Many business owners ask a simple question: Is cyber liability insurance required by law?Learn whether any state requires cyber insurance, when contracts require it, and what businesses should know. The short answer is generally no.
There is no broad federal law requiring every U.S. business to purchase cyber liability insurance. Similarly, cyber liability insurance is generally not a blanket requirement imposed on every business by any state. However, the answer can become more complicated depending on the business’s industry, contracts, customers, government relationships, licensing requirements, and regulatory obligations.
A company may not be legally required to carry cyber insurance, but it may still be effectively required to purchase coverage to do business with certain customers or organizations.
Is Cyber Liability Insurance Required by Law in the United States?
For most ordinary businesses, cyber liability insurance is not legally mandatory.
Businesses are generally not required to purchase cyber insurance simply because they:
- Operate a website
- Accept online payments
- Store customer information
- Have employees
- Use cloud software
- Maintain an email system
- Conduct business online
- Collect personal information
However, businesses may have legal obligations relating to cybersecurity, privacy, data protection, and breach notification.
These obligations are different from an insurance mandate.
For example, a state may require a business to take reasonable steps to protect personal information or notify affected individuals following a data breach. That does not necessarily mean the business must purchase a cyber liability insurance policy.
This distinction is critical:
Cybersecurity laws generally regulate what a business must do to protect information. Cyber insurance protects the business financially when a cyber incident creates covered losses and expenses.
Is Cyber Liability Insurance Required in Any State?
Based on a review of state cybersecurity and insurance requirements, there is no general state-level requirement that every ordinary business purchase cyber liability insurance.
Instead, state laws typically focus on areas such as:
- Data security
- Consumer privacy
- Breach notification
- Cybersecurity programs
- Protection of nonpublic information
- Cybersecurity risk assessments
- Incident response
- Regulatory reporting
The laws differ substantially from state to state.
For example, New York’s Department of Financial Services Cybersecurity Regulation, 23 NYCRR Part 500, imposes cybersecurity requirements on covered financial-services organizations. The regulation requires covered entities to maintain a cybersecurity program and implement specified cybersecurity controls. It is not a general law requiring every New York business to purchase cyber liability insurance. (Department of Financial Services)
Florida’s data-breach law similarly establishes obligations relating to the security of personal information and breach notification. It does not generally require every Florida business to buy cyber liability insurance. (Florida Legislature)
California imposes extensive data privacy and breach-related obligations on businesses. These requirements do not create a general mandate that all businesses purchase cyber liability insurance. (California Legislative Information)
50-State Overview: Cyber Insurance Requirements
For practical purposes, businesses can generally think about state requirements in three categories.
Category 1: States With No General Cyber Insurance Mandate for Ordinary Businesses
The general rule across the United States is that ordinary businesses are not required by state law to purchase cyber liability insurance solely because they operate a business or handle electronic information.
This includes major commercial states such as:
- New York
- Florida
- California
- Texas
- New Jersey
- Pennsylvania
- Illinois
- Georgia
- Massachusetts
- Virginia
- Washington
- Colorado
- Arizona
- North Carolina
- Ohio
- Michigan
- Minnesota
- Tennessee
- Maryland
- Connecticut
- Oregon
The same general principle applies throughout the remaining states: cybersecurity and privacy obligations do not automatically create a requirement to purchase a cyber insurance policy.
However, a business should not interpret this as meaning that cyber insurance is unnecessary or that no specific requirement can apply to it.
Category 2: States With Cybersecurity Requirements for Certain Regulated Industries
Some states impose cybersecurity requirements on specific regulated entities.
These may include:
- Banks
- Insurance companies
- Financial institutions
- Healthcare organizations
- Investment firms
- Licensed professionals
- Government contractors
- Organizations that maintain sensitive personal information
New York is a prominent example. The New York Department of Financial Services regulates covered financial-services organizations under 23 NYCRR Part 500. The regulation requires covered entities to assess cybersecurity risks and maintain a cybersecurity program. (Department of Financial Services)
Connecticut also has laws governing cybersecurity and information security obligations for certain regulated entities and businesses. Its insurance data security framework, for example, addresses cybersecurity events and the protection of nonpublic information held by insurance licensees. (Connecticut General Assembly)
These laws may require cybersecurity controls, written policies, risk assessments, employee training, incident response procedures, or other safeguards.
They do not necessarily require cyber liability insurance.
Category 3: Businesses That Must Purchase Cyber Insurance Because of a Contract
This is where cyber insurance becomes practically mandatory for many businesses.
A company may be required to maintain cyber liability insurance under a contract with:
Customers
Large companies frequently require vendors and contractors to carry cyber insurance before signing a contract.
