Most small businesses pay between $100 and $200 per month for cyber liability insurance in 2026, or roughly $1,200 to $2,400 a year for a $1 million policy. Sole proprietors and low-risk freelancers can find coverage starting around $30 to $60 a month, while mid-sized firms handling sensitive data often pay $400 to $1,000 monthly. Your industry, revenue, security controls, and even the state you operate in all push the final number up or down.
How much does cyber liability insurance cost?
Cyber liability insurance pricing has stabilized in 2026 after several years of sharp rate hikes. The market softened in late 2024 as new capacity entered and ransomware claim severity flattened — which means small businesses with decent security hygiene can finally find affordable quotes again.
That said, “average” is doing a lot of heavy lifting here. A solo bookkeeper with five clients doesn’t pay the same rate as a 40-person medical billing firm sitting on tens of thousands of patient records. The numbers below are starting points — your real quote depends on what you actually do, how much data you touch, and what security controls you have in place.
If you’re shopping for cyber liability insurance right now, get quotes from two or three carriers before you settle. Rates between insurers writing the same risk can differ by 40% or more.
Average cost of cyber liability insurance in 2026
Median monthly premium for small businesses
The median small business pays about $140 per month for a standalone cyber liability policy with $1 million in coverage and a $2,500 deductible. Businesses with fewer than 10 employees and minimal data exposure often land in the $45 to $90 range.
Industry research based on rate filings and quote data from major insurers puts the typical annual premium for a moderate-risk business at roughly $1,500 to $1,600 per year — consistent with what you’ll see quoted for a $1 million limit policy with a $10,000 deductible. For context, industry research tracking small business premiums over time showed average annual costs around $1,485 in 2020 and $1,501 in 2019, before the hard market pushed rates sharply higher in 2021 and 2022. Rates have since stabilized. Low-risk states like Michigan and Minnesota tend to sit at the lower end of the current range; higher-cost states like California, Connecticut, and Delaware tend to run 6% to 8% above the national average.
Median annual premium for small businesses
Annualized, that median works out to roughly $1,680 per year. Premiums under $1,000 are realistic for very small, low-risk operations. Premiums above $5,000 are common once you store regulated data — health records, payment card data, or large customer databases.
Cost range: cheap vs. comprehensive coverage
Minimum coverage tiers and what they cost
Bare-bones cyber endorsements added to a business owners policy can start at $25 to $50 per month. These typically cap out at $50,000 to $250,000 in coverage and are best thought of as “better than nothing” rather than real protection. They handle small notification costs and basic forensics — not a full breach response.
Industry data from rate filings shows that $250,000 in coverage with a $2,500 deductible averages around $739 per year for a moderate-risk business, while $500,000 in coverage with a $5,000 deductible averages about $1,146 per year. The jump to $1 million is not proportional — each additional layer of coverage costs less per dollar than the one before it.
Broad coverage tiers and what they cost
A comprehensive standalone cyber policy — $1 million or more in limits, first-party and third-party coverage, ransomware, business interruption, and regulatory defense — typically runs $150 to $500 per month for a small business. Mid-market firms regularly write policies in the $1,000 to $5,000 monthly range.
What does cyber liability insurance cost by business size?
Size matters, but not always in the way people assume. Carriers care less about your headcount and more about how much data you touch and how much revenue is at stake if you go offline.
Cyber insurance cost for sole proprietors and freelancers
Solo operators — consultants, writers, designers, coaches — typically pay $30 to $75 per month for a $500,000 to $1 million policy. If you handle client files but don’t store credit card numbers or health data, you’re in the cheapest tier of the market.
It’s worth noting that small businesses often get targeted precisely because their security tends to be lighter than larger companies. Attackers cast wide nets against hundreds of small, under-protected targets rather than spending enormous effort cracking one well-defended enterprise — the economics work out in the attacker’s favor either way. That makes cyber coverage more relevant for small operators than many assume.
