Church Cyber Liability Insurance: Cost, Coverage, and MA Ch. 93H Rules

Church cyber liability insurance for a typical Massachusetts congregation runs $800 to $3,500 per year. It covers the direct costs of a data breach, a ransomware attack, wire fraud from a compromised email account, and phishing incidents that trace back to your online giving, member database, or staff email. In Massachusetts, this coverage is not optional in any meaningful sense: every church that stores personal data on a Massachusetts resident is required by state law (Ch. 93H) to maintain a Written Information Security Program, and the cyber policy is what pays when that program is tested.

This guide answers the four questions congregational treasurers, executive pastors, and church boards ask most: what does it cost, what does it cover, does our church legally need it, and what is the difference between the cheap package endorsement and a real standalone policy.

How much does church cyber liability insurance cost in Massachusetts?

Pricing scales with three factors: the number of people whose data you store, the systems you run (online giving, member portal, email, cloud storage), and whether you operate additional programs like a preschool or school. Here is what typical Massachusetts churches pay for a standalone cyber policy with the limits that actually respond to a real incident:

Church size Typical annual premium Recommended limits
Under 150 members$800 to $1,500$1M aggregate
150 to 500 members$1,200 to $2,500$1M aggregate, $500K ransomware, $250K social engineering
500 to 1,500 members$1,800 to $3,500$2M aggregate, $1M ransomware, $500K social engineering
Church with preschool or school$2,500 to $5,000+$2M to $3M aggregate, tuition-billing data endorsement

Cyber premium moves less on square footage and more on data volume. A 200-member country church that only takes offering-plate cash and has no member database can sit at the low end of the table. A 200-member church running full online giving through a third-party vendor, a member portal, and a preschool sits at the high end. Underwriters ask about your systems, not your pews.

Do Massachusetts churches legally need cyber liability insurance?

Massachusetts General Laws Chapter 93H is the strictest state data protection statute in the country. It applies to every entity, of every size, of every tax status, that owns or licenses personal information about a Massachusetts resident. Personal information under 93H includes a person's first name (or first initial) and last name in combination with a Social Security number, driver's license number, or financial account number. It also picks up date of birth in some combinations.

Every Massachusetts church that keeps this data on staff, on volunteers, on scholarship recipients, on preschool families, on payroll, or on major donors is subject to 93H. There is no exception for religious organizations and no exception based on member count.

93H requires two things. First, a Written Information Security Program (WISP) that documents administrative, technical, and physical safeguards for the personal information your church holds. Second, breach notification to every affected resident, to the Attorney General, and to the Office of Consumer Affairs and Business Regulation if a breach occurs.

The insurance question is what happens when a church without a WISP has a breach. Legal defense, forensic response, notification, credit monitoring, and possible fines are all costs the church incurs regardless of insurance. With a cyber policy, most of these costs are covered. Without one, they land on the operating budget and, in escalated cases, on the personal liability of the board (which is why D&O insurance and cyber insurance work together for churches).

Practically: no Massachusetts church that runs email, online giving, or a member database should be uninsured for cyber. The premium is one to two thousand dollars. A single incident easily runs six figures.

What does church cyber liability insurance cover?

A cyber policy is built in two halves. The first-party half covers what the church spends after an incident. The third-party half covers what the church owes to others.

First-party coverage. This is the money that flows out of the church's bank account immediately after a breach. It includes forensic investigation to figure out what happened (typically $25,000 to $80,000 for a church-scale incident), breach notification to every affected member and every required agency, credit monitoring services for the affected population (usually 12 to 24 months at $10 to $30 per person per year), ransomware payment and negotiation if the church chooses to pay, data restoration from backup or from reconstruction, and business interruption for the days or weeks the church cannot process giving or run operations.

Third-party coverage. This is what the church owes to people or agencies after the breach. It includes defense costs for lawsuits by affected members, regulatory defense and fines from the Massachusetts Attorney General or federal regulators, PCI-DSS fines if the breach involves payment card data, and settlements or judgments within policy limits.

Two coverage parts matter far more than the rest for churches. Social engineering (also called crime endorsement or funds transfer fraud) covers wire fraud through business email compromise, which is the single most common church cyber loss. Ransomware coverage with a sublimit of at least 50 percent of the aggregate covers the increasingly common attack pattern of a $50,000 to $150,000 ransom demand against a mid-sized congregation without adequate backups. Missing either of these coverages effectively means the policy will not respond to what actually goes wrong.

Cyber endorsement on your package policy vs standalone cyber policy: which does your church need?

