(312) 395 0872

Cyber Liability Insurance for Small Businesses: Coverage, Risks, Costs, and Quote Guide

Cyber liability insurance for small businesses is no longer a topic limited to software companies and large corporations. A local contractor may receive payment instructions through email. A restaurant may rely on a point-of-sale system and online reservations. An accounting firm may store tax documents in the cloud. A medical office may depend on electronic records. A retailer may process card payments and hold customer information.

Each of these businesses has a different cyber exposure, but they share one important reality: a digital incident can create financial loss, operational disruption, legal questions, customer communication needs, and urgent response costs.

The scale of reported cyber-enabled crime helps explain why business owners are paying more attention. The FBI’s Internet Crime Complaint Center reported 1,008,597 complaints and $20.877 billion in reported losses for 2025. Business Email Compromise alone accounted for about $3.047 billion in reported losses, while phishing/spoofing generated 191,561 complaints. These figures are complaint data, not insurance claim statistics, and not every business loss is reported to the FBI.

This guide explains what cyber liability insurance is, how first-party and third-party coverage differ, which cyber events may be addressed, what exclusions and sublimits can matter, how security controls affect resilience and underwriting, what information to prepare for a cyber insurance quote, and what a small business should do after a suspected incident.

This article provides general educational information only. It is not legal, cybersecurity, financial, incident-response, underwriting, or coverage advice. Actual coverage depends on the carrier, policy form, selected limits, retentions or deductibles, sublimits, endorsements, exclusions, underwriting, state availability, and claim facts.

Want to understand your cyber insurance options?

Explore Cover AI’s Cyber Liability Insurance page for coverage guidance and access to the approved quote path.

Quote flow powered by Cowbell. Coverage, pricing, eligibility, limits, exclusions, and policy issuance are subject to underwriting and policy terms.

What Is Cyber Liability Insurance?

Cyber liability insurance is business insurance designed to help with certain financial losses, response costs, and liability claims arising from covered cyber events. Depending on the policy, coverage may address events such as data breaches, ransomware, cyber extortion, business email compromise, social engineering, privacy incidents, data restoration, forensic investigation, notification expenses, and cyber-related business interruption.

The phrase ‘cyber liability insurance’ is often used broadly, but a modern cyber policy can include both first-party and third-party coverage. First-party coverage generally focuses on losses and response costs experienced by the insured business itself. Third-party cyber liability generally focuses on covered claims, defense costs, or liabilities arising when customers, clients, regulators, or other parties allege harm connected to a covered privacy or security event.

The distinction matters because a business can face both types of consequences after the same incident. A data breach may require forensic work, restoration, notification, and crisis communication while also creating third-party claims or regulatory proceedings. Whether a specific policy responds depends on its wording and the facts of the event.

Why Cyber Risk Is a Business Risk, Not Only an IT Problem

A cyber incident can affect revenue, operations, contracts, customer trust, employee productivity, banking relationships, vendors, and legal obligations. That is why cyber risk should involve business leadership, not only the person who manages computers.

CISA’s small-business guidance recommends practical actions such as enabling multi-factor authentication, performing and testing backups, keeping software updated, using logging, identifying critical systems, and preparing for incident response. These measures are important because insurance does not prevent attacks. Cyber insurance can be part of a broader risk-management plan, but it does not replace security controls.

For a small business, the objective is not to become immune to cyber risk. The objective is to reduce preventable exposure, detect problems earlier, respond in an organized way, recover essential operations, and understand which financial consequences may be transferred to insurance under the policy.

Common Cyber Incidents Small Businesses Should Understand

Ransomware and Cyber Extortion

Ransomware can encrypt files, disrupt systems, or be combined with data theft and extortion demands. The business may need forensic investigation, legal guidance, restoration support, communications, and operational recovery.

FBI IC3 data should be interpreted carefully when evaluating ransomware. The FBI notes that reported ransomware loss amounts normally do not include lost business, time, wages, files, equipment, or third-party remediation services. That means a low reported ransom-loss figure should not be treated as the total economic impact of ransomware.

Phishing and Business Email Compromise (BEC)

Business Email Compromise is a sophisticated fraud scheme in which attackers use social engineering or compromised email accounts to trick businesses or individuals into transferring funds. A fake vendor invoice, changed wire instruction, executive impersonation, payroll diversion request, or closing-payment fraud can create a large loss without encrypting a single computer.

