📞 240-243-0042 ✉ info@terrapininsurance.com

Cyber insurance for Maryland businesses

Breach response, ransomware and funds transfer fraud coverage for firms that hold other people’s data.

A dental practice in Bethesda, a two-partner law firm in Silver Spring, a biotech startup in a Gaithersburg incubator and an online retailer shipping out of Germantown have one thing in common: each holds data someone else would pay to steal or lock up. Cyber insurance pays for what happens next, from the forensics firm and notification letters to ransom negotiation, lost income while systems are down, and the lawsuit from the client whose records were exposed. General liability covers none of that.

Terrapin Insurance Group places cyber coverage for Montgomery County businesses from our office on Piccard Drive in Rockville. Because so much of the local economy runs on regulated data, with medical practices, federal contractors, life-science firms and professional offices up and down the I-270 corridor, we spend a lot of time on this line. This page explains what a cyber policy does, who needs one, what underwriters ask, and how it differs from the technology E&O many IT firms already carry.

Get a Maryland cyber insurance quote — usually same day. Call 240-243-0042 or request a business insurance quote online.

First-party cyber coverage: breach response, ransomware and lost income

First-party coverage pays your own costs after an incident. It is the part of the policy Maryland small businesses actually use, and the part most often underbought.

Third-party cyber liability: when someone else sues you over a breach

Third-party coverage responds when the people whose data you held, or businesses that relied on your systems, come after you. It pays defense costs, settlements and judgments, plus certain regulatory costs.

For a medical or dental practice that means a patient class action after records are exposed. For a law or accounting firm it means a client whose deal documents or tax returns leaked. For an e-commerce business it means card brands and the payment processor assessing PCI fines and reissuance costs after a checkout-page compromise.

Most policies also cover regulatory investigations and, where insurable, fines and penalties, along with media liability for defamation or copyright claims tied to your website. Third-party and first-party costs usually share a single aggregate limit, so a large breach can exhaust an underpriced policy quickly.

Who needs cyber insurance in Montgomery County

Any business that stores customer, patient or employee information, takes electronic payments, or would lose money if its computers stopped for a week. The firms with the sharpest exposure around Rockville, Bethesda and the I-270 corridor:

Maryland breach notification obligations and why a policy helps you meet them

Maryland has a data-breach notification law, the Maryland Personal Information Protection Act, that governs how businesses protect personal information of Maryland residents and what they must do when it is compromised. We are not your attorney and will not summarize its specific requirements here, but the practical point is this: after a breach you have legal obligations to the people affected and potentially to the state, and determining and meeting those obligations quickly is expensive work.

A well-built cyber policy puts a breach coach, a privacy attorney specializing in incident response, on the phone with you within hours. That attorney determines which state laws apply (customers in DC and Virginia trigger their own rules), what the notification must say and who receives it, and the carrier’s vendor panel executes the mailing, call center and monitoring.

What cyber underwriters ask: MFA, backups, EDR and email security

Cyber applications have become security audits. Carriers know which controls prevent claims and price around them, or decline when they are missing. Know your answers to these before you apply:

If you are weak on one of these, tell us. The fix is often inexpensive, and completing it before the application turns a decline into an approval at a better premium.

Cyber insurance vs. technology E&O: which one does an IT firm need?

Technology companies often ask whether their technology errors and omissions policy already covers cyber. Sometimes partly, rarely fully. Tech E&O responds when your product or service fails and a client suffers financial loss: the software had a bug, the migration went wrong. Cyber responds to security and privacy incidents: data was stolen, systems were encrypted, money was wired to a criminal.

The overlap is real. If a managed service provider’s client is hit with ransomware through the MSP’s tools, the claim is both a professional failure and a security incident. That is why the better technology forms, including those we place with Chubb and Travelers, combine tech E&O, network security liability and first-party cyber in one policy. For a software startup in Rockville a combined form is usually right. For a dental practice or law firm with no technology product, a standalone cyber policy is what you need.

