For businesses in Santa Fe Springs and throughout Los Angeles County, standard commercial general liability (CGL) insurance provides little to no meaningful protection against cyber incidents -- data breaches, ransomware attacks, phishing fraud, and other digital threats are either explicitly excluded from most CGL policies or fall into coverage gaps that leave your business exposed.
Most small businesses assume their CGL handles it. It doesn't -- and the exclusions have been getting broader, not narrower, with every ISO policy update.
Why CGL Was Not Designed for Cyber Risk
Commercial general liability insurance was designed in an era when business risks were primarily physical -- slip and falls, property damage, advertising in printed materials. The ISO CGL form was standardized before the internet became a core business infrastructure component.
Over the past decade, insurance carriers have responded to the explosive growth of cyber claims by adding explicit cyber exclusions to standard CGL policies. The ISO introduced a formal cyber exclusion endorsement (ISO CG 21 06) that many carriers now attach to CGL policies, specifically excluding:
- •Claims arising from unauthorized access to computer systems
- •Data breaches and disclosure of personal information
- •Denial of service attacks
- •Transmission of malware or ransomware
- •Failure to protect electronic data
Even policies without an explicit cyber endorsement often fail to respond to cyber claims because the standard CGL coverage triggers (bodily injury and property damage to tangible property) do not naturally fit cyber losses.
What Happens When CGL Is Tested Against Cyber Claims
The legal history of CGL cyber coverage is instructive. Courts across the U.S. have reached inconsistent conclusions about whether CGL covers cyber losses, but the trend in California is increasingly toward exclusion:
| Cyber Claim Type | CGL Coverage? | Why |
|---|---|---|
| Customer data stolen from your servers | Generally no | Data is intangible property under most CGL definitions |
| A customer's system infected by malware from your network | Sometimes | Property damage to third-party systems may trigger CGL |
| Ransomware payment demanded | No | Not a covered liability claim type |
| Business email compromise fraud | No | Not bodily injury or property damage |
| Defamation posted by a hacker on your website | Possibly | Personal/advertising injury may apply in limited circumstances |
| Regulatory fines for data breach | No | Fines and penalties are excluded from CGL |
The Insurance Information Institute advises that businesses relying on CGL to cover cyber incidents are taking significant uninsured risk.
The California Data Breach Landscape
California has some of the strictest data privacy laws in the United States, including:
- •California Consumer Privacy Act (CCPA) -- requires businesses to disclose data breaches and provides consumers the right to sue for certain violations
- •California Privacy Rights Act (CPRA) -- expanded CCPA with a new enforcement agency
- •California data breach notification law -- requires notification to affected individuals and the state Attorney General within specific timeframes
Los Angeles County businesses that handle customer personal information -- names, addresses, email addresses, payment card data, health information -- face significant statutory obligations and potential civil claims if a breach occurs.
The California Attorney General's office has actively enforced these laws, and private lawsuits under the CCPA have become common. A significant breach affecting California residents can generate both regulatory penalties and class action litigation that CGL will not cover.
What Cyber Liability Insurance Covers
A standalone cyber liability policy fills the coverage gaps that CGL leaves exposed. Cyber policies typically cover two categories:
First-party coverage (losses to your own business):
- •Costs to respond to a data breach (forensic investigation, notification letters, credit monitoring)
- •Business income lost during a cyber-related outage
- •Ransomware extortion payments and response costs
- •Costs to restore or recreate lost electronic data
- •Cyber fraud and business email compromise (BEC) losses
Third-party coverage (liability to others):
- •Legal defense and settlements for lawsuits by affected customers
- •Regulatory fines and penalties (where insurable under state law)
- •Privacy liability claims from individuals whose data was compromised
- •Media liability for defamatory or infringing digital content
Annual cyber liability premiums for small businesses in Los Angeles County typically range from $500 to $3,000 per year for $1M in coverage, depending on revenue, the type of data handled, and existing security controls.
What Cyber Insurance Does Not Cover
Cyber liability insurance does not cover incidents that began before your policy started, losses caused by security controls you claimed to have but did not, bodily injury or physical property damage, the cost of upgrading your systems after a breach, or attacks attributed to a nation-state under the war exclusion.
