Typical cyber premiums
Cyber pricing depends on revenue, records held, and controls. Businesses handling protected health information or payment data pay more.
| Business profile | Typical annual premium |
|---|---|
| Under $1M revenue, low data volume | $700 – $1,400 |
| $1M–$5M revenue, professional services | $1,200 – $2,800 |
| Healthcare / PHI, under $5M revenue | $1,800 – $4,500 |
| $5M–$25M revenue | $4,000 – $12,000 |
Controls carriers now require
Since the ransomware surge, carriers underwrite controls before price. Expect the application to ask about multi-factor authentication on email and remote access, offline or immutable backups tested within the last 90 days, endpoint detection and response, email filtering, and separation of administrative accounts. Missing MFA alone will get many submissions declined outright.
What the policy actually pays for
First-party coverage handles forensics, notification, credit monitoring, ransom payment where legal, data restoration, and business interruption. Third-party coverage handles lawsuits from affected customers and regulatory defense. Social engineering and funds-transfer fraud — the wire-fraud claim most small businesses actually experience — is often a sublimited endorsement that must be requested specifically.
Frequently asked questions
Is cyber insurance worth it for a small business?
For any business holding customer data or moving money by wire, yes. The average small-business ransomware event costs far more than a decade of premium, and the policy's breach-response team is usually more valuable than the money.
Does my general liability policy cover a data breach?
No. Standard GL forms exclude electronic data. Breach costs require a dedicated cyber policy.
What limit should I buy?
$1M is the common starting point for small businesses. Healthcare, financial, and contract-driven businesses often need $2M or more.