Cyber Liability Insurance in Northwest Arkansas | Cribb Insurance
Cyber Liability · Northwest Arkansas

The breach is the incident. The notification is the bill.

Arkansas law requires you to notify affected people without unreasonable delay, and to notify the Attorney General once a breach reaches more than 1,000 individuals. Even deciding not to notify creates a written determination you must keep for five years. Cyber insurance funds the response that produces all of that — forensics, breach counsel, notification, restoration, lost income. But two things decide whether it responds: who you call first, and what you put on the application. We shop it across 40+ carriers.

The short answer

Cyber insurance pays your own costs after an incident — forensics, breach counsel, restoration, ransomware response, notification, lost income — and defends claims brought when someone else's data is affected. What owners undervalue isn't the money: it's the vetted response team the carrier already has on retainer. Two things decide whether it works. Call the carrier's hotline before hiring anyone, because most policies have consent requirements. And answer the application accurately — those questions about MFA and backups are part of the basis the policy was issued on.

The part worth knowing

The most expensive words in a cyber claim: "we handled it ourselves."

One phone call before anything else costs money

Most cyber policies carry consent requirements. Spend incurred before you notify the carrier may not be covered — even when the spend was entirely sensible.

Why the hotline comes before the IT firm and before the lawyer.

The instinct after discovering an attack is to fix it: call your IT provider, call your own attorney, maybe open a channel with whoever is demanding money. All three of those can land outside coverage if the carrier wasn't consulted first, because the policy is written around a panel of vetted vendors and a consent process.

There's a better reason than coverage, though. The carrier's panel does this work constantly — breach counsel who know what your state statute requires, forensic teams who can tell you what was actually taken rather than what might have been. The decisions made in the first forty-eight hours shape your legal obligations, your recovery time and the final cost of the claim.

1Call the hotlineBefore hiring vendors, before negotiating, before promising anyone notification.
2Contain itForensics identify affected systems, compromised accounts and the entry point.
3RestoreSystems, files and backups assessed so operations can resume safely.
4Legal dutiesBreach counsel works out what notification, privacy and contract obligations apply.
5RecoverResponse costs, restoration and lost income documented for the claim.

One more thing worth doing before you ever need it: make sure the hotline number is somewhere that isn't your email. If the compromise is the email system, a policy document stored in it is a policy document you can't reach.

Arkansas rules

What Arkansas actually requires after a breach.

This is the part most cyber pages skip, and it's the part that generates the cost. The Arkansas Personal Information Protection ActArk. Code § 4-110-101 and following, amended by Act 1030 of 2019 — does two separate things.

First, it imposes an affirmative duty. Businesses holding personal information about Arkansas residents must implement and maintain reasonable security procedures and practices to protect it. That obligation exists before anything goes wrong; it isn't only a reporting statute.

Second, it sets out what happens after a breach of computerized personal information:

No fixed deadlineNotice to individuals must be made in the most expedient time and manner possible and without unreasonable delay — Arkansas doesn't set a day count.
1,000+ individualsMust also notify the Arkansas Attorney General — at the same time as individuals, or within 45 days of determining a reasonable likelihood of harm, whichever comes first.
Data you don't ownIf you hold computerized personal information belonging to another business, notify the owner or licensee immediately on discovery.
Law enforcementNotice may be delayed where law enforcement determines it would impede a criminal investigation.

Two scope points that matter. The statute covers computerized data — paper records sit outside it. And "personal information" means a name combined with specified data elements where neither is encrypted or redacted, which is a genuine reason encryption is worth the trouble.

Deciding not to notify is a formal step, not the end of it.

This is the least-known consequence in the statute, and it catches businesses that thought a quiet incident was over. Where a reasonable investigation determines notification isn't required, you must retain a written determination of the breach along with supporting documentation for five years from the date of that determination. The Attorney General may request it, and you then have 30 days to hand over the determination and the documentation. The determination itself is confidential and not subject to public disclosure.

