Typical cyber insurance for small business covers the costs from hacking and/or a data breach including: costs associated with forensic investigation, costs to notify customers, costs to provide credit monitoring, costs to negotiate and pay ransoms, costs to cover loss of revenue during the time systems are offline, and costs of lawsuits or regulatory actions. Because general liability, property, and businessowners policies exclude or barely touch cyber losses, small businesses purchase this type of coverage separately. The typical cyber insurance policy has $1,000,000 limits and is priced around $1,500 per year based on data collected by Insureon in regard to its customer base.[1]
Most owners assume hackers only target big companies. The data points the other way. Verizon's 2025 Data Breach Investigations Report found ransomware present in 88 percent of breaches at small organizations, against 39 percent at large ones.[2] Attackers also use a small vendor's network as the backdoor into a larger customer's systems.
Cyber Insurance
The cyber insurance covers financial losses due to hacking, data breach, ransomware or other cyber events. They also provide two types of coverage in one package. First party coverage to help pay for an organization's response costs associated with the incident such as forensics, notification of those affected etc., and for lost income, and secondly they include liability coverage to protect against claims brought by affected customers, regulators, and card networks for the damages suffered as a result of the organizations' loss.
What is cyber liability insurance?
Cyber liability insurance (data breach insurance) is an insurance product that provides protection against hacking, data breaches, or ransomware as well as legal action resulting from these types of events. The term "cyber liability" describes a type of risk that traditional coverage was never designed to handle. It is stated in your general liability policy that electronic data is not considered a tangible form of property. A businessowners policy is designed to provide only limited electronic data sub limits, and commercial crime insurance picks up some types of computer fraud but nothing close to full breach response.
What does cyber insurance cover?
Cyber insurance protects against two types of losses that may occur from cyber-attacks. The first type is known as "first-party" coverage which provides for costs incurred by your business due to the direct impact of a cyber-attack (i.e., forensic analysis to determine if there was an actual breach, customer notifications mandated by law, consumer credit monitoring services, restoring lost data, paying ransoms, etc.). In addition, first-party coverage will pay for lost income resulting from the time it takes to get back on-line. The second type of coverage is referred to as "third-party" coverage which will provide for damages and/or legal defense associated with claims brought by third-parties as a result of a cyber-attack including but not limited to: customers who sue because their personal information has been compromised, regulators enforcing privacy laws like HIPAA or the CCPA, and card networks who impose fines under the Payment Card Industry Data Security Standard. A single incident commonly triggers several of these at once.
The ISO benchmark form organizes this into eight insuring agreements, and most proprietary forms map to the same skeleton under different names:
| Insuring agreement | Side | What it pays |
|---|---|---|
| Breach response expense | First party | Forensics, notification, call centers, credit monitoring, PR |
| Cyber extortion | First party | Ransom payments, negotiators, interest on a loan to pay quickly |
| Data restoration | First party | Cost to restore data and programs, including re-entry |
| Business income | First party | Lost net income and continuing expenses during downtime |
| Breach liability | Third party | Damages and defense for people whose data was compromised |
| Regulatory proceeding | Third party | Regulatory defense, consumer redress, insurable fines |
| Payment card liability | Third party | PCI assessments, card reissuance, fraud recoveries |
| Media liability | Third party | Defamation, privacy, and copyright claims from your content |
What does cyber insurance not cover?
Cyber insurance will not insure against the cost of war, and many recently developed cyber insurance forms will exclude widespread events or the failure of infrastructure which you rely on to operate your business but are unable to control. Following an attack sponsored by a government, there may be a question as to whether foreign-government hacking constitutes "war" for purposes of determining whether such loss falls within a policy's "war exclusion." In Merck & Co., Inc. v. ACE American Insurance Company, a New Jersey Appellate Court held in 2023 that a traditional "war exclusion" provision was not applicable to bar recovery under Merck's $1.4 billion NotPetya loss.[3] Carriers rewrote their war language in response, so many policies now exclude nation-state and widespread events outright, and the base form also excludes outages at your own power or internet provider, so a cloud failure that takes your systems down needs contingent business interruption coverage, added by endorsement and usually sub-limited.
How much does cyber insurance cost for a small business?
Typically the monthly premium for a small business averages $129 per month, or about $1,552 per year, based on an analysis by Insureon of their customers' policies, and 41 percent of policyholders pay less than $100 each month.[1] This is usually enough to buy a $1,000,000 coverage limit with a retention that falls in the $1,000 to $2,500 range. Most small businesses cannot afford the average cyber claim for an SME (small or medium enterprise), which NetDiligence reports at $246,000 over a five-year period.[4] Premiums scale with revenue, industry, the volume of personal and card data you hold, prior incidents, and the security controls you can attest to.