Almost every church package policy sold today includes a cyber endorsement of some kind. These endorsements are cheap (often $100 to $300 in additional premium) and they look reassuring on the declarations page. In practice, most of them are inadequate for what a real church breach costs. The comparison:

Coverage element Typical package endorsement Standalone cyber policy
Aggregate limit$25,000 to $100,000$1,000,000 to $3,000,000
RansomwareOften sublimited to $10,000 to $25,000 or excluded entirely$500,000 to full aggregate
Social engineering / wire fraudUsually excluded$100,000 to $500,000 by endorsement
Breach response servicesBasic notification onlyPanel of forensic, legal, and PR vendors on retainer
Business interruption waiting period24 to 72 hours6 to 12 hours
Regulatory defenseOften not itemizedItemized with dedicated sublimit

A package endorsement with a $50,000 aggregate can be exhausted by the forensic investigation alone, before a single notification letter is mailed or a single dollar of credit monitoring is paid. For any Massachusetts church that runs online giving or a member database, the standalone policy is the correct product. The package endorsement is a placeholder that should be replaced, not a coverage that should be relied on.

Four real scenarios where church cyber coverage matters

Wire fraud through business email compromise. An attacker compromises the treasurer's email account, watches the message pattern for several weeks, and then sends a wire request to the bookkeeper that matches the tone and timing of a legitimate vendor payment. The bookkeeper wires $35,000. The general liability policy does not respond. The crime endorsement on the package (if the church has one) sometimes does, but only if the endorsement includes social engineering, which most do not. A standalone cyber policy with a social engineering endorsement covers this.

Ransomware against the operational network. The church's primary file server is encrypted overnight. Backups are 30 days out of date. The ransom demand is $80,000 in Bitcoin. The church is offline for ten days, missing an entire Sunday of online giving and unable to process payroll on time. The cyber policy covers the ransom payment (subject to policy terms and current federal guidance), the forensic engagement, the restoration, and the business interruption.

Vendor data breach. The church's giving platform vendor is breached. Member records, including names, emails, addresses, and in some cases the last four digits of payment cards, are exposed. The church has independent notification obligations under 93H even though it was the vendor that was breached. The cyber policy covers the church's notification costs, credit monitoring for affected members, and regulatory defense.

Phishing of staff credentials. A staff member clicks a phishing link and enters credentials into a fake login page. The attacker then uses that access to send fraudulent invoice requests to congregation members, several of whom pay. Some members lose meaningful sums. The church has potential legal exposure for failing to prevent the credential compromise. The cyber policy covers defense, and depending on the endorsements, indemnity within limits.

Frequently asked questions about church cyber liability insurance

Does our church really need cyber insurance if we do not process credit cards ourselves? Yes, in almost every case. Cyber exposure is not limited to payment card data. It includes any personal information your church holds on staff, volunteers, scholarship recipients, preschool families, or major donors. Massachusetts Ch. 93H applies to all of that data.

Is cyber insurance the same as identity theft insurance? No. Identity theft insurance covers an individual whose personal information was misused. Cyber liability insurance covers the organization that held the data. They are different products for different parties.

Will our cyber policy pay the ransom if we are hit with ransomware? Most policies will, subject to the current federal guidance on ransomware payments (the Treasury Department's OFAC advisory has significantly complicated ransom payments to sanctioned entities), the sublimit for ransomware, and the insurer's requirement that the church use the panel of negotiation firms. Some policies have moved to a "reimbursement" model where the church pays and is reimbursed.

What if the breach originates from a vendor rather than from the church directly? The church still has independent notification obligations under 93H if the exposed data is Massachusetts resident data. The cyber policy covers the church's response costs. Whether the church can recover from the vendor is a separate question of vendor contracts and the vendor's own insurance.

Does D&O insurance cover cyber losses? Rarely, and only for very specific claims. D&O covers board decisions and management liability. If a lawsuit alleges the board failed to implement reasonable cybersecurity controls, some claims might reach D&O. But the operational cost of a breach (forensics, notification, credit monitoring, ransomware) is squarely cyber policy territory, not D&O.

How long does the cyber underwriting process take? A standalone cyber policy for a church typically takes seven to fourteen days from application to bound coverage. Underwriters ask about backup procedures, multi-factor authentication on email, whether the church uses a shared password manager, and how the online giving platform authenticates. Churches without MFA on email are increasingly declined by top-tier cyber carriers.

Does our church need a WISP if we already have cyber insurance? Yes. The WISP is required by Massachusetts law regardless of insurance. Insurance responds to a breach; the WISP is what the state expects the church to have documented in advance. Most cyber policies now require a WISP as a condition of coverage.

If you would like a second opinion on whether your church cyber liability coverage matches the exposure your operations actually carry, contact us for a free church risk assessment.

Contact Hale Street Insurance at 978.712.0111 or [email protected] for a free church insurance review. You can also visit our church insurance page or request a quote to get started.


Jake Lubinski is the founder of Hale Street Insurance and a licensed insurance broker with years of church board and stewardship experience. Based in Boxford, MA he works with churches throughout Massachusetts and the US to build insurance and risk programs designed around how ministry actually operates. Reach Jake at [email protected] or 978.712.0111.


Related reading: How Much Does Church Insurance Cost in Massachusetts? (2026 Guide) | Church Directors and Officers Insurance | Church Employment Practices Liability: HR Risks | Church Endowment Fund Governance: Financial Risks

Previous
Previous

Church Umbrella Insurance: Limits, Cost, and Who Needs It in 2026

Next
Next

Church Insurance in Boston, Massachusetts