SMB Coverage

Compare Cyber Insurance Quotes

Protect your business from ransomware, data breaches, and wire fraud. Compare policies from specialist carriers in minutes.

4.6/5 from 2,900+ reviews

Free quotes. Licensed commercial broker review.

Licensed Agents
A+ Rated
Secure & Private
No Spam
Free Quotes

Coverage Options

First-Party Coverage

Covers your own losses: ransomware, system restoration, lost revenue.

From $95/mo

Third-Party Liability

Covers claims from customers whose data you lost.

From $55/mo

Wire Fraud / BEC

Reimburses funds lost to business email compromise.

+$25-40/mo

Business Interruption

Replaces lost revenue while systems are down after an attack.

+$30-60/mo

Regulatory Defense

Pays legal costs and fines from HIPAA, GDPR, or state privacy laws.

+$20-45/mo

Cyber Extortion

Ransom payment coverage (where legally permitted).

Included in most

Why Act Now

$1.85M average ransomware cost to a small business
43% of cyberattacks target small businesses
$4.88M average data breach cost (all businesses, 2024)
60% of small businesses close within 6 months of a breach

Compare Top Providers

Provider rate comparison
Provider
Coalition
At-Bay
Travelers
Chubb

How It Works

  • Ransomware Response Pays ransom (where legal), restores systems, and covers business interruption losses.
  • Data Breach Coverage Notification costs, credit monitoring, forensics, and regulatory fines after a breach.
  • Social Engineering / Wire Fraud Reimburses funds lost to CEO fraud, BEC attacks, and fraudulent wire transfers.
  • 24/7 Incident Response Direct access to IR firms, legal counsel, and PR teams the moment an incident hits.
1

Tell Us What You Need

Answer a few quick questions about your coverage needs. Takes less than 2 minutes.

2

Compare Top Quotes

We match you with A-rated carriers and show you side-by-side comparisons.

3

Choose & Save

Pick the plan that fits your budget. Most customers save 20-40% vs. their current policy.

What to Look For

What Good Carriers Offer
  • A.M. Best "A" rating or higher
  • Transparent pricing with no hidden fees
  • Fast claims processing (under 48 hours)
  • 24/7 customer support
Red Flags to Avoid
  • No financial strength rating listed
  • Unusually low quotes with exclusions buried in fine print
  • Pressure tactics or "limited time" pricing
  • Poor BBB rating or excessive complaints

What Our Customers Say

“A phishing attack hit our controller and $140K was wired to a fake vendor. Coalition had 80% of it recovered in 30 days through their IR team.”
Jessica W. CFO, 45-employee firm
“At-Bay's security scan flagged a vulnerable VPN before we bought the policy. We patched it and the quote dropped $1,200/year.”
Michael P. IT Director, manufacturer
“Ransomware locked our servers on a Friday. Travelers had the IR firm on the phone within an hour. Back online by Monday, claim paid in full.”
Anthony R. Accounting firm, 22 staff

What Is Cyber Insurance?

Cyber insurance is a commercial policy that covers losses from cyberattacks and data incidents. It breaks into two sides: first-party coverage pays for your losses (system restoration, ransom, lost revenue), and third-party coverage pays for claims from others (customers whose data was exposed, vendors harmed by a disruption).

A modern cyber policy also bundles incident response services: 24/7 hotlines, pre-vetted forensics firms, breach coaches, PR specialists, and legal counsel. When an incident happens, you call one number and the insurer's machinery takes over. For most small businesses, this bundled response capability is more valuable than the dollars on the policy.

How Much Does Cyber Insurance Cost?

A small business with under $5M in revenue typically pays $1,200-$3,500 per year for a $1M/$1M cyber policy (first-party and third-party limits). Cost scales with revenue, data sensitivity, and security posture. Here's the 2024 range by industry:

  • Retail, trades, professional services: $1,200-$2,500/year for $1M coverage.
  • Healthcare, finance, law: $2,500-$5,500/year — higher data sensitivity and regulatory exposure.
  • Technology / SaaS: $2,000-$6,000/year depending on whether customer data is hosted.
  • Enterprises ($50M+ revenue): $15,000-$75,000/year for higher limits and broader coverage.

Carriers now underwrite based on active security scans. Having MFA, EDR, and backup segregation can drop premiums 20-40%. Missing basic controls often results in declined quotes.