BEC deserves separate attention because not every cyber policy treats social engineering, funds-transfer fraud, computer fraud, and invoice manipulation the same way. Coverage may be subject to dedicated insuring agreements, definitions, verification requirements, or sublimits.

Data Breach and Privacy Incident

A breach can involve customer, employee, patient, vendor, or client information. The business may need to determine what happened, what data was involved, who was affected, whether notification duties apply, and how to reduce further exposure.

The FTC’s business breach-response guidance emphasizes securing operations, fixing vulnerabilities, mobilizing a response team, preserving evidence, working with forensic experts, and determining appropriate notification steps. State, sector, contract, and regulatory duties can differ, so businesses should involve qualified counsel and response professionals when needed.

Cyber Business Interruption

A cyber event can stop normal operations even when no physical property is damaged. A business may be unable to access files, process payments, take orders, schedule work, ship products, communicate with customers, or use critical cloud services.

Cyber business interruption coverage may help with certain covered income loss and extra expense, but the details are important. Policies can have waiting periods, restoration periods, calculation rules, coverage triggers, and limits. Some policies may also address dependent business interruption involving certain third-party technology providers, but this should never be assumed without reviewing the actual policy.

Vendor, Cloud, and Supply-Chain Incidents

A small business can suffer disruption because a vendor, managed service provider, cloud platform, payment processor, or other technology dependency experiences an incident. Coverage for dependent systems, contingent business interruption, vendor incidents, or system failure varies widely, so contract dependencies should be part of the insurance review.

First-Party vs. Third-Party Cyber Insurance Coverage

Understanding first-party and third-party coverage is one of the most useful ways to evaluate a cyber policy.

 

Coverage CategoryWhat It Generally AddressesExamples to Review
First-party cyber coverageCosts and losses experienced by the insured business after a covered event.Forensics, data restoration, extortion response, incident response, notification, business interruption, crisis management, certain cybercrime losses.
Third-party cyber liabilityCovered claims or liability allegations brought by customers, clients, regulators, or other parties.Privacy claims, network-security liability, defense costs, certain regulatory proceedings, media liability where included.
Cybercrime / social engineeringCertain fraudulent transfer or deception-based losses when specifically covered.BEC, invoice manipulation, social engineering, funds-transfer fraud, computer fraud; terms and sublimits can differ.

The names of insuring agreements differ by carrier. A checklist or website summary is not a substitute for the policy wording, endorsements, declarations, limits, and sublimits.

What Cyber Liability Insurance May Help Cover

A cyber policy may include several categories of protection. The list below describes common concepts, not guaranteed coverage.

Breach Response and Notification Costs

After a covered breach, the business may need forensic analysis, legal review, notification services, call-center support, credit or identity-monitoring services, and other response resources. The policy may define which vendors can be used and how services must be approved.

Digital Forensics and Incident Response

Forensic specialists may help determine how an incident occurred, what systems or data were affected, whether attackers still have access, and what containment steps are appropriate. Incident-response services are often time-sensitive, so policyholders should understand the carrier’s reporting process before a crisis.

Data Restoration and System Recovery

Coverage may help with certain costs to restore or recreate electronic data and recover systems after a covered event. Definitions, restoration standards, exclusions, and limits can affect what qualifies.

Cyber Extortion and Ransomware Response

A policy may provide access to specialists who help assess an extortion event, coordinate response, evaluate legal and sanctions issues, and support recovery. Coverage for ransom payments, negotiation expenses, and related costs depends on policy terms and applicable law.

Business Interruption and Extra Expense

Coverage may help with certain income loss and extra expense when a covered cyber event interrupts operations. Review the waiting period, restoration period, revenue calculation method, system-failure wording, and whether dependent-provider events are covered.

Privacy and Network Security Liability

Third-party coverage may respond to certain claims alleging failure to protect information, failure to prevent a security event, or other covered privacy or network-security allegations. Defense obligations, consent provisions, regulatory coverage, and exclusions should be reviewed.

Business Email Compromise and Social Engineering

Some cyber policies include or offer coverage for certain social engineering, funds-transfer fraud, computer fraud, or invoice-manipulation losses. Because these losses can be treated differently across policies, review the exact insuring agreement, verification conditions, and sublimits.