So the small incident you investigated and closed still leaves you with a file to build and keep. And producing that file properly — the investigation, the reasoning, the documentation that stands up if it's ever requested — is precisely the work breach counsel does, and breach counsel is one of the things the policy pays for. Handling it alone can leave you with the obligation and none of the paperwork.

A breach rarely stays in one state.

This is the difference between cyber and every other line on this site. A fire happens in one building. A data breach happens wherever your customers live. If your records include residents of more than one state, you're looking at more than one notification statute at once — and Oklahoma, Missouri and Texas each set their own thresholds, deadlines and regulator-notice rules, which differ from Arkansas's. Cribb is licensed in all four, and this is one of the few coverages where the multi-state question is the norm rather than the exception.

Other regimes can stack on top too. HIPAA, GLBA, payment-card rules and your own customer contracts may impose obligations independent of state law, and none of those are described on this page. Working out which apply to a specific incident is legal work.

Everything above is a general summary, not legal advice, and not a determination of what any statute requires of your business in any particular situation. Confirm your obligations with the Arkansas Attorney General and with qualified counsel. For the coverage side — (479) 286-1066.

Underwriting

The application is part of the policy.

This is the most common way a business that bought cyber insurance ends up without the protection it thought it had. Cyber applications ask narrow, specific questions — and the answers form part of the basis the policy was issued on.

Ask "on what, exactly"

Multifactor authentication

Carriers ask whether MFA protects email, remote access and administrator accounts — and those are three separate questions. "We have MFA" is rarely a complete answer, and the gap between the three is where claims get examined.

"Tested" means restored

Isolated, tested backups

A backup reachable with the same credentials an attacker steals isn't a backup. And "tested" means someone has actually restored from it — not that the job reports success. Ransomware negotiations turn on this single fact.

Cheapest control there is

Callback verification

An independent phone call to a known number before acting on any change to banking or payment instructions. Some carriers require it as a condition of social-engineering coverage. It defeats most wire fraud on its own.

Documented, not informal

Phishing training

Simulations and password practice, with records. Underwriters increasingly want to know that it happens on a schedule rather than that it happened once.

Known holes get exploited

Patching & endpoint protection

Timely updates and monitored endpoint protection. Most successful intrusions use a vulnerability that had a fix available — which is exactly why underwriters ask about the process rather than the product.

Where the hotline lives

A written response plan

Who to call, what to disconnect, where the policy number is. Stored somewhere that survives the systems going down — printed, or somewhere outside the network.

Fill in the application with the person who runs your systems.

Not from memory, and not from what's planned for next quarter. Answer what is true today, and where a control is partial, say it's partial. An accurate application with a few honest gaps puts you in a far stronger position than a perfect application that doesn't match reality — because the second one gets read closely at exactly the moment you need the policy to work.

If a control the carrier asked about isn't in place, that's a conversation worth having before binding. Sometimes the answer is a different carrier. Sometimes it's a fortnight of work that materially changes both the price and the coverage.

Two sides of the policy

Your losses, and other people's claims.

A cyber policy should be read from both directions: what the incident costs you directly, and what you owe when someone else's information is involved.

Your own costs

First-party coverage

  • Forensic investigation and incident response
  • Breach counsel — including the written determination work
  • Ransomware and cyber-extortion response
  • Data and system restoration
  • Cyber business interruption and extra expense
  • Notification, call-center and credit-monitoring services
  • Dependent interruption when a critical vendor is attacked
  • Social engineering and funds-transfer fraud — usually optional, usually sublimited
Claims against you

Third-party liability

  • Privacy liability and legal defense
  • Network security liability
  • Claims from customers or employees whose data was exposed
  • Media liability for qualifying online content
  • Certain regulatory investigation and defense costs
  • Payment-card assessments, where covered
  • Covered settlements and judgments
  • Claims from a business whose data you held — see the notify-the-owner duty above

Read the sublimits, not the headline limit.

