
Independent since 2011 · Large Carrier Partner Network · CLU · ChFC · SC · NC · GA
Licensed in South Carolina · North Carolina · Georgia
By Mark Turley, Owner — Priority Insurance LLC
Independent agent serving the Upstate since 2011 · Published September 14, 2026
I'm going to start this one with a story I'd rather not have to tell, because it happened to me — right here in my own agency.
I had an administrator on my team who had access to all of our business banking and a lot of sensitive information. One day a notice popped up on her email that looked like it came from Microsoft, asking her to re-enter her password to log back in. She did what any of us might do in a busy moment. It wasn't Microsoft. It was cyber fraud, and that one password was all it took.
From there, the criminals got into our system. They stole her bank account information, redirected her direct deposit to a fraudulent account, and took two of her paychecks before we caught it. We were lucky in one important way: our client files weren't touched. But because an intruder had been inside a system that held personal information, South Carolina law kicked in and required us to follow a specific protocol to protect everyone involved.
Handling that the right way — through a cyber law firm, with all the steps the state requires — cost more than $50,000. I didn't pay that out of my own pocket, because I carry Cyber Liability insurance and it covered the response. Without it, that would have been a $50,000-plus bill landing on my desk with no warning.
That's why I'm writing this to my clients. This really happened, and it happened to me. Here's what every Upstate business owner needs to understand about it.
"We're too small to be a target" is why you're a target
For years I heard business owners across the Upstate say it, and I'd be lying if I told you the thought never crossed my own mind: we're too small for anyone to bother with. Then it happened in my office. The truth is that criminals aren't only chasing the big names in the headlines — they run automated attacks that hunt for the easiest way in, and a small business in Simpsonville or Mauldin often fits the bill perfectly: real customer data, real money moving through the accounts, and far less security than a large corporation with a full IT department. You've got what they want and fewer locks on the door.
The numbers back it up. Industry studies consistently estimate that a large share of cyberattacks are aimed at small businesses, that a majority of small firms report an incident in a given year, and yet only a small fraction actually carry cyber coverage. That last gap is the one that keeps me up at night on behalf of my clients, because the businesses least able to absorb the hit are the ones least likely to be protected.
It's not the ransom that closes the doors — it's everything after
When people imagine a cyberattack, they picture a ransom demand. But the ransom is often the smallest line on the bill. Here's what actually piles up after an incident:
- Downtime. Every hour your systems are locked is an hour you can't book jobs, run cards, or serve customers.
- Forensics. You have to hire specialists to figure out how they got in and what they touched — you can't legally guess.
- Notification. If personal information was exposed, the law requires you to tell the people affected. Printing, mailing, and staffing that is a real cost.
- Credit monitoring. It's now standard to offer monitoring to affected customers, and that's on your dime.
- Legal and regulatory. Attorneys to steer you through your obligations, plus any penalties.
- Reputation. The hardest to measure and often the most damaging — customers who don't come back.
For a typical small business, a serious incident routinely runs well into six figures once all of that is added up. It's no surprise that in survey after survey, a striking share of small-business owners say an attack of that size could put them out of business for good.
"Doesn't my business policy already cover this?"
This is the part that surprises people the most, so I want to be clear about it. Your general liability policy and even a standard business owners policy (BOP) were built for the physical world — a customer slips on your floor, a pipe bursts, your delivery van backs into something. When it comes to data breaches and cyber events, most of these policies either say nothing or specifically exclude them. Under the standard industry forms, electronic data isn't treated as tangible property, so the loss of it simply isn't a covered claim.
Some business owners policies now bolt on a small cyber endorsement, and that sounds reassuring — until you see the limit. A little breach-response amount tucked into a BOP usually won't stretch to cover the incident that actually happens to a business holding customer records or moving money. The exposure that can genuinely sink a small company tends to sit right in that gap, and the worst time to discover it is at claim time.
What cyber liability insurance actually covers
A real cyber policy is built in two halves, and you want both.
Your own losses (first-party). This is the money you spend cleaning up your own mess: breach response and forensics, the cost of notifying affected people, credit monitoring, lost income while you're shut down, restoring your data and systems, and ransomware or extortion response with experts who negotiate these situations for a living.
