Cybersecurity Education
Cyber Insurance: What's the difference from General Liability and why does it matter?
Plenty of business owners believe they are covered for a cyber incident because they carry general liability insurance. Most find out otherwise at the worst possible moment: after the incident, during the claim. The two policies cover different risks, and the gap between them is exactly where the expensive events live.
General Liability Insurance
General liability protects your business against claims arising from accidents: someone slips in your lobby, an employee damages a customer’s property, a product causes an injury. It is often required for licensing or contracts, and every business should carry it.
What it almost never covers is a cyberattack. Some policies include a small cyber rider, but the limits are usually so low relative to real incident costs that the practical answer is the same: general liability does not protect you from cyber crime.
Cyber Insurance
Cyber insurance is built specifically for the financial fallout of digital incidents, and that fallout has more pieces than most people expect: forensic investigation, legal fees, regulatory notification, credit monitoring for affected customers, ransom negotiation, system restoration, and the income you lose while systems are down.
Side by Side
| General liability | Cyber insurance | |
|---|---|---|
| Someone is injured on your property | Covered | Not covered |
| Employee damages a client’s property | Covered | Not covered |
| Ransomware locks your systems | Not covered | Covered |
| Stolen client or donor data | Not covered | Covered |
| Fraudulent wire transfer via email | Not covered | Covered, with the right policy |
| Lost income from cyber downtime | Not covered | Covered |
| Forensics, notification, and legal costs after a breach | Not covered | Covered |
One nuance worth checking with your broker: fraudulent funds transfer, the email scam where an attacker impersonates a vendor and redirects a payment, is sometimes a separate rider rather than part of the base cyber policy. It is also the most common expensive incident for businesses your size, so it is the coverage to confirm first.
The Part That Matters After You Buy the Policy
Every cyber insurance application asks what controls you have: MFA everywhere, tested backups, endpoint protection, supported software. Your answers become part of the contract. If an incident happens and the insurer finds an answer was not true, or that you cannot produce evidence it was true, they have a documented basis to deny the claim, precisely when you need it most.
This is where insurance and your actual security stop being separate topics. The controls that make you insurable are the same controls that make an incident less likely and less severe. If you are not confident which of your application answers you could actually evidence today, that is one of the specific things a Sentry Inspect assessment documents, in a form you can hand to your broker or your board.
The Bottom Line
Carry both policies; they answer different questions. Then make sure the answers on your cyber application are true, provable, and kept true. A policy you cannot claim against is just a subscription.