A customer may require:
- $1 million of cyber liability insurance
- $2 million or more in limits
- Specific privacy liability coverage
- Network security liability coverage
- Technology errors and omissions coverage
- Breach response coverage
- Ransomware or cyber extortion coverage
The requirement may appear in a master services agreement, vendor contract, procurement agreement, or cybersecurity addendum.
Government Contracts
Government agencies may require contractors to maintain specific insurance policies as part of a procurement agreement.
The requirement can vary depending on:
- The government agency
- The type of work
- The sensitivity of the data
- The contract value
- The information systems involved
- Federal or state cybersecurity requirements
A business may therefore need cyber insurance to qualify for a contract even though the state does not generally require every business to purchase it.
Healthcare Organizations
Healthcare providers and their vendors frequently handle sensitive medical and personal information.
A hospital, health system, physician group, or healthcare technology company may require a vendor to carry cyber liability insurance as a condition of doing business.
The contractual requirement may be especially important for companies that:
- Store protected health information
- Provide software to healthcare organizations
- Process medical billing
- Provide cloud hosting
- Handle patient data
- Provide information technology services
Financial Institutions
Banks, credit unions, investment firms, and other financial institutions may require vendors to maintain cyber insurance.
A financial institution may require coverage from:
- Technology vendors
- Payment processors
- Managed service providers
- Cloud service providers
- Consultants
- Software companies
These requirements are often part of a vendor risk-management program.
Does a Data-Breach Law Require Cyber Insurance?
Generally, no.
Every state has laws addressing data security or data breaches, although the specific requirements differ.
A data-breach law may require a business to:
- Investigate a suspected breach
- Determine whether personal information was accessed
- Notify affected individuals
- Notify regulators
- Provide credit monitoring or identity theft services in certain situations
- Cooperate with law enforcement
- Maintain reasonable security procedures
These activities can be extremely expensive.
Cyber liability insurance may help cover certain expenses, depending on the policy wording and circumstances of the incident.
Potential covered expenses may include:
- Forensic investigation
- Legal counsel
- Notification costs
- Public relations services
- Credit monitoring
- Regulatory defense
- Regulatory investigations
- Cyber extortion response
- Data restoration
- Business interruption losses
- Network security liability claims
- Privacy liability claims
Coverage varies significantly between policies.
Does New York Require Cyber Liability Insurance?
For most New York businesses, no.
New York has some of the country’s most significant cybersecurity requirements for certain regulated financial-services organizations.
The New York Department of Financial Services Cybersecurity Regulation, known as 23 NYCRR Part 500, requires covered entities to maintain cybersecurity programs and implement cybersecurity protections. The regulation is aimed at cybersecurity risk management and does not generally require every business in New York to purchase cyber liability insurance. (Department of Financial Services)
However, a New York business may still need cyber insurance if:
- A customer requires it
- A contract requires it
- A lender requires it
- A government contract requires it
- A vendor agreement requires it
- A professional-services client requires it
For New York business owners, the question is therefore not simply:
“Is cyber insurance required by New York law?”
The more practical question is:
“Do my contracts, customers, industry regulations, or business partners require me to carry cyber insurance?”
Does Florida Require Cyber Liability Insurance?
For most Florida businesses, no.
Florida has laws governing the security of personal information and data-breach notification. The Florida Information Protection Act establishes requirements relating to breaches involving personal information. It does not generally require every private business to purchase cyber liability insurance. (Florida Legislature)
Nevertheless, a Florida business may be contractually required to carry cyber insurance by a customer, vendor, lender, or other business partner.
What About California?
California is one of the nation’s most heavily regulated states when it comes to privacy and consumer data.
California law includes requirements relating to data breaches and the protection of personal information. For example, California law requires certain businesses that own or license computerized data containing personal information to provide notice following qualifying security breaches. (California Legislative Information)
However, these obligations do not create a general requirement for every California business to purchase cyber liability insurance.
A California company may still need coverage because of:
- Customer contracts
- Vendor agreements
- Industry requirements
- Government contracts
- Professional obligations
- Risk-management requirements imposed by a business partner
Cyber Insurance Versus Cybersecurity Compliance
These are two separate concepts.
Cybersecurity compliance
Cybersecurity compliance generally involves:
- Password security
- Multi-factor authentication
- Access controls
- Encryption
- Security policies
- Employee training
- Incident response
- Risk assessments
- Vendor management
Cyber liability insurance
Cyber insurance is designed to transfer certain financial risks to an insurance company.