Cyber insurance cost for small businesses (1–50 employees)
This is the bulk of the market. Expect $100 to $400 per month depending on industry. A 12-person marketing agency might pay $110 monthly. A 30-person dental practice with the same coverage limits could pay $350 or more.
Cyber insurance cost for mid-size businesses (51–250 employees)
Mid-sized companies usually pay $500 to $2,500 per month. Coverage limits jump to $2 million to $5 million, deductibles climb, and underwriters demand documented evidence of MFA, endpoint detection, and tested backups before they’ll quote.
Cyber insurance cost for large enterprises (250+ employees)
Enterprise pricing is fully bespoke. Premiums often start at $25,000 annually and climb into six figures for companies handling millions of records. Most large enterprises layer multiple policies across primary, excess, and specialty markets. Demand for cyber coverage among enterprise clients has grown substantially over the past decade — industry surveys from leading brokers suggest the share of enterprise-level clients carrying cyber insurance roughly doubled between 2016 and 2020.
What does cyber liability insurance cost by industry?
Industry is the single biggest pricing lever after revenue. Carriers maintain detailed loss data by business type, and some verticals get hit so often that base rates are two or three times the cross-industry average. The core driver: companies that store sensitive information — Social Security numbers, dates of birth, financial data, health records — pay the highest premiums. Companies with minimal customer data (think: a small manufacturer with just a few clients) pay the least.
| Industry | Typical small business annual premium |
|---|---|
| Nonprofits & education | $900 – $1,800 |
| Marketing & creative services | $1,000 – $2,000 |
| Retail & e-commerce | $1,500 – $3,500 |
| Technology & IT consulting | $1,800 – $4,000 |
| Legal services | $2,000 – $4,500 |
| Financial services & accounting | $2,500 – $5,500 |
| Healthcare & medical practices | $3,000 – $7,500 |
Healthcare and medical practices
Healthcare pays the most. HIPAA penalties, the volume of protected health information stored, and ransomware operators specifically targeting clinics and hospitals push premiums up. Even a small practice with 2,000 patient records can pay $4,000 a year for $1 million in coverage. Some insurers have responded to the severity of healthcare claims by reducing coverage limits or placing stricter ransomware sub-limits specifically for this vertical — read your policy form carefully.
Retail and e-commerce
PCI-DSS exposure is the main issue here. Anyone storing or processing payment card data faces breach notification costs that scale with transaction volume. Payment processors like Stripe handle a lot of the direct card exposure, but if you keep customer accounts or run your own checkout, you’re still on the hook.
Financial services and accounting firms
Accountants, financial advisors, and bookkeepers store Social Security numbers, tax returns, and bank account data — basically the full identity-theft starter kit. Small-business surveys consistently put these professions in the top tier for cyber claims frequency. Many state-licensed financial firms now also face data security regulations with real teeth.
Technology companies and IT consultants
Tech firms face a unique problem: a single incident can trigger both first-party data loss and third-party professional liability claims. That’s why many carriers recommend pairing cyber liability with tech E&O insurance — combined policies are usually cheaper than buying the two separately.
Law firms and legal services
Law firms sit on privileged client data, M&A documents, and litigation files that ransomware crews actively target. Bar association rules on client confidentiality create regulatory exposure on top of standard state breach laws.
Nonprofits and educational organizations
Generally the cheapest vertical. Donor data and student records still create some exposure, but lower revenue and smaller record counts keep premiums modest compared to other sectors. That said, education was one of the verticals where some insurers reduced maximum available limits during the hard market years — verify that the limits you’re offered are sufficient before binding.
What does cyber liability insurance cost by state?
State plays a meaningful role. California, New York, and Illinois have the strictest breach notification and data privacy laws, which pushes premiums slightly higher for businesses operating there. But the variation across states is real even before factoring in legislation — rate filings differ by state, and local claims experience affects regional pricing.
Industry research on rate filings shows a premium spread of roughly 15% to 20% between the cheapest and most expensive states for identical moderate-risk business profiles. Higher-cost states include California, Delaware, North Carolina, and Connecticut. Lower-cost states include Michigan, Minnesota, Massachusetts, Hawaii, and Ohio.
