Insurance

Cyber Insurance for Small Business: What $1,740 a Year Actually Buys You

62% of businesses now carry cyber insurance, yet only 1 in 5 small firms do. With the average claim at $221,000, here is what the policy covers and what it costs.

A brass padlock resting on a laptop keyboard in red and green light
A padlock on a laptop keyboard: cyber insurance is the financial backstop for the digital risks you cannot fully prevent. (Photo: Unsplash)
Advertisement

Relevant ads will appear here once AdSense is connected.

A few months ago, a friend who runs a 12-person e-commerce brand in Austin called me in a panic. Someone had hijacked her email, sent fake invoices to three of her suppliers, and one of them had already wired $18,000. Her IT guy (a freelancer she pays by the hour) told her the mailbox was compromised for at least two weeks. She asked me a question I hear a lot now: "Is there insurance for this?"

There is. It's called cyber insurance, and I spent the last month digging into what it actually covers, what it costs, and whether a small business should buy it. I read the industry claims reports, compared quotes, and talked to two independent brokers who sell this stuff every day. What I found surprised me: the median small business pays around $1,740 a year, the average claim costs $221,000, and most of the businesses who get hit never thought they were a target.

This guide is the short version of everything I learned. No jargon, no scare tactics, just the numbers and the fine print that matters.

What it actually covers (first-party vs third-party)

Cyber insurance splits into two halves, and the split matters more than the brand name on the policy. First-party coverage pays for your own losses: getting your systems back online, notifying customers, paying a forensics firm to figure out what happened. Third-party coverage pays when someone else comes after you: a customer sues because their data leaked, or a regulator fines you.

Think of it like car insurance. First-party is the repair bill for your own car. Third-party is the damage you pay to the other driver. Most small business cyber policies bundle both, but the limits for each can be very different, so always check.

First-party: your own recovery bill

This is the part most small businesses actually use. When ransomware locks your files or a phishing email empties your accounts, first-party coverage can pay for the incident response team, the forensic investigation, legal advice on your notification duties, customer notification letters, credit monitoring for affected customers, lost income while you're down, and in some policies, the ransom payment itself.

The NetDiligence 2025 Cyber Claims Report, which analyzed 10,402 claims from 2020 to 2024, found the five-year average cost of SME cyber claims was $264,000, up 29% over the period. Ransomware and business email compromise together made up about half of all claims. The five-year average ransomware claim for SMEs was $631,000. Those numbers are why insurers now spend so much on the "get us in early" hotline feature: the faster their response team gets involved, the cheaper the claim. Source: Scott Insurance / NetDiligence

Third-party: lawsuits and regulatory trouble

Third-party coverage handles the legal fallout. If customer data you hold gets stolen and those customers sue, the policy can pay for your defense and settlements. It also covers regulatory investigations and fines where the law allows insurance to pay them. This is the part that has been growing fast. Chubb reports that privacy lawsuits are now the primary cyber risk, with claims tripling between 2020 and 2025.

For a small business, third-party exposure usually comes from one place: you hold other people's data. Email addresses, payment details, employee records, client files. If you hold it, you can be liable for losing it. A 12-person shop with a mailing list of 40,000 customers has real third-party exposure, even if the revenue is modest.

Pro tip: When you compare quotes, ask which of these limits is first-party and which is third-party. A "$1M policy" can mean $1M for your own losses and $250K for lawsuits, or the other way around. The split decides what you actually get in a crisis.

What it costs in 2026

Let's talk money, because this is where cyber insurance beats most people's expectations. The median annual premium for firms with fewer than 250 employees is about $1,740, according to industry data compiled by SQ Magazine. That's roughly $145 a month. Less than most businesses spend on coffee.

The US average for small businesses runs closer to $1,550 a year. In the UK, micro-businesses can find cover from around £175 a year, while a typical small business pays £350 to £5,000 depending on size and risk. Source: MacUser

Person typing on a laptop displaying green security monitoring dashboards
Security monitoring is expensive. A policy that pays for the response team is often the most valuable line in the contract. (Photo: Pexels)

Here's the catch: premiums are expected to rise 15 to 20% in 2026. Claims keep getting bigger (average cyber claim now $221,000, ransomware incidents averaging $508,000 per event), and insurers are repricing to match. That $1,740 median won't stay $1,740 for long.

Business sizeTypical annual premium (US)Common coverage limit
Micro (1 to 5 staff)$600 - $1,200$250K - $500K
Small (6 to 50 staff)$1,200 - $2,500$1M
Growing (51 to 250 staff)$2,500 - $7,500$1M - $3M

What moves your quote up or down? Revenue and headcount set the baseline, but the big levers are your industry (healthcare and finance pay more), how much sensitive data you hold, your security controls, and your claims history. A 10-person marketing agency with basic controls lands near the middle of the table. A 10-person dental practice holding patient records pays more, because the data is more valuable and more regulated.

