Skip to content

Cyber Liability Insurance — Texas & Oklahoma

A spoofed email moved $77,000 in minutes. The right endorsement paid $72,000 back.

  • Social Engineering Coverage — We verify your policy covers fraudulent payment instructions. Most don't.
  • Ransomware & Business Interruption — Coverage structured to respond when systems and revenue go down.
  • Texas Compliance — Breach notification duties under Tex. Bus. & Com. Code §521, mapped and covered.
Businessmans Hands at Laptop in Dark Office at Night

 

The four events that drive most cyber claims

Cyber policies are not standardized the way general liability is. Two carriers can use the words "cyber liability" and deliver materially different coverage. What follows is how the exposure usually presents, and the questions worth asking about any specific form before you buy it.

Ransomware and extortion
An attacker encrypts or exfiltrates data and demands payment. The insurance questions are whether extortion payments are covered, whether the carrier requires pre-approval, what the sublimit is, whether restoration costs are included, and whether specific security controls are a condition of coverage.
Business email compromise
An attacker gains access to an email account and uses it to redirect payments or harvest information. The question is whether the loss is treated as a computer fraud, a social engineering loss, or an uncovered voluntary transfer.
Social engineering and funds transfer fraud
An employee is deceived into sending money to an attacker. This is the single most common way small and mid-sized businesses lose real cash, and on many forms it is a low sublimit or an optional endorsement rather than a core coverage. It is worth checking by name.
Data breach and privacy
Personal or protected information is exposed. This triggers notification obligations, credit monitoring, forensic work, regulatory attention and third-party claims from the people whose information was involved.

First-party and third-party coverage do different jobs

Every cyber policy splits into what the event costs you and what other people claim from you. Most coverage disagreements come from assuming one side of that line covers the other.

First party: your own loss

Incident response and forensics, legal counsel, notification and credit monitoring, data restoration, extortion payments where covered, cyber business interruption for income lost while systems are down, and dependent business interruption when the outage is at a vendor rather than at you.

Third party: what others claim

Privacy liability from individuals whose data was exposed, network security liability where your systems were used to harm someone else, regulatory defense and, where insurable by law, fines and penalties, plus media liability on some forms.

Business interruption is usually the largest number

Notification costs are visible and finite. Downtime is neither. A manufacturer whose production system is encrypted, a professional services firm that cannot access client files, or a property manager locked out of accounting all keep incurring cost while revenue stops. Two details decide whether the policy actually responds.

  • The waiting period. Many forms apply an hourly retention, often eight to twelve hours, before business interruption starts to accrue. A shorter outage produces no recovery.
  • Dependent business interruption. If the outage happens at a vendor, a hosting provider or a platform you depend on rather than on your own network, coverage depends on whether dependent or contingent business interruption is included and whether that vendor category is scheduled.

If you think a transfer has already gone out, speed matters more than paperwork. Contact your bank immediately to attempt a recall, preserve the email thread, and notify the carrier through the incident response hotline rather than waiting for a formal claim. Most cyber policies give access to a breach coach and forensic vendors from the first call, and using the panel vendors is usually a condition of full coverage.

What underwriters ask, and why it changes price

Cyber underwriting has tightened. Controls that were optional a few years ago now decide both eligibility and price.

  • Multifactor authentication on email, remote access and privileged accounts
  • Backup frequency, whether backups are segregated or immutable, and whether restoration has actually been tested
  • Endpoint detection and response, and how quickly patches are applied
  • Payment verification procedures, specifically out-of-band callback before changing bank details
  • Employee phishing training and testing
  • Volume and type of records held, and which regulatory regimes apply
  • Dependence on third-party platforms and vendors
  • Prior incidents, including ones that produced no claim

Limitations worth reading before you buy

These are the provisions that most often surprise a policyholder. None of them are universal, and that is the point: they vary by carrier and by form, so they need to be checked against the specific quote rather than assumed.

  • Social engineering and funds transfer sublimits that sit far below the policy limit
  • Conditions requiring specific security controls to be in place and maintained
  • Waiting periods and dependent business interruption exclusions
  • Prior known circumstances and retroactive date limitations on claims-made forms
  • War, hostile act and state-sponsored attack wording, which has been actively rewritten across the market
  • Betterment and system upgrade costs excluded from restoration
  • Panel vendor requirements for counsel and forensics

A cyber event rarely stays inside one policy. These are the coverages that most often need to be read alongside it, and the operational reason why.

Crime and fidelity

If money can leave the business by wire or check, crime and cyber forms overlap unevenly. Employee theft usually sits in crime, while an outsider-deceived transfer may sit in either, or in neither.

Commercial insurance program

Professional liability

If you deliver a service that clients rely on, an outage or a breach can produce a claim that you failed to perform, which is a professional liability allegation rather than a cyber one.

