On this page
What cyber insurance costs in 2026
For a typical small business, cyber insurance with $1 million in coverage runs a median of about $130 to $145 per month — roughly $1,550 to $1,740 per year. That’s the middle of a wide range. Low-risk businesses (retail shops, light contractors) can find policies for $45 to $100 a month, while healthcare, financial services, and tech firms handling regulated data commonly pay $300 to $700+ a month.
Rates stabilized in 2026 after several years of sharp increases, which is good news if you’ve been putting this off. Insurers are competing for small business policies again, and businesses with basic security controls — multi-factor authentication, regular backups, employee training — are seeing meaningfully lower quotes than those without.
What it actually covers
Most commercial cyber policies bundle two kinds of coverage:
First-party coverage pays for costs your own business incurs after an attack: digital forensics to figure out what happened, data recovery, business interruption while systems are down, customer notification (legally required in most states), credit monitoring for affected customers, and ransomware or extortion payments where the policy allows them.
Third-party coverage pays when others come after you: customer lawsuits over exposed data, regulatory fines and defense costs, and settlements. Privacy lawsuits are now the primary cyber claim driver — one industry report noted they tripled between 2020 and 2025.
Two fine-print items to read carefully: ransomware coverage often carries its own sub-limit below the overall policy limit, and many policies exclude losses tied to state-sponsored attacks. Neither is a reason to skip the coverage, but both are reasons to read the policy before you need it.
Do small businesses actually get attacked?
Yes, and disproportionately. Industry surveys consistently find that around 43% of cyberattacks target small businesses, yet only about 10 to 20% of small and midsize businesses carry cyber insurance. Attackers like small businesses precisely because the defenses are weaker — no dedicated security team, outdated software, reused passwords.
The average cyber claim runs $115,000 to $221,000, and ransomware claims average $269,000 to $631,000. For a business doing $500,000 in annual revenue, one incident can be existential. Research on small business breaches finds that a majority of small firms that suffer a major breach close within six months. The premium — about the cost of a nice laptop per year — buys survival.
What moves your premium
Industry: Healthcare and financial services pay the most because the data they hold is the most sensitive and the most regulated. A dental practice and a landscaping company with identical revenue will get very different quotes.
Data volume and type: Storing thousands of customer records with payment details costs more to insure than storing a few hundred email addresses.
Security controls: This is the lever you control. MFA on all accounts, encrypted backups kept offline, endpoint protection, and documented incident response plans can cut premiums substantially — and some insurers now require MFA and backups as a condition of coverage at all.
Revenue: Bigger businesses are bigger targets with bigger losses, so premiums scale with revenue.
Claims history: A prior breach raises your rate, just like any other insurance.
What it doesn’t cover
Cyber insurance won’t cover losses from systems you knew were unpatched, attacks your own staff commit intentionally, or future profits lost beyond the policy’s interruption period. And it doesn’t replace basic security — insurers increasingly treat missing MFA or missing backups as coverage-voiding failures, not just premium factors.
The honest way to think about it: cyber insurance is the backup plan for when your defenses fail, not a substitute for having defenses. Pair a reasonable policy with real security hygiene, and you’re covering the risk from both ends. A business owner’s policy sometimes offers a small cyber endorsement, but standalone coverage is usually broader for businesses that actually hold customer data.
Real attack scenarios for small businesses
The attacks that hit small businesses aren’t sophisticated heists — they’re opportunistic. A phishing email to your bookkeeper installs ransomware that encrypts your client files. A vendor’s compromised credentials give attackers access to your shared systems. An employee reuses a password from a breached site on your business accounts. A disgruntled former employee still has access to your cloud storage months after leaving.
Each of these triggers the same expensive chain: forensics to determine what was accessed, legal counsel to navigate breach notification laws (every state has them, and they differ), customer notification and credit monitoring, system restoration, and lost income during downtime. A single phishing email can generate a $100,000 response bill before any lawsuit is filed. That’s the math cyber insurance is priced against.
How to qualify for the best rates
Cyber insurers have gotten specific about what they want to see. The application will ask about multi-factor authentication (now effectively mandatory for coverage), encrypted and tested backups, endpoint detection software, email filtering, employee security training, and an incident response plan. Businesses that can answer yes across the board get the best rates; businesses that can’t may get declined outright.
The good news: these controls are also just good security. MFA is free. Automated cloud backups cost a few dollars a month. The same measures that lower your premium lower your chance of ever filing a claim — which is the actual goal.
Standalone policy vs BOP endorsement
Many BOPs offer a small cyber endorsement — typically $25,000 to $100,000 in limits for a modest additional premium. For a business with minimal data exposure, that’s reasonable. But if you store customer payment data, health information, or thousands of personal records, a standalone $1 million policy is the appropriate level. The BOP endorsement is a starter; the standalone policy is the real coverage. Match the limit to what a breach would actually cost you, using the average claim figures above as a guide.
The application process: what to expect
Applying for cyber insurance takes longer than other small business policies because the underwriting is more involved. Expect a detailed questionnaire about your IT setup: how you store data, who has access, what security tools you run, whether you’ve had prior incidents. Some carriers require a brief external security scan of your network. Answer accurately — misrepresenting your security posture can void coverage when you file a claim, which is exactly when you discover the problem. If the application asks whether you have MFA and you don’t, the right move is to implement MFA and then apply, not to check the box and hope.
Who needs it most urgently
Any business that stores customer data — which is nearly every business with a website, a point-of-sale system, or an email list. But the urgency is highest for: professional services holding client financial data (accountants, bookkeepers, financial advisors), healthcare-adjacent businesses with patient information, e-commerce stores processing payments, and any business with remote workers on home networks. If you answered “we’re too small to be a target” — that’s the exact profile attackers prefer. Small, under-defended, and likely to pay a ransom quickly to get back to business.