If your business operates in a high-regulation state, the compliance exposure alone — not just the breach cost — raises the stakes. Our California cyber liability guide covers key data privacy law changes that took effect in 2025. New York’s SHIELD Act and Illinois’s BIPA create their own pricing pressures — see our New York and Illinois state pages for specifics.
What factors affect the cost of cyber liability insurance?
Underwriters look at roughly a dozen variables. Some you can change, some you can’t.
Industry and data sensitivity
Covered above. Regulated data — PHI, PCI, PII at scale — drives base rates. Low-risk businesses with few customer records get the cheapest quotes. High-risk businesses storing sensitive personal or financial data pay two to three times more.
Annual revenue and company size
Revenue is the primary proxy carriers use for “how much business interruption could cost us.” Most carriers rate primarily on revenue; some use employee count. Either way, more revenue means more downtime exposure and higher premiums.
Number of records stored and data types
A business with 500 customer email addresses is in a completely different risk class than one with 500,000 records that include SSNs and birthdates. Most applications ask for an exact record count — don’t estimate high. Be accurate: misrepresenting record counts is one of the most common reasons claims get disputed or denied.
Prior cyber claims history
A claim in the last five years can double your rate or result in non-renewal. Be honest on the application; misrepresentation voids coverage.
Security controls and IT infrastructure
This is the lever most owners can actually pull. Carriers now require specific controls before they’ll quote at all — and documented controls can meaningfully reduce your premium. Think of it like this: your IT security posture is to cyber insurance what your driving record is to car insurance.
Multi-factor authentication (MFA)
MFA on email, remote access, and admin accounts is non-negotiable in 2026. No MFA, no quote — at most major carriers, full stop.
Endpoint detection and response (EDR)
Modern EDR replaces traditional antivirus and is increasingly required for limits above $1 million. Carriers want to see it actively deployed, not just purchased.
Employee security training programs
Documented annual security training — even a basic third-party phishing simulation program — can knock 5% to 15% off premiums and is required by some carriers. Phishing and employee negligence are among the most frequent sources of cyber claims, so this isn’t just box-checking. Regular training on how to recognize phishing emails, suspicious links, and social engineering attempts is one of the highest-ROI investments a small business can make in cyber risk management.
Patch management and vendor access controls
Underwriters also ask whether you patch software vulnerabilities regularly and whether you monitor third-party vendors who have access to your systems. Gaps here show up on applications and affect pricing. Some of the most damaging real-world breaches started with a vulnerable, forgotten server that hadn’t been patched in months — underwriters know this and ask about it directly.
Data backup practices
Carriers increasingly ask about backup strategy — specifically whether you maintain offline or “air-gapped” backups that ransomware can’t reach. If your only backups are on a continuously connected cloud drive, ransomware can encrypt those too. Documented offline backups (tested regularly) signal to underwriters that your recovery costs will be lower, which can modestly reduce premiums.
Coverage limits and deductible selection
The math you control. Higher limits and lower deductibles raise premiums. Moving from a $1,000 to a $5,000 deductible typically cuts premiums by 10% to 20%. Going to $10,000 can shave another 10%. Just make sure you can actually write that check during a live incident.
First-party vs. third-party coverage choices
Buying both is more expensive than buying one, but most modern policies bundle them. Splitting them apart usually doesn’t save money.
First-party vs. third-party cyber liability coverage costs
The two halves of a cyber policy cover different victims of the same incident.
What first-party cyber coverage includes and what it costs
First-party coverage pays you for your own losses: forensic investigation, customer notification, credit monitoring, business interruption, ransomware payments, and PR crisis response. A standalone first-party policy for a small business typically runs $80 to $200 per month for $1 million in limits.
