Your General Liability Policy Will Not Pay for a Cyber Loss

Ask a contractor whether cyber crime is a real threat to the business and you usually get the same answer. We pour concrete. We frame houses. We do not store credit card numbers. Hackers have nothing to take from us. That answer was wrong five years ago and it is dangerous now. Construction is one of the most targeted industries in the country, and the reason has nothing to do with anyone wanting your blueprints. It is that construction firms move large sums of money on predictable schedules, run lean back offices, share email threads with dozens of outside parties on every project, and depend on software that ties the field to the office to the bank. A general contractor releasing a four hundred thousand dollar draw on the fifteenth of the month is an easier and more profitable target than a bank with a full security team. Criminals are not breaking through firewalls to get to you. They are sitting quietly in an email account, waiting for the right invoice to come through, and then asking someone in accounting to update the wire instructions. The industry spent the last decade adding technology to the jobsite and spent almost none of it adding controls around that technology.


The losses look nothing like what most owners picture. The most common one in this industry is funds transfer fraud. A criminal compromises an email account belonging to you, your subcontractor, your architect, or your title company. They watch the thread for weeks. When a legitimate payment is about to move, they send a message from the real account, or from a lookalike domain that is off by one character, with new banking details and a plausible reason for the change. The money leaves, the wire clears, and by the time anyone catches it the funds have been moved through three accounts overseas. The second most common is ransomware. Your estimating files, your project management platform, your accounting system, your submittals and RFIs and daily reports all go dark at once. Crews show up and nobody can pull a drawing set or process payroll. Every day of downtime carries liquidated damages exposure on top of the direct cost. Then there is the exposure people forget entirely, which is data. You hold employee Social Security numbers, I-9s, workers compensation claim files, driver information, banking details for direct deposit, and increasingly homeowner or tenant information on residential and tenant improvement work. If that gets out, you own the notification obligation, the credit monitoring, the regulatory response, and the lawsuits.


Here is where the coverage conversation goes wrong. Most contractors assume the commercial general liability policy handles it, because the CGL handles almost everything else. It does not. Coverage A responds to bodily injury and property damage, and property damage is defined as physical injury to tangible property. Standard ISO language states plainly that electronic data is not tangible property. A ransomware attack that destroys your project files is not a covered loss because nothing physical was damaged. Coverage B covers personal and advertising injury, and while that grant historically included publication that violates a right of privacy, ISO has issued endorsements that strip access to or disclosure of confidential information out of both coverage parts. Most CGL policies written today carry that exclusion. Builders risk covers the structure under construction. Inland marine covers tools and equipment in transit. Neither one covers stolen money, corrupted data, or a shut down network. Your crime policy may cover employee dishonesty and forgery, but a standard crime form frequently will not respond to a voluntary transfer made by an authorized employee who was tricked, which is exactly how social engineering works. The result is that a contractor with a complete and well built insurance program can still take a total loss on the most likely cyber event they will ever face.


Cyber insurance closes that gap, and a properly structured policy does more than write a check after the fact. The first party side covers what happens to you. That includes forensic investigation to find out what was taken, legal counsel to determine your notification obligations, notification and credit monitoring costs, data restoration, business interruption for lost income during the outage, extra expense to keep working, and cyber extortion including ransom payments where legally permitted. The third party side covers what you owe everyone else. That includes privacy liability, network security liability when your systems are used to attack someone downstream, defense costs, and regulatory fines and penalties where insurable. Social engineering and funds transfer fraud coverage is the piece that matters most for contractors, and it is usually an endorsement with its own sublimit rather than something included at the full policy limit. Read that sublimit carefully. A five million dollar cyber policy with a fifty thousand dollar social engineering sublimit does not protect you from the loss you are actually most likely to suffer. Contingent business interruption is worth asking about as well, since it responds when a vendor or software provider you depend on gets hit instead of you.


The market has also changed who gets to buy coverage and at what price. Underwriters now ask real questions before they quote. They want to know whether you have multifactor authentication on email and remote access, whether backups are segmented and tested, whether you run endpoint detection, whether you train employees on phishing, and whether you have a written procedure requiring verbal callback verification on any change to payment instructions. That last control costs nothing and stops the majority of wire fraud attempts. Firms with those controls in place get better pricing and broader terms. Firms without them get declined or get a policy full of coinsurance and sublimits. Contract language is pushing the same direction. General contractors, project owners, public entities, and lenders are writing cyber requirements into agreements the same way they wrote in additional insured and waiver of subrogation requirements twenty years ago. If you bid work with a cyber limit requirement and cannot produce a certificate, you do not bid the work. For most small and mid sized contractors, a one million dollar cyber policy costs a fraction of what the general liability costs, and it is the only policy on the schedule that responds to the event most likely to actually happen.

Let’s Find the Gap Before Someone Else Does

Eagle National Insurance Group works with contractors and commercial businesses across Oklahoma, Texas, Missouri, and Arkansas. We are 100 percent independent, which means we shop your risk across the market instead of defending one carrier’s appetite.

Send us your current general liability and crime policies and we will show you in writing exactly where your cyber exposure sits uncovered, what a policy would cost, and which controls will get you the best terms. No obligation and no pressure.

Eagle National Insurance Group, Inc. 20 E 5th St, Suite 1203, Tulsa, OK 918-213-4443 enatinsurance.com

Want to compare your options?

Click the button below to head to our quotes page where you can enter some basic information to have our team help with your insurance!

Ready to get started?

Start Your Quotes Today

Enter some basic information below to get the process started.

Service Options

Call Email Claims Payments