Published On: September 1, 2026Categories: Business Insurance8.4 min read

The breach that costs a Bethesda accounting firm a six-figure recovery bill usually doesn’t start with a sophisticated attacker. It starts with an employee who clicks a link in what looks like a vendor email.

That’s not a reassuring observation. It’s the structural reality of how cyber incidents actually unfold for small and mid-sized businesses in the DC metro, and it’s worth sitting with — because the insurance market for this risk has shifted considerably in the past few years in ways that catch business owners off guard when a claim arrives.

No current-events headlines arrived in our queue this week, so rather than attach this to a wire story, we want to use the space to walk through what we’re actually seeing when we sit down with small business clients across DC, Maryland, and Virginia who think cyber liability is either covered somewhere in their existing policies or not worth the premium.

Both assumptions, in our experience, tend to be expensive.

Why “I Have a Business Policy” Is Not an Answer

The most common version of this conversation goes something like this: a business owner in Rockville or Arlington has a business owner’s policy, maybe a general liability endorsement, possibly a commercial property policy. They’ve been operating for a decade. They’ve never had a claim. When cyber comes up, they say some version of “I think we’re covered for that.”

General liability covers bodily injury and property damage — meaning physical property. A data breach, a ransomware event, or a business email compromise incident doesn’t produce bodily injury. It produces a compromised client list, a frozen network, a fraudulent wire transfer, and a notification obligation. Standard GL does not step in for any of those.

Commercial property covers physical assets. A server that gets fried in a fire is a property claim. A server that gets encrypted by ransomware while physically sitting undamaged in your closet is a cyber claim. The distinction is precise, and carriers have worked hard to make sure it is.

Some older business owner’s policies, written before cyber exclusions became standard, have ambiguous language that has generated litigation in courts around the country. A few of those cases have gone in the policyholder’s favor. Most haven’t. We would not advise any client to build a risk-management strategy on “maybe a court will see it our way.”

Standalone cyber liability policies exist specifically to cover what everything else excludes: notification costs, credit monitoring for affected individuals, ransomware payments (where legally permissible), business interruption from a network outage, regulatory defense costs, and first-party losses from fraudulent wire instructions. The gap between what a BOP covers and what a cyber policy covers is where the real exposure lives.

The Threat Profile Is Particularly Acute Here

The DC metro area is not a random sample of American small businesses. A disproportionate share of firms here — government contractors, consultants, law firms, healthcare-adjacent practices, nonprofits doing federal grant work — handle sensitive data as part of their core function. That’s not a scare line; it’s a description of the client base.

A boutique consulting firm in Tysons handling federal agency work. A CPA practice in Chevy Chase with years of client tax files. A property management company in Alexandria holding tenant Social Security numbers and payment information. A nonprofit in Cleveland Park processing donor data. None of these are large enterprises. All of them hold data that creates real liability if it’s exposed.

The attackers who target small businesses generally aren’t after the prestige. They’re running volume operations — phishing campaigns, credential stuffing, business email compromise — that succeed precisely because small businesses have fewer technical controls than large ones and less capacity to respond when something goes wrong. The firm in Rockville gets hit not because anyone specifically wanted them; they got hit because a campaign hit everyone, and they were among the ones that didn’t filter it out.

What that means for a claim is that the incident itself is often not the expensive part. Notification is expensive. Depending on the nature of the data and the jurisdictions of affected individuals, the notification obligations can reach across state lines with different timing requirements and content rules. Forensics to determine the scope of exposure is expensive. If the incident is reportable to a regulator — and this is increasingly common in certain industries — defense costs accumulate fast. Most of that sits outside a BOP.

What Cyber Policies Actually Cover, and What They Don’t

This is where the market has gotten complicated in recent years, and where we see the most misunderstanding among clients who do have a cyber policy in place.

Carriers have tightened underwriting requirements significantly. A policy issued a few years ago under more permissive underwriting may have broader coverage than a renewal quote today — or the renewal may have added exclusions that weren’t there before. Multi-factor authentication requirements, for example, have moved from a best-practice recommendation to a hard underwriting condition at many carriers. If a business represents at MFA in place and experiences an incident that turns on whether MFA was actually enabled, that’s a coverage question.