Two cyber policies advertising the same limit can behave completely differently, because the coverages that matter most are frequently sublimited well below it. Ransomware, social engineering and funds-transfer fraud, dependent business interruption and regulatory response are the usual candidates. Social engineering in particular is often a fraction of the policy limit — and it's the one small businesses claim on most.

Also check the waiting period on business interruption. A twelve-hour waiting period and an eight-hour one are materially different policies for a business that can't take orders while systems are down.

Avoid the coverage gap

Cyber, general liability and crime aren't interchangeable.

One incident can touch several policies, and rarely does one policy cover all of it. We review these together so nothing falls between forms.

Loss scenarioCyberGeneral liabilityCrime
Ransomware encrypts your networkCore cyber exposureNot designed for itNot designed for it
Customer information is exposedCore cyber exposureCommonly excludedNot the primary policy
Employee wires money after a fake vendor emailNeeds social-engineering coverageNot coveredMay be, with the right endorsement
Systems go offline and revenue stopsCyber interruption may applyNot designed for itNot designed for it
Your cloud vendor is attacked and you can't operateNeeds dependent interruptionNot designed for itNot designed for it
Employee deliberately steals company moneyNot the primary policyNot coveredCore crime exposure
Client alleges your tech work caused them lossOnly if tied to covered servicesProfessional services excludedNot designed for it

A general illustration only; actual coverage depends on the forms, endorsements, definitions, exclusions, limits and the facts of the loss. That last row is the technology E&O boundary, and it's where gaps hide for IT firms — see professional liability.

Exposure matcher

Which cyber protections should you review?

Select what applies. The tool characterises exposure and flags coverage features worth raising with an agent — it does not recommend a limit or a price, and it doesn't assess your security. Educational only.

Build your cyber exposure profile Check every item that applies to your business.

How does your organization use technology and information?

Cyber exposure

Coverage features to review

    Want an agent to compare cyber options and read the sublimits?

    Start Your Quote
    Who needs it

    The businesses that assume it doesn't apply usually hold the most data.

    Cyber exposure follows the data and the dependency, not the industry label. A business with no technology department, one compromised email password and a customer list is fully exposed to all of it.

    Medical and dental offices hold patient records and depend on scheduling and billing systems. Contractors exchange invoices, banking instructions and payroll by email, which makes impersonation and payment diversion the dominant risk rather than data theft. Restaurants and retailers run payment systems, online ordering and loyalty data across several third-party platforms. Property managers and real estate firms hold tenant records, deposits and closing instructions — a combination that attracts wire fraud specifically. Manufacturers can lose production, shipping and inventory control from a single compromise. Professional offices hold confidential client files while living in email and document platforms. Churches and nonprofits run donation platforms and member records with limited internal support, which is a genuinely difficult combination.

    And technology firms sit in a category of their own, because they need cyber coordinated with technology errors and omissions. A client alleging your software or hosting failed them is a professional liability claim; your own systems being breached is a cyber claim. The same incident can be both, which is exactly why the boundary between the two policies is worth mapping deliberately rather than discovering.

    Where we earn it

    On this line, the sublimits are the policy.

    The failures here are specific and repetitive. An application answered from memory rather than by the person who administers the systems. Social engineering sublimited far below the headline limit, on the one coverage a small business is most likely to claim. No dependent business interruption at a company that would stop trading if one cloud vendor went down. A waiting period longer than the outage the business could actually absorb. Vendors hired before the hotline was called. Cyber and technology E&O bought separately from different places, with a gap between them nobody owns. A policy document stored only in the email system that the incident took out.

    What we do about it: complete the application with your systems administrator present and answer it accurately, compare the sublimits and waiting periods rather than the headline limits, check whether social engineering is in the cyber policy or belongs on a crime policy, confirm dependent interruption covers the vendors you'd actually stop without, map the boundary between cyber and technology E&O if you're a technology firm, and make sure the hotline number and policy number live somewhere outside your network. We don't adjust your claim and can't overrule an adjuster — but we build the policy to respond, across 40+ carrier markets. Cyber appetite and security requirements shift faster than any other commercial line, so ask us rather than working from last year's answer.