Crisis Management and Public Relations

A significant cyber event can create urgent customer, employee, vendor, and media communication needs. Some policies may provide covered crisis-management or public-relations services.

The Details That Matter: Limits, Sublimits, Waiting Periods, and Retentions

Two policies with the same headline limit can provide very different practical protection. Before buying cyber insurance, review how the policy allocates limits and conditions.

Policy Limit

The policy limit is not the only number that matters. Some costs may share an aggregate limit, while other coverages may have separate or lower sublimits.

Sublimits

A policy may have lower limits for specific exposures such as social engineering, cybercrime, telecommunications fraud, reputational harm, dependent interruption, or certain response costs. A business that is especially concerned about invoice fraud should not assume the full policy limit applies to that risk.

Deductible or Retention

The business may be responsible for a deductible or self-insured retention before certain coverage responds. The amount can differ by coverage category.

Waiting Period

Business interruption coverage may start only after a specified waiting period. A business that cannot operate for several hours or days should understand how the waiting period is measured.

Panel Vendors and Consent Requirements

Cyber response often involves specialized breach counsel, forensics, negotiators, restoration vendors, and notification providers. Policies may require the use of approved vendors or prior consent. Using an outside vendor without following policy procedures can create coverage questions.

What Cyber Liability Insurance May Not Cover

Cyber policies contain conditions and exclusions. The following issues are examples to review, not a universal list.

  • Known incidents, circumstances, or losses that began before the applicable policy period or were known before coverage.
  • Intentional, dishonest, criminal, or fraudulent acts by the insured or certain responsible persons, depending on policy wording.
  • Losses outside the policy’s definitions, limits, sublimits, retentions, deductibles, waiting periods, or endorsements.
  • Certain infrastructure failures, utility events, system failures, or provider outages unless the policy specifically responds.
  • War, cyber-war, hostile-action, or systemic-event exclusions as defined by the policy.
  • Cybersecurity upgrades, routine system improvements, or betterment costs unless covered by specific wording.
  • Contractual liabilities or voluntary payments beyond what the policy covers.
  • Certain unencrypted-device, access-control, security-practice, or misrepresentation issues where policy language and underwriting representations make them relevant.

Coverage interpretation can be fact-specific. Business owners should review the policy and speak with qualified insurance professionals before relying on assumptions based on a marketing summary.

Cyber Insurance vs. Other Business Insurance

 

ProductPrimary Risk FocusWhy Cyber Insurance Is Different
General LiabilityThird-party bodily injury, property damage, and certain personal/advertising injury claims.Cyber policies are designed around digital events, data, systems, cybercrime, breach response and related liability.
Business Owner’s Policy (BOP)Package that may combine General Liability and business property, sometimes with business income.A BOP should not be assumed to provide the same scope as standalone cyber insurance; limited endorsements may differ materially.
Professional Liability / E&OClaims involving professional services, advice, design, missed deadlines, or service errors.Cyber insurance focuses on covered cyber events and digital response costs. Technology E&O is a separate product concept.
Workers’ CompensationEmployee work-related injuries or illnesses.Cyber insurance does not replace workers’ compensation obligations.
RiskHubBusiness risk intelligence and document review support.RiskHub is informational support, not an insurance policy and not a substitute for cyber coverage.

What Security Controls Matter Before You Request a Cyber Insurance Quote?

Cyber insurance underwriting is not only about company size and revenue. The quote flow may ask how the business protects accounts, devices, data, backups, remote access, email, and critical systems.

CISA, FTC, and NIST all emphasize practical security controls and preparation. The exact questions vary by carrier, but the following areas are useful to review before requesting a cyber insurance quote.

Multi-Factor Authentication (MFA)

MFA adds another authentication step beyond a password. CISA and FTC guidance recommend MFA for important accounts and sensitive systems. A business should know where MFA is enforced, especially for email, remote access, administrative accounts, cloud services, and systems containing sensitive information.

Backups and Recovery Testing

Backups are valuable only if they are available when needed. CISA advises businesses to maintain and test backups and protect them from the same incident that affects production systems. A quote may ask whether backups are offline, immutable, segmented, or regularly tested.

Software Updates and Vulnerability Management

Unsupported software and unpatched vulnerabilities can create avoidable exposure. The business should understand who is responsible for updates, how critical vulnerabilities are prioritized, and whether third-party providers manage part of the process.