Two terms decide how much a policy actually pays when you have a loss:
- Eroding limits: on most cyber forms, defense costs reduce the limit as they are spent. A $1,000,000 policy that spends $400,000 on lawyers has $600,000 left for the judgment.
- Sublimits: extortion, social engineering, and regulatory fines are frequent sublimit targets. A $1,000,000 policy with a $100,000 ransomware sublimit is not a $1,000,000 ransomware policy.
What do cyber insurers require before they quote?
Cyber insurance underwriters today require a set of baseline cybersecurity protections prior to offering you a quote, and when you submit your application for cyber insurance, that information becomes an integral part of your policy. Carriers near-universally require multifactor authentication on all forms of email, remote access and administrator accounts. Furthermore, they expect that you have tested offline backup data, Endpoint Detection and Response (so as to detect malicious activity) and phishing education/training. Many carriers will initially conduct a review of your public exposure by scanning your publicly available footprint. The most common vulnerability identified is Remote Desktop Protocol (RDP) being accessible from the Internet via Port 3389. Coalition's 2024 Cyber Claims Report reported that policyholders with RDP accessible over the Internet were 2.5 times more likely to experience claims.[5] Answer with precision, since what you answer in your applications become the insurers' reliance upon those answers, and a misstatement found after a loss can negate coverage.
Frequently asked questions
Does a BOP or general liability policy cover cyber attacks?
Not meaningfully. CGL does not cover electronic information as it considers it intangible. The CGL also includes a mandatory endorsement limiting cyber exposure. BOP and commercial property forms provide only small electronic data sublimits tied to a narrow set of perils. However, each type of policy can add a cyber endorsement, and those carry sublimits well below real breach costs. A stand-alone cyber policy is the reliable route.
Does cyber insurance cover ransomware payments?
Yes. Cyber extortion coverage will pay for this. The ISO form provides payment of the ransom (including cryptocurrency) as well as payment for a negotiator and/or reward payment. There are conditions however. You must generally be able to verify that the loss has occurred, attempt restoration via backup(s), notify your insurance company prior to making the ransom payment and receive approval. The approval process also includes a review by the carrier for any sanctions on the threat actor due to the Treasury Department's Office of Foreign Assets Control ("OFAC") ransomware advisory, which warns that paying a sanctioned attacker can itself constitute a violation of federal law.[6]
Is cyber insurance required by law?
No state requires businesses to purchase cyber insurance. However, all states have laws (breach notification) that apply regardless of whether you purchased cyber insurance. Privacy regulations such as HIPAA and CCPA will create additional obligation and penalty for your organization. While these legal requirements are in place, most organizations encounter their practical cyber insurance requirements through contractual obligations, since many customer, lender, and government agreements make proof of cyber coverage a condition of doing business.
This guide is for educational purposes and summarizes standard ISO policy language. Your policy's specific terms, conditions, and endorsements control. Talk to a licensed broker about your actual exposures.
The Bottom Line
Cyber coverage will pay for your company's own breach expenses, as well as claims that other entities make, resulting from a data breach. Your general liability and property policies leave that gap wide open. For example, a small business might expect to spend around $1,500 per annum to obtain this type of coverage in comparison with an average claim being approximately $246,000, making the economics favorable for purchasing cyber insurance. Be sure to answer all the application security questions accurately. If you never deployed a security measure that you indicated was in place during the application process, the entire policy may be voided should your company experience a loss. Additionally, ask your agent/broker how your cyber insurance policy is written regarding wire transfer fraud limits and ransomware sub-limits.
References
- 1.Insureon. “Cyber Liability Insurance Cost.” Accessed July 2026. https://www.insureon.com/small-business-insurance/cyber-liability/cost ↩
- 2.Verizon. “2025 Data Breach Investigations Report: Small- and Medium-Sized Business Snapshot.” Accessed July 2026. https://www.verizon.com/business/resources/infographics/2025-dbir-smb-snapshot.pdf ↩
- 3.Superior Court of New Jersey, Appellate Division. “Merck and Co., Inc. v. ACE American Insurance Company.” Accessed July 2026. https://www.njcourts.gov/system/files/court-opinions/2023/a1879-21a1882-21.pdf ↩
- 4.NetDiligence. “Cyber Claims Study 2025 Report.” Accessed July 2026. https://netdiligence.com/cyber-claims-study-2025-report/ ↩
- 5.Coalition. “2024 Cyber Claims Report.” Accessed July 2026. https://www.coalitioninc.com/blog/2024-cyber-claims-report ↩
- 6.U.S. Department of the Treasury, OFAC. “Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments.” Accessed July 2026. https://ofac.treasury.gov/media/912981/download?inline ↩
