Home › Commercial Insurance › Cyber Liability
Breach response, ransomware, and the notification duties Pennsylvania law puts on any business that loses customer data.
For any business holding data
Cyber liability insurance splits into first-party coverage, your own costs after an incident, and third-party coverage, claims from the people whose data you held. Any Pennsylvania business that stores customer records, processes cards, or runs on email carries both exposures, whether or not it carries the policy.
First-party is where small businesses feel it: forensics to find what happened, notification letters the law requires, credit monitoring for affected customers, ransomware response, and the income lost while systems are down. Third-party arrives later, as claims and regulatory attention from the data’s owners.
The product has matured fast. What used to be an exotic add-on now behaves like any other core commercial coverage, priced by revenue, record counts, and the controls you can prove, multifactor authentication and tested backups above all.
What is covered
The response machinery, funded, in the order a real incident needs it.
The specialists who determine what was taken, from where, and whether it is over. The first invoice of every incident.
The legally required letters and the monitoring services offered to affected individuals, at scale.
Negotiation, response, and, subject to sublimits and conditions, payments, plus restoring systems either way.
Income lost while systems are encrypted, wiped, or offline, the loss that outlasts the headline.
Defence and damages when customers, partners, or regulators pursue the business over compromised data.
Funds tricked out the door by impersonation and fake invoices, covered only when specifically added, and worth adding.
Cost
Premiums price the data, not the square footage: revenue, how many records you hold, what kind, and the security controls you can demonstrate. Small firms with modest data and good hygiene buy meaningful limits cheaply; businesses with rich records and no multifactor authentication pay for the gap, when they can buy at all.
We publish no average premium here because cyber pricing has moved too fast in recent years for a static number to stay honest, and because controls change quotes more than any average suggests. The practical lever is preparation: carriers now ask specific questions about MFA, backups, and email security, and the answers move both price and insurability.
Ten minutes on your systems produces a real quote, and often a short list of cheap fixes that lower it.
One scale note worth holding onto: for a small business, the notification and monitoring duties alone on a few thousand compromised records produce invoices that dwarf the annual premium. The policy is priced against exactly that arithmetic, which is why the smallest firms often see the clearest value in it.
The Pennsylvania layer
The Breach of Personal Information Notification Act, 73 P.S. § 2301 and following, requires entities that suffer a breach of Pennsylvania residents’ personal information to notify affected individuals without unreasonable delay. Amendments under Act 33 of 2024, effective September 26, 2024, added sharper duties.
Under the amended law, a breach affecting more than 500 Pennsylvania residents must be reported concurrently to the Office of Attorney General, consumer reporting agencies are notified when more than 1,000 residents are affected, and breaches compromising Social Security, driver’s license, state ID, or bank account numbers oblige the entity to offer twelve months of credit monitoring. Those duties arrive with real invoices attached, which is precisely the first-party coverage a cyber policy funds.
Sources: Breach of Personal Information Notification Act, 73 P.S. § 2301 et seq., as amended by Act 33 of 2024 (Pennsylvania General Assembly). Verified August 2026.
Read this part
The boundaries carriers hold, and the ones businesses discover late.
Why independent
There is no standard cyber policy. Sublimits for ransomware, conditions on controls, social engineering treatment, and even what counts as a computer system vary form to form, and two policies at the same premium can behave completely differently in the same incident. Reading those differences is the actual work.
We compare cyber forms across markets the way we compare everything else, and we fit the policy into the wider stack: a business owners policy in Pennsylvania whose thin cyber endorsement needs upgrading, employment practices liability insurance in Pennsylvania where employee data overlaps employment risk, and the full map at business insurance in Drexel Hill, PA.
Questions
Ten minutes on systems and records. Real cyber quotes, forms compared, and the cheap fixes that lower them.
Get a QuoteCall (610) 259-6700