How to get a Maryland cyber insurance quote from Terrapin

  1. Start with the basics. Use the business quote form or call 240-243-0042 with your industry, revenue, headcount, the types of data you hold and roughly how many records.
  2. Complete the security questionnaire honestly. We send a short application covering MFA, backups, EDR and email controls. If a gap would cause a decline, we tell you before submitting so you can fix it first.
  3. Compare and bind. We bring back options from markets such as Chubb and Travelers, explain the ransomware and funds transfer sublimits, confirm the retroactive date, and bind. Many small-business cyber policies are issued within a few business days.

Ready to get covered? Call 240-243-0042 or request a business insurance quote online. Our office is at 1300 Piccard Dr. #201, Rockville, MD 20850.

Common questions

Does a small business in Maryland really need cyber insurance?

If you store customer, patient or employee information electronically, take card payments, or rely on email to move money, yes. The most common claims are not sophisticated hacks; they are a staff member clicking a phishing link, a wire sent to a fraudulent account, or ransomware locking the practice-management system on a Monday morning.

What does cyber insurance not cover?

Common exclusions include bodily injury and property damage (that is general liability), prior known incidents, intentional acts by owners, failure to maintain the security controls you represented on the application, and in some forms losses from regional power or internet outages. Many policies also sublimit funds transfer fraud, social engineering and losses tied to unsupported software.

Does general liability or my BOP cover a data breach?

No. Standard general liability and business owners policies exclude claims arising from disclosure of confidential information and electronic data. Some BOPs offer a small cyber endorsement with a low limit and limited breach services. For a Rockville retailer with a simple point-of-sale system that may be enough; for a medical practice, law firm or anyone with thousands of records it is not.

Does Maryland law require me to notify customers after a breach?

Maryland has a data-breach notification statute, the Maryland Personal Information Protection Act, that sets out obligations for businesses holding personal information of Maryland residents. The specific requirements depend on the data and circumstances, and customers in DC and Virginia bring their own state laws into play. We are not attorneys and will not interpret the statute for you; that is the job of the breach coach your cyber policy provides, who determines what must be sent, to whom and when.

How much cyber coverage should a medical or dental practice carry?

It depends on how many patient records you hold, your revenue, your contracts and your risk tolerance, so we do not give a one-size figure. Think of it this way: estimate notification and monitoring costs across your full patient list, add a realistic ransomware restoration and several weeks of lost production, then consider the lawsuit on top. Many Bethesda and Rockville practices discover their existing limit would not cover notification alone.

Will I be denied cyber insurance if I do not have multi-factor authentication?

Quite possibly, or you will be offered restricted terms with ransomware excluded or sharply sublimited. MFA on email, remote access and administrator accounts is a baseline requirement for most carriers. We regularly tell clients to turn on MFA before we submit the application rather than after a decline, because the result is broader coverage and a better premium.

Is funds transfer fraud covered under cyber insurance or a crime policy?

It can be either, and the distinction trips up many owners. Cyber policies typically cover social engineering and funds transfer fraud as an optional insuring agreement with its own sublimit, often well below the overall policy limit. A commercial crime policy can also cover it, sometimes with higher limits. If wiring money is a regular part of your business, as it is for law firms handling closings and property managers paying vendors, tell us so we can size the sublimit correctly or add crime coverage.

Which carriers does Terrapin use for cyber insurance in Maryland?

For technology, life-science and professional firms with meaningful data exposure, Chubb is a core market with strong breach response services and the ability to combine cyber with tech E&O and management liability. Travelers writes cyber for a broad range of small and mid-size Maryland businesses and can pair it with a commercial package. For unusual risks or firms with prior incidents we access additional carriers through wholesale partners.

Get a Maryland cyber insurance quote — usually same day

Tell us what kind of data you hold and how your systems are protected, and we will bring back cyber options sized to your actual exposure.

Get Your Quote