Commercial guide
Cyber and Professional Liability for California Businesses
Protect against data incidents, technology failures, and claims that professional services caused financial harm.
Educational examples updated . This update does not represent a new staff or legal review.
What to know first
- GL generally does not replace cyber or professional liability.
- Cyber coverage can include response costs, notification, restoration, extortion, and liability.
- Professional liability is usually written on a claims-made basis.
What to compare in your policy
Compare each coverage's own limit, deductible or retention, reporting conditions, and exclusions. A headline cyber limit does not mean every fraud or interruption receives that full amount.
These are educational benchmarks, not a recommendation for every applicant.Cyber coverage can address incident response, forensic investigation, notification, credit monitoring, data restoration, business interruption, extortion, fraud, regulatory matters, and third-party liability, subject to the form.
Professional liability or errors and omissions coverage can address claims that advice, design, technology, or professional services caused financial loss. The retroactive date and continuous coverage are critical on claims-made policies.
Review contracts, revenue, largest-client exposure, record count, payment processes, remote access, backups, multifactor authentication, vendor dependencies, and professional services. Limits should reflect a credible severe event—not only the smallest contract.

A stolen file is different from a costly mistake
Cyber insurance addresses specified digital incidents and their consequences. First-party coverage concerns your business's own eligible costs, such as incident response or data restoration. Third-party coverage concerns covered claims against you. Professional liability, also called errors and omissions (E&O), concerns allegations that your professional services caused a client's loss.
Hypothetical examples: an intruder steals customer records, requiring a response under applicable law; separately, a consultant's error causes a client financial harm. Those events raise different coverage questions. A fraudulent email directing a payment also needs a specific funds-transfer or social-engineering review; do not assume every cyber policy reimburses that money.
Dates and security answers matter
Claims-made coverage ties protection to when a claim is first made and, where required, reported. A retroactive date identifies how far back eligible acts can go. Moving that date forward or allowing coverage to lapse can leave earlier work exposed. Ask us to compare those dates before changing insurers.
Multifactor authentication (MFA) adds a verification step beyond a password. Describe your actual security controls, backups, vendors, and services accurately. Ask who to call first after an incident and whether the insurer must approve response providers or expenses; do not wait until after hiring help to discover a condition.