A cyber policy is not a blank check. It is a narrowly worded contract with its own exclusion list, and that list has tightened considerably since 2023 as carriers absorbed heavy ransomware losses.
| Exclusion | What It Means | Why It Exists |
|---|---|---|
| Prior acts / prior known circumstances | A breach that began before your retroactive date is not covered, even if you discovered it during the policy period | Attackers often sit inside a network for months before detonating ransomware |
| Failure to maintain security standards | If you attested to MFA, backups, or endpoint detection on the application and did not have them, the carrier can deny or rescind | Underwriting is priced entirely on your stated controls |
| War and state-backed attacks | Attacks attributed to a nation-state or its proxies are excluded under most current forms | Lloyd's Market Bulletins Y5381 and Y5433 mandated state-backed exclusions, phased in across 2023 to 2025 |
| Bodily injury and property damage | Physical harm to people or tangible property is not a cyber loss | That is what your CGL is for -- the two policies deliberately do not overlap |
| Betterment and system upgrades | Restoring your systems is covered; improving them beyond their pre-breach state is not | Insurance restores, it does not fund capital improvements |
| Loss of intellectual property value | Stolen trade secrets and the lost market value of proprietary data | The loss is real but not measurable in a way carriers will underwrite |
| Contractual liability and PCI fines | Penalties you agreed to in a merchant services contract are often excluded or heavily sublimited | You assumed that liability voluntarily by signing |
| Criminal acts by owners or principals | Fraud committed by a principal of the business | Standard moral hazard exclusion in every commercial line |
The Sublimit Trap
Some of the most common losses are technically covered but capped far below your policy limit. Social engineering and funds transfer fraud -- the wire scam where an employee is tricked into paying a fraudulent invoice -- is typically sublimited to $25,000 to $250,000 on a $1M policy.
Business email compromise is among the most frequent cyber losses for small businesses in Los Angeles County, and it is routinely the coverage written at pennies on the dollar. Read the sublimit schedule on your declarations page, not the headline limit on the quote.
Does Cyber Insurance Actually Pay Out?
Yes. Cyber insurance pays out routinely, and breach response and ransomware claims are settled every day. But cyber has a higher rate of disputed claims than CGL, and nearly all of those disputes trace back to three things: what you said on your application, when the incident actually began, and who the attack gets attributed to.
Cyber claims are denied for different reasons than liability claims. A CGL denial usually turns on whether the event fits the coverage grant. A cyber denial often turns on whether the policy should have been issued at all.
1. Application Misrepresentation
This is the single biggest risk. In Travelers v. International Control Services, the insured stated on its application that it used multi-factor authentication. After a May 2022 ransomware attack, Travelers alleged that representation was false and moved to rescind the policy. Both parties stipulated to rescission, and the policy was declared null and void from inception -- meaning no coverage existed at all, not merely a denied claim.
Cyber applications now function as warranties in practical effect. Whoever signs yours should verify every control with your IT provider before answering a single question.
2. The Retroactive Date
Cyber policies are claims-made. If your retroactive date is the day the policy incepted, and forensics later show the attacker had access to your network three months earlier, the claim falls outside the coverage period. When you switch carriers, insist on full prior acts coverage or continuity of your original retroactive date.
3. Attribution to a Nation-State
Following Lloyd's Market Bulletins Y5381 and Y5433, state-backed cyber attack exclusions became standard on cyber policies, phased in across 2023 to 2025. Because many significant ransomware operations have alleged ties to state-tolerated groups, attribution is now a live coverage question rather than a theoretical one. Ask your agent how your specific form defines a state-backed attack, and who carries the burden of proving attribution.
What Improves Your Odds of a Payout
- •Answer the application with your IT provider in the room, question by question
- •Keep evidence that your stated controls were actually running -- MFA logs, backup reports, EDR dashboards
- •Report the incident inside the notice period written in the policy, not when it is convenient
- •Use the carrier's approved breach response panel; going to your own vendor without pre-approval is a common and entirely avoidable reason for reduced payment
Industries with the Highest Cyber Risk in LA County
Not all businesses face equal cyber exposure. The following industries in Los Angeles County have above-average cyber liability risk:
| Industry | Primary Cyber Risk | Why |
|---|---|---|
| Healthcare and medical | Patient data breach | HIPAA obligations, sensitive PHI |
| Retail and e-commerce | Payment card data breach | PCI DSS obligations, high transaction volume |
| Professional services (law, accounting) | Client confidential data | Privileged information, high regulatory exposure |
| Financial services | Financial data theft | Direct financial liability, strict regulatory requirements |
| Technology and software | System failures, IP theft | Errors and omissions, intellectual property |
| Restaurants and hospitality | Payment card data | High transaction volume, often older POS systems |
| Education and tutoring | Student data | FERPA obligations, minor data |
Even low-tech businesses that use email, accept payments online, or store any customer information in cloud-based systems face meaningful cyber exposure.
CGL Plus Cyber: Building Complete Protection
For most businesses in Santa Fe Springs and the LA metro area, the ideal protection program combines:
- •CGL -- for bodily injury, property damage, advertising injury, and premises liability
- •Cyber liability -- for data breaches, ransomware, business interruption from cyber events, and privacy liability
- •Professional liability (E&O) -- if you provide technology services or digital products, tech E&O overlaps with some cyber exposures
Some carriers now offer combined technology E&O and cyber policies for technology companies, or cyber endorsements added to a BOP for eligible small businesses. Discuss these options with your agent.