Depending on the policy, coverage may address:
- First-party losses suffered by the insured business
- Third-party liability claims
- Data breach response costs
- Business interruption
- Cybercrime
- Social engineering fraud
- Ransomware
- Regulatory defense
A company can be compliant with applicable cybersecurity laws and still suffer a cyberattack.
Likewise, a company can carry cyber insurance and still fail to comply with cybersecurity laws.
Insurance does not replace cybersecurity.
Can a Contract Make Cyber Insurance “Mandatory”?
Yes.
This is one of the most important points for business owners.
Suppose no state law requires a small technology company to carry cyber insurance.
The company then applies to become a vendor for a large corporation.
The corporation’s vendor agreement requires:
“Cyber liability insurance with limits of not less than $1 million per occurrence.”
The company now has a practical requirement to purchase the coverage if it wants to sign the contract.
The government did not directly require the insurance.
The customer’s contract did.
This is why cyber insurance can be effectively mandatory even when no statute requires it.
Which Businesses Should Consider Cyber Liability Insurance?
Although not generally mandatory by law, cyber liability insurance may be especially important for businesses that:
- Store customer information
- Accept credit cards
- Maintain employee information
- Use cloud-based software
- Operate online stores
- Provide technology services
- Manage websites or networks
- Handle healthcare information
- Process financial information
- Provide professional services
- Store confidential client files
Small businesses are not immune from cyberattacks.
In fact, a small business may face serious financial consequences from a single incident because it may lack the financial resources of a large corporation.
A cyber incident can create costs even when the business did not intentionally do anything wrong.
For example, a business may face expenses associated with:
- Investigating the incident
- Hiring attorneys
- Determining whether data was compromised
- Notifying affected individuals
- Responding to regulators
- Restoring computer systems
- Recovering lost data
- Replacing compromised equipment
- Responding to ransomware
- Defending liability claims
The availability of coverage depends on the specific policy.
What Should Businesses Check Before Buying Cyber Insurance?
Businesses should not simply purchase the cheapest cyber policy available.
Before buying coverage, business owners should review:
Coverage limits
How much coverage is available for a single claim and during the policy period?
Retentions
How much must the business pay before insurance responds?
Business interruption coverage
Does the policy cover lost income caused by a covered cyber incident?
Social engineering coverage
Does the policy cover fraudulent instructions that cause an employee to transfer money?
Ransomware coverage
Does the policy provide coverage for cyber extortion and related response expenses?
Regulatory coverage
Does the policy cover defense costs or fines and penalties where legally insurable?
Vendor and cloud-provider incidents
Does coverage respond when an incident occurs through a third-party service provider?
Required cybersecurity controls
Some insurers require businesses to maintain specific controls, such as:
- Multi-factor authentication
- Endpoint detection and response
- Backups
- Email security
- Password controls
- Employee training
Failure to accurately complete an insurance application or maintain required security controls can create coverage problems.
Frequently Asked Questions
Is cyber liability insurance required by federal law?
Generally, no. There is no broad federal law requiring every U.S. business to purchase cyber liability insurance.
Is cyber insurance required in New York?
Generally, no. New York requires certain regulated organizations to maintain cybersecurity programs, but cyber insurance is not generally mandatory for every business. (Department of Financial Services)
Is cyber insurance required in Florida?
Generally, no. Florida has data-security and breach-notification requirements, but there is no general requirement for every private business to purchase cyber liability insurance. (Florida Legislature)
Is cyber insurance required in California?
Generally, no. California imposes significant privacy and data-security obligations, but those laws do not generally require every business to purchase cyber insurance. (California Legislative Information)
Can a customer require my business to carry cyber insurance?
Yes. A contract can require a business to maintain cyber liability insurance as a condition of doing business.
Does cybersecurity compliance replace cyber insurance?
No. Cybersecurity controls and insurance serve different purposes. Security controls help reduce the likelihood and severity of an incident. Insurance may help transfer certain financial risks.
The Bottom Line
Cyber liability insurance is generally not mandatory for ordinary businesses under U.S. federal or state law.
However, a business may still be required to purchase cyber insurance because of:
- A customer contract
- A government contract
- A vendor agreement
- A lender requirement
- An industry-specific relationship
- A licensing or contractual obligation
State cybersecurity and privacy laws should also not be confused with insurance requirements. A state may require a business to implement cybersecurity controls or notify individuals following a data breach without requiring the business to purchase cyber insurance.
For business owners, the most accurate answer is:
Cyber liability insurance is generally not required by law for every business, but it may be required by contract and can be an important part of a business’s overall risk-management strategy.
Because insurance requirements and cybersecurity regulations can change, businesses should review their contracts, applicable industry regulations, and current state laws with qualified insurance and legal professionals before concluding that coverage is or is not required.