Key first-party coverages to look for:
- Data breach response — notification letters, call center setup, legal review
- Data recovery — costs to restore or reconstruct corrupted or destroyed data (including data belonging to others that you store on your systems)
- Business interruption — lost income when a cyber event shuts down operations; most policies have a 6- to 12-hour waiting period before this kicks in
- Cyber extortion / ransomware — ransom payments (where legally permissible), negotiator fees, and system restoration costs; note sub-limits here carefully
- Crisis PR — fees for a public relations firm to manage reputational fallout
What third-party cyber coverage includes and what it costs
Third-party coverage pays others — customers, business partners, regulators — when they sue you or issue fines. Defense costs, settlements, and regulatory penalties live here. Standalone third-party coverage runs $60 to $180 per month for similar limits.
Key third-party coverages include:
- Network security liability — claims that your security failure allowed a breach affecting others
- Privacy liability — lawsuits from customers or employees whose personal data was exposed
- Regulatory defense and fines — attorney fees and insurable penalties from HIPAA, CCPA, GDPR, and state breach law investigations
- Employee privacy liability — claims from employees whose data was compromised
Which coverage type do most small businesses need?
Both. Buying them together as a packaged cyber policy is almost always cheaper than buying separately, and a real breach triggers both halves simultaneously. Don’t try to save money by skipping one side.
What does cyber liability insurance cover?
Coverage varies by carrier and policy form, but a standard small business policy in 2026 typically includes the following.
Data breach response and notification costs
Forensics, legal review, customer notification letters, call center setup, and state attorney general notifications. This is often the single largest expense in a real incident. For a breach affecting even a few thousand customers, notification alone can run into six figures.
Business interruption and lost revenue
Reimburses lost income when a cyber event shuts down your operations. Most policies have a 6- to 12-hour waiting period before coverage kicks in.
Ransomware and cyber extortion
Pays ransom demands (where legally permissible), negotiator fees, and system recovery costs. Watch for sub-limits — some carriers cap ransomware coverage at 50% of the total policy limit or as low as $25,000 on otherwise robust policies. The insurer’s consent is typically required before you pay any ransom. Read the fine print carefully — this is the coverage that varies most dramatically between carriers.
Regulatory fines and legal defense
Covers defense costs for HIPAA, CCPA, GDPR, and state breach law investigations, plus insurable fines where state law allows.
Credit monitoring and PR crisis management
Most policies include 12 to 24 months of credit monitoring for affected customers and a budget for a crisis PR firm.
Most frequent cyber insurance claims
Knowing what actually drives claims helps you understand what your policy is defending against. The four most common causes of cyber insurance claims are:
- Hacking — unauthorized access to your network, followed by data theft and potential third-party liability. Costs typically include forensic services, legal defense, notification, and regulatory fines.
- Ransomware — malicious software that locks your systems or threatens to publish data until you pay. Costs include the ransom, negotiators, forensics, and system restoration. Coverage sub-limits here can be shockingly low — some policies cap ransomware payouts at $25,000 even when the overall policy limit is $1 million.
- Phishing — employees tricked into handing over login credentials via malicious emails, fake websites, or phone calls. Once inside, attackers steal data or initiate fraudulent wire transfers. Training employees to recognize phishing attempts is one of the most effective ways to reduce both your risk and your premium.
- Employee negligence — something as simple as a lost laptop with unencrypted customer data can trigger notification requirements, lawsuits, and regulatory attention, even without any malicious intent.
Each of these is covered under most modern cyber policies, though the specific limits, waiting periods, and sub-limits vary significantly by carrier.
What cyber liability insurance does not cover
- Loss of your own intellectual property value
- Bodily injury or physical property damage (that’s general liability insurance)
- Acts of war or state-sponsored attacks (the war exclusion has broadened significantly since 2023 — review this language carefully)
- Failure to maintain the security controls you disclosed on your application
- Prior known incidents and claims
- System upgrade costs after a breach
- Reputational damage and resulting lost future business — if a breach hurts your public image and customers leave, that revenue loss generally isn’t covered
For coverage focused specifically on notification and response, look at data breach insurance as a complementary or alternative product.
Should small businesses worry about cyber risk?
Short answer: yes. Here’s the honest picture.