    What it costs

    Priced off your controls as much as your size.

    Controls move it more than revenue does

    Cyber premium turns on the volume and sensitivity of the records you hold, annual revenue, industry and regulatory environment, dependence on systems for daily operation, payment-card activity, the cloud and technology vendors you rely on, the limit and retention chosen, which sublimits you buy up, the business-interruption waiting period, and prior incidents. What distinguishes this line is how much the security controls matter — multifactor authentication on email and remote access, isolated and tested backups, documented phishing training, callback verification on payment changes and monitored endpoint protection all affect eligibility as well as price, and on some risks they decide whether coverage is available at all. Worth saying plainly: price is not the only comparison here, and on this line it isn't even the main one. Two quotes at the same limit can differ enormously on the sublimits that actually get claimed. This isn't a quote or a guarantee.

    Frequently asked questions

    Cyber liability questions.

    What does cyber liability insurance cover?

    It covers two different things, and the second one is what businesses actually use. First-party coverage pays your own costs after an incident: forensic investigation, breach counsel, data and system restoration, ransomware and extortion response, notification and call-center services, credit monitoring, and lost income while systems are down. Third-party coverage answers claims brought against you when someone else's information is affected, including privacy liability, network security liability, legal defense and certain regulatory response costs.

    The part owners tend to undervalue is not the money at all. It is the access to a breach-response team the carrier has already vetted and put on retainer, which is worth having on the morning you discover the problem. Actual protection depends on the policy form, the limits and sublimits, waiting periods, security conditions, consent requirements and exclusions.

    What should we do first after discovering a cyberattack?

    Call the carrier's incident-response hotline before you do anything else that costs money. Protect people and keep the business running, do not delete anything that could be evidence, and then make that call. The reason is specific rather than procedural. Most cyber policies contain consent requirements, which means expenses you incur before notifying the carrier may not be covered, even where the expense was entirely sensible. Hiring your own forensic firm, engaging your own lawyer or opening a negotiation with an attacker can all fall outside coverage if the carrier was not consulted first. The two most expensive words in a cyber claim are we handled it ourselves.

    There is a second reason to make the call early. The carrier's panel already includes breach counsel and forensic specialists who do this work constantly, and the decisions taken in the first forty-eight hours shape your legal obligations, your recovery time and what the claim ultimately costs.

    What does Arkansas law require after a data breach?

    The Arkansas Personal Information Protection Act, at Arkansas Code section 4-110-101 and following, does two things. It requires businesses holding personal information about Arkansas residents to implement and maintain reasonable security procedures and practices, which is an affirmative duty rather than only a reporting one. And it requires notification after a breach of computerized personal information. Notice to affected individuals must be made in the most expedient time and manner possible and without unreasonable delay, consistent with the needs of law enforcement and with the work of determining the scope of the breach and restoring the integrity of the system. Arkansas does not set a fixed number of days for that individual notice.

    Where a breach affects the personal information of more than one thousand individuals, the business must also disclose it to the Arkansas Attorney General, either at the same time individuals are notified or within forty-five days of determining a reasonable likelihood of harm, whichever comes first. If you hold computerized personal information you do not own, you must notify the owner or licensee immediately on discovery. This is a general summary rather than legal advice, the statute covers computerized data rather than paper records, and other regimes may apply on top of it.

    What if we investigate and decide notification is not required?

    Then you have a documentation obligation that a great many businesses do not know exists, and it is the least-known consequence in the Arkansas statute. Where a reasonable investigation determines that notification is not required, the business must retain a written determination of the breach along with supporting documentation for five years from the date of the determination. The Attorney General may submit a written request for that determination, and the business then has thirty days to provide it along with the supporting documentation. The determination itself is confidential and not subject to public disclosure.

