Skip to content
InsureMax

Cyber Insurance

Cyber Insurance for Small Business: What It Covers and What It Costs

First-party breach response, third-party liability, ransomware, and social engineering fraud — how a cyber policy is structured and what underwriters now require before quoting.

Daniel Okafor··11 min read

Cyber insurance moved from a specialty product to a near-standard business coverage in under a decade, driven almost entirely by ransomware. Small businesses are now the majority of claims by count: they hold usable data, they are reachable by the same automated attacks as large firms, and they rarely have a dedicated security function.

Premiums for a business under $5 million in revenue typically run $1,000 to $3,500 per year for $1 million of cover. The policy is best understood as two distinct halves — money spent on you, and money spent on other people because of you.

First-party coverage: what the policy spends on your business

Breach response is the core benefit and the one used most: forensic investigation to establish what happened, legal counsel to determine notification duties, notification letters to affected individuals, credit monitoring, and a call centre. For a 10,000-record breach this alone commonly runs $50,000–$150,000.

Business interruption pays lost income while systems are down, after a waiting period that is typically 8 to 12 hours. Extra expense covers the cost of working around the outage. Contingent business interruption extends this to outages at your IT provider or cloud host — increasingly important as small firms concentrate on a handful of SaaS vendors.

Data restoration pays to rebuild corrupted or encrypted data, and cyber extortion covers ransom negotiation, the payment itself where lawful, and the specialist firms that handle it.

Third-party coverage: what the policy spends because of you

Privacy liability responds to claims from customers, employees, or partners whose data you held. Network security liability responds when your compromised systems are used to harm someone else — spreading malware to a client, for example.

Regulatory defence and penalties covers investigations and fines from data protection regulators where insurable by law: state attorneys general in the US, the ICO in the UK, EU supervisory authorities under GDPR.

Media liability covers defamation, copyright, and trademark claims arising from your website and marketing content, which is a genuinely useful inclusion for any business that publishes.

Social engineering and funds transfer fraud — usually a separate sub-limit

The most common small-business cyber loss is not a technical breach. It is an invoice fraud or CEO-impersonation email that causes an employee to wire money to a criminal account.

Standard cyber policies exclude or heavily sub-limit this, often at $25,000–$250,000 against a full policy limit of $1 million, and typically require dual authorisation and out-of-band verification controls to be in place.

If your business pays suppliers by transfer, negotiate this sub-limit upward specifically. It is the coverage most likely to be used and most likely to be inadequate.

What underwriters now require before they will quote

The market hardened sharply after 2020, and controls are now conditions rather than discounts. Expect a questionnaire covering multi-factor authentication on email, remote access, and administrative accounts; offline or immutable backups tested within the last 90 days; endpoint detection and response; and email filtering.

Missing MFA is now a decline for most carriers, not a surcharge. Some policies contain a warranty clause allowing the insurer to reduce or deny a ransomware claim if the stated controls were not actually in place at the time of loss.

The practical implication: implementing MFA and tested backups both lowers your premium and preserves your claim. Do them before shopping the policy, not after.

Exclusions to check before binding

War and state-sponsored attack exclusions were rewritten across the market after NotPetya litigation. Read the wording carefully — a broad exclusion can theoretically capture attacks attributed to a nation state, which describes a great deal of ransomware activity. Prefer wordings with a narrow, evidence-based attribution standard.

Prior known circumstances are excluded: anything you were aware of before the policy incepted. So are unpatched-system exclusions in some wordings, which bite when a known vulnerability sat unremediated for an extended period.

Bodily injury and property damage sit under general liability, not cyber. Loss of your own intellectual property value, and the cost of upgrading systems to a better state than before the loss, are also generally excluded.

How much limit to buy

Base the limit on record count and regulatory exposure rather than revenue. A rough planning figure is $150–$250 per record for notification, monitoring, and legal in the US, before any liability or business interruption.

A professional services firm holding 5,000 client records with a modest revenue base still faces a plausible $750,000 to $1.5 million event. A retailer processing card payments faces PCI fines and card-brand assessments on top, which many policies cover only if specifically endorsed.

For most businesses under $10 million revenue, $1 million is the working baseline, with $2–$5 million appropriate for healthcare, financial services, and anyone holding sensitive personal data at scale.

Cyber cover bundled into a BOP is rarely enough

Many business owners policies now include a cyber endorsement at $25,000 or $50,000. That is roughly one third of a single small breach response and will not fund a forensic investigation and notification exercise.

Treat the endorsement as a starting point and price a standalone policy alongside it. Standalone cyber also brings the incident response panel — pre-vetted forensic, legal, and PR firms on retainer — which is often worth more in the first 48 hours than the limit itself.

Finally, confirm the policy is written on a claims-made basis with a retroactive date that covers the period you have actually been operating, and understand the notification deadlines. Late notice is the most avoidable reason a cyber claim fails.

Frequently asked questions

How much does cyber insurance cost for a small business?

Typically $1,000–$3,500 per year for $1 million of cover for a business under $5 million in revenue, with security controls being the biggest pricing factor.

Does cyber insurance pay ransomware demands?

Most policies cover extortion including negotiation and payment where lawful, but only if the required controls — MFA and tested offline backups — were genuinely in place.

Is invoice fraud covered?

Only under a social engineering or funds transfer fraud extension, usually at a sub-limit well below the main policy limit. Ask to increase it if you pay suppliers by transfer.

Do I need cyber insurance if I use cloud software?

Yes. Liability for your customers' data stays with you regardless of where it is hosted, and contingent business interruption covers outages at your providers.

Will my general liability policy cover a data breach?

No. Standard general liability covers bodily injury and property damage, and most modern wordings explicitly exclude electronic data.

Related reading