Cyber insurance used to be something only banks and hospitals bought. That changed once ransomware gangs figured out that a 12-person accounting firm with no IT department is an easier target than a Fortune 500 company with a security team. Today, only about 17 percent of US small businesses carry cyber coverage, yet small firms are the most frequent victims of ransomware, phishing, and payment fraud. This guide explains what cyber liability insurance actually pays for, what it costs in 2026, and how to decide whether your business needs it.
If you already know you need coverage, several of the top-rated business insurance companies we review sell standalone cyber policies or add cyber protection to a business owner's policy online in minutes.
What Cyber Insurance Actually Covers
Cyber liability insurance pays for the costs of a data breach, ransomware attack, or other cyber incident. Policies are split into two halves: first-party coverage, which pays for your own losses, and third-party coverage, which pays for claims other people bring against you.
First-Party Coverage (Your Own Losses)
- Incident response: Forensic investigators, breach counsel, and IT specialists who figure out what happened and shut it down
- Notification costs: Letters, call centers, and credit monitoring for affected customers, which every state now requires
- Ransomware and cyber extortion: Negotiation services and, where legal, the ransom payment itself
- Data restoration: Rebuilding systems and recovering lost or corrupted data
- Business interruption: Lost income while your systems are down, usually after a waiting period of 8 to 24 hours
- Funds transfer fraud: Money lost when a criminal tricks you or an employee into wiring payment to the wrong account (often called social engineering coverage, and often sublimited)
Third-Party Coverage (Claims Against You)
- Privacy liability: Lawsuits from customers or employees whose personal data was exposed
- Regulatory defense and fines: Costs of responding to state attorneys general, the FTC, or HIPAA investigations, and penalties where insurable
- PCI fines and assessments: Penalties from card networks if payment card data is compromised
- Media liability: Claims that your website or social content defamed someone or infringed a copyright
What Cyber Insurance Does Not Cover
Every policy has exclusions, and the cyber market has tightened them since 2021. Watch for these common gaps:
- Unpatched, known vulnerabilities: Some insurers exclude losses from software flaws you failed to patch within a set window
- Social engineering sublimits: A $1 million policy may cap wire fraud losses at $25,000 to $100,000 unless you buy a higher sublimit
- Prior incidents: Anything that started before your retroactive date is excluded
- Bodily injury and property damage: These belong to general liability, not cyber
- Future lost profits and reputational harm: Most policies limit business interruption to a defined period
- War and state-sponsored attacks: Newer policy forms carry broad war exclusions that can extend to nation-state hacking
- Failure to maintain security controls: If you told the insurer you use multi-factor authentication and did not, the claim can be denied
That last point matters. Cyber applications ask detailed questions about your security practices, and insurers do verify answers after a claim.
What Cyber Insurance Costs in 2026
Cyber insurance is one of the more affordable commercial policies for a small business. Based on 2026 market data, here is what small firms typically pay for a $1 million aggregate limit:
- Overall typical range: $500 to $2,500 per year
- Most common premiums: roughly $80 to $130 per month, or about $1,000 to $1,550 per year
- Lower-risk industries (construction, landscaping, trades with little customer data): $500 to $1,200 per year
- Higher-risk industries (healthcare, accounting, law, IT services, e-commerce): $1,500 to $5,000 per year
Treat these as typical ranges, not quotes. Your actual premium depends on several factors:
- Annual revenue: The single biggest driver, because it proxies for how much you could lose during downtime
- Records stored: Number and sensitivity of customer records (health data and Social Security numbers cost more to insure than email addresses)
- Industry: Regulated industries face higher notification and fine exposure
- Security controls: Multi-factor authentication, offline backups, endpoint detection, and employee training can cut premiums by 20 to 30 percent
- Limits and deductible: A $250,000 limit with a $2,500 deductible may cost half as much as a $1 million limit with a $1,000 deductible
- Claims history: A prior incident, even uninsured, raises rates for three to five years
Is Your Business Actually at Risk?
It is fair to be skeptical of vendor statistics, so here are the numbers that hold up under scrutiny. The frequently repeated claim that 60 percent of small businesses close within six months of a cyberattack was disavowed by the organization it was attributed to and should be ignored. The reliable data is still sobering:
- Ransomware was involved in roughly 88 percent of small and midsize business breaches analyzed in the 2025 Verizon Data Breach Investigations Report, compared with about 39 percent for large organizations
- Among small-business cyber claims with recorded losses, the median loss was approximately $38,000, and ransomware accounted for close to 40 percent of claims
- Around 40 percent of small business owners say a single $100,000 cyber loss could put them out of business
- Roughly one in five small businesses that suffered a serious breach reported facing bankruptcy afterward
The average breach cost figures you see in headlines, like the $10 million average for US companies in IBM's 2025 report, describe large enterprises and are not relevant to a business with 15 employees. The realistic small-business scenario is a $20,000 to $150,000 loss from a few days of downtime, a forensic bill, a ransom demand, or a fraudulent wire transfer. That is enough to wipe out a year's profit for many firms, and it is exactly the size of loss insurance handles well.