Related reading: can I bundle general liability insurance with other policies.
What to Ask Your Agent
When reviewing your CGL and cyber coverage, ask your agent:
1. Does my current CGL policy contain a cyber exclusion endorsement (such as ISO CG 21 06)?
2. If my business suffers a data breach, what CGL coverage (if any) would respond?
3. What cyber liability coverage options are available from my current CGL carrier?
4. What first-party cyber coverages are included in your proposed cyber policy?
5. Does the cyber policy include coverage for CCPA regulatory defense and penalties?
Frequently Asked Questions
What is cyber insurance for?
Cyber insurance exists to pay the costs a data breach or cyber attack creates that no other business policy covers: forensic investigation, legal notification of affected individuals, credit monitoring, ransomware response, lost income during a system outage, and lawsuits or regulatory action from people whose data was exposed. Your CGL covers physical-world liability. Cyber covers digital-world liability.
What does cyber insurance actually cover?
Two buckets. First-party coverage pays your own losses -- breach forensics, customer notification, credit monitoring, business interruption, data restoration, and ransomware negotiation and payment. Third-party coverage pays what you owe others -- legal defense and settlements from affected customers, privacy liability, regulatory defense and CCPA penalties where insurable, and media liability for digital content claims.
What does cyber insurance not cover?
Prior acts before your retroactive date, losses where you misrepresented your security controls on the application, bodily injury and physical property damage, system upgrades beyond pre-breach condition, the market value of stolen intellectual property, and state-backed attacks under the war exclusion. Social engineering and funds transfer fraud are usually covered only up to a sublimit well below your policy limit.
What is not covered by cyber insurance?
Beyond the formal exclusions, three things business owners commonly assume are covered and are not: the full amount of a wire transfer fraud loss (typically sublimited to $25,000 to $250,000 rather than paid at the policy limit), the cost of upgrading systems to prevent the next attack, and the lost value of stolen trade secrets. On the formal side, the exclusions that generate the most denied claims are prior acts, failure to maintain the security controls you attested to, and state-backed attack attribution.
Does cyber insurance pay out?
Yes. Breach response and ransomware claims are paid routinely. Disputes concentrate around three issues: application misrepresentation, the retroactive date, and attribution of the attack to a nation-state. Answering the application accurately with your IT provider, and reporting promptly through the carrier's breach panel, are the two factors most within your control.
Is it worth having cyber insurance?
For any business in Santa Fe Springs that stores customer personal information, accepts card payments, or runs on cloud software, generally yes. At $500 to $3,000 a year for $1M in coverage, the premium is a fraction of the cost of a single notification event under California's breach laws. It is harder to justify for a business with no employees, no stored customer data, and no online payments. The practical test is not company size -- it is whether a forced three-day shutdown of your systems and email would cost you more than the annual premium.
How much should cyber insurance cost?
Most small businesses in Los Angeles County pay $500 to $3,000 per year for $1M in cyber liability coverage. Pricing is driven by revenue, the type and volume of data you hold, your industry, and your security controls. Businesses with MFA, tested backups, endpoint detection, and employee security training quote meaningfully lower than those without -- and in a hardened market, some applicants without MFA cannot obtain a quote at all.
If my business website is hacked and customer data is stolen, does CGL respond?
Likely not, especially if your policy contains a cyber exclusion. Even without an explicit exclusion, customer data is considered intangible property under most CGL forms, and the coverage trigger for property damage typically requires physical injury to tangible property.
Can my BOP cover cyber incidents?
Some BOPs include a basic cyber endorsement, typically with limits of $10,000 to $50,000 -- far below the average data breach cost. A standalone cyber liability policy is recommended for businesses that handle significant customer data.
Is cyber insurance required by California law?
California does not require businesses to carry cyber insurance. However, California's data breach notification laws and CCPA create significant financial exposure for businesses that suffer a breach -- making cyber insurance a financially prudent investment for most businesses that handle personal data.
How much cyber coverage does a small business in LA need?
Most small businesses start with $500,000 to $1,000,000 in cyber liability coverage. Businesses handling payment cards, health information, or large volumes of personal data should consider $1M to $5M in coverage.
What security practices can reduce my cyber insurance premium?
Carriers evaluate your security posture when quoting cyber coverage. Having multi-factor authentication (MFA), regular data backups, employee security training, and an incident response plan in place can significantly reduce your premium.
The Bottom Line
If your business accepts credit cards, stores customer email addresses, or uses any cloud-based software, you have cyber exposure. Pull out your current CGL policy and look for the words "cyber" or "electronic data" in the exclusions section. If they're there -- and in most modern policies they are -- you have an uninsured gap that a standalone cyber policy closes for as little as $500 a year.
External resources: Insurance Information Institute -- Cyber Insurance | California Attorney General -- CCPA