Endpoint Protection and Email Security

Businesses should know what security tools protect laptops, desktops, servers, and email accounts. The carrier may ask about endpoint detection, antivirus or anti-malware tools, spam filtering, domain protections, and monitoring.

Access Control and Privileged Accounts

Administrative access should be limited to people who need it. Former employee accounts should be disabled promptly, and high-privilege accounts should receive stronger controls and monitoring.

Incident Response Plan

NIST’s Cybersecurity Framework organizes cybersecurity around Govern, Identify, Protect, Detect, Respond, and Recover. For a small business, an incident-response plan can be simple but should identify decision-makers, technical contacts, insurance reporting information, legal resources, critical systems, communication responsibilities, and recovery priorities.

What Affects Cyber Insurance Cost?

There is no responsible single-price answer for small business cyber insurance. Pricing varies by business and underwriting. Publishing an unsupported average price can mislead readers because two businesses with similar revenue may have very different data, systems, controls, contracts, and exposure.

  • Industry and type of operations.
  • Annual revenue and organization size.
  • Number of employees and users.
  • Type and volume of sensitive or regulated information.
  • Payment processing and financial-transfer exposure.
  • Dependence on cloud services, vendors, and critical digital systems.
  • Prior cyber incidents, claims, and known events.
  • MFA implementation and account-security practices.
  • Backup strategy and recovery testing.
  • Endpoint, email, patching, logging, and monitoring controls.
  • Desired policy limits, sublimits, retentions, and endorsements.
  • Contract requirements and requested coverage features.

The practical lesson is to improve the accuracy of the quote information, not to chase a generic price. An inaccurate answer about security controls can create underwriting and claim problems later.

What Information May You Need for a Cyber Liability Quote?

A cyber insurance quote may ask for both business information and cybersecurity information. The exact questions depend on the flow and underwriting requirements.

  • Legal business name, address, and website.
  • Industry, operations, and services.
  • Annual revenue and employee count.
  • States or countries of operation where relevant.
  • Types of customer, client, employee, patient, vendor, or payment information stored or processed.
  • Payment processing and wire-transfer practices.
  • Use of cloud services, remote access, email platforms, and critical vendors.
  • MFA deployment for email, remote access, administrative and cloud accounts.
  • Backup frequency, isolation, immutability, and testing practices.
  • Endpoint protection, email security, logging, patching, and monitoring.
  • Prior cyber incidents, claims, breach events, extortion events, or known circumstances if requested.
  • Current or prior cyber insurance information.
  • Desired effective date, limits, and contract requirements.

Do not provide passwords, authentication secrets, detailed vulnerability data, protected health information, Social Security numbers, or sensitive incident evidence through a generic form. Use approved secure channels when sensitive cybersecurity information must be shared.

Ready to start the cyber quote process?

Use the Cover AI quote path to continue to the approved Cowbell-powered flow.

Quote flow powered by Cowbell. Coverage, pricing, eligibility, limits, exclusions, and policy issuance are subject to underwriting and policy terms.

What to Do After a Suspected Cyber Incident

A suspected incident can be chaotic. The exact response depends on the event, but an organized first response is more useful than improvisation.

  1. Protect people and essential operations. If physical safety or critical services are affected, address those needs first.
  2. Activate the incident-response plan and identify the internal decision-maker.
  3. Contact the cyber insurer or reporting channel promptly if a policy may respond. Follow policy instructions before hiring vendors or making payments when possible.
  4. Preserve logs, devices, emails, transaction records, and other evidence. Avoid unnecessary changes that could destroy evidence.
  5. Work with qualified forensic, legal, and incident-response professionals to contain the event and determine scope.
  6. Secure compromised accounts, credentials, remote access, and affected systems in a coordinated manner.
  7. Assess what data, systems, vendors, customers, employees, or partners may be affected.
  8. Determine notification, regulatory, contractual, law-enforcement, and customer-communication obligations with qualified guidance.
  9. Document decisions, expenses, communications, and recovery actions.
  10. After recovery, review lessons learned and update controls, backups, training, vendor management, and the incident-response plan.

The FTC’s breach-response guide emphasizes securing operations, fixing vulnerabilities, mobilizing a response team, preserving evidence, and evaluating notification. CISA’s ransomware guidance also stresses preparation and coordinated response. These public resources can support planning, but they do not replace policy instructions or professional incident response.

