What is Cyber Liability Insurance?
Cyber liability insurance protects your firm from the financial fallout of digital threats — a breached email account, a ransomware attack, stolen wire transfers, or a lawsuit from a client whose personal information was exposed through your systems.
Some cyber protection is sold as an endorsement bolted onto a general liability or E&O policy, but those add-ons are almost always narrow and thinly limited. A stand-alone cyber policy is now the standard for any real estate firm that handles client funds or client data — which is to say, every real estate firm.
But here's what most buyers miss: cyber insurance is not standardized. Two policies with the same limit on the declarations page can respond completely differently to the same claim. The only way to understand what you actually own is to understand what each section of the policy does. That's what this guide walks through.
Why Do Real Estate Firms Need Cyber Insurance?
Many broker/owners assume cyber criminals only target large national companies. The opposite is true. Small businesses are a favorite target precisely because their security is thinner — and real estate is one of the most lucrative industries a criminal can attack.
Think about what flows through a brokerage, title agency, or property management firm in a single week: wiring instructions for six-figure closings, escrow deposits, earnest money, rent payments, Social Security numbers on loan applications, and a constant stream of email between agents, lenders, attorneys, and clients. To a cyber criminal, a real estate transaction is a map showing exactly where the money is and exactly when it moves.
That's why business email compromise and wire fraud remain the number one cyber threat to real estate — and why the structure of your cyber policy matters far more than its price.
Inside a Cyber Policy: What Each Coverage Section Actually Protects
A well-built cyber policy is really several policies working together. Using the structure of PBI Group's exclusive Arch NetSafe® 2.0 cyber program as the model, a complete policy has five integrated coverage parts plus a set of endorsements that do a surprising amount of the heavy lifting. Here's what each section does, in plain English.
Coverage Part A: Network Security and Privacy Liability (Third Party)
What it protects: your firm when someone else sues you because of a cyber event.
This is the liability backbone of the policy, and for real estate firms it may be the single most important section — and the most commonly misunderstood.
Picture the most common real estate cyber claim in America: a hacker breaches your firm's email, quietly monitors a pending transaction, then sends your buyer a convincing email with fraudulent wiring instructions. The buyer wires their down payment to the criminal's account. The money is gone.
Here's the part most people don't think through: that buyer's next call may be to a lawyer — and the defendant is your firm. The client's claim is that your network was breached, your systems exposed their information, and your compromised email was the instrument of their loss. Network Security and Privacy Liability coverage is what responds to that lawsuit — the defense costs and any resulting damages.
This coverage part also responds to claims for unauthorized access to data, transmission of malicious code, denial-of-service attacks, and failures to protect private information. It extends to regulatory proceedings as well: defense costs and, where insurable, civil fines and penalties when a state attorney general or federal regulator investigates a privacy violation. The Arch program's definition of privacy law is broad by endorsement — HIPAA, GLBA, state breach notification statutes, and even GDPR and CCPA are named — and it includes PCI-DSS assessments if payment card data is involved.
Why this section deserves scrutiny: many commodity cyber policies are first-party-dominant — they'll pay to clean up your breach, but they have weak or missing third-party liability coverage. If a policy can't respond when your client sues you over stolen closing funds, it's not built for real estate.
Coverage Part B: Media Liability (Third Party)
What it protects: your firm's published content.
Real estate firms are publishers, whether they think of themselves that way or not. Listings, marketing materials, virtual tours, drone footage, blog posts, and a steady stream of social media content all create exposure to claims of copyright infringement, defamation, trade libel, and invasion of privacy.
Media liability covers the defense and damages for those claims. One caution: on many competitor policies this is an optional coverage that firms quietly decline to save premium — the declarations page shows a $0 limit. If your firm markets online (and every firm does), check that this coverage was actually purchased.
Coverage Part C: Data Incident Response Expense (First Party)
What it protects: your wallet during the chaotic first weeks after a breach.
