Coming soon Prevent Insurance is not open for business yet. We're accepting requests now and will be in touch as soon as we open.
← Back to preventinsurance.com

Massachusetts business insurance

Cyber Insurance for Massachusetts Businesses

πŸ—£ Falamos portuguΓͺs Β· Hablamos espaΓ±ol Β· English β€” call (617) 913-4859

Cyber liability insurance pays for what happens after a data breach, a ransomware attack, or a system failure: the forensic investigation, the breach lawyer, the legally required notifications, and the income lost while systems are down. A commercial general liability policy generally does not respond to any of it β€” most modern forms exclude the electronic loss of data β€” and in Massachusetts the breach notification obligations apply to businesses of every size.

The Massachusetts rules apply to smaller businesses than most owners think

Two Massachusetts requirements are worth knowing by name, because both are triggered by the data you hold rather than by your revenue or headcount.

Two consequences follow that catch owners off guard. First, "personal information" here is a defined term that reaches ordinary business records β€” a Massachusetts resident's name together with a Social Security number, a driver's license or state ID number, or a financial account, credit card, or debit card number that would permit access to the resident's financial account. A payroll file qualifies. A folder of employee I-9 paperwork qualifies. A contractor with eight employees and no customer database is very likely holding personal information about Massachusetts residents.

Second, these obligations follow the resident, not your address. A New Hampshire company with Massachusetts customers or Massachusetts employees is inside the rules.

This is not legal advice

We are an insurance agency, not your lawyer. Whether and how these requirements apply to your specific business β€” and what your WISP needs to say β€” is a question for counsel. What we can do is make sure that if something goes wrong, the cost of complying is insured rather than paid out of your operating account. The current text of both requirements is published by the Commonwealth; links are at the bottom of this page.

What a cyber policy actually pays for

Cyber policies split into two halves. The first-party side pays your costs. The third-party side pays what you owe other people. Most small-business claims land on the first-party side.

The coverage parts you will see on a small-business cyber policy. Terms, sublimits, and availability vary by carrier and by policy.
CoverageWhat it responds toSide
Breach response / incident responseForensics, breach counsel, notifying affected people and regulators, call center, credit monitoringFirst-party
Cyber extortion / ransomwareRansom negotiation and payment where legally permitted, and the recovery work around itFirst-party
Business interruptionIncome lost and extra expense incurred while systems are downFirst-party
Dependent business interruptionIncome lost when it is your vendor or cloud provider that goes down, not youFirst-party
Data restorationRecreating or restoring data and systems that were corrupted or destroyedFirst-party
Funds transfer fraud / social engineeringMoney wired on a fraudulent instruction β€” very commonly sublimited, sometimes excluded, and sometimes only on the crime policyFirst-party
Network security & privacy liabilityClaims brought against you by people whose data you held, or by parties harmed through your networkThird-party
Regulatory defense and penaltiesRegulatory proceedings and fines, where fines are insurable by lawThird-party
Media liabilityDefamation and intellectual-property claims arising from your website and contentThird-party
PCI fines and assessmentsCard-brand assessments after a payment card breach, if you take cardsThird-party

The three things to check before you buy

  1. Is social engineering actually covered, and for how much? The most common way a small Massachusetts business loses real money is not a dramatic hack β€” it is an email that looks like it came from a supplier or a boss, and a payment sent to the wrong account. Many cyber policies sublimit that coverage far below the policy limit, or push it to a separate crime policy. Ask for the number, not the reassurance.
  2. How is business interruption triggered, and what is the waiting period? A twelve-hour waiting period on a policy covering a business that would be back up in eight hours is a coverage part you will never collect on. Match it to how long an outage would actually last for you.
  3. What does the application commit you to? Cyber applications ask whether you use multi-factor authentication, whether you keep offline backups, and how you handle patching. Answering optimistically is how a claim gets denied. If the honest answer is no, say no β€” and then go fix it, because it will also lower your premium.

