Hablamos Español Insurance Companies We Work With
Home›Private Client›Personal Cyber Insurance
Personal Cyber Insurance

This one is for the household, not the company.

Personal cyber coverage responds to things that happen to a family. Identity theft, an extortion demand on a home computer, a fraudulent wire at a closing, a claim arising from something posted online. It is a different policy from the cyber liability a business buys, written for a different exposure, and neither one reaches the other.

Running a business as well? Read this page and the commercial cyber page. They are separate questions.

Personal cyber insurance is coverage written for a household and its family members, usually as an endorsement to a homeowners policy or as a standalone personal policy. It typically contemplates identity theft and restoration, cyber extortion, funds transfer and social engineering fraud, online liability and reputational harm, and damage involving personal devices and connected home systems. It is a separate thing from commercial cyber liability. A personal policy is not designed to respond to a business exposure, and a business policy is not designed to respond to a household one.

Read this first: personal is not commercial

We publish a large amount of material about cyber insurance for businesses. That material is about a different product and a different exposure, and the distinction is the most important thing on this page.

Commercial cyber liability is written for an organization. It contemplates a business's systems, its employees, its client and patient records, its regulatory duties, its contractual obligations, its income when operations stop, and its liability to third parties whose data it held. If you want that, it is covered on our business cyber insurance pages.

Personal cyber is written for a household. It contemplates a family's own money, a family's own identity, a family's own devices, and a family's own liability for what its members do online. It does not carry the machinery a business needs, and it is not priced or underwritten as though it did.

Say it plainly, because people get this wrong in both directions. A personal cyber policy does not respond to a business exposure. A commercial cyber policy does not respond to a household exposure. If a household member owns or operates a business, or works from home in a way that touches company systems or client records, the two need to be looked at separately and then read against each other. Business owners and executives covers that crossover more broadly.

The blurred cases are worth naming, because they are where the mistake actually happens: a home office holding client files, a side venture run from a personal laptop, a family member managing a small rental portfolio from a home computer, a board seat with documents on a personal device, and a family office or household staff member handling money on the family's behalf. Each of those is worth reviewing on both sides rather than assumed into one.

Identity theft and restoration

Identity theft is the exposure most people already associate with this coverage, and the restoration piece is usually the part that matters most.

The direct financial loss from a fraudulent account is often recoverable through the bank or card issuer. What is not recoverable that way is the work of putting the identity back together: the correspondence, the affidavits, the credit bureau disputes, the tax filings that now conflict, the time off work, the legal fees, and the months during which a mortgage or a refinance cannot move because the credit file is wrong.

Personal cyber forms commonly contemplate case management support, expenses incurred in restoring an identity, and some categories of lost income and legal cost. What is included, and at what limit, varies considerably from carrier to carrier. Worth confirming against the policy rather than assuming the phrase on the renewal notice means what it sounds like.

Related exposures that sometimes sit in the same section and sometimes do not: fraudulent tax filings in a family member's name, medical identity theft, a child's identity used to open credit, and identity misuse of a deceased relative during estate administration.

Cyber extortion in a household

Extortion is not only a business problem. Households hold decades of photographs, financial records, tax returns, appraisals, estate documents and correspondence, and they hold them on equipment that nobody patches on a schedule.

The household versions look like this. A home computer or network attached backup is encrypted and a payment is demanded. A cloud account is taken over and the family is locked out of its own archive. A family member is threatened with the release of material taken from a compromised account or device. A connected home system is interfered with and a demand follows.

Personal cyber forms that address extortion typically contemplate the response costs: the specialists who assess and remediate, the negotiation support, and the data restoration work. Some forms contemplate the extortion payment itself under stated conditions, and conditions in this area are usually meaningful rather than formalities. Prior consent requirements and notification requirements are common. This is a section where reading the actual wording matters more than usual, because the differences between forms are large.

Funds transfer and social engineering fraud

This is the section households most often need and least often have, and the closing wire is the reason.

The pattern is well documented and unglamorous. Somebody compromises or imitates an email account in a real estate transaction. The buyer receives wiring instructions that look correct, sent from an address that looks correct, referencing a transaction that is genuinely underway, often on the day of closing when there is no time to think. The money goes to the wrong account, and once it has moved it is frequently gone.

The same mechanism reaches households in other ways. A contractor's invoice with changed banking details during a renovation. An instruction that appears to come from a family member travelling abroad. A request that appears to come from an advisor, a trustee or a household manager. An instruction to a household employee who handles payments.

Personal cyber forms addressing this commonly contemplate the direct loss of funds transferred as a result of a fraudulent communication, subject to a limit that is often lower than the main policy limit and subject to conditions about verification. Whether a specific incident falls inside a specific form depends on the wording, the conditions and the facts. Eligibility and terms vary by carrier and by state, and this is not something to find out during a closing week.

The practical control is older than the exposure and still works. Call the title or escrow company on a number you obtained independently, before the wire, every time, and confirm the instructions verbally. Treat any change to banking details as suspect by default. If you are buying property, read this before the transaction rather than during it, alongside our page on custom homes if a build is involved.

Online liability and reputational harm

This is the section that does not feel like insurance until it does.

Household members post, comment, review, publish and share. A claim can arise from a review of a contractor, a comment about a neighbor, a post by a teenager, a dispute in a community forum, or material shared from an account that was not secured. Allegations in this area typically sound like defamation, invasion of privacy, or harassment.

Two things are worth understanding. First, a personal umbrella may address some categories of personal injury liability depending on the form, and may exclude others, and the wording differs. See personal umbrella insurance and confirm what your own form actually says. Second, personal cyber forms sometimes add an online liability component and sometimes contemplate the cost of responding to reputational harm directed at the family, including the specialists who handle it.

