Two sides of the coverage
First-party coverage pays your own costs: forensic investigation, data restoration, business interruption, ransomware negotiation and payment where lawful, notification to affected people, and credit monitoring. Third-party coverage responds to claims against you — a customer whose data was exposed, a vendor whose systems you infected, regulatory proceedings. Most small-business policies include both; check the sub-limits.
Funds transfer fraud and social engineering
The most common small-business loss is money sent to a criminal who impersonated a customer, vendor or executive. This is “social engineering” or “funds transfer fraud” coverage, and it is often a lower sub-limit or an optional add-on. If your business moves money on instruction — a law office, a title company, a contractor paying suppliers — make sure this limit is meaningful.
What carriers require now
Expect questions about multi-factor authentication on email and remote access, backups that are tested and kept offline or immutable, endpoint protection, and staff training. Some carriers will not quote without MFA. The controls are not just underwriting — they are the reason the loss stays small.
Who needs it
Anyone who stores customer information, takes card payments, uses email to move money, or would lose revenue if their systems were locked. That is every professional office, medical and dental practice, retailer and contractor with a laptop. Limits of $250,000 to $1,000,000 are common for small businesses; the price is usually modest relative to the exposure.
This guide is general information about insurance in Michigan, not advice about a specific policy. Coverage depends on the policy’s terms, limits, exclusions and eligibility, and a request does not bind or change insurance.