A lot of small business owners assume they’re too small to be worth targeting. That’s backwards logic. Attackers running mass phishing campaigns or deploying ransomware via automated tools aren’t cherry-picking big targets — they’re hitting thousands of businesses at once and collecting modest payoffs from whoever gets hooked. A small business with lighter security is often easier to breach than a larger company with dedicated IT staff.
The data to store makes the target. If you hold Social Security numbers, financial account details, payment card data, or health information — even a small number of records — you have something criminals can sell or leverage. Industry research suggests passwords alone sell for $12 to $40 each on dark web markets. A customer database with a few hundred records has real street value to a criminal.
The regulatory angle matters too. State breach notification laws apply to businesses of all sizes. A one-person accounting firm that loses a laptop with 200 client SSNs on it faces the same notification obligations as a Fortune 500 company operating in the same state. The fines and attorney fees don’t scale down because you’re small.
How to get cheap cyber liability insurance without sacrificing coverage
There are five reliable ways to lower your premium without gutting your protection.
Bundle cyber coverage with a business owners policy (BOP)
Adding cyber as an endorsement to a BOP can save 15% to 25% versus a standalone policy. The trade-off is lower limits and narrower coverage — acceptable for very small operations, risky for anyone with meaningful data exposure.
Improve security posture before applying
Enabling MFA, deploying EDR, running annual employee training, patching publicly facing systems, and documenting your backup procedures before you apply will get you better quotes. Carriers reward documented controls — and in some cases, you won’t get quoted at all without them. This is the single most actionable thing you can do to reduce your cost.
Compare quotes from multiple carriers
Pricing variance between carriers writing the same risk routinely hits 30% to 50%. Never accept the first quote. Three quotes is the minimum; five is better.
Choose a higher deductible to lower your premium
Moving from $1,000 to $10,000 in deductible can cut premiums by 20% or more. Only do this if you have cash reserves to cover the deductible during a live incident — incident response gets expensive fast and you’ll need to pay your share before coverage kicks in.
Work with an independent agent or broker
Independent agents can quote across 10+ carriers in one shot. Direct-to-consumer platforms work for simple risks, but anything involving regulated data benefits from a broker who understands the cyber market and can advocate for you at claims time. A broker with cyber specialization will also flag coverage gaps — like inadequate ransomware sub-limits — that you might miss reviewing a policy on your own.
Top cyber liability insurance companies and their average costs in 2026
The cyber market has consolidated around a handful of carriers with meaningful appetite for small business.
Simply Insurance may receive compensation when readers click partner links and an eligible quote is requested.
Coalition Cyber Insurance
Tech-forward carrier that includes free vulnerability scanning with every policy. Strong for tech, professional services, and digitally mature small businesses. Average small business premium: $1,200 to $2,800 annually.
Chubb Cyber ERM
Premium product with deep claims-handling experience. Targets mid-market and larger accounts. Average premium for small business: $2,000 to $5,000+.
Travelers CyberRisk
Broad small business appetite, strong BOP-cyber bundling options. Average premium: $1,000 to $2,500 annually.
Hiscox Cyber Insurance
Specialist in small business and professional services. Fast quoting, strong for sub-$5M revenue companies. Average premium: $900 to $2,200 annually.
Nationwide Cyber Insurance
Often bundled with broader business insurance packages. Best for existing Nationwide customers. Average premium: $1,100 to $2,600 annually.
How to compare carriers beyond price
Look at: ransomware sub-limits, war exclusion language, panel counsel requirements (some carriers require you to use their lawyers), incident response hotline quality, and whether the carrier pays claims on time. A cheap policy that fights every claim is more expensive in practice than a slightly pricier policy that pays. Also check AM Best financial strength ratings — you want a carrier that will still be solvent and paying claims when you need them.
Is cyber liability insurance worth the cost?
For almost any business that stores customer data, yes. The math is pretty stark.