Where this matters most is households with a public profile, a family name attached to a business, board or charitable service, or family members who are active online in a professional capacity. Worth reviewing rather than assumed either way.

Connected home systems

A large modern home has more attack surface than a small office. Cameras, locks, thermostats, irrigation, water shutoff valves, lighting, alarm panels, audio, electric vehicle chargers, solar and battery systems, and whatever a home technology contractor installed and configured with default credentials five years ago.

Three distinct exposures come out of that, and they do not all sit in the same place on a policy.

  • Physical damage triggered through a connected system. A compromised water or climate control system causing damage inside the house. Whether the homeowners policy responds to the resulting damage is a question about the peril and the exclusions on that form, not about cyber coverage.
  • Damage to the devices and data themselves, which personal cyber forms sometimes contemplate, including the cost of restoring systems and data after an attack.
  • Privacy exposure, particularly with cameras and microphones inside a home, and particularly where household staff, guests or contractors are recorded.

For households with household staff, the intersection of cameras, recordings and employment matters is worth thinking about on its own terms. See domestic employee insurance.

The controls that actually matter

Insurance is the last line. Most household incidents are stopped by ordinary practice, and carriers increasingly ask about that practice when they underwrite.

  • Multi factor authentication on email first, then on banking, brokerage, cloud storage and anything that can reset a password. Email is the master key, because almost everything else recovers through it.
  • A password manager and unique passwords, particularly for financial accounts. Reused passwords are how one old breach turns into a current problem.
  • Verbal verification for money, on an independently obtained number, for every transfer and every change of banking detail, with no exception for urgency. Urgency is the tell.
  • Backups that are not attached to the network, and a check once in a while that they actually restore.
  • A separated home network for connected devices, with default credentials changed and firmware kept current.
  • A credit freeze at the credit bureaus for adults in the household, and for children where applicable.
  • A conversation with everyone in the house, including younger family members and anyone who works there, because the control only holds if the whole household practices it.
  • Separation between household and business equipment and accounts, which is both good practice and the thing that keeps the personal and commercial coverage questions clean.

What to check on your own policy

Before anything else, find out whether you have a personal cyber endorsement at all. Many households do not, and many of those who do have one at a limit set by default years ago.

Then read four things: the limit, the sublimits that apply to each section, the conditions attached to extortion and funds transfer, and the definition of who is an insured, which determines whether it reaches adult children, family members elsewhere, and household employees. Then ask the separate question of whether any business activity in the household needs its own policy.

Send us the declarations page and we will read it. A coverage review is educational, carries no pricing and no obligation, and quite often ends with us saying the existing program is fine. If you want terms, start with a private client quote. The private client overview shows how this sits alongside the home, the vehicles and the umbrella, and the learning center collects the underlying answers.

Frequently asked

Common questions.

Is personal cyber insurance the same as business cyber liability?
No. They are separate policies written for separate exposures. A personal cyber endorsement or policy is written around a household and its family members. A commercial cyber liability policy is written around a business, its systems, its records and its duties to third parties. A personal policy is not designed to respond to a business exposure, and a business policy is not designed to respond to a household one. If both exist in your life, both need to be read.
Doesn't my homeowners policy already cover this?
Standard homeowners policies were not written with these exposures in mind, and many carry no meaningful response to identity restoration, extortion, transfer fraud or online liability. Some carriers offer a personal cyber endorsement that adds them, with its own limits and conditions. Whether you have it, and what it actually includes, is worth confirming against your own declarations page rather than assuming.
Does it cover wire fraud at a home closing?
Funds transfer and social engineering fraud is a common component of personal cyber coverage, and a fraudulent closing wire is the example that comes up most. Whether a specific incident falls inside the wording depends on the form, the limit, the conditions and how the transfer happened. Eligibility and terms vary by carrier and by state. Read the form before a closing rather than after one.
What is cyber extortion coverage for, in a household?
Ransomware and extortion reach households through home computers, backup drives, family photo archives and connected home systems. Coverage in this area typically contemplates the response costs and, on some forms, the payment itself under stated conditions. Forms differ substantially and conditions usually apply, so confirm against the policy.
I run a business from home. Which policy responds?
That depends on whether the incident touched the household or the business, and the line is not always obvious. A home office that holds client records, processes payments or connects to a company network is a business exposure even though it sits in a house. That combination is worth reviewing on both sides, because the assumption that one policy will reach the other is the most common mistake we see.
Do controls affect eligibility?
Frequently. Carriers ask about multi-factor authentication, backups, password practice and how connected devices are managed, and the answers can affect terms. Improving them is worth doing regardless of insurance, because most household incidents are stopped by ordinary controls rather than by a policy.
Compare your coverage

Do you have personal cyber coverage at all?

Send the declarations page. We will tell you whether a personal cyber endorsement exists, what the limits and sublimits are, what conditions attach to extortion and funds transfer, and whether any business exposure in the household needs its own separate policy.

We check whether a personal cyber endorsement exists at all
We read the limits, sublimits and conditions rather than the brochure
We separate the household exposure from any business exposure
Educational, with no pricing and no obligation

Vantage Point Risk is an independent insurance agency. This page is general information about personal cyber coverage for households, not advice about your policy, and it does not confirm or deny coverage. Personal cyber coverage and commercial cyber liability are separate products written for separate exposures. Coverage availability, eligibility, limits, forms, endorsements and settlement terms vary by carrier, by form and by state, and are subject to underwriting and to the policy as issued. Mention of an insurance company does not guarantee availability, appointment status, eligibility, or placement.

Independent, on your side

The household exposure needs its own answer.

Identity, extortion, transfer fraud and online liability are not what a homeowners policy was built for, and they are not what a business cyber policy was built for either. Let us read what you actually have.