Cyber insurance is a special insurance policy that covers your business’ losses and liability for intrusions into your business’s computers, computer networks, software, payment processing, and other information technology (cyber events). Cyber events that may be covered by cyber insurance include data breaches, malware, ransomware, viruses, spyware, wire transfer fraud, phishing, denial-of-service (DoS) attacks, Trojans, adware, botnets, man-in-the-middle attacks, credit card web skimming, and others.
In addition to breaching a business’s own valuable information and processes, a data breach may target a business’s sensitive customer information, such as credit card numbers, account numbers, telephone numbers, mailing addresses, passwords, driver’s license numbers, Social Security numbers, health records, and other personally identifiable information (PII).
In Vermont, as in many other states, businesses can purchase cyber insurance to protect against losses and liabilities resulting from cyber events. Cyber insurance policies typically cover a range of incidents, including data breaches, malware, ransomware, and other forms of cyberattacks that compromise a business's information technology systems and sensitive data. The coverage can extend to both the business's own data and customer information, such as credit card details, personal identification numbers, and health records. Vermont businesses seeking cyber insurance should carefully review policy terms to understand the extent of coverage, exclusions, and any requirements for cybersecurity practices that may be a condition of coverage. While Vermont does not have specific statutes mandating cyber insurance, businesses that handle personal information are subject to state laws regarding data security and breach notification. Therefore, cyber insurance can be a critical component of a business's risk management strategy, particularly in light of the Vermont Security Breach Notice Act (9 V.S.A. §§ 2430, 2435), which requires businesses to notify individuals affected by a security breach involving their personal information.