy fills the coverage gaps that CGL leaves exposed. Cyber policies typically cover two categories:

First-party coverage (losses to your own business):

  • Costs to respond to a data breach (forensic investigation, notification letters, credit monitoring)
  • Business income lost during a cyber-related outage
  • Ransomware extortion payments and response costs
  • Costs to restore or recreate lost electronic data
  • Cyber fraud and business email compromise (BEC) losses

Third-party coverage (liability to others):

  • Legal defense and settlements for lawsuits by affected customers
  • Regulatory fines and penalties (where insurable under state law)
  • Privacy liability claims from individuals whose data was compromised
  • Media liability for defamatory or infringing digital content

Annual cyber liability premiums for small businesses in Los Angeles County typically range from $500 to $3,000 per year for $1M in coverage, depending on revenue, the type of data handled, and existing security controls.

What Cyber Insurance Does Not Cover

Cyber liability insurance does not cover incidents that began before your policy started, losses caused by security controls you claimed to have but did not, bodily injury or physical property damage, the cost of upgrading your systems after a breach, or attacks attributed to a nation-state under the war exclusion.

A cyber policy is not a blank check. It is a narrowly worded contract with its own exclusion list, and that list has tightened considerably since 2023 as carriers absorbed heavy ransomware losses.

ExclusionWhat It MeansWhy It Exists
Prior acts / prior known circumstancesA breach that began before your retroactive date is not covered, even if you discovered it during the policy periodAttackers often sit inside a network for months before detonating ransomware
Failure to maintain security standardsIf you attested to MFA, backups, or endpoint detection on the application and did not have them, the carrier can deny or rescindUnderwriting is priced entirely on your stated controls
War and state-backed attacksAttacks attributed to a nation-state or its proxies are excluded under most current formsLloyd's Market Bulletins Y5381 and Y5433 mandated state-backed exclusions, phased in across 2023 to 2025
Bodily injury and property damagePhysical harm to people or tangible property is not a cyber lossThat is what your CGL is for -- the two policies deliberately do not overlap
Betterment and system upgradesRestoring your systems is covered; improving them beyond their pre-breach state is notInsurance restores, it does not fund capital improvements
Loss of intellectual property valueStolen trade secrets and the lost market value of proprietary dataThe loss is real but not measurable in a way carriers will underwrite
Contractual liability and PCI finesPenalties you agreed to in a merchant services contract are often excluded or heavily sublimitedYou assumed that liability voluntarily by signing
Criminal acts by owners or principalsFraud committed by a principal of the businessStandard moral hazard exclusion in every commercial line

The Sublimit Trap

Some of the most common losses are technically covered but capped far below your policy limit. Social engineering and funds transfer fraud -- the wire scam where an employee is tricked into paying a fraudulent invoice -- is typically sublimited to $25,000 to $250,000 on a $1M policy.

Business email compromise is among the most frequent cyber losses for small businesses in Los Angeles County, and it is routinely the coverage written at pennies on the dollar. Read the sublimit schedule on your declarations page, not the headline limit on the quote.

Does Cyber Insurance Actually Pay Out?

Yes. Cyber insurance pays out routinely, and breach response and ransomware claims are settled every day. But cyber has a higher rate of disputed claims than CGL, and nearly all of those disputes trace back to three things: what you said on your application, when the incident actually began, and who the attack gets attributed to.

Cyber claims are denied for different reasons than liability claims. A CGL denial usually turns on whether the event fits the coverage grant. A cyber denial often turns on whether the policy should have been issued at all.

1. Application Misrepresentation

This is the single biggest risk. In Travelers v. International Control Services, the insured stated on its application that it used multi-factor authentication. After a May 2022 ransomware attack, Travelers alleged that representation was false and moved to rescind the policy. Both parties stipulated to rescission, and the policy was declared null and void from inception -- meaning no coverage existed at all, not merely a denied claim.

Cyber applications now function as warranties in practical effect. Whoever signs yours should verify every control with your IT provider before answering a single question.

2. The Retroactive Date

Cyber policies are claims-made. If your retroactive date is the day the policy incepted, and forensics later show the attacker had access to your network three months earlier, the claim falls outside the coverage period. When you switch carriers, insist on full prior acts coverage or continuity of your original retroactive date.

3. Attribution to a Nation-State

Following Lloyd's Market Bulletins Y5381 and Y5433, state-backed cyber attack exclusions became standard on cyber policies, phased in across 2023 to 2025. Because many significant ransomware operations have alleged ties to state-tolerated groups, attribution is now a live coverage question rather than a theoretical one. Ask your agent how your specific form defines a state-backed attack, and who carries the burden of proving attribution.

What Improves Your Odds of a Payout

  • Answer the application with your IT provider in the room, question by question
  • Keep evidence that your stated controls were actually running -- MFA logs, backup reports, EDR dashboards
  • Report the incident inside the notice period written in the policy, not when it is convenient
  • Use the carrier's approved breach response panel; going to your own vendor without pre-approval is a common and entirely avoidable reason for reduced payment

Industries with the Highest Cyber Risk in LA County

Not all businesses face equal cyber exposure. The following industries in Los Angeles County have above-average cyber liability risk:

IndustryPrimary Cyber RiskWhy
Healthcare and medicalPatient data breachHIPAA obligations, sensitive PHI
Retail and e-commercePayment card data breachPCI DSS obligations, high transaction volume
Professional services (law, accounting)Client confidential dataPrivileged information, high regulatory exposure
Financial servicesFinancial data theftDirect financial liability, strict regulatory requirements
Technology and softwareSystem failures, IP theftErrors and omissions, intellectual property
Restaurants and hospitalityPayment card dataHigh transaction volume, often older POS systems
Education and tutoringStudent dataFERPA obligations, minor data

Even low-tech businesses that use email, accept payments online, or store any customer information in cloud-based systems face meaningful cyber exposure.