Professional services insurance

General liability

Standard general liability forms increasingly exclude data and network events outright, which is precisely why a separate cyber policy exists.

General liability insurance

Property and business income

If a cyber event damages or disables physical equipment, the line between property business income and cyber business interruption becomes the question that decides who pays.

Commercial property and package

Industry context matters: see manufacturing, professional services, property management and real estate or contractors and construction, or start at the commercial insurance practice hub. Terminology is defined in the cyber liability glossary.

Coverage descriptions on this page are general summaries. Cyber policy forms are not standardized, and carriers differ materially in what they cover, sublimit and exclude. Nothing here amends, alters or extends any policy, and actual coverage is determined solely by the terms, conditions, limits and exclusions of the issued policy, subject to underwriting.

4j-cyber-system-outage-hero

A cyber audit, not a policy pitch

  • Social Engineering endorsement review
  • Business interruption trigger analysis
  • Third-party vendor contract alignment
  • Texas & HIPAA regulatory compliance check
  • Carrier response capability review
What does cyber liability insurance cover?

Cyber liability insurance covers breach response costs — forensic investigation, legal counsel, customer notification, and credit monitoring — plus ransomware and cyber extortion response, business interruption from a covered attack, and lawsuits or regulatory penalties that follow a data breach. 4J Insurance structures cyber policies for Texas and Oklahoma businesses so the coverage matches how you actually operate.

Does my small business really need cyber insurance?

Yes — attackers target small businesses precisely because they have fewer security controls. A single spoofed email can redirect payroll or a vendor payment, and breach notification duties under the Texas Business & Commerce Code apply regardless of company size. If your business stores customer data, invoices by email, or banks online, you carry cyber risk — the only question is whether it's insured.

Does cyber insurance cover funds transfer fraud and social engineering?

 Often not by default. Many cyber policies exclude losses from fraudulent payment instructions unless a social engineering or funds transfer fraud endorsement is added, and it is the single most common gap we find in policies written elsewhere. 4J verifies that endorsement is in place before you need it. In one claim, a threat actor spoofed a client's payroll provider and changed the payment instructions, sending about $77,000 to a fraudulent account. Because the endorsement had been verified in advance, the carrier confirmed coverage seven days after the claim was reported and paid $72,000 after the $5,000 deductible. 

What's the difference between first-party and third-party cyber coverage?

First-party coverage pays your own costs after an attack — forensics, data restoration, lost income while systems are down, notification, and credit monitoring. Third-party coverage defends and pays claims brought against you by customers, partners, or regulators whose data was exposed. A complete cyber program needs both, sized to how your business actually handles data and payments.

How much does cyber liability insurance cost in Texas?

Premiums depend on your revenue, industry, how much sensitive data you hold, and your security controls — carriers price MFA, offsite backups, and employee training directly into the quote. Many small Texas businesses are surprised how affordable a well-structured policy is. 4J quotes multiple cyber markets side-by-side so you see the real range for your risk profile instead of one carrier's number.

What should I do the moment I suspect a breach or fraudulent transfer?

Move fast. Call your bank immediately to attempt a wire recall, notify your cyber carrier's incident hotline, preserve evidence — don't wipe or rebuild systems yet — and don't negotiate with attackers on your own. As a former claims adjuster and SIU investigator, Deon R. Williams walks 4J clients through claim documentation from the very first call, because how the first 48 hours are handled often decides how the claim pays.

What is dependent business interruption in a cyber policy?

Dependent, sometimes called contingent, business interruption responds when the outage happens at a vendor you rely on rather than on your own network: a hosting provider, a software platform, a payment processor or a managed service provider. It is not automatically included on every form, and where it is included the covered vendor categories are sometimes scheduled by name. If your operation stops when a specific platform stops, that is the provision to check.

What security controls do cyber underwriters require?

Requirements vary by carrier, but the recurring list is multifactor authentication on email, remote access and privileged accounts; segregated or immutable backups with tested restoration; endpoint detection and response; timely patching; out-of-band callback verification before any change to payment details; and documented phishing training. Several of these appear as conditions of coverage rather than merely as rating factors, which means a control that lapses can affect a claim.

Does my general liability policy cover a data breach?

Generally no. Standard commercial general liability forms increasingly carry explicit exclusions for access to or disclosure of confidential information and for electronic data. That exclusion is the reason a separate cyber policy exists. Assuming general liability responds to a network event is one of the more expensive assumptions a business can make.

What should happen in the first hours after a suspected incident?

Contain first, then notify. Preserve the affected accounts and email threads rather than deleting them, contact the bank immediately if funds moved so a recall can be attempted, and call the carrier's incident response hotline before engaging your own forensic vendor or counsel. Most cyber policies provide a breach coach and panel vendors from the first call, and using non-panel vendors without consent can reduce what is ultimately reimbursed.

One click can cost you six figures. Get ahead of it.