Cyber insurance is a special insurance policy that covers your business’ losses and liability for intrusions into your business’s computers, computer networks, software, payment processing, and other information technology (cyber events). Cyber events that may be covered by cyber insurance include data breaches, malware, ransomware, viruses, spyware, wire transfer fraud, phishing, denial-of-service (DoS) attacks, Trojans, adware, botnets, man-in-the-middle attacks, credit card web skimming, and others.
In addition to breaching a business’s own valuable information and processes, a data breach may target a business’s sensitive customer information, such as credit card numbers, account numbers, telephone numbers, mailing addresses, passwords, driver’s license numbers, Social Security numbers, health records, and other personally identifiable information (PII).
In Nebraska, as in many states, there is no specific regulation that mandates businesses to obtain cyber insurance. However, given the increasing prevalence of cyber threats, many businesses opt to purchase cyber insurance policies to mitigate the financial risks associated with cyber events. These policies typically cover expenses and liabilities resulting from data breaches, malware, ransomware, and other cyber incidents that compromise a business's or customers' sensitive information. The coverage can include costs related to investigation, data recovery, legal fees, settlements, and regulatory fines. Nebraska businesses that handle personally identifiable information (PII) are subject to the Nebraska Personal Information Protection Act (PIPA), which requires them to implement reasonable security measures to protect PII and to notify affected individuals in case of a data breach. While PIPA does not require cyber insurance, having such a policy can be beneficial in meeting the financial obligations imposed by a breach. It's advisable for businesses to consult with an attorney to understand the scope of coverage needed based on their specific risk profile and to ensure compliance with applicable state and federal regulations.