
Most small business owners assume cyberattacks are a big company problem. They're not. In 2023, the FBI's Internet Crime Complaint Center recorded over $12.5 billion in losses from cybercrime, and a significant share of those incidents involved small and mid-sized businesses. The reason is straightforward: small businesses typically have weaker security than enterprises, they often hold valuable data, and attackers know that the payout-to-effort ratio can be better with smaller targets than with heavily defended corporations.

Cyber insurance exists to limit the financial damage when something goes wrong – and it's a category of coverage that most small business owners either don't have or fundamentally misunderstand. This guide explains what it actually covers, what it doesn't, what it costs, and whether your business genuinely needs it.
Cyber liability insurance is designed to cover the costs that follow a cyberattack or data breach. Those costs come in two main forms, and most policies cover both.
First-party coverage handles the direct costs to your business. This includes notification costs (you're often legally required to notify affected customers or employees after a breach – that process costs money), credit monitoring services for affected individuals, forensic investigation to figure out what happened and how, data restoration, and business interruption losses if your systems go down and you can't operate. If you get hit with ransomware that encrypts your business files, first-party coverage may also help with ransom payments and recovery, though this varies by policy and is increasingly scrutinized by insurers.
Third-party coverage handles claims made against your business by others. If a data breach at your company exposes a client's customer data, that client – or their customers directly – may sue you. Third-party cyber coverage pays for legal defense costs, settlements, and regulatory fines or penalties that result from the breach. For businesses that hold client data as part of their service (accountants, healthcare-adjacent businesses, marketing agencies, IT service providers, e-commerce companies), this side of the policy can be the most critical.
Some policies also include coverage for social engineering attacks – where an employee is tricked into transferring money or handing over credentials through a fraudulent email – and cyber extortion beyond ransomware. Coverage specifics vary significantly between providers, so reading the actual policy language matters more than trusting a general description.
Understanding the exclusions is as important as understanding what's covered, because many business owners have unrealistic expectations about what a cyber policy will do.
Most cyber policies do not cover losses from a failure to maintain basic security standards. If a breach occurs because you were running software with known unpatched vulnerabilities, never updated your passwords, had no multi-factor authentication in place, or ignored clear security warnings, a claim can be denied on the grounds that you failed to meet the minimum security posture the policy assumes. Insurers are increasingly specific about the security practices they require as a condition of coverage, and they will investigate how a breach occurred before paying a claim.
Cyber insurance also typically doesn't cover physical damage to hardware, intellectual property theft (the value of stolen trade secrets or proprietary code isn't typically covered), reputational damage, future revenue lost because customers leave after a breach, or losses from pre-existing breaches discovered after the policy started. The policy covers the incident response and liability consequences of a covered event, not the full downstream business impact.
Prior incidents are also excluded. If you've had a breach before and didn't disclose it on the application, you're looking at potential policy rescission. Insurers ask about your security history upfront, and misrepresentation on the application voids coverage.
Cyber insurance premiums for small businesses have risen significantly over the past few years as the volume and cost of claims has increased across the industry. The days of very cheap coverage are gone, but the cost is still manageable for most businesses.
For a small business (under $1 million in annual revenue), annual premiums for basic cyber coverage typically range from $500 to $1,500. A business in the $1–$5 million revenue range might pay $1,500 to $3,500. Higher-risk industries – healthcare, financial services, e-commerce, businesses holding large volumes of personal data – pay more. The deductible on a basic policy often runs $1,000–$5,000, with higher deductibles available in exchange for lower premiums.
Coverage limits matter significantly. A $250,000 limit might be adequate for a very small service business but insufficient for a company handling thousands of customer records. Breach notification and response costs alone can exceed $100,000 for a moderate-sized incident once you factor in forensics, legal counsel, and notification to affected parties. Get enough coverage to actually cover a realistic incident, not just the minimum that keeps the annual premium low.
Factors that affect your premium include your industry and the type of data you hold, your annual revenue, your existing security practices, whether you've had prior incidents, the coverage limits and deductible you select, and which insurer you're working with. Answering the security questionnaire accurately and demonstrating good practices (MFA enabled, regular backups, employee training) genuinely lowers your premium.
The honest answer is that it depends on two things: what data you hold and what a breach would actually cost you.
You handle any personal data for customers, clients, or employees – names, email addresses, payment card information, health records, Social Security numbers, or any data that triggers notification requirements under state or federal law. All 50 US states have data breach notification laws, and the cost of compliance after a breach can be substantial even before any lawsuits are filed.
You store client data as part of your service. Accountants hold sensitive financial data. Marketing agencies hold customer lists and campaign data. IT service providers have access to client systems. Lawyers hold privileged communications. Healthcare-adjacent businesses hold patient-adjacent records. Any of these situations creates meaningful third-party liability if that data is compromised.
You process payments. If you accept credit or debit card payments through any digital system, you're a target. Payment card data is among the most immediately monetizable data type for attackers, and a breach creates both notification obligations and PCI DSS compliance consequences.
You rely heavily on your systems to operate. If a ransomware attack locked you out of your systems for two weeks, what would that cost in lost revenue and recovery expenses? If the answer is more than you could absorb comfortably from cash reserves, the business interruption component of cyber coverage is doing real work for you.
You're a solo freelancer or very early-stage business with no client data, no payment processing, no employees, and all work done through platforms that hold the data on their end. In this scenario, your direct cyber exposure is limited. If you're writing articles through a platform, the platform holds the data – not you. But even here, that window is usually short, and many freelancers gain client data access quickly once real client relationships develop.