The Core Coverages in a Cyber Policy

Every cyber policy should include these eight coverages. If any are missing, push back on the broker.

  • Incident response — 24/7 hotline, forensics, breach coaching.
  • Data breach notification — Notifying affected customers, credit monitoring, call-center costs.
  • Cyber extortion / ransomware — Ransom payment and negotiation support.
  • Business interruption — Lost revenue and extra expenses during downtime.
  • Social engineering / funds transfer fraud — Wire fraud, CEO fraud, BEC attacks.
  • Regulatory defense — Legal fees and fines from HIPAA, GDPR, state privacy laws.
  • Third-party liability — Lawsuits from affected customers and partners.
  • PCI / payment card liability — Fines from card networks after a payment breach.

Security Controls Insurers Now Require

As of 2024, underwriting standards have tightened dramatically. Most carriers will decline to quote — or charge 2-3x higher premiums — if you're missing these controls:

  • Multi-factor authentication (MFA) on email, remote access, and privileged accounts.
  • Endpoint detection and response (EDR) — not just antivirus. CrowdStrike, SentinelOne, Defender for Endpoint all qualify.
  • Offline or immutable backups tested at least quarterly. Ransomware that also encrypts backups is the #1 catastrophic loss scenario.
  • Email filtering with attachment sandboxing and URL rewriting.
  • Vulnerability management — regular patching, especially for internet-facing assets.
  • Written incident response plan, tested annually.

Insurers run external scans before binding. If your perimeter shows exposed RDP, unpatched VPN appliances, or open database ports, expect a declined quote.

What to Do When an Incident Happens

Time matters. The first 24 hours drive 80% of the eventual cost.

  1. Call the insurer's 24/7 hotline before doing anything else. The incident response team will coach you through evidence preservation. Do NOT wipe systems, reset passwords, or power off servers until you've talked to forensics.
  2. Do NOT negotiate with attackers directly. The insurer's ransom negotiators have leverage you don't.
  3. Preserve logs and system images, even if you're restoring from backups. Forensics needs them.
  4. Notify legal counsel and law enforcement (FBI's IC3 at ic3.gov). Your policy almost always requires it.
  5. Do NOT issue public statements until the breach coach approves. Premature disclosures create legal exposure.

A typical SMB incident runs 7-14 days from discovery to restoration. Your premium and deductible will rise at renewal, but the alternative — no coverage and no IR team — is often business-ending.

Frequently Asked Questions

What is cyber insurance?

Cyber insurance (also called cyber liability) covers losses from cyberattacks, data breaches, ransomware, and fraud. It pays for technical response, legal fees, regulatory fines, customer notifications, credit monitoring, lost revenue, and ransom payments where legal.

Do small businesses really need cyber insurance?

Yes. 43% of cyberattacks target small and midsize businesses. The average ransomware incident costs an SMB $1.85M including downtime, recovery, and lost business. 60% of SMBs close within 6 months of a major cyber incident. Most general liability policies specifically exclude cyber events.

How much does cyber insurance cost?

Small businesses typically pay $1,200-$3,500 per year for $1M in coverage. Price depends on industry, revenue, data volume, existing security controls, and prior claims. Healthcare, finance, and law firms pay 30-60% more due to regulatory exposure.

What does cyber insurance NOT cover?

Standard exclusions: acts of war (increasingly including state-sponsored attacks), prior known incidents, intentional acts, loss of intellectual property value, hardware damage, and upgrades to security systems after a breach. Read the policy carefully — exclusions vary widely.

Will cyber insurance pay a ransom?

Most policies will, within limits and provided payment doesn't violate OFAC sanctions. The insurer's IR team usually negotiates the ransom to reduce the payout. Some insurers are moving away from ransom payments and instead funding system rebuilds — ask before binding.

What security controls do insurers require?

Most carriers now require: multi-factor authentication (MFA) on all privileged accounts, endpoint detection and response (EDR) software, offline or immutable backups, email filtering with link/attachment scanning, and documented incident response plans. Weak controls = higher premiums or declined quotes.

Ready to Save on Cyber Insurance?

Protect your business from ransomware, data breaches, and wire fraud. Compare policies from specialist carriers in minutes.

Licensed Agents
A+ Rated
Secure & Private
No Spam

Simply Insurance is a licensed independent broker. We may receive compensation from carriers when you purchase a policy. This does not affect the rates you receive.