CGL Plus Cyber: Building Complete Protection

For most businesses in Santa Fe Springs and the LA metro area, the ideal protection program combines:

  • CGL -- for bodily injury, property damage, advertising injury, and premises liability
  • Cyber liability -- for data breaches, ransomware, business interruption from cyber events, and privacy liability
  • Professional liability (E&O) -- if you provide technology services or digital products, tech E&O overlaps with some cyber exposures

Some carriers now offer combined technology E&O and cyber policies for technology companies, or cyber endorsements added to a BOP for eligible small businesses. Discuss these options with your agent.

Related reading: can I bundle general liability insurance with other policies.

What to Ask Your Agent

When reviewing your CGL and cyber coverage, ask your agent:

1. Does my current CGL policy contain a cyber exclusion endorsement (such as ISO CG 21 06)?

2. If my business suffers a data breach, what CGL coverage (if any) would respond?

3. What cyber liability coverage options are available from my current CGL carrier?

4. What first-party cyber coverages are included in your proposed cyber policy?

5. Does the cyber policy include coverage for CCPA regulatory defense and penalties?

Frequently Asked Questions

What is cyber insurance for?

Cyber insurance exists to pay the costs a data breach or cyber attack creates that no other business policy covers: forensic investigation, legal notification of affected individuals, credit monitoring, ransomware response, lost income during a system outage, and lawsuits or regulatory action from people whose data was exposed. Your CGL covers physical-world liability. Cyber covers digital-world liability.

What does cyber insurance actually cover?

Two buckets. First-party coverage pays your own losses -- breach forensics, customer notification, credit monitoring, business interruption, data restoration, and ransomware negotiation and payment. Third-party coverage pays what you owe others -- legal defense and settlements from affected customers, privacy liability, regulatory defense and CCPA penalties where insurable, and media liability for digital content claims.

What does cyber insurance not cover?

Prior acts before your retroactive date, losses where you misrepresented your security controls on the application, bodily injury and physical property damage, system upgrades beyond pre-breach condition, the market value of stolen intellectual property, and state-backed attacks under the war exclusion. Social engineering and funds transfer fraud are usually covered only up to a sublimit well below your policy limit.

What is not covered by cyber insurance?

Beyond the formal exclusions, three things business owners commonly assume are covered and are not: the full amount of a wire transfer fraud loss (typically sublimited to $25,000 to $250,000 rather than paid at the policy limit), the cost of upgrading systems to prevent the next attack, and the lost value of stolen trade secrets. On the formal side, the exclusions that generate the most denied claims are prior acts, failure to maintain the security controls you attested to, and state-backed attack attribution.

Does cyber insurance pay out?

Yes. Breach response and ransomware claims are paid routinely. Disputes concentrate around three issues: application misrepresentation, the retroactive date, and attribution of the attack to a nation-state. Answering the application accurately with your IT provider, and reporting promptly through the carrier's breach panel, are the two factors most within your control.

Is it worth having cyber insurance?

For any business in Santa Fe Springs that stores customer personal information, accepts card payments, or runs on cloud software, generally yes. At $500 to $3,000 a year for $1M in coverage, the premium is a fraction of the cost of a single notification event under California's breach laws. It is harder to justify for a business with no employees, no stored customer data, and no online payments. The practical test is not company size -- it is whether a forced three-day shutdown of your systems and email would cost you more than the annual premium.

How much should cyber insurance cost?

Most small businesses in Los Angeles County pay $500 to $3,000 per year for $1M in cyber liability coverage. Pricing is driven by revenue, the type and volume of data you hold, your industry, and your security controls. Businesses with MFA, tested backups, endpoint detection, and employee security training quote meaningfully lower than those without -- and in a hardened market, some applicants without MFA cannot obtain a quote at all.

If my business website is hacked and customer data is stolen, does CGL respond?

Likely not, especially if your policy contains a cyber exclusion. Even without an explicit exclusion, customer data is considered intangible property under most CGL forms, and the coverage trigger for property damage typically requires physical injury to tangible property.

Can my BOP cover cyber incidents?

Some BOPs include a basic cyber endorsement, typically with limits of $10,000 to $50,000 -- far below the average data breach cost. A standalone cyber liability policy is recommended for businesses that handle significant customer data.

Is cyber insurance required by California law?

California does not require businesses to carry cyber insurance. However, California's data breach notification laws and CCPA create significant financial exposure for businesses that suffer a breach -- making cyber insurance a financially prudent investment for most businesses that handle personal data.

How much cyber coverage does a small business in LA need?

Most small businesses start with $500,000 to $1,000,000 in cyber liability coverage. Businesses handling payment cards, health information, or large volumes of personal data should consider $1M to $5M in coverage.

What security practices can reduce my cyber insurance premium?

Carriers evaluate your security posture when quoting cyber coverage. Having multi-factor authentication (MFA), regular data backups, employee security training, and an incident response plan in place can significantly reduce your premium.

The Bottom Line

If your business accepts credit cards, stores customer email addresses, or uses any cloud-based software, you have cyber exposure. Pull out your current CGL policy and look for the words "cyber" or "electronic data" in the exclusions section. If they're there -- and in most modern policies they are -- you have an uninsured gap that a standalone cyber policy closes for as little as $500 a year.

External resources: Insurance Information Institute -- Cyber Insurance | California Attorney General -- CCPA

Ready to Get Covered?

Fast general liability quotes for California small businesses. Same-day COI available.

Same-day COI available · Fast response guaranteed

Call NowFree Quote
Does General Liability Insurance Cover Cyber Incidents? | CGL Santa Fe Springs | CGL Santa Fe Springs