What cyber insurance does not do

It does not make you compliant. A policy is not a Written Information Security Program, and buying one does not satisfy 201 CMR 17.00. It does not pay to upgrade the systems that let the incident happen β€” betterment is generally excluded. It rarely responds to a loss you could have prevented by applying a patch you told the carrier you had applied. And it does not cover the reputational cost of the phone call you have to make to your best customer.

What it does is make the difference between an expensive week and the end of the business. Breach response costs land in the first seventy-two hours, before you have any idea what the ultimate liability will be, and they land whether or not anyone ever sues you.

Who needs this in Massachusetts

Where it fits in the rest of your program

Cyber is usually one of the last coverages a business adds and one of the cheapest lines on the account relative to what it does. It sits alongside the general liability, the property, the commercial auto, and the workers' compensation β€” and when those are spread across four agencies, nobody is looking at the whole exposure. Consolidating the account is how that gets fixed.

Keep reading

Questions & answers

Does my business need cyber insurance if I don't store customer credit cards?

Probably yes. Massachusetts defines personal information broadly enough that payroll records alone β€” a resident's name plus a Social Security number β€” put you inside 201 CMR 17.00 and the breach notification law. Card data is one trigger among several, not the only one.

What is a WISP, and am I required to have one?

A Written Information Security Program is the documented security plan that 201 CMR 17.00 requires of anyone who owns or licenses personal information about a Massachusetts resident. Whether the requirement reaches your specific business, and what your WISP must contain, is a legal question β€” ask counsel. A cyber insurance policy is not a substitute for one.

Doesn't my general liability policy cover a data breach?

Generally no. Commercial general liability responds to bodily injury and physical property damage, and most modern forms carry an explicit exclusion for the electronic loss of data. Breach response costs, notification, business interruption from a system outage, and privacy liability sit on a cyber policy.

Does cyber insurance cover ransomware?

Cyber policies commonly include a cyber extortion coverage part covering negotiation, payment where it is legally permitted, and the recovery work, along with business interruption while you are down. Terms and sublimits vary considerably between carriers, and some carriers now condition coverage on controls such as multi-factor authentication and offline backups.

We got tricked into wiring money to a fake vendor. Is that covered?

That is social engineering or funds transfer fraud, and it is the coverage part to check hardest. Many policies sublimit it well below the policy limit, some exclude it, and on some accounts it belongs on a crime policy instead. Ask for the specific sublimit in writing before you bind.

Do the Massachusetts rules apply if my business is based in another state?

The obligations attach to the personal information of Massachusetts residents, not to your business address. If you hold data about Massachusetts residents β€” customers or employees β€” assume the requirements reach you, and confirm with counsel.

How much cyber coverage does a small business need?

Start from what a real event would cost you: how many individuals' records you hold, what notification and credit monitoring for that many people would run, and how much income you would lose per day of downtime. That produces a defensible number. A limit picked because it was the cheapest option does not.

Primary sources 201 CMR 17.00, Standards for the Protection of Personal Information of Residents of the Commonwealth β€” published by the Commonwealth (17.01 scope, 17.02 definitions, 17.03 the Written Information Security Program requirement). Massachusetts data breach notification β€” M.G.L. c. 93H Β§ 3 (notice to residents, the Attorney General, and the Office of Consumer Affairs and Business Regulation) and Β§ 3A (credit monitoring). Requirements change; confirm the current text and how it applies to your business with your attorney.

Find out what you're actually exposed to.

Send us your current business policies. We will tell you whether you have any cyber coverage at all, what the sublimits are, and where the gaps sit β€” at no cost and with no obligation.

This page is general information for Massachusetts businesses. It is not legal advice, not a quote, and not a promise of coverage. Whether any statute or regulation applies to your business, and what it requires of you, is a question for your attorney. Coverage terms, sublimits, exclusions, and availability vary by carrier and by policy; coverage is subject to underwriting and is bound only when confirmed in writing by an insurer. Nothing here modifies the terms of any issued policy.