Average cost of a data breach vs. average annual premium
IBM’s Cost of a Data Breach research has consistently put the average U.S. enterprise breach above $9 million. Small business incidents are smaller in absolute terms but proportionally devastating — small business breach response costs typically run $120,000 to $1.2 million before any lawsuits. For small and mid-sized businesses, recovery costs from a breach can easily reach tens of thousands to hundreds of thousands of dollars depending on the number of records exposed. Against an annual premium of $1,500 to $3,000, the math on a single avoided incident is obvious.
Regulatory penalties without coverage
HIPAA penalties run up to $50,000 per violation. CCPA penalties run up to $7,500 per intentional violation. GDPR fines can reach 4% of global revenue. None of these scale down because you’re a small business.
Real-world claim examples for small businesses
A 12-person dental practice hit with ransomware paid $185,000 in forensics, notification, and recovery — covered by a $1M policy with a $5,000 deductible. A 5-person law firm tricked into wiring $310,000 to a fraudulent account recovered most of it through social engineering coverage on a $2M policy. An employee at a retail store losing a laptop with unencrypted customer payment data triggered notification obligations in multiple states — a five-figure expense handled entirely by the cyber policy.
When you might not need cyber coverage
If you’re a one-person operation with no customer data, no email list, no payment processing, and no professional services exposure, you might be able to skip cyber coverage. But errors and omissions insurance still likely applies — and almost every modern business clears some cyber risk threshold once you account for email phishing exposure alone.
How to organize and manage cyber risk (beyond just buying insurance)
Insurance transfers risk — it doesn’t eliminate it. The businesses that recover fastest from cyber incidents combine good coverage with basic security practices. Here’s what actually matters.
Back up your data offline
The single most impactful thing most small businesses can do is maintain tested, offline backups. If ransomware hits and you have a clean offline backup from yesterday, you don’t need to pay the ransom — you restore and move on. If your only backups are cloud-connected storage that ransomware can reach, you’re at the attacker’s mercy. Run regular restore tests; a backup you’ve never tested isn’t really a backup.
Train your employees on phishing
Most breaches start with a human clicking something they shouldn’t. Regular phishing awareness training — even once a year with a basic third-party simulation — materially reduces your risk and is increasingly required by insurers. Train employees to go directly to a website rather than clicking email links, especially for banking and account-related messages.
Apply software updates promptly
Some of the most damaging breaches in history started with an unpatched, known vulnerability. Set systems to update automatically where possible. Pay particular attention to internet-facing software — your web server, VPN, email gateway — since those are the entry points attackers probe first.
Control third-party vendor access
Your vendors can be a backdoor into your systems. Know which third parties have access to your data or network, limit that access to what’s necessary, and review vendor security practices. Underwriters ask about this on applications — it’s not theoretical risk.
Enable MFA everywhere
Two-factor authentication on email, remote desktop, banking portals, and admin accounts stops a huge percentage of credential-based attacks cold. It’s free or nearly free to implement and is the closest thing to a universal cyber security requirement in 2026.
How to buy cyber liability insurance
Five steps from “I should look into this” to bound coverage.
Step 1: Assess your business’s data risk
List the data you store: customer names, emails, payment info, health records, SSNs, login credentials. Count the records. Identify regulated categories (PHI, PCI, PII). Also note any third-party vendors who have access to your systems — underwriters will ask. This is the application’s hardest section, but getting it right matters.
Step 2: Decide on coverage limits
Default to $1 million for most small businesses. Move to $2 million if you store regulated data, have client contract requirements, or do more than $2 million in annual revenue. The cost difference between $500K and $1M coverage is smaller than most people expect — it’s worth the upgrade.
Step 3: Get and compare multiple quotes
Three to five quotes minimum. Use a broker or a comparison platform that shops multiple carriers in one application. Rate and form differences between carriers can be significant.
Step 4: Review policy exclusions carefully
Read the war exclusion, ransomware sub-limits, social engineering coverage (often a separate sub-limit), retroactive date, and panel counsel requirements. These are where claims disputes actually happen. Don’t just compare premiums — compare what the policy actually pays when something goes wrong.
