Cyber Liability Insurance in California
A policy-review guide and a precise explanation of California's 2026 breach-notice rules.
Cyber insurance can combine first-party coverage for the insured business's response costs with third-party coverage for claims against the business. Forms vary materially, so a policy name or headline limit does not establish what a particular incident will cover. The Federal Trade Commission's cyber-insurance guide recommends comparing both kinds of coverage and reading the response, defense, vendor, and territorial terms.
What SB 446 actually requires
California SB 446 amended Civil Code section 1798.82. For an individual or business within that section that owns or licenses covered computerized personal information, the current text requires resident disclosure within 30 calendar days after discovery or notification of the breach. The statute permits delay for legitimate law-enforcement needs or as necessary to determine the breach's scope and restore the reasonable integrity of the data system. A business that only maintains data it does not own has a separate duty to notify the owner or licensee immediately after discovery when the statutory conditions are met.
The Attorney General rule is different from the resident-notice rule. If one breach requires notice to more than 500 California residents, the business must electronically submit one sample consumer notice to the Attorney General within 15 calendar days after notifying affected consumers. It is not a 15-day-from-discovery deadline. Read the enrolled SB 446 text and the Attorney General's breach-reporting instructions.
Coverage to compare, not assume
- Breach response — Review whether the form addresses forensic investigation, legal counsel, required notices, call-center services, credit monitoring, and crisis communications.
- Data and systems — Confirm whose data is covered, whether incidents at cloud or other vendors qualify, and how the policy treats restoration of data and systems.
- Business interruption — Check the triggering event, waiting period, measurement method, maximum period, and whether a vendor outage can qualify.
- Cybercrime and extortion — Review definitions, sublimits, authorization requirements, exclusions, and any required insurer consent before funds are transferred or paid.
- Third-party and regulatory matters — Check defense wording, covered claims and proceedings, limits, retentions, and whether fines or penalties are covered only where legally insurable.
The FTC describes these as common areas to consider, not guaranteed coverage. The NAIC notes that cyber forms are highly customized, and that most commercial property and general-liability policies do not cover cyber risks. The issued policy controls.
Information to prepare for a policy review
- The kinds and approximate volume of personal, payment, health, employee, and confidential business data you hold.
- The systems and outside vendors that store, process, back up, or can access that data.
- Current safeguards, including multi-factor authentication, access controls, software updates, backups, staff training, and an incident-response plan.
- Prior incidents, known circumstances, and the retroactive dates on any existing policy.
- The first-party, third-party, cybercrime, dependent-business, and social-engineering limits and sublimits you want compared.
- The response vendors you may use, when insurer consent is required, and whom to call before incurring costs.
Security controls reduce operational risk whether or not a policy is purchased. The FTC small-business cybersecurity guide recommends data inventories, multi-factor authentication, updates, backups, access controls, training, and tested response and continuity plans.
Did SB 446 create a 15-day deadline from discovery to notify the Attorney General?
No. The 30-day resident-disclosure rule runs from discovery or notification, subject to the statute's permitted delays. The 15-day Attorney General rule applies after consumer notice and only when a single breach requires notice to more than 500 California residents.
Does cyber insurance make a business compliant with California privacy law?
No. Insurance can fund only covered costs and services under the issued form. Compliance duties remain with the business, and breach counsel should assess the facts and applicable law.
Does a BOP or general-liability policy automatically cover a data breach?
Do not assume it does. The NAIC says most commercial property and general-liability policies do not cover cyber risks. Review the actual forms, endorsements, and exclusions.
What is the difference between first-party and third-party cyber coverage?
First-party coverage may address the insured business's own response and recovery costs. Third-party coverage may address covered claims brought against the business. Limits, retentions, exclusions, and triggers vary by form.
Related business-insurance guides
Small Business Insurance
Build a coverage inventory around the operation you actually run.
Read the guide →Business Owners Policy
Understand the core property and liability package before adding specialized coverage.
Read the guide →General Liability
Compare general liability's purpose and boundaries with cyber coverage.
Read the guide →Reviewed August 11, 2026. General insurance and statutory information only; not legal advice, incident-response advice, or an offer or guarantee of coverage. Civil Code section 1798.82 has defined scope and fact-dependent duties. The issued policy and current law control. Consult qualified breach counsel promptly after a suspected incident.
For a coverage review: Describe your data, systems, vendors, current security controls, and the policy forms or proposals you want compared. Do not include passwords, account credentials, or breach evidence in the website form.