Skip to content
florin

Cost

How much does cyber insurance cost for a small business?

Shaurya Aggarwal 4 min read

Cyber insurance used to be something only large companies bought. Now small businesses are frequent targets, especially of email fraud. The FBI’s Internet Crime Complaint Center received 24,768 business email compromise complaints in 2025, with reported losses of about $3.05 billion. Here is what coverage costs and what it covers.

Typical cyber insurance costs

Among Insureon’s customers, 41% pay less than $100 a month and 26% pay $100 to $200. Deductibles commonly range from $1,000 to $2,500, and limits typically run from $1 million to $5 million. Industry makes a big difference: IT and technology businesses average about $179 a month, while finance and accounting firms average about $59.

Cyber insurance benchmarks (Insureon, April 2026)
MeasureFigure
Median monthly premium$129
Median annual premium$1,552
Annual range~$400 to $8,000+
Typical deductible$1,000–$2,500
Typical limits$1 million–$5 million

What cyber insurance pays for

Policies usually combine first-party coverage, for your own costs, and third-party coverage, for claims against you. The FTC suggests looking for coverage of data breaches, cyberattacks on data held by your vendors, breaches of your network, and incidents anywhere in the world.

  • Breach response: forensic investigation, legal counsel, customer notification and credit monitoring.
  • Data recovery and replacement.
  • Business interruption: lost income while systems are down.
  • Cyber extortion and ransomware response.
  • Liability: claims and settlements from affected customers, and costs of responding to regulators.
  • Social engineering and funds transfer fraud, often as an optional or sub-limited coverage — check this carefully given how common email fraud is.

What it usually does not cover

Insureon notes that cyber policies generally exclude professional mistakes and missed deadlines, which fall under errors and omissions coverage, and data loss from power outages or physical damage. Many policies also limit or exclude losses from known vulnerabilities left unpatched, prior incidents, and some acts of war. Read the exclusions and sub-limits, not just the headline limit.

What drives your premium

Insurers increasingly price — and decide whether to offer coverage at all — based on your security controls. Expect application questions about:

  • Multi-factor authentication on email, remote access and admin accounts.
  • Regular, tested backups kept separately from your main network.
  • Endpoint protection and timely patching.
  • Employee training on phishing and payment-verification procedures.
  • How much sensitive data you store: payment cards, health information, Social Security numbers.
  • Revenue, industry and prior incidents.

An example: the fake invoice

A bookkeeper receives an email that appears to come from a regular supplier, asking that future payments go to a new bank account. The email account was actually compromised. Two invoices are paid to the fraudster before anyone notices. This is the pattern behind business email compromise, which the FBI reports as one of the costliest cybercrimes.

How a policy responds depends on its parts. Forensic investigation and legal advice may fall under breach response. Customer notification may be needed if the attacker accessed personal data in the mailbox. The lost payments themselves are usually covered only if the policy includes social engineering or funds transfer fraud coverage, often with a lower sub-limit than the main policy. That is why it pays to read the sub-limits before buying.

How to get better cyber pricing

Turn on multi-factor authentication everywhere it is available, especially email. Keep offline or immutable backups and test restoring them. Require call-back verification before changing vendor bank details or sending wires — a simple control against the business email compromise schemes the FBI reports as one of the costliest. Limit the sensitive data you keep. Then compare policies on what they include, not just price: ask the FTC’s suggested questions about duty to defend, whether coverage is excess of other insurance, and whether the insurer offers a 24/7 breach hotline.

Frequently asked questions

Is cyber insurance worth it for a small business?

For many, yes, if you rely on email, store customer data or move money electronically. A single breach response or fraudulent wire transfer can cost more than years of premiums. Whether it is worth it depends on your data, revenue and how well you could absorb a loss.

Does general liability cover data breaches?

Generally no. Data breaches are commonly excluded from general liability; cyber insurance is designed for them.

Does cyber insurance cover wire fraud?

Sometimes. Social engineering or funds transfer fraud coverage is often optional or carries a lower sub-limit. Ask for it specifically and confirm the limit.

Figures are third-party estimates and examples, not quotes. Coverage depends on the policy terms and underwriting, and rules vary by state.

← All questions