Pro tip: Get quotes for two limit levels, like $500K and $1M. The price jump is often smaller than you'd expect, sometimes 20 to 30% more premium for double the limit. If the jump is small, take the higher limit.

Why small businesses get attacked anyway

Here is the stat that should end the "we're too small to be a target" argument. Only 10 to 20% of SMEs buy cyber insurance, even though 62% of global businesses now carry a dedicated cyber policy, up from 49% in 2024. Source: SQ Magazine Attackers know the small end of the market is underinsured and underprotected. That's exactly why they go there.

A masked figure typing on a backlit keyboard next to a glowing monitor
Attackers run automated campaigns that hit thousands of small businesses at once. Size doesn't protect you; it just makes you quieter. (Photo: Pexels)

Most attacks on small businesses aren't personal. Nobody picked your company. Automated botnets scan the internet for vulnerable servers, phishing kits blast a million emails, and ransomware gangs buy access from brokers who specialize in small networks. My friend's e-commerce brand wasn't targeted. Her supplier's accounts payable inbox just looked like a normal invoice thread, and someone clicked.

The human factor is the throughline in almost every claim. Roughly 95% of breaches involve human error: a clicked link, a reused password, a misconfigured cloud bucket. That is not a technology problem you can buy your way out of with one firewall. It's a people problem, and insurance is priced around that reality.

There's a second reason small businesses skip coverage: nobody ever asked them to. Big companies buy cyber insurance because their clients, lenders, or regulators demand it. Small firms don't get asked, so they don't shop. But that's changing fast. More vendor contracts and client RFPs now include a cyber insurance clause, and "we don't have it" is starting to cost people deals.

Pro tip: Check your biggest client contracts for an insurance clause before you shop. Some require $1M in cyber coverage specifically. It's cheaper to buy the right limit once than to upgrade mid-contract when a client asks.

What insurers demand before they cover you

This part surprised me the most. Cyber insurance is not like buying car insurance online in ten minutes. Insurers now typically require multi-factor authentication (MFA) and reliable backups before they'll cover you at all. If you don't have both, expect a decline or a quote so high it's effectively a no.

The application reads like a security audit. Typical questions: Do you use MFA on email and remote access? Do you have offline or immutable backups? Do you patch critical vulnerabilities within 30 days? Do you train staff on phishing? Do you use endpoint detection? Answer "no" to too many and you don't get a policy. The insurers learned the hard way that covering unprotected businesses loses money.

IT professional with glasses reviewing terminal screens full of code
Insurers want evidence, not promises: MFA logs, backup test results, and patch records are the new application form. (Photo: Pexels)

The good news: these requirements are also just good security, and most of them cost little. MFA is free on Google Workspace and Microsoft 365. A 3-2-1 backup setup (three copies, two media types, one offline) runs under $100 a month for most small businesses. One broker told me that businesses with MFA, tested backups, and basic phishing training routinely get quotes 30 to 40% lower than similar businesses without them.

Be honest on the application. Insurers investigate claims, and if they find you claimed MFA was enabled when it wasn't, they can deny the claim. The application is part of the contract. Treat it like a tax return, not a survey.

Pro tip: Turn on MFA and set up tested backups before you request quotes, not after. You'll qualify for more insurers, get lower prices, and the application takes half the time.

What it doesn't cover

Cyber insurance is broad, but it has edges, and you should know them before you buy. It generally doesn't cover losses from your own intentional wrongdoing, and it won't pay fines in jurisdictions where insuring fines is illegal. Property damage and bodily injury from a cyber event usually sit in a gray area, and many policies exclude them or cap them tightly.

Masked hacker at a desk with multiple monitors showing system data in red light
Social engineering losses are the most common small business claim, and the most commonly underinsured one. Check your sublimit. (Photo: Pexels)

The exclusion that bites small businesses most is the sublimit. Many policies cover social engineering (the fake-invoice scam that hit my friend) but cap it far below the main limit. Your policy might say $1M, while the social engineering sublimit is $100K. Business email compromise is one of the two biggest claim drivers for SMEs, so a low sublimit here can leave the most likely loss half uncovered.

War and state-sponsored attack exclusions also exist in many policies, though they rarely affect small business claims in practice. And cyber insurance won't cover the slow bleed: lost customers who quietly leave, reputational damage you can't put a number on, or the weekends you spend rebuilding instead of selling. The policy pays for defined costs, not for the full experience of being attacked.

How to buy the right policy in 5 steps

Buying cyber insurance is a two-week project, not a two-hour one. Here's the process that the brokers I spoke with recommended for small businesses buying for the first time.

Step 1: Fix the basics first

Turn on MFA everywhere, set up tested backups, and run a phishing test with your team. Do this before you apply. It takes a weekend for a small team, and it's the single biggest factor in both approval and price. Document what you did, because you'll need to describe it on the application.