    Read practically, that means deciding not to notify is a formal step with a paper trail rather than the end of the matter. It is also precisely the work breach counsel exists to do properly, and breach counsel is one of the things a cyber policy pays for. Handling a quiet incident without that support can leave you with the obligation and none of the documentation.

    Does general liability insurance cover a cyberattack?

    Not in the way a dedicated cyber policy does, and increasingly not at all. General liability is built for bodily injury, property damage and certain personal and advertising injury allegations arising from your operations. It was never designed for digital data, and most modern general liability forms carry explicit exclusions for data and access-or-disclosure related injury.

    Even where an older form is silent, the coverage a cyber event actually requires simply is not there. There is nothing in a general liability policy that pays for forensic investigation, notifying thousands of customers, restoring encrypted systems, replacing lost revenue during an outage, or retaining breach counsel to work out what a state statute requires of you. A cyber incident can touch several policies at once, which is why cyber, crime, professional liability and your commercial package should be reviewed together rather than separately.

    Does cyber insurance cover ransomware and wire transfer fraud?

    Ransomware and cyber extortion are commonly included, subject to the policy's terms, applicable legal restrictions, consent requirements, retention, sublimits and security conditions. Carriers typically provide access to breach counsel, forensic specialists and professional negotiators as part of that, and the consent requirement matters here more than almost anywhere else in insurance.

    Wire transfer fraud is a different question and it is the one that catches people. When an employee is deceived into sending money to a fraudulent account, that is social engineering or fraudulent instruction, and coverage for it is frequently optional, frequently carries a much lower sublimit than the headline policy limit, and is sometimes written under a crime policy rather than the cyber policy. Some carriers also require documented callback verification procedures as a condition. Ask specifically whether it is included, at what sublimit, and what verification the carrier expects.

    Can wrong answers on the application affect our coverage?

    Yes, and this is the most common way a business that bought cyber insurance ends up without the protection it thought it had. Cyber applications ask detailed and specific questions: whether multifactor authentication protects email and remote access and administrator accounts, whether backups are isolated from the network and tested, whether employees receive phishing training, whether payment changes get verified by callback. Those answers are part of the basis on which the policy was issued. If a claim arrives and the honest answer turns out to have been different from the answer given, the carrier will look at that, and the consequences can reach as far as the policy responding at all.

    The practical instruction is straightforward. Complete the application with the person who actually administers your systems in the room, answer what is true today rather than what is planned, and if a control is partial then say it is partial. An accurate application with a few gaps is a far better position than a perfect application that does not match reality.

    Is cyber liability insurance only for technology companies?

    No, and the businesses that most often assume it does not apply to them are the ones that hold the most data. Any organization that uses email, stores customer or employee information, accepts electronic payments, depends on computer systems for daily operations, or moves money electronically can suffer a cyber loss.

    That covers medical and dental offices, contractors who exchange invoices and banking instructions by email, restaurants and retailers running payment systems, property managers holding tenant records and deposits, manufacturers dependent on production systems, professional offices holding confidential client files, and churches and nonprofits running donation platforms with limited internal support. The exposure follows the data and the dependency, not the industry label. A business with no technology department and one compromised email password can still face notification obligations, an interrupted operation and a wire that has already left.

    How do I get a cyber liability quote?

    Start the commercial quote form or call (479) 286-1066, and bring whoever administers your systems into the conversation. This line is quoted off security controls and data volume, so those answers matter more than the general business description.

    Useful to have: roughly how many individuals' records you hold and what categories of information they include, annual revenue, employee count, whether you accept card payments and how, which cloud and technology vendors you depend on, whether multifactor authentication is in place and on exactly what, how backups are stored and whether they have been tested by restoring from them, whether staff receive phishing training, whether payment or banking changes get verified by callback, whether you hold data belonging to other businesses, any contractual cyber requirements, and any prior incident however small. If you already carry cyber cover, send the declarations and the application. Comparing the sublimits and the security conditions matters more than comparing the headline limit.