When a breach happens, a cascade of expensive obligations begins immediately, most of them required by law. This coverage part pays for:
- Legal counsel (a specialized breach coach) to guide the response and keep it privileged
- Forensic IT investigation to determine what was accessed and how
- Breach notification to affected clients, as required by state law
- Credit monitoring and identity theft services for affected individuals
- Public relations and crisis management to protect your reputation
- Data recovery and restoration to rebuild what was corrupted or destroyed
For a real estate firm holding years of transaction files — Social Security numbers from loan applications, bank details, copies of driver's licenses — notification and monitoring costs alone can run well into six figures. The Arch program pairs this coverage with a 24/7 data security event hotline connecting insureds directly to a pre-arranged breach response legal team, so the first hours after discovery aren't spent searching for help.
Coverage Part D: Business Interruption (First Party)
What it protects: your income when a cyber event takes your systems down.
If ransomware locks your transaction management platform, your email, and your MLS access, deals stall and income stops — but rent, payroll, and franchise fees don't. Business interruption coverage replaces lost income and pays the extra expenses of keeping the firm running during the outage.
The coverage exists in nearly every cyber policy. Its real-world value lives entirely in the conditions, and this is where policies diverge dramatically:
- What triggers it? Most policies only pay if a security breach caused the outage. A strong policy also covers system failure — an unplanned IT outage with no hacker involved, like a botched update that takes your systems down for a week. Many competitor policies exclude this entirely.
- What about your vendors? Real estate firms run on third-party technology — cloud transaction platforms, hosted email, MLS systems, showing services. If their breach or outage interrupts your business, does your policy respond? A well-built policy covers dependent business and technology contractor interruption; many declarations pages flatly say “NOT COVERED.”
- How long does it wait? Every BI coverage has a waiting period before it begins paying. The Arch program uses 12 hours; some policies make you absorb 24 hours or more of losses first.
- How long does it pay? The maximum “period of recovery” caps how long income loss is measured. The Arch program extends this to 180 days by endorsement; many policies cap it at 30, 60, or 120 days. A serious ransomware recovery routinely takes months — a 30-day cap can leave the majority of the loss uncovered.
- Can you shut down proactively? If your team discovers an intruder and deliberately takes systems offline to contain the damage, some policies treat that voluntary shutdown as uncovered. The better ones cover it.
Coverage Part E: Cyber Extortion (First Party)
What it protects: you during a ransomware or extortion event.
This section covers ransom payments (made with the insurer's consent), the specialists who negotiate with attackers, and the costs of investigating the threat. Strong policies cover both security threats (threats to attack or lock your systems) and privacy threats (threats to publish stolen client data — an increasingly common tactic).
One trap to check for: some policies advertise a full-limit cyber extortion section on the declarations page, then attach an endorsement near the back that caps ransomware events at $25,000–$50,000. The endorsement supersedes the headline number. A policy is what its last endorsement says it is — always read to the end.
There's also a practical reason to let the insurer handle payment rather than reimbursing you later: few firms keep ransom-sized amounts (let alone cryptocurrency) on hand, and paying certain sanctioned criminal organizations can itself be illegal. An experienced cyber insurer's pay-on-behalf-of approach and vetted negotiators matter here.
The Cyber Crime Section: Where Real Estate Firms Win or Lose
Everything above is important. But for real estate, the coverage that most often separates a survivable event from a catastrophe is cyber crime coverage — and it's the section most commodity policies handle worst.
In the Arch program this arrives by endorsement and adds four distinct protections:
Social Engineering Coverage pays when your firm is deceived into sending money based on fraudulent instructions — an email that appears to come from a title company, escrow agent, closing attorney, lender, client, or vendor, but doesn't. Notice those examples: the Arch endorsement was written with real estate transaction parties named in the policy language itself, which removes ambiguity about the exact scenarios brokerages face.
Electronic Transfer Fraud Coverage responds to a different attack: no one at your firm is tricked — instead, a criminal gains access to your account and moves the money directly.
Invoice Manipulation Coverage pays when a criminal uses your breached network to send fraudulent invoices to your clients, leaving you unable to collect what you're owed.
Telephone Fraud Coverage handles fraudulent use of your phone systems.
Two features within this section deserve special attention from any real estate buyer:
Customer funds in your care, custody, and control. Most cyber crime coverage only pays for the insured's own money. But real estate firms hold other people's money — escrow deposits, earnest money, security deposits, rent, closing funds. The Arch endorsement expressly extends social engineering and electronic transfer fraud coverage to a customer's funds under the insured's care, custody, and control, including funds in an insured account. If a policy limits coverage to “direct financial loss sustained by the insured,” a stolen escrow deposit may not be covered at all — a gap that only becomes visible on the worst day of your business life.
