Forensics and legal review
Working out what actually happened, what data was involved, and what that means legally. It is usually the first cost and often not the smallest.
Moon Insurance Managers, Inc. · TDI license #5595
Cyber coverage answers two different bills: what an event costs the business directly — forensics, notification, restoring data, the days the systems were down — and what other people later claim from it. Most commercial property and general liability policies do not address these risks, which is why this is a separate conversation rather than an assumption.
If something is happening right now, do not start with a quote form. Start with the section directly below.
If it is happening now
We are an insurance agency, not an emergency response service, and the honest thing to do with an event in progress is point you at the people whose job it is. The published federal guidance runs in roughly this order:
Start your own response plan
If the business has one, this is the moment it exists for. Mobilise whoever is on it — internally, and the outside technical and legal help it names.
Secure operations, and preserve evidence
Federal guidance is consistent on the order: contain the problem and fix the vulnerability, but do not destroy what happened on the way. Improvised cleanup is how the forensic trail — and sometimes the claim — disappears.
Tell your current insurer, under its own terms
If you hold a cyber policy, its reporting instructions are what govern, and they often name the vendors you are expected to use. Read that page of the policy before engaging anyone. That clock is not ours to hold.
Get legal advice early
Whether an event meets a statutory definition, who has to be told, and by when are legal questions with deadlines attached. An insurance agency cannot answer them and should not try.
Consider law enforcement
Published guidance for ransomware in particular is to involve law enforcement and to avoid improvised action. Paying a ransom is not supported as a general response strategy, and it does not settle the notification duties either way.
Do not send incident details, affected names, contracts or system information through the form on this page. If you are insured with us, call (281) 484-8320 and we will help you work through what your policy asks for, or start at file a claim. If you are not, your own insurer’s reporting instructions come first.
Sources: FTC — data breach response guide for business; CISA — StopRansomware guide. Verified .
Texas
Texas requires an organisation whose breach affects 250 or more Texans to report it to the Attorney General as soon as practicably possible and no later than 30 days after discovery. Affected consumers must also be notified.
Two caveats travel with that, and dropping either one is how businesses talk themselves into a mistake. The 250 figure governs the report to the Attorney General — it is not a floor below which nobody has to be told. And being under it settles nothing about a customer contract, a regulated-data rule, or another state’s law applying to residents there.
The definitions and duties sit in Chapter 521 of the Business & Commerce Code. Whether a particular event meets them is a legal question with a deadline attached, and it belongs with counsel rather than with an insurance agency — including ours.
Sources: Texas Attorney General — data breach reporting; Texas Business & Commerce Code — Chapter 521. Verified .
Your own costs
These are the costs that land on the business itself. Every one is written here as something a policy can address, because cyber products are highly customised and no two forms carry the same set.
Working out what actually happened, what data was involved, and what that means legally. It is usually the first cost and often not the smallest.
Telling affected people, and whatever monitoring or support is offered alongside it. Volume drives this cost more than anything else.
Rebuilding or restoring data and systems. Backups shorten this; they rarely remove it.
Some policies can address income lost during cyber-caused downtime. Features vary widely and some use a waiting period measured in hours before anything attaches.
Ransom demands and certain fraud losses are addressed by some forms, often with their own sublimits and conditions, and often requiring the insurer’s prior involvement.
Communications help while the business explains itself to customers, staff and sometimes the press.
Sources: NAIC and FTC — cyber insurance guide; NAIC — cybersecurity topic. Verified .
What others claim from you
Suits and demands from people whose data was involved, or from businesses affected by a security failure on your network.
Dealing with a regulator’s investigation. Whether any resulting fine or penalty is insurable is a form question and a legal one, and varies by jurisdiction.
The resolution end of a third-party claim, subject to the policy’s limits, retention and defense terms.
Increasingly the reason a policy gets bought at all. A customer contract may set a limit, name coverages, or require notice terms — read the clause rather than the summary.
Whether a fine, penalty or card-brand assessment can be insured is a form question and a legal one, and the answer differs by jurisdiction. Nobody should promise it in advance, and this page does not.
A boundary worth knowing
The dividing question is what caused whose loss. A data, privacy or network-security event is this page’s question. An allegation that the work, the advice or the service itself failed and cost a client money is a different policy — professional errors or service failures are answered there.
One incident can raise both. A software defect that also exposes customer data is the obvious case, and it is exactly why customer contracts often require the two together rather than treating them as alternatives. A technology company trying to assemble both requirements at once should start at insurance for technology companies.
There is a third boundary, and it catches people out: downtime that began with physical damage — a fire, a burst pipe — is business interruption insurance’s question, not this one. The two triggers are different and a business can need both.
Before binding
Cyber is the line where two proposals at similar limits can behave completely differently. These are the questions that expose it:
The control questions deserve particular care. Applications increasingly ask a business to state what security measures it has in place, and answering optimistically is a genuinely bad idea — good controls also do not guarantee eligibility, price or that a claim gets paid. A recognised framework is a reasonable place to start if you are being asked questions you cannot yet answer, and regulated data brings its own separate duties on top.
Sources: NIST — Cybersecurity Framework 2.0 for small business; HHS — HIPAA breach notification rule. Verified .
No obligation
Tell us what the business does, what data it holds, what it runs on, and whether a customer contract has set a requirement. We will work through what your current policies do and do not address and what the form questions are going to ask before anyone fills one in. The phone is fastest: (281) 484-8320, or use the form below.
Monday to Thursday, 9:00 to 5:00; Friday, 9:00 to 4:00. 360 FM 1959, Houston, TX 77034. Policies written statewide — you do not have to be local.
First party addresses the business’s own costs after an event — forensics, legal review, notification, data restoration, interruption while systems are down, extortion and crisis support. Third party addresses what other people claim from the business, including litigation, regulatory response, settlements and judgments. Most policies combine some of both, and products are highly customised, so which items are present is a question for the specific form.
Some forms can address extortion events, and many attach conditions — sublimits, prior consent from the insurer, and required use of named vendors. That is different from saying a ransom payment is covered, which no responsible page can promise in advance. Published federal guidance also does not support paying a ransom as a general response strategy, and paying does not resolve the notification questions either way.
Some policies can address income lost during cyber-caused downtime, and the features vary a great deal — some use a waiting period measured in hours before anything attaches. This is a different trigger from the interruption coverage on a property policy, which generally needs direct physical loss or damage to start.
It depends on the form. Some address events at a third party the business depends on; some exclude them; some require the vendor to be scheduled. Given how much of a small business now runs on other people’s systems, this is one of the more important questions to ask before binding rather than after an outage.
Sometimes, often at a separate and much lower sublimit, and often with conditions about verification procedures the business is expected to follow. It is also an area where crime coverage and cyber coverage overlap and neither may respond the way the business assumed. Ask specifically; do not assume it is included.
Texas law requires an organisation whose breach affects 250 or more Texans to report it to the Texas Attorney General as soon as practicably possible and no later than 30 days after discovery. Affected consumers must also be notified. The 250 figure governs the report to the Attorney General — it does not mean a smaller breach carries no duty, and contracts, regulated-data rules and other states’ laws can each add their own. Whether a particular event meets the statutory definition is a question for legal counsel.
No, and a customer contract asking for both is not being redundant. Cyber answers data, privacy and network-security events. Professional liability answers an allegation that the work or service itself failed and cost a client money. One incident can genuinely raise both — a software defect that also exposes data — which is exactly why the two are often required together.
Moon Insurance Managers, Inc. — 360 FM 1959, Houston, TX 77034 — (281) 484-8320