Common Cyber Insurance Mistakes Small Businesses Should Avoid

Assuming Cyber Insurance Prevents Attacks

Insurance can help with covered financial consequences and response services. It is not a firewall, backup system, security team, or substitute for basic controls.

Assuming a BOP Automatically Provides Full Cyber Coverage

Some package policies may include limited cyber endorsements, but the scope, limits, and triggers may be very different from standalone cyber coverage.

Ignoring Social Engineering Sublimits

A policy may advertise a high total limit while applying a much lower sublimit to social engineering or certain cybercrime losses. Review the numbers that apply to the scenarios your business actually faces.

Treating Every Outage as Covered Business Interruption

Cyber business interruption coverage depends on the event, cause, waiting period, restoration period, definitions, and policy language. A general system outage is not automatically a covered claim.

Misstating Security Controls on the Application

Do not answer ‘yes’ to MFA, backups, monitoring, or other controls unless the business can accurately support that answer. Underwriting representations matter.

Waiting Until an Incident to Learn the Reporting Process

Know the insurer’s incident hotline or reporting method before an event occurs. Save the information somewhere accessible even if normal systems are unavailable.

Buying Only to Satisfy a Contract

A client requirement may start the insurance conversation, but the business should still review whether the limits, sublimits, retroactive dates, waiting periods, and coverage categories fit its actual exposures.

A Practical Cyber Insurance Buying Checklist

  • Identify the systems and data the business cannot operate without.
  • List important cloud, payment, technology, and vendor dependencies.
  • Understand the most likely fraud and interruption scenarios for the business.
  • Review MFA coverage across email, remote access, administrative and cloud accounts.
  • Confirm backup frequency and test whether critical systems can be restored.
  • Document security responsibilities between the business and outside IT providers.
  • Gather prior incident and claims information accurately.
  • Review first-party and third-party coverage categories.
  • Compare policy limits and important sublimits.
  • Review deductible or retention amounts by coverage.
  • Review business interruption waiting periods and restoration periods.
  • Review social engineering, cybercrime and funds-transfer coverage separately.
  • Understand vendor, dependent system and cloud interruption wording.
  • Know the incident reporting process and approved response vendors.
  • Review exclusions, endorsements and contract requirements before relying on coverage.

How Cover AI and the Cowbell-Powered Quote Flow Fit Into the Process

Cover AI’s Cyber Liability Insurance page is designed to explain the product in clear language before the visitor starts a quote. When a user is ready, the Get Cyber Liability Quote button connects through a tracked Cover AI redirect to the approved Cowbell-powered quote flow.

The quote flow may request business and cyber-risk information and present next steps based on eligibility and underwriting. Cover AI does not guarantee pricing, approval, limits, coverage availability, quote speed, binding, claim payment, or policy issuance.

The tracked redirect allows Cover AI to maintain a stable internal quote path while updating the approved partner destination when operationally necessary.

Not Ready to Quote? Use RiskHub as a Secondary Starting Point

Some business owners are not ready to start a cyber insurance quote because they first need to organize contracts, policies, business documents, or risk questions. RiskHub can be used as an optional informational starting point for broader business risk review.

RiskHub is not cyber insurance, does not create coverage, and does not replace legal, cybersecurity, financial, or insurance advice. Its role is to support risk understanding and help users identify questions to review.

Prefer to review business risk first?

Use RiskHub as an optional informational step before or alongside insurance planning.

RiskHub is informational support. It is not legal, cybersecurity, financial, or insurance coverage advice.

Final Takeaway: Cyber Insurance Works Best as Part of a Broader Risk Plan

Cyber liability insurance for small businesses can be an important part of financial resilience, but the value of a policy depends on more than the headline limit. Business owners should understand the events most relevant to their operations, review first-party and third-party coverage, check sublimits and waiting periods, answer underwriting questions accurately, and know how to report an incident.

The best preparation combines practical security controls, tested recovery plans, clear vendor responsibilities, organized incident response, and insurance that is reviewed against the business’s real exposures.

When you are ready, visit the Cover AI Cyber Liability Insurance page for coverage guidance and access to the Cowbell-powered quote path.

Frequently Asked Questions About Cyber Liability Insurance

What is cyber liability insurance?

