Cyber Liability
Coverage for a data breach, network failure, or cyber extortion — and everything it costs to respond to one.
This is an estimate, not a bound policy — a licensed VAB producer confirms final terms before coverage starts. Sgt. Savings can answer questions but can't quote, bind, or guarantee coverage.
A data breach hits a nonprofit's donor database exactly as hard as it hits a business's customer database — the notification costs, the regulatory exposure, and the reputational damage don't care about your tax status. Cyber Liability covers both sides of a cyber event: third-party liability when someone sues you over a breach or network failure, and first-party breach-response costs — forensics, notification, credit monitoring, legal, and extortion payments — that start the moment you discover the incident. Most organizations that think they're covered because of a rider on another policy find out too late that a cyber event needs a dedicated policy built for it.
Who This Is Really For
The ideal buyer.
The ideal buyer is a risk-aware operations, finance, or IT lead at a business or nonprofit that assumed a small cyber rider bundled into another policy was enough — until a broker, board member, or a headline about a similar-sized organization getting hit with ransomware made them actually compare that rider's sublimits to what a real breach-response bill would look like. Nonprofits in particular often carry this exact blind spot, assuming a smaller donor or member database makes them a less attractive target, when in reality leaner IT resources and weaker in-house incident response make them an easier one. The trigger is frequently concrete: a new payment-processing relationship that requires PCI-DSS assessment coverage, onboarding an AI tool into the tech stack and wanting that exposure addressed, or simply realizing there's no in-house team that could actually run a breach response without outside forensics, legal, and notification help. This buyer needs a dedicated policy with real breach-response grants, not a rider that was never sized for an actual incident.
- Any business or nonprofit that stores customer, donor, member, or employee personal data in a system connected to the internet
- Organizations processing payment cards and needing PCI-DSS assessment coverage in case a card-brand fine follows a breach
- Nonprofits and small businesses that assume 'we're too small to be a target' — most ransomware operators target under-resourced organizations specifically because response is weaker
- Companies using AI systems in their technology stack, where a technology-related wrongful act could originate from an AI-driven process
- Any organization that would need outside forensic, legal, and notification help to respond to a breach — which is nearly every organization without an in-house incident-response team
What It Covers
Coverage, broken down.
Technology E&O, including AI systems
Third-party, claims-made liability for wrongful acts in the technology services or products you provide, extended to address AI systems within that technology.
Network Security and Privacy Liability
Third-party liability for claims arising from a failure of network security or a breach of private information you're responsible for protecting.
Regulatory Proceedings and PCI-DSS Assessments
Coverage for regulatory investigations and proceedings tied to a privacy or security event, plus assessments and fines that can follow a payment-card breach.
Optional Media Liability
An available extension for liability arising from your organization's media content — website copy, social posts, published materials — where that's a real exposure.
Breach response and cyber incident costs (first-party)
Discovery-based coverage for the direct costs of responding to a breach or cyber incident — forensics, legal guidance, notification, and related crisis-response expense.
Cyber extortion and funds transfer fraud
First-party coverage for ransomware and other cyber extortion demands, plus loss from fraudulent funds-transfer instructions carried out through a cyber incident.
Illustrative Scenario — How This Coverage Responds
Illustrative scenario — ransomware locks a donor database
A nonprofit's donor management system is hit with ransomware, encrypting donor records and payment history and halting operations for several days. Under an illustrative Cyber Liability policy, the first-party breach-response grants — forensic investigation to determine what happened, legal guidance on notification obligations, notification costs to affected donors, and the cyber extortion coverage part addressing the ransom demand itself — are what this policy is built to respond to, subject to its terms, sublimits, and exclusions. This is a description of how the coverage is structured to respond, not a specific claim outcome or payout VAB is promising.
Illustrative example for education only — not a claim outcome or a promise of payment. Every claim depends on the actual policy issued and its terms.
More Than One Way In
More scenarios.
Real coverage doesn't fit one story. Here's who else this shows up for.
The nonprofit rethinking its donor database exposure
A nonprofit reviewing its insurance realizes that a breach of its donor management system would trigger the same notification laws and forensic costs a for-profit business would face, and that its current coverage was never sized for that response. It places a dedicated Cyber Liability policy specifically because donor and payment data carries the same real exposure regardless of tax status. This illustrates a common realization nonprofits reach, not a claim outcome.
The retailer scaling card payment volume
A growing retailer processing a larger volume of card transactions is told by its payment processor that a card-brand assessment could follow a breach, and wants PCI-DSS assessment coverage sized to its actual transaction volume. It reviews its cyber policy's sublimit for that specific grant before renewing its processing agreement. This is an illustration of a common trigger tied to payment growth, not a claim scenario.
The company embedding AI tools into its product
A business adds an AI-driven feature to its customer-facing technology and wants to confirm that a technology-related wrongful act originating from that AI component would actually be addressed under its Technology E&O grant. It describes the AI system accurately at application so the coverage is structured to reflect real usage. This illustrates how a technology change can prompt a coverage review, not a claim outcome.
Know The Gaps
What this doesn't cover.
Every policy has limits. Knowing them before you buy is how you avoid a denied claim later.
Bodily injury or property damage
This is a data and technology liability policy, not a general liability form — physical injury or property damage, even if a cyber event somehow contributed, needs separate coverage.
War and hostile cyber activity
Broadly excluded across the cyber insurance market, with a narrow carve-back for certain state-sponsored attacks in some policy versions — confirm the specific war exclusion language with your advisor, since attribution disputes after a major attack are common.