Step 2: Estimate your real exposure

Count what you'd lose in a bad month: how much revenue stops if your systems are down for two weeks, how many customer records you'd have to notify, and what a forensics firm costs in your area (budget $300 to $500 an hour). This number tells you what limit to shop for. Most small businesses land on $1M because the premium difference from $500K is small.

Step 3: Use a broker who knows cyber

Your general business insurance agent may sell cyber policies as an add-on, but a broker who specializes in cyber knows which insurers actually pay claims fast and which ones fight. Ask them two questions: which insurers have the best incident response panels, and what does the social engineering sublimit look like on each quote. Their answers will tell you if they know the product.

Step 4: Compare the response, not just the price

The most valuable part of the policy might be the 24/7 breach hotline and the pre-approved response vendors. In the first hours of an incident, you don't want to be Googling forensics firms. You want to call one number and have the insurer's team take over. Ask each broker to walk you through what happens in the first 24 hours after you report an incident.

Step 5: Read the exclusions page before you sign

Read the last three pages of the policy first, not last. That's where the sublimits, the social engineering cap, the war exclusion, and the definition of "your systems" live. If the social engineering sublimit is a tenth of your main limit and BEC is your biggest risk, negotiate it up or pick a different insurer.

Cyber insurance pairs well with the rest of a founder's safety net. We run the same numbers-first approach across our insurance coverage, from term life insurance in 2026 to the HDHP vs PPO health plan math. The principle is identical: insure the losses you can't absorb, skip the ones you can.

Advertisement

Relevant ads will appear here once AdSense is connected.

FAQ

How much does cyber insurance cost for a small business?

The median for firms under 250 employees is about $1,740 a year. US small businesses average around $1,550, while UK micro-businesses can start near £175 a year. Your price depends on revenue, headcount, industry, the data you hold, and your security controls. Expect premiums to keep rising 15 to 20% a year as claims grow.

Does my general liability policy already cover cyberattacks?

Almost certainly not. General liability policies routinely exclude cyber events, and many now carry explicit cyber exclusions. Some business owner's policies offer a small cyber endorsement, but the limits are usually $25K to $50K, which barely covers a forensics investigation. If you want real protection, you need a standalone cyber policy.

Will the insurer pay a ransomware demand?

Many policies include coverage for extortion payments, but it's never automatic. Insurers typically require their response team to manage the negotiation, and payment decisions involve legal review because paying sanctioned groups is illegal. The trend is toward paying for recovery (rebuild from backups) rather than paying the ransom, which is another reason tested backups matter so much.

Do I need it if everything runs on Google Workspace or Microsoft 365?

Cloud software reduces some risks but doesn't remove yours. Microsoft secures the servers; you secure your accounts, and most small business breaches start with a compromised account, not a hacked data center. Business email compromise runs entirely inside legitimate cloud accounts. The shared responsibility model means the account-level failures are still on you.

What does the claims process actually look like?

You call the breach hotline, usually answered 24/7. The insurer assigns a breach coach (a lawyer) and a forensics firm from their panel. They investigate, contain the damage, and advise on notifications. Covered costs get paid or reimbursed according to the policy. Businesses that call early consistently report smoother and cheaper outcomes than those that try to handle it quietly for a week first.

Can I buy cyber insurance without an IT team?

Yes. Most insurers that serve small businesses don't expect an in-house IT department. They expect the basics: MFA on, backups tested, software patched, and someone (even a freelancer or MSP) accountable for security. A one-person business with good cloud hygiene can qualify. A 50-person business with no MFA cannot.

Your next steps

If you take one thing from this guide, make it this: enable MFA and test your backups this week, then get two quotes. The security work is free or nearly free, it cuts your premium, and it's the part that actually stops most attacks. The insurance is for the day the prevention fails, and at roughly $145 a month, it's the cheapest worst-case plan a small business can buy.

Want one practical business or money idea every morning? Our newsletter breaks down topics like this in about three minutes, no jargon, no spam. The signup is right below.

Filed under: Insurance
Share on XShare on FacebookShare on LinkedIn
Advertisement

Relevant ads will appear here once AdSense is connected.

F
FounderPaths Team

We test business ideas, AI tools, and money strategies in the real world — then write down exactly what worked, what didn't, and what it costs. No hype, no affiliate bait.

Keep Reading

Term Life Insurance in 2026: How Much You Really Need (and What It Costs)Term Life Insurance in 2026: How Much You Really Need (and What It Costs)HDHP vs PPO in 2026: The Math That Tells You Which Plan WinsHDHP vs PPO in 2026: The Math That Tells You Which Plan WinsHybrid Life Insurance: The Policy That Pays You While You're AliveHybrid Life Insurance: The Policy That Pays You While You're AliveIs Pet Insurance Worth It? The 2026 Numbers Say It Depends on ThisIs Pet Insurance Worth It? The 2026 Numbers Say It Depends on This

Get one smart idea every morning

Join 10,000+ readers. Business, money and AI — explained simply, in 3 minutes. Free, forever. No spam.

Unsubscribe anytime. We never share your email.