A data breach, ransomware attack, or business email compromise can cost a small NC business tens of thousands of dollars before the first lawsuit is filed. ALLCHOICE Insurance compares cyber liability options across multiple top-rated carriers — evaluating both the coverage form and the premium, not just the price.
NC Cyber Exposure Thresholds Risk-driven
Many government contracts, healthcare vendor agreements, and larger client contracts now require cyber coverage
Any business collecting customer names, emails, SSNs, payment data, or health information has breach notification exposure
Businesses using networked systems, email, or cloud storage have ransomware and business interruption exposure
Standard GL and BOP policies have progressively excluded cyber events in recent years. Many NC small businesses assume their GL covers a data breach — it typically doesn’t. Cyber liability is now a standalone requirement for any business that collects customer data, processes payments, or operates on any networked system.
Covers your direct costs after a breach: forensic investigation, legal counsel, breach notification to affected individuals, credit monitoring services, and public relations. Required by NC ITPA compliance regardless of breach size.
Core coverage
Pays ransom demands, negotiation costs, and the forensic services needed to resolve a ransomware attack. Also covers business income lost while systems are locked and being restored.
Core coverage
Replaces lost income during a network outage caused by a cyber event. Covers both direct attack downtime and, in some policies, downtime caused by attacks on third-party vendors or cloud providers you rely on.
Core coverage
Pays claims from customers, partners, or vendors whose data was compromised in your breach. Covers legal defense, settlements, and regulatory fines arising from the NC ITPA and federal privacy regulations.
Core coverage
Covers financial losses from business email compromise (BEC), wire transfer fraud, and social engineering attacks that trick employees into sending money to fraudulent accounts.
Optional endorsement
Covers legal defense and insurable fines from regulatory investigations triggered by a breach — including state AG investigations, FTC enforcement, and HIPAA enforcement for healthcare businesses.
Optional endorsement
Did you know?
In June 2024, CDK Global — a software platform used by thousands of auto dealerships — suffered a ransomware attack that shut down dealership operations across North America for weeks. Thousands of small dealerships had no cyber coverage and bore the full cost of the outage themselves. Ransomware doesn’t target only large corporations — NC small businesses are among the most common targets precisely because their security posture is weaker than larger enterprises. Cyber coverage has moved from optional to essential.
Cyber policy forms vary more between carriers than almost any other commercial insurance product. What one carrier covers as a core feature, another excludes entirely. ALLCHOICE compares both the price and the coverage form — not just the premium — to find the policy that actually fits your data environment and security posture.
We compare cyber policy forms across multiple carriers — not just price — to find the one whose coverage terms actually match your business’s data risk profile.
We help you understand which security controls most affect your cyber pricing and eligibility — so you can improve your posture before the next renewal.
Typically no. Standard GL and BOP policies have progressively excluded cyber events in recent policy years. Many NC small businesses assume their existing commercial coverage addresses a breach — but when a claim is filed, cyber events are excluded. Standalone cyber liability coverage is now required for adequate protection.
NC’s Identity Theft Protection Act requires prompt notification to affected residents and, in some cases, to the NC Attorney General’s office. The notification must be made in the most expedient time possible following discovery. Failure to comply can result in AG enforcement action. Cyber insurance typically covers the cost of breach counsel, forensic investigation, and notification required by NC ITPA.
If you collect any customer personal information, process payments, or operate any networked systems, yes. NC small businesses are among the most common ransomware targets because their defenses are weaker than large enterprises. The cost of a single breach response — investigation, legal, notification, credit monitoring — can easily exceed $50,000 for a small business with a few thousand customer records.
Most cyber carriers now require multi-factor authentication (MFA) on email and remote access, endpoint detection and response (EDR) on networked devices, and a documented backup and recovery process. Some carriers also require employee security awareness training and a written incident response plan. Businesses without MFA in particular may face reduced coverage or higher premiums.
We compare cyber policy forms and pricing across multiple top-rated carriers — not just premium. Takes about five minutes to get started.
Log in to the Member Center to review your current cyber policy limits, update your security control documentation, or discuss coverage gaps before your next renewal.