Who Needs Cyber Insurance (and Who Can Probably Skip It)
The honest answer is that most businesses with a computer, a bank account, and customers benefit from cyber coverage, but the priority varies. Use these groups to place yourself.
You Should Strongly Consider It If You:
- Store customer payment cards, Social Security numbers, health records, or financial account details
- Send or receive wire transfers or ACH payments based on email instructions
- Sell online or run a business that stops entirely when your systems go down
- Work in healthcare, legal, accounting, real estate, insurance, or IT services
- Have client contracts that require cyber coverage (increasingly common in B2B work)
- Employ people who use email, because phishing remains the most common entry point
You May Be Able to Wait If You:
- Are a solo operator with no employees, no stored customer data, and no online payments
- Run a cash-heavy local trade where a computer outage is an inconvenience, not a shutdown
- Already have a business owner's policy with a cyber endorsement that matches your real exposure
Even in the second group, a low-limit policy at $500 to $800 per year is often worth it purely for the incident response help. When you discover a breach at 6 p.m. on a Friday, having a hotline that dispatches a breach coach and forensic firm is worth more than the money.
If you are still deciding what belongs in your overall program, our guide to calculating how much business insurance you need walks through the same revenue-and-exposure logic insurers use.
Standalone Cyber Policy vs BOP Endorsement
Many small businesses first encounter cyber coverage as an add-on to a business owner's policy. These endorsements are cheap, often $100 to $300 per year, but they are limited:
- Low limits: Typically $25,000 to $100,000, sometimes with a $10,000 sublimit for ransomware
- Narrow triggers: Often cover data breach notification costs only, not business interruption or funds transfer fraud
- No dedicated response team: You may be handling the incident yourself and submitting receipts
A standalone cyber policy usually starts at $250,000 in limits, includes a 24/7 breach hotline, and covers the full menu of first- and third-party costs. If your revenue is above roughly $250,000 or you store sensitive data, a standalone policy is the better fit. If you are a very small operation with minimal data, a BOP endorsement can be a sensible starting point.
How to Lower Your Cyber Premium
Cyber is the one line of business insurance where you can measurably change your rate in a weekend. Insurers reward these controls, and most now require several of them just to issue a policy:
- Multi-factor authentication on email, remote access, and any admin account. This is the single most important control and often a condition of coverage
- Tested, offline or immutable backups that ransomware cannot encrypt
- Endpoint detection and response (EDR) software on every laptop and server, not just traditional antivirus
- Email filtering and phishing training for every employee, repeated at least annually
- Patch management with critical updates applied within days, not months
- Wire transfer verification by phone call-back for any payment instruction change
- A written incident response plan, even a two-page one
Businesses with all of these in place commonly see quotes 20 to 30 percent below those without, and they are far less likely to have a claim denied for misrepresentation.
How to Buy Cyber Insurance
Buying cyber coverage is faster than it used to be. Digital-first carriers like NEXT Insurance and Hiscox offer online quotes in minutes for typical small-business risks, and larger carriers like The Hartford, Travelers, and Chubb sell cyber both as a standalone policy and as part of a package. Chubb in particular is known for incident response services that come bundled with the policy. Before you apply:
- Answer the security questionnaire honestly. Overstating your controls is the fastest route to a denied claim
- Ask specifically about the social engineering and funds transfer fraud sublimit, and raise it if you move money on client instructions
- Check the business interruption waiting period and whether it covers outages at your cloud vendors (dependent business interruption)
- Confirm the retroactive date is set to your policy start or earlier
- Compare at least three quotes, because cyber pricing varies more between carriers than almost any other line
Sole proprietors and single-member LLCs sometimes assume their personal identity theft coverage extends to the business. It does not. Our guide to insurance for LLCs and sole proprietors covers where the personal and business lines actually fall.
Making Your Decision
For most small businesses in 2026, cyber insurance is worth it. The typical premium of $1,000 to $1,500 per year buys protection against a category of loss that is now more common than fire or theft, and it comes with a response team you would struggle to assemble on your own in a crisis. The businesses that can reasonably defer are solo operators with no stored data and no dependence on their systems, and even they should revisit the question each year as they grow.
Start by tightening the security controls above, since they lower both your risk and your premium. Then compare quotes from the best-rated business insurance companies to find a policy with limits that match your revenue and a sublimit structure that matches how you actually move money.
Ready to Find the Right Business Insurance?
Compare the top-rated business insurance companies and get a quote for your business in minutes.
Compare Top Insurers →