Prior notice, prior knowledge, or a proceeding already pending
A vulnerability or incident you already knew about before the policy started, or litigation already underway, generally won't be covered — full disclosure at application is what makes the rest of the policy actually work when you need it.
Contract or promised-performance claims
A claim that you simply failed to deliver a promised service level isn't a cyber liability claim — this covers wrongful acts and security/privacy failures, not contract performance.
Patent and trade-secret disputes
Intellectual property litigation is excluded here — that risk needs to be addressed through IP-specific coverage if it's relevant to your organization.
Betterment and vulnerability-remediation costs
The policy pays to respond to and recover from an incident — it generally doesn't pay to upgrade your security beyond where it was before the incident. Budget for security improvement separately from breach response.
Behind The Quote
What goes into the decision.
What actually moves your price and your approval — no black box.
Data types held and volume
The kinds of personal data an organization holds — customer, donor, member, employee — and how much of it, directly shapes both the liability exposure and the first-party notification costs a breach would trigger, so an accurate data inventory at application is what sizes the coverage correctly.
Payment card processing volume
PCI-DSS assessment coverage is sized to actual card-processing exposure, so an organization's transaction volume and processor relationship matter directly to whether that sublimit is adequate.
AI systems in the technology stack
Since Technology E&O is written to include AI Systems, describing how AI is actually used in the organization's technology at application is what lets that inclusion apply meaningfully rather than being a line nobody checked.
In-house incident-response capability
An organization with no dedicated incident-response team relies more heavily on the policy's breach-response grants — forensics, legal, notification — which is worth confirming are sized to reflect that reality rather than assuming a smaller organization needs less.
Prior incidents or known vulnerabilities
A vulnerability or incident already known before the policy starts, or litigation already pending, generally isn't covered — full disclosure at application is what makes the rest of the policy's response coverage actually usable later.
Getting Covered
How it actually works.
- Tell us your data types, systems, payment processing, and any AI systems in your technology stack.
- We match coverage limits and sublimits to your actual breach-response and liability exposure.
- The moment you discover an incident, your policy's breach-response team — forensics, legal, notification — is who you call first.
- First-party response costs and any resulting third-party claims are handled under the same policy, so you're not coordinating two separate carriers mid-crisis.
Let's get you covered.
Tell us what you need on Cyber Liability — a licensed VAB advisor follows up personally. No bots, no runaround.
Looking for a session that's already scheduled? Browse upcoming webinars.
Availability
Placed nationwide, with terms adjusted state by state.
Questions, answered straight
No jargon on cyber liability — just what you're actually asking.
Yes. A breach of donor records, member data, or a nonprofit's financial systems triggers the same notification laws, the same forensic costs, and the same reputational damage as a breach at a for-profit business — the coverage is built for the exposure, not the tax status.
The liability grants (Network Security, Privacy, Tech E&O, Regulatory) respond when someone else — a customer, regulator, card brand — brings a claim against you. The breach-response grants are first-party: costs you incur directly to investigate, notify, and recover from the incident, whether or not anyone ever sues you.
Cyber extortion is one of the first-party coverage parts, addressing ransom demands from an incident like ransomware — subject to the policy's terms, sublimits, and any conditions on how the payment is handled. Talk to your advisor about the specific process before an incident happens, not during one.
The Technology E&O grant is written to include AI Systems, so wrongful acts tied to AI components of your technology are contemplated — describe your actual AI use accurately at application so it's reflected correctly in the policy.
Add-on cyber riders are usually built with low sublimits and narrow triggers compared to a dedicated cyber policy's eleven insuring agreements. If a real breach happens, the difference between a sublimited add-on and dedicated coverage is usually the difference between adequate response funding and a shortfall you cover yourself.
PCI-DSS assessment coverage is one of the specific grants in this policy, built for exactly that scenario — confirm your sublimit for it matches your actual card-processing volume and exposure.
Beyond This Coverage
What people in your situation also need.
Credit Card Processing
A business handling card transactions has real cyber exposure specifically tied to that payment flow, which is exactly what the PCI-DSS assessment grant in this policy is built to address.
ExploreBusiness Banking
Breach-response costs hit fast and before any claim payment arrives, so an operating banking relationship helps a business or nonprofit bridge that gap.
ExploreRelated Coverage
Coverage people pair with this.
Crime & Fidelity Coverage
Protection against employee theft, forgery, and funds-transfer fraud — the internal-controls gap trust-based organizations feel hardest.
Learn moreDigital Asset Protocol Coverage
Liability and loss protection built specifically for DeFi protocols, staking, and validator operations.
Learn moreDigital Asset Custody & Crime Coverage
First-party crime coverage for digital assets and private keys you hold — your own, or your clients'.
Learn moreReady to talk it through?
Get a quote in minutes, or ask Sgt. Savings a straight question first — no pressure, no runaround.
Insurance products described on this page are marketed by The Veteran Alliance, a licensed insurance producer, and underwritten by one or more separately licensed insurance companies, which may include Corgi Insurance Company and its affiliates. The insurer that actually underwrites your policy, its licensing status in your state, and any state-required notices will be identified in your quote and policy documents. Coverage, limits, eligibility, and pricing are determined by the underwriting insurer, may vary by state, and may change. Nothing on this page is a quote, an offer of insurance, a binder, or a guarantee of coverage — coverage takes effect only when a policy is issued.
