Free tool
Insurance ComparisonCompare coverage stacks cleaning contractors actually need.
$50,000
average total cost of a ransomware attack on a small business, including IT recovery, downtime, and mandatory breach notification
Free Tool
Assess your cleaning business's cyber risk exposure based on data volume and technology use.
Cleaning companies don't think of themselves as cyber targets. No financial records to steal, no intellectual property to ransom, just mop schedules and client addresses. The reality: any business with email, a scheduling system, client payment data, and internet connectivity is a viable ransomware target. Attackers don't discriminate by industry; they automate attacks against all small businesses, knowing that few have enterprise-grade security.
When an attack succeeds (or when an employee emails a client list to the wrong address) cyber liability insurance pays the recovery costs. Whether cleaning businesses actually need it depends on what data they hold and what contracts they service.
What Data Cleaning Companies Actually Hold
Before buying cyber coverage, assess what you're protecting:
- Client contact and access information: Key codes, alarm codes, facility access schedules for dozens or hundreds of buildings. In the wrong hands, this is a physical security liability for clients, and a lawsuit liability for you.
- Employee personal information: Social Security numbers, direct deposit banking info, I-9 documentation, tax records
- Payment card data: If you accept credit cards directly (not through Stripe/Square), you may hold cardholder data subject to PCI-DSS compliance
- Client contracts and pricing: Commercially sensitive information that clients may not want exposed
- Scheduling and CRM data: Client history, contact preferences, service logs
This data profile isn't as sensitive as a healthcare company's, but it's enough to trigger breach notification obligations under most state breach notification laws, and enough to expose your clients to physical security risks if access codes are compromised.
What Cyber Liability Insurance Covers
Cyber liability policies are structured with first-party and third-party coverage components:
| Coverage Component | Type | What It Pays | Relevant Scenario |
|---|---|---|---|
| Ransomware/cyber extortion | First-party | Ransom payment, negotiation costs | Ransomware locks your scheduling system |
| Business interruption | First-party | Lost revenue during system downtime | Scheduling system down for 5 days |
| Data restoration | First-party | IT forensics and data recovery costs | Database corrupted by malware |
| Breach notification | First-party | Legal, notification, credit monitoring costs | Employee data exposed in breach |
| Network security liability | Third-party | Client claims for breach of your system | Client's access codes stolen from your CRM |
| Privacy liability | Third-party | Regulatory fines and third-party claims | Accidental exposure of client PII |
| Social engineering/fraud | First-party | Losses from fraudulent wire transfers | CFO impersonation scam targets your AP |
Do Cleaning Businesses Actually Need Cyber Coverage?
The answer depends on four factors:
1. Contract requirements: Healthcare, financial, and government contracts increasingly require cyber liability. If you service a hospital or bank, expect to see cyber insurance minimums in the contract's insurance exhibit.
2. Volume of sensitive access data: If you hold building access codes for 50+ commercial clients, a breach creates physical security exposure. A unique liability that general business insurance doesn't cover.
3. Technology dependence: If your scheduling, billing, or communication systems are cloud-based and you'd lose significant revenue if they went down for a week, business interruption cyber coverage has real value.
4. Employee count and data volume: The more employees you have, the more personal identifying information you hold (SSNs for I-9s, banking for payroll), and the higher your breach notification cost exposure.
Most cleaning businesses serving commercial accounts with 10+ employees and cloud-based scheduling systems should carry at least $250,000–$500,000 in cyber coverage.
| Category | Value |
|---|---|
| Ransomware | $50K |
| Business Email Compromise | $65K |
| Data breach notification | $35K |
| System downtime | $20K |
What Cyber Insurance Costs for Cleaning Businesses
Cyber liability premiums for small cleaning businesses are modest:
- $250,000 limit: $400–$800/year
- $500,000 limit: $700–$1,400/year
- $1,000,000 limit: $1,200–$2,500/year
Premiums are affected by: number of employees, annual revenue, data sensitivity, security controls in place (MFA enabled, backup systems, employee training), and whether you've had prior incidents. Carriers now ask detailed security questionnaires, honest answers are critical, as misrepresentation can void coverage.
Minimum Security Controls to Obtain Coverage
Most cyber insurers now require baseline security controls to issue coverage to small businesses:
- Multi-factor authentication (MFA) on email and all cloud accounts, required by virtually all carriers
- Regular data backups (tested, offsite or cloud, not connected to primary systems during backups)
- Email security (spam filtering, anti-phishing controls)
- Software and OS updates (unpatched systems dramatically increase risk)
- Employee security training (phishing awareness, most breaches start with a phishing email)
These aren't burdensome for cleaning businesses. Most are free or low-cost configurations of existing systems.
| Business Type | Priority Level | Recommended Limit | Key Reason |
|---|---|---|---|
| Residential cleaning, cash-based, under 5 employees | Low | $100–$250K if any tech used | Minimal sensitive data held |
| Commercial cleaning, 10–25 employees, cloud scheduling | Medium | $500K | Employee data + client access codes |
| Healthcare or financial sector cleaning | High | $1M+ | Contract requirements + sensitive facility access |
| Government contract cleaning | High | $1M+ | Federal contract insurance requirements |
Internal Link Network
- Hub: Insurance for Cleaning Businesses: The Complete Guide
- Related: Cleaning Business Insurance Gap Analysis
- Related: Government Contract Insurance for Cleaning Companies
- Tool: Cyber Risk Assessment
- Site: Opora Supply Business Resources
Frequently Asked Questions
My general liability policy is active, am I covered if client data gets breached?
No. Commercial general liability was built around bodily injury and physical property damage, and the standard ISO form (CG 00 01) carves out "electronic data" losses by name. A breach that exposes client records, building access information, or payment data sits entirely outside that policy. Closing the gap takes a standalone cyber liability policy or a cyber endorsement added to your business owner's policy.
We accept credit cards from commercial accounts. Does that make cyber insurance mandatory?
No law requires it, but the moment you process cards you fall under PCI-DSS compliance obligations. If cardholder data is exposed in a breach, the card brands can assess fines ranging from $5,000 to $100,000 per month, and they can revoke your ability to accept cards at all. The practical answer is both: PCI compliance lowers the odds of a breach, and cyber insurance absorbs the cost when one happens anyway.
I think someone got into our systems overnight. What happens in the first hour?
Resist the urge to investigate or clean things up yourself, well-meaning IT work routinely destroys the forensic evidence your carrier will need. Call the incident response hotline printed on your cyber policy first, since that call brings in the specialists and puts the claim in motion. Then disconnect the affected systems from the network and notify your insurance broker. Do not pay any ransom demand before that team has weighed in.
We're a four-person crew with no IT staff. Is this exposure real for a shop our size?
Headcount doesn't change the coverage math. The electronic data exclusion in the standard CGL form applies to a four-person operation exactly as it applies to a regional contractor, so a small cleaning business holding client access codes, employee files, or card payments has nothing standing behind it. If you run cards, PCI-DSS applies to you too. The remedy is identical at any size: a cyber endorsement on the BOP or a separate cyber policy.
How we built this guide
Opora editorial sources from BLS OEWS wage tables, ISSA-447 production rates, NCCI workers' compensation classifications, EPA List N, OSHA 29 CFR standards, and primary state regulatory filings. We don't recycle blog posts. We audit primary documents.
Methodology · Editorial standards · Corrections policy · About Opora