The theft of funds carve-back. Standard cyber forms exclude theft of money and securities from the definition of covered loss. The Arch program removes that exclusion by endorsement. Some competitor policies go the opposite direction — attaching an absolute theft-of-funds exclusion that expressly eliminates coverage for customer account balances. That single page can undo everything the declarations page seems to promise.
One condition to know and follow: like most well-underwritten social engineering coverage, the Arch endorsement requires that wire instructions be verified through a different channel than the one the request arrived on — if the request came by email, confirm by phone using a known number before sending money. This mirrors FBI guidance on wire security, and frankly, every firm should follow a callback procedure whether or not their policy requires it. It's the single cheapest wire fraud control that exists.
Endorsements: Read to the Last Page
The endorsements stapled to the back of a cyber policy are where the most valuable enhancements — and the most damaging restrictions — live. On the enhancement side, the Arch program's endorsements add coverages like bricking (replacing hardware rendered useless by an attack), reputational harm (lost income from adverse publicity after a breach), cryptojacking (utility costs from hijacked systems mining cryptocurrency), extended 90-day claim reporting, and court attendance expense reimbursement.
On the restriction side, competitor endorsements are where you'll find ransomware sublimits, business interruption reductions, and — most dangerous of all for this industry — real-estate-specific exclusions: escrow and title activities exclusions, trust account exclusions, and closing/settlement services carve-outs that eliminate coverage precisely where a real estate firm needs it most. A cyber policy with an escrow activities exclusion is, for a title or escrow company, close to no cyber policy at all.
The rule is simple: the declarations page tells you what the policy appears to cover; the endorsements tell you what it actually covers.
Does My E&O Cover Cyber?
Real estate E&O policies are designed for errors, omissions, and negligence in professional services — not cyber events. Some E&O policies include a cyber endorsement, but the limits are typically small ($25,000–$50,000 is common) and the coverage narrow. Critically, real estate E&O policies generally do not cover third-party wire fraud claims arising from a breach of the firm's own email or network.
If wire fraud, ransomware, or a data breach worries you (it should), a stand-alone cyber policy is the answer. E&O and cyber are complements, not substitutes.
How Much Does Cyber Insurance Cost?
Pricing scales with the funds and data flowing through your firm. For a $500,000 policy limit, annual premiums for real estate firms typically fall in these ranges:
- Around $1M in revenue: $700–$1,200
- $1M–$5M: $1,200–$2,000
- $5M–$10M: $2,000–$3,000
- $10M–$20M: $3,000–$5,500
- $20M–$50M: $5,000–$15,500
- $50M+: $15,000–$25,000
In other words, a $500,000 cyber policy runs from roughly $700 a year for a small firm to about $25,000 for the largest brokerages. Higher limits and richer coverage raise those figures — and for a firm that holds client funds, that added protection is usually worth it. For a deeper breakdown of what drives the number, see our cyber liability insurance cost guide.
Put that against the exposure: cyber claims are routinely six figures, and a single misdirected closing wire can exceed the annual premium a hundred times over. Strong risk management practices — multi-factor authentication on all email, callback verification procedures, endpoint detection — will generally earn better pricing, which is one more reason accurate applications matter.
A word of caution on shopping by price alone: in cyber insurance, a meaningfully cheaper quote usually reflects meaningfully less coverage — a missing system failure trigger, a 30-day recovery period, a ransomware sublimit, or no customer funds protection. The premium difference is visible on day one; the coverage difference is only visible on claim day.
How to Get the Right Policy
PBI Group is an independent agency specializing in the residential real estate industry, and our exclusive Arch NetSafe® 2.0 cyber program was built around the exposures described in this guide — customer funds protection, real-estate-specific social engineering language, system failure business interruption, and no escrow or title activity exclusions.
Already have a cyber policy? We'll put it side by side with the Arch program, coverage part by coverage part, endorsement by endorsement — including the ones at the back. Email your policy to policycoveragereview@pbigroupsolutions.com or fill out our quick request a quote form and we'll be in touch.
This article is a general educational overview. Coverage terms, limits, sublimits, and conditions vary by policy and by insured. Always refer to the actual policy language, and consult a licensed insurance professional about your firm's specific situation.