Step 5: Bind coverage and set a review date
Bind the policy, save the documents somewhere accessible during an incident, and set a calendar reminder 60 days before renewal to re-shop. Cyber rates and coverage forms move quickly — annual shopping is normal and often worth it.
Frequently asked questions about cyber liability insurance cost
How much is cyber liability insurance per month?
Most small businesses pay between $45 and $200 per month for cyber liability insurance in 2026, with a median around $140 per month for a $1 million policy. Sole proprietors and very low-risk businesses can find coverage starting near $30 monthly. Healthcare, financial services, and businesses storing regulated data typically pay $300 to $700 per month or more.
Does the state I’m in affect my cyber insurance premium?
Yes, though it’s a secondary factor. State data breach notification laws, local regulatory exposure, and regional claims experience all affect pricing. Businesses in states with strict privacy laws — California, New York, Illinois — tend to pay slightly higher premiums. Industry research on rate filings shows a spread of roughly 15% to 20% between the most and least expensive states for identical risk profiles.
Is cyber insurance required by law?
Cyber insurance is not federally required, but it is often contractually required. Many client contracts, vendor agreements, and government RFPs mandate specific coverage limits — commonly $1 million or $2 million. Some state regulators (notably New York’s DFS for financial institutions) effectively require it through cybersecurity rules. State breach notification laws don’t mandate insurance but make incidents far more expensive without it.
Does cyber liability insurance cover ransomware?
Yes, virtually all modern cyber policies cover ransomware — including the ransom payment itself (where legally permissible), negotiator fees, forensic investigation, system restoration, and business interruption losses. The catch: watch for sub-limits. Some carriers cap ransomware coverage at 50% of the total policy limit, or as low as $25,000 even on a $1 million policy. Coverage may also be denied if you didn’t have required security controls like MFA and EDR in place at the time of the attack.
What causes the most cyber insurance claims?
Hacking, ransomware, phishing, and employee negligence are the top four. Phishing attacks — where employees are tricked into handing over credentials or clicking malicious links — are especially common and lead to both data theft and fraudulent wire transfer claims. Employee negligence (like losing an unencrypted laptop) can trigger significant notification costs even without a malicious attack.
Can a sole proprietor get cyber insurance?
Yes. Sole proprietors and freelancers can buy cyber liability insurance, and they’re typically in the cheapest tier of the market — often $30 to $75 per month for $500,000 to $1 million in coverage. Most carriers write policies for one-person businesses. It’s especially worth considering if you handle client files, store any customer data, or sign contracts that mention data security.
Does my general liability policy cover cyber attacks?
No. Standard general liability insurance specifically excludes cyber events, data breaches, and electronic data damage. Most policies contain an explicit “electronic data” exclusion. You need a dedicated cyber liability policy or a cyber endorsement on a business owners policy. Some BOPs bundle a small amount of cyber coverage, but limits are usually too low to cover a real breach response.
What is a retroactive date and does it affect cost?
A retroactive date is the earliest date for which your policy will cover incidents — claims arising from events before that date are excluded. A longer retroactive period (covering potential older incidents) costs more, sometimes 10% to 25% extra. For most small businesses buying their first cyber policy, the retroactive date matches the policy inception date. If you’ve had prior coverage, push to match your original first cyber policy date to avoid gaps.
How does the number of records I store affect my premium?
Directly. Insurers view record count as one of the clearest indicators of potential breach cost. The more records you store — and especially the more sensitive those records are — the higher your premium. A business storing 500 email addresses pays very different rates than one holding 500,000 records that include SSNs and financial data. Be accurate on your application: misrepresenting record counts is a common reason claims get disputed.
Is it worth paying a higher premium for better ransomware coverage?
Usually yes, especially if your business relies heavily on its systems. Look at the ransomware sub-limit relative to your policy’s total limit. If a $1 million policy caps ransomware at $25,000, that sub-limit will be exhausted before forensic investigators have finished their first day of work. Either negotiate the sub-limit up or pick a carrier whose base form doesn’t cap it so aggressively. The premium difference between adequate and inadequate ransomware coverage is often less than $200 per year.