Social engineering — specifically, someone calling your accounts payable person, impersonating a vendor, and convincing them to update banking information — is a meaningful exposure for small businesses, but it’s often a sublimit or a separate insuring agreement within a cyber policy. The main policy limit doesn’t automatically apply. We’ve seen businesses with what looked like adequate cyber coverage discover that their actual recovery for a wire fraud event was capped well below their loss.

Ransomware coverage has become a pressure point in the market. Carriers have responded to a surge in claims by tightening terms, increasing retentions, and in some cases writing explicit sublimits for ransomware events that are lower than the overall policy limit. Business owners who purchased a cyber policy at one limit several years ago and renewed without careful attention may have ransomware coverage that doesn’t match what they think they bought.

Workers’ compensation is not where this gets solved, but it’s worth raising here for a specific reason: when a cyber incident involves a disgruntled employee or an insider threat, employers sometimes assume the workers’ comp framework is relevant. It isn’t. The relevant coverage for an insider threat scenario spans cyber liability for data exposure, crime coverage for theft, and potentially employment practices liability depending on what followed the incident. Those are three different policies.

The Timing Problem We’re Watching

We do want to name something without overstating it. Maryland employers are in the midst of absorbing a significant new payroll-related administrative obligation — the state’s paid family and medical leave program is underway. We’re not going to pretend we’re surprised when business owners in Rockville and Gaithersburg tell us they’ve had a hectic few months getting their payroll processes updated, training HR staff, and communicating changes to employees.

Administrative transitions matter for cyber risk because distraction and system change are exactly the conditions under which human error concentrates. An employee who is processing something unfamiliar, on a new system, under deadline pressure, is more likely to click the wrong thing. That’s not a theoretical observation — it tracks with how incident timelines tend to look when we hear about them from clients after the fact.

We’re not suggesting businesses in Maryland are uniquely vulnerable right now. We’re suggesting that if you’re a small employer who has been heads-down on benefit administration changes and hasn’t looked at your cyber liability coverage in the same review cycle, this is a reasonable moment to put it on the list.

What We’re Actually Watching in the Market

The underwriting environment for small-business cyber has stabilized somewhat after a period of sharp tightening, but the terms are not what they were several years ago, and the coverage questions are more nuanced. We’re watching a few things in particular for clients across DC, Maryland, and Virginia.

Industry-specific regulation is expanding. Healthcare-adjacent businesses, financial services firms, and businesses doing federal contract work face layers of regulatory frameworks that affect what “adequate response to a breach” actually means — and therefore what a meaningful policy needs to fund. That alignment between regulatory obligation and policy scope is something we evaluate on a per-client basis.

The smallest businesses — sole proprietors, two-person shops, boutique practices — are increasingly interesting to cyber carriers as a market segment, which has brought some more accessible products to the table. But accessible doesn’t mean adequate. A low-premium cyber endorsement tacked onto a BOP is not the same as a properly underwritten standalone policy, and the difference shows up in the claims.

If your group benefits structure has recently changed — whether that’s because of Maryland’s new leave program, a staff change, or a vendor transition — and that change involved a new system or a new vendor with system access, that’s worth a conversation with your IT contact about what access was provisioned and whether it was fully cleaned up afterward. Credential hygiene around employee transitions is one of the most consistently underestimated exposure points we see.

A Practical Starting Point

If you run a business in the DC metro and have never done a formal review of what your cyber policy actually covers — meaning a line-by-line look at the insuring agreements, the sublimits, and the conditions — you probably don’t know what you have. That’s not a criticism; most business owners don’t have time to read policy forms for recreation.

What we’d want to know, for any client: Does the policy cover first-party losses (your own costs) as well as third-party liability (claims from affected clients)? What are the sublimits for ransomware, social engineering, and business interruption? What are the security conditions you represented at binding, and are they still accurate? Is there a retention (deductible), and if so, is it per incident or per event?

Those questions don’t require a crisis to be worth answering.

We work with multiple carriers on cyber liability placement for businesses across DC, Maryland, and Virginia — if you want a side-by-side look at where your current coverage sits and what the market looks like right now, that’s a conversation worth having at 301.468.9600 or info@capitalpointins.com.
The Capital Point Insurance Team