    Help Google recognize Cribb Insurance as a trusted Arkansas source.

    If our coverage explainers are useful, mark Cribb Insurance as a preferred source so more Arkansas business owners can find our local, plain-English guides.

    ⭐ Trust Cribb Insurance in Google AI Opens Google preferences in a new tab.

    Bring whoever runs your systems to the call.

    This is the one line where the technical answers matter more than the business description. What's protected by multifactor authentication, whether backups have actually been restored from, whether payment changes get a callback. If you already have cyber cover, send the declarations and the application — the sublimits and the security conditions are where we'll find the difference. And write the hotline number down somewhere that isn't your email.

    Cribb Insurance Group Inc. 📍 1601 SW Regional Airport Blvd, Bentonville, AR 72713 📞 (479) 286-1066 ✉️ service@cribbinsurance.com

    Cribb Insurance Group Inc. is an independent insurance agency licensed in Arkansas, Oklahoma, Missouri and Texas. This page describes cyber liability insurance in general, industry-standard terms for informational purposes only. It is not a policy, not an offer of insurance, and not a guarantee of coverage, availability, eligibility, or price. It is not legal advice and not cybersecurity advice. Agency licensure is not the same as carrier appointment; product and carrier availability differ by state, by line and over time.

    Cyber policies vary substantially between carriers and are not standardized. Coverage, definitions, limits, sublimits, retentions, business-interruption waiting periods, security conditions and warranties, consent and reporting requirements, panel-vendor requirements and exclusions are set by the carrier and apply only as written in the policy issued to you. Coverage for ransomware and cyber extortion, social engineering, fraudulent instruction and funds-transfer fraud, dependent business interruption, regulatory investigation and defense, payment-card assessments, and media liability is not automatic, is frequently optional, and is frequently subject to sublimits materially below the headline policy limit. Statements on this page about consent requirements and panel vendors describe common market practice; your own policy governs. Descriptions of underwriting questions about multifactor authentication, backups, training, patching and payment verification are general and do not state any carrier's specific eligibility standards or thresholds. Answers given on an insurance application may affect coverage; complete applications accurately and with the assistance of the people who administer your systems.

    About the Arkansas law described on this page. References to the Arkansas Personal Information Protection Act, Ark. Code § 4-110-101 et seq., including §§ 4-110-103, 4-110-104 and 4-110-105 as amended by Act 1030 of 2019, are a general summary provided for information only. They are not legal advice, not a legal opinion, and not a determination of what any statute requires of your business in any particular incident. The statute applies to computerized data; paper records are outside its scope. "Personal information" is defined by reference to specified data elements and to whether the information is encrypted or redacted. Statutes are amended and are interpreted by regulators and courts. Oklahoma, Missouri and Texas each have their own breach-notification statutes with different thresholds, deadlines and regulator-notice requirements, and a single breach affecting residents of several states can trigger several statutes simultaneously. Federal and contractual regimes — including HIPAA, the Gramm-Leach-Bliley Act, payment-card industry requirements and customer contracts — may impose additional or different obligations and are not described on this page. Determining which obligations apply to a specific incident, and complying with them, is legal work. Confirm your obligations with the Arkansas Attorney General and with qualified legal counsel.

    The interactive exposure matcher is an educational illustration only. It does not evaluate your computer systems, security controls, legal obligations or insurance needs, does not determine eligibility or coverage, and does not recommend a limit or a price. No premium figures, rate ranges, eligibility thresholds or underwriting criteria are published on this page. Any cost or coverage descriptions are general and illustrative, not a quote, and not a guarantee; your premium and coverage are determined at quote and by the policy issued. Carrier availability referenced as "40+ carriers" reflects the agency's overall market access across personal and commercial lines.

    Last reviewed July 2026.