Cyber liability insurance is business insurance that may help with certain financial losses, response costs, and liability claims after a covered cyber event. Depending on the policy, coverage may address data breaches, ransomware, cyber extortion, privacy incidents, business interruption, digital forensics, notification costs, and certain cybercrime events.

Is cyber liability insurance only for technology companies?

No. Many non-technology businesses depend on email, cloud platforms, websites, payment systems, customer records, vendor portals, online banking, or remote access. Cyber exposure can affect professional firms, contractors, retailers, restaurants, healthcare-related offices, nonprofits, and other small businesses.

Does General Liability insurance cover cyber attacks?

General Liability insurance is generally designed for risks such as third-party bodily injury, property damage, and certain personal or advertising injury claims. It should not be assumed to provide the same breach-response, ransomware, cybercrime, privacy, and interruption coverage as a dedicated cyber policy.

Does a Business Owner’s Policy include cyber insurance?

Some package policies may include limited cyber endorsements, but the scope may be different from standalone cyber coverage. Review actual limits, sublimits, definitions, exclusions, and endorsements rather than assuming a BOP provides complete cyber protection.

What does cyber insurance cover?

Coverage varies. A cyber policy may help with certain breach-response expenses, digital forensics, data restoration, cyber extortion, business interruption, privacy liability, network-security liability, and certain cybercrime or social-engineering losses. The policy wording controls.

Does cyber insurance cover ransomware?

A cyber policy may cover certain ransomware or cyber-extortion response costs, subject to the policy, exclusions, limits, sublimits, consent requirements, and applicable law. Coverage and claim outcomes are not guaranteed.

Does cyber insurance cover phishing and business email compromise?

Some policies include or offer coverage for certain social-engineering, funds-transfer fraud, computer fraud, invoice manipulation, or BEC losses. These coverages can have separate definitions, conditions, verification requirements, and sublimits.

What is a cyber insurance sublimit?

A sublimit is a lower limit that applies to a specific coverage category inside the policy. For example, a policy may have a larger overall limit but a smaller limit for social engineering, cybercrime, dependent interruption, or another defined exposure.

What information is needed for a cyber insurance quote?

The quote flow may ask about industry, revenue, employee count, data types, payment practices, cloud services, remote access, MFA, backups, endpoint protection, email security, prior incidents, claims history, desired limits, and contract requirements.

What affects the cost of cyber insurance?

Pricing can depend on industry, revenue, size, data exposure, transaction risk, cloud and vendor dependence, prior incidents, security controls, MFA, backups, monitoring, selected limits, sublimits, retentions, and underwriting rules.

What does ‘quote flow powered by Cowbell’ mean?

It means the cyber quote process is routed through an approved Cowbell-powered quote destination. Cover AI provides education and tracked access, while availability, underwriting, pricing, limits, terms, and policy issuance depend on the applicable carrier and policy process.

What is the difference between RiskHub and cyber liability insurance?

RiskHub is informational business risk support and is not an insurance policy. Cyber liability insurance is an insurance product subject to underwriting, policy terms, exclusions, limits, and claim procedures.

What should a business do after a suspected cyber incident?

Activate the incident-response plan, protect essential operations, preserve evidence, contact the insurer or reporting channel promptly if a policy may respond, and coordinate with qualified forensic, legal, and response professionals. Notification and reporting duties can vary by event, jurisdiction, sector, and contract.

Related Business Insurance Guides

Educational Disclaimer

This article provides general educational information only and is not legal, cybersecurity, financial, incident-response, underwriting, or coverage advice. Cyber insurance coverage varies by carrier, policy form, limits, sublimits, retentions, deductibles, endorsements, exclusions, underwriting, state availability, and claim facts. Review policy documents and qualified professional guidance before relying on coverage.

Ready to review cyber liability options?

Start with Cover AI and continue through the approved online quote path when ready.

Quote flow powered by Cowbell. Coverage, pricing, eligibility, limits, exclusions, and policy issuance are subject to underwriting and policy terms.

Other articles

Property Inquiry Received

Thank you. Your initial property claim inquiry has been sent to Vitalii Korobov for review. This confirmation is not notice to your insurance company, does not create a public adjuster contract or representation, and does not guarantee that services will be offered.

If you have not already done so, report the loss directly to your insurance company as soon as possible.

Simon — Cover AI Assistant