A small accounting firm with three employees gets hit by a phishing attack. An employee clicks a link, enters their credentials into a fake login page, and attackers access client records for two weeks before the breach is detected. The firm must notify affected clients, hire a forensic firm to assess the scope of the breach, engage a lawyer to handle a regulatory inquiry from the state attorney general, and defend against a civil claim from a client whose information was used fraudulently. Without cyber insurance, those costs easily reach $75,000–$150,000. With a policy carrying a $500,000 limit and a $2,500 deductible, the business pays the deductible and the insurer handles the rest.
A small e-commerce business gets hit by ransomware that encrypts their inventory management system and order database. They lose four days of operations, need to pay a specialist to restore data from backups (which were fortunately in place), and must notify customers whose stored payment details were potentially exposed. First-party coverage handles the business interruption losses and the notification costs. Third-party coverage handles the customer claims that follow.
Neither of these scenarios is exotic. They're the most common categories of small business cyber incidents, and both illustrate why the coverage-to-cost ratio makes sense for businesses with meaningful data exposure.
Most major business insurers now offer cyber coverage, either as a standalone policy or as an endorsement on a Business Owner's Policy. Standalone cyber policies from dedicated providers tend to offer more comprehensive coverage and higher limits than endorsements, which may only add limited coverage to an existing policy.
Online platforms that specialize in small business insurance – Next Insurance, Hiscox, Coalition, Corvus, and Embroker are frequently cited options – allow you to get quotes and purchase policies quickly. For more complex needs or higher revenue businesses, working with an independent broker who can compare policies across multiple carriers is worth the time. The security questionnaire you complete as part of the application process is also a useful self-assessment – if the questions reveal gaps in your security practices, addressing them before applying can lower your premium and improve your overall security posture simultaneously.
Before buying, compare coverage on: the specific events covered (phishing, ransomware, social engineering, insider threats), coverage limits for both first-party and third-party claims, business interruption provisions including the waiting period before coverage kicks in, the deductible, and any security requirements built into the policy that you need to maintain to keep coverage valid.
Assuming your general liability policy covers cyber incidents is one of the most expensive misconceptions in small business insurance. Standard GL policies specifically exclude cyber events in most cases. Unless you have explicit cyber coverage – either a standalone policy or a clearly stated endorsement – you're not covered.
Buying the minimum limits to keep the premium low is a false economy. A $100,000 cyber policy limit sounds like a lot until you're looking at a forensic investigation, legal fees, regulatory fines, and notification costs for a breach affecting 5,000 customer records. Model what an actual incident would cost before selecting your limit.
Completing the security questionnaire carelessly is another common mistake. Insurers ask about your security practices to assess risk – and to establish whether you meet the minimum requirements for coverage. If you say you have MFA enabled and you don't, and a breach happens because of a compromised password, that misrepresentation can void your claim. Be accurate, and use the questionnaire as an opportunity to identify and close real security gaps.
Finally, treating cyber insurance as a substitute for basic security practices is backwards logic. Insurance pays the costs of an incident after it happens. Good security hygiene – regular software updates, strong password policies, multi-factor authentication, employee training on phishing, and regular backups stored offline – reduces the likelihood of the incident happening in the first place. The two work together.
Does cyber insurance cover ransomware payments? Some policies include ransomware coverage, but this is an area of active change in the industry. Some insurers are limiting or excluding ransomware payments in certain circumstances, particularly where there are government sanctions against paying certain threat actors. Review the policy language carefully and ask your broker specifically about ransomware coverage and any limitations.
Is cyber insurance required by law for small businesses? It's not legally mandated in most cases, but it may be required by contract. Enterprise clients increasingly require vendors and contractors to carry cyber liability coverage as a condition of doing business. If you're pursuing contracts with larger organizations, check whether their vendor requirements specify cyber coverage minimums.
How is cyber insurance different from data breach insurance? Data breach insurance is a narrower term sometimes used to describe coverage focused specifically on the notification and response costs following a breach. Cyber liability insurance is broader, typically covering both the first-party response costs and third-party liability claims. When evaluating policies, look at what events are covered and what costs are covered rather than relying on the label.
What security practices do insurers require? Requirements vary by insurer and coverage level, but common baseline requirements include multi-factor authentication on email and critical systems, regular data backups stored separately from primary systems, up-to-date software and security patches, and basic employee security training. Higher coverage limits and more complex businesses face more stringent requirements.
My business is very small – is cyber insurance worth it? If you hold any customer or client data, process payments, or rely on digital systems to operate, the answer is generally yes for most small businesses. The annual cost of a basic policy ($500–$1,500) is modest compared to the cost of a single incident, and the threshold for "data worth protecting" is lower than most small business owners assume. Even a list of client email addresses and billing records triggers notification obligations in most US states.
Cyber insurance isn't the most exciting thing you'll buy for your business, but it's increasingly one of the more necessary ones. The question isn't whether cyberattacks happen to small businesses – they do, regularly. The question is whether you can absorb the cost if one happens to yours. For most businesses holding client data, processing payments, or depending on digital systems to operate, a properly structured cyber policy costs less per year than a single day of response to a serious incident.
Get the coverage that matches your actual exposure. Understand what it covers and what it doesn't. And pair it with the basic security practices that reduce your odds of needing it in the first place.
This article is for informational purposes only and does not constitute legal or insurance advice. Consult a licensed insurance professional for guidance specific to your business situation.
FBI Internet Crime Report 2023 – FBI IC3: https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf
Small business cybersecurity resources – US Small Business Administration: https://www.sba.gov/business-guide/manage-your-business/strengthen-your-cybersecurity
Cyber liability insurance overview – Insurance Information Institute: https://www.iii.org/article/cyber-risk-and-small-business
State data breach notification laws