Cyber Liability Insurance in California
California gives you 30 days to notify, 15 to tell the Attorney General, and a private right of action if you got security wrong.
If your business holds California residents' personal information — customer records, employee files, payment data — you are inside one of the strictest privacy regimes in the country, and it got stricter this year.
Cyber liability insurance in California typically runs $500 to $3,000 per year for a small business, with roughly $999–$1,500 common for a $1 million limit and a median around $140 per month. California businesses pay about 20% above the national average, reflecting CCPA/CPRA complexity and active enforcement.
SB 446: the 2026 notification deadlines
Under California Civil Code §1798.82, as amended by SB 446 effective January 1, 2026, a business that discovers a breach must:
- Notify affected California residents within 30 calendar days of discovery
- Notify the California Attorney General within 15 days
Those are hard clocks, and they start at discovery — not at the point you finish investigating. Meeting them requires knowing in advance who your forensics vendor is, who drafts the notice, and who staffs the phones. That readiness is exactly what a cyber policy's incident response component provides, and it is the part of the coverage most worth having.
Notification alone is expensive. For a breach affecting 5,000 people, mailings, call centers and credit monitoring commonly total $75,000 to $150,000 — before any legal exposure.
CCPA penalties and the private right of action
Two distinct exposures:
- Regulatory: CCPA penalties of up to $2,500 per unintentional violation and up to $7,500 per intentional violation. "Per violation" is commonly read per affected consumer, which is what makes the arithmetic serious
- Private right of action: where a business failed to implement reasonable security and a breach follows, California consumers may seek statutory damages of $100 to $750 per consumer per incident, or actual damages if greater — without having to prove individual harm
A 5,000-record breach at the low end of that statutory range is $500,000 of exposure. This is why cyber is no longer an optional line for a California business holding consumer data.
What a cyber policy actually covers
- Incident response: forensics, legal counsel, notification, credit monitoring, PR. The operationally valuable part
- Regulatory defense and fines where insurable by law
- Third-party liability: claims from customers and partners
- Business interruption: lost income while systems are down
- Ransomware / extortion: subject to carrier conditions, which have tightened
- Social engineering / funds transfer fraud: frequently a sub-limit, and frequently the claim that actually happens to a small business. Check that number specifically
Underwriters now expect basic controls — MFA, backups, endpoint protection, patching. Having them improves both eligibility and price, so do them before you shop rather than after.
Who needs it in California
Any business holding personal data: professional services with client files, medical and dental offices, retail taking payments, property managers, and any employer holding SSNs and payroll records — which is every employer.
Cyber is not included in a business owners policy and is not covered by general liability. It pairs naturally with EPLI, since an employee-data breach can trigger both.
How much is cyber liability insurance in California?
Typically $500–$3,000 per year for a small business, with $999–$1,500 common for a $1 million limit and a median around $140 per month. California runs about 20% above the national average because of CCPA/CPRA complexity and enforcement activity.
How fast must I report a data breach in California?
Under Civil Code §1798.82 as amended by SB 446, effective January 1, 2026: affected California residents within 30 calendar days of discovery, and the Attorney General within 15 days.
What are the penalties under the CCPA?
Up to $2,500 per unintentional violation and $7,500 per intentional violation. Separately, consumers may seek statutory damages of $100–$750 per consumer per incident where a business failed to implement reasonable security and a breach occurred.
Does my business owners policy cover a data breach?
No. A BOP covers property, general liability and business interruption. Cyber liability is a separate policy, and general liability does not respond to data breach claims.
What do underwriters require before they will quote cyber?
Most now expect multi-factor authentication, tested backups, endpoint protection and a patching process. Having these in place before you apply improves both your eligibility and your premium.
Related pages
Small Business Insurance
The full program.
Learn more →Business Owners Policy
What a BOP leaves out.
Learn more →EPLI
Employee claims and employee data.
Learn more →General Liability
Why GL does not cover breaches.
Learn more →This page is general information for California consumers, not legal, tax, or financial advice, and not an offer of coverage. Rates, rules, and carrier appetite change frequently — figures shown are typical ranges as of mid-2026 from public sources. Your own premium and eligibility depend on your specific situation. Confirm current requirements with the [California Department of Insurance](https://www.insurance.ca.gov/) or talk to a licensed agent. Express Financial & Insurance Services, Inc. is an independent brokerage in Santa Monica, CA — call 310-453-5736 for a no-obligation review.