Massachusetts business insurance
π£ Falamos portuguΓͺs Β· Hablamos espaΓ±ol Β· English β call (617) 913-4859
Cyber liability insurance pays for what happens after a data breach, a ransomware attack, or a system failure: the forensic investigation, the breach lawyer, the legally required notifications, and the income lost while systems are down. A commercial general liability policy generally does not respond to any of it β most modern forms exclude the electronic loss of data β and in Massachusetts the breach notification obligations apply to businesses of every size.
Two Massachusetts requirements are worth knowing by name, because both are triggered by the data you hold rather than by your revenue or headcount.
Two consequences follow that catch owners off guard. First, "personal information" here is a defined term that reaches ordinary business records β a Massachusetts resident's name together with a Social Security number, a driver's license or state ID number, or a financial account, credit card, or debit card number that would permit access to the resident's financial account. A payroll file qualifies. A folder of employee I-9 paperwork qualifies. A contractor with eight employees and no customer database is very likely holding personal information about Massachusetts residents.
Second, these obligations follow the resident, not your address. A New Hampshire company with Massachusetts customers or Massachusetts employees is inside the rules.
We are an insurance agency, not your lawyer. Whether and how these requirements apply to your specific business β and what your WISP needs to say β is a question for counsel. What we can do is make sure that if something goes wrong, the cost of complying is insured rather than paid out of your operating account. The current text of both requirements is published by the Commonwealth; links are at the bottom of this page.
Cyber policies split into two halves. The first-party side pays your costs. The third-party side pays what you owe other people. Most small-business claims land on the first-party side.
| Coverage | What it responds to | Side |
|---|---|---|
| Breach response / incident response | Forensics, breach counsel, notifying affected people and regulators, call center, credit monitoring | First-party |
| Cyber extortion / ransomware | Ransom negotiation and payment where legally permitted, and the recovery work around it | First-party |
| Business interruption | Income lost and extra expense incurred while systems are down | First-party |
| Dependent business interruption | Income lost when it is your vendor or cloud provider that goes down, not you | First-party |
| Data restoration | Recreating or restoring data and systems that were corrupted or destroyed | First-party |
| Funds transfer fraud / social engineering | Money wired on a fraudulent instruction β very commonly sublimited, sometimes excluded, and sometimes only on the crime policy | First-party |
| Network security & privacy liability | Claims brought against you by people whose data you held, or by parties harmed through your network | Third-party |
| Regulatory defense and penalties | Regulatory proceedings and fines, where fines are insurable by law | Third-party |
| Media liability | Defamation and intellectual-property claims arising from your website and content | Third-party |
| PCI fines and assessments | Card-brand assessments after a payment card breach, if you take cards | Third-party |
It does not make you compliant. A policy is not a Written Information Security Program, and buying one does not satisfy 201 CMR 17.00. It does not pay to upgrade the systems that let the incident happen β betterment is generally excluded. It rarely responds to a loss you could have prevented by applying a patch you told the carrier you had applied. And it does not cover the reputational cost of the phone call you have to make to your best customer.
What it does is make the difference between an expensive week and the end of the business. Breach response costs land in the first seventy-two hours, before you have any idea what the ultimate liability will be, and they land whether or not anyone ever sues you.
Cyber is usually one of the last coverages a business adds and one of the cheapest lines on the account relative to what it does. It sits alongside the general liability, the property, the commercial auto, and the workers' compensation β and when those are spread across four agencies, nobody is looking at the whole exposure. Consolidating the account is how that gets fixed.
Probably yes. Massachusetts defines personal information broadly enough that payroll records alone β a resident's name plus a Social Security number β put you inside 201 CMR 17.00 and the breach notification law. Card data is one trigger among several, not the only one.
A Written Information Security Program is the documented security plan that 201 CMR 17.00 requires of anyone who owns or licenses personal information about a Massachusetts resident. Whether the requirement reaches your specific business, and what your WISP must contain, is a legal question β ask counsel. A cyber insurance policy is not a substitute for one.
Generally no. Commercial general liability responds to bodily injury and physical property damage, and most modern forms carry an explicit exclusion for the electronic loss of data. Breach response costs, notification, business interruption from a system outage, and privacy liability sit on a cyber policy.
Cyber policies commonly include a cyber extortion coverage part covering negotiation, payment where it is legally permitted, and the recovery work, along with business interruption while you are down. Terms and sublimits vary considerably between carriers, and some carriers now condition coverage on controls such as multi-factor authentication and offline backups.
That is social engineering or funds transfer fraud, and it is the coverage part to check hardest. Many policies sublimit it well below the policy limit, some exclude it, and on some accounts it belongs on a crime policy instead. Ask for the specific sublimit in writing before you bind.
The obligations attach to the personal information of Massachusetts residents, not to your business address. If you hold data about Massachusetts residents β customers or employees β assume the requirements reach you, and confirm with counsel.
Start from what a real event would cost you: how many individuals' records you hold, what notification and credit monitoring for that many people would run, and how much income you would lose per day of downtime. That produces a defensible number. A limit picked because it was the cheapest option does not.
Send us your current business policies. We will tell you whether you have any cyber coverage at all, what the sublimits are, and where the gaps sit β at no cost and with no obligation.
This page is general information for Massachusetts businesses. It is not legal advice, not a quote, and not a promise of coverage. Whether any statute or regulation applies to your business, and what it requires of you, is a question for your attorney. Coverage terms, sublimits, exclusions, and availability vary by carrier and by policy; coverage is subject to underwriting and is bound only when confirmed in writing by an insurer. Nothing here modifies the terms of any issued policy.