Claims from others (third-party liability). This is where the "liability" in the name earns its keep. If a customer, patient, or business partner comes after you because their information was exposed on your watch, this side pays to defend you and covers the damages. It also helps with the cost of dealing with regulators — and in our state, that part isn't optional.
Why South Carolina law makes this hard to skip
This is the exact law that kicked in the day we discovered the fraud in my office. South Carolina has a data breach notification law on the books — S.C. Code § 39-1-90, part of the state's Financial Identity Fraud and Identity Theft Protection Act. In plain English: any business operating in South Carolina that owns or licenses computerized personal information has to notify the residents affected when there's a breach, "in the most expedient time possible and without unreasonable delay." If more than 1,000 residents are involved, you also have to notify the South Carolina Department of Consumer Affairs and the credit reporting agencies.
The law also allows residents harmed by a breach to pursue damages, and it carries penalties for willful violations. So this isn't just a "nice to have" — the moment customer data walks out the door, you have legal obligations that cost real money to meet, before anyone even files suit. Cyber coverage is what pays for that response instead of you writing the checks out of the business account. For me, that was the difference between a $50,000-plus obligation and a claim I simply reported.
Who in the Upstate actually needs this
More businesses than realize it. A few examples I see every week:
- A dental or accounting office in Simpsonville storing Social Security numbers, health records, and financial details.
- A Main Street shop or online seller in Greenville taking card payments and keeping customer accounts.
- A contractor or HVAC company in Mauldin with customer names, addresses, and card numbers sitting in a scheduling or invoicing app.
If you hold information about your customers or move money electronically — and nearly every business does now — you're carrying this exposure whether or not you've insured it.
The wire-transfer trap most owners miss
Here's the scenario I see cost Upstate businesses real money more than any dramatic "hack": a convincing email. Someone impersonates a vendor, or the owner, and talks an employee into wiring funds or quietly changing the account where payments go. It's called social engineering, and a lot of base cyber policies don't automatically cover it — it takes a specific social engineering or fraudulent-instruction endorsement. If your business ever sends payments based on emailed instructions, ask about that coverage by name. It's one of the most common gaps and one of the easiest to close.
What it costs — and how we help
Good news for small businesses: cyber coverage is one of the more affordable lines relative to everything it protects. In my own case, the policy that absorbed that $50,000-plus response costs me less than $1,000 a year. Let that sink in — a bill that could have ended a smaller business, covered for the price of a modest monthly expense. Your premium depends mostly on your revenue, the kind of data you hold, and the basic safeguards you already have in place — things like multi-factor login and regular backups often lower your cost, and some carriers now require them. As an independent agency, we shop it across our carrier network and match the coverage to your real exposure rather than selling you a one-size box.
So here's my honest advice, owner to owner: if you run a small business, carry this coverage. And if you're the customer handing your personal information to a small business, ask whether they carry it — because their protocol becomes your protection. I learned that from the other side of the desk, and I'd rather you learn it from me than the way I did.
If you run a business anywhere in Greenville, Greer, Taylors, Simpsonville, Mauldin, Easley, Anderson, Spartanburg, or the surrounding Upstate, let's take fifteen minutes to look at where you're exposed. It's a short conversation now that can save you a very bad month later.
See where your business is exposed
Fifteen minutes now beats a very bad month later. We'll shop cyber coverage across our carrier network and match it to your real risk.
Mark Turley is the owner of Priority Insurance LLC, an independent insurance agency in Greenville, SC serving the Upstate since 2011. Priority shops a large network of top-rated carriers across South Carolina, North Carolina, and Georgia, and has a CLU · ChFC–credentialed advisor on staff for life and financial planning. Office: 140 Milestone Way, Suite A, Greenville, SC 29615. Phone: (864) 297-9744.
This article is general information for South Carolina and North Carolina business owners and is not legal advice or a statement of coverage. Workers' compensation rules, employee thresholds, and state-set payroll figures change and vary by situation and entity type. Coverage depends on the specific terms of your policies. Contact Priority Insurance or the applicable state Workers' Compensation Commission to confirm what applies to your business.
Related coverage from Priority Insurance
Business Insurance | Business Owners Policy (BOP) | General Liability Insurance | Professional Liability (E&O)









