Commercial guide

Cyber and Professional Liability for California Businesses

Protect against data incidents, technology failures, and claims that professional services caused financial harm.

Written and reviewed by Abraham Nunez-ChavezCalifornia Insurance Agent/Broker · Lic. No. 4357305

What to know first

  • GL generally does not replace cyber or professional liability.
  • Cyber coverage can include response costs, notification, restoration, extortion, and liability.
  • Professional liability is usually written on a claims-made basis.

California limits and common starting points

$1 million is a common starting point for small-business cyber or professional liability. Revenue, records, contract requirements, regulated data, and potential client loss may justify higher limits.

These are educational benchmarks, not a recommendation for every applicant.

Cyber coverage can address incident response, forensic investigation, notification, credit monitoring, data restoration, business interruption, extortion, fraud, regulatory matters, and third-party liability, subject to the form.

Professional liability or errors and omissions coverage can address claims that advice, design, technology, or professional services caused financial loss. The retroactive date and continuous coverage are critical on claims-made policies.

Review contracts, revenue, largest-client exposure, record count, payment processes, remote access, backups, multifactor authentication, vendor dependencies, and professional services. Limits should reflect a credible severe event—not only the smallest contract.

Official California resources

California Cybersecurity Integration Center resourcesCDI Commercial Insurance guide
Important: This information is educational and does not modify any policy. Coverage is subject to eligibility, underwriting, policy terms, conditions, limitations, and exclusions. Laws, programs, limits, and carrier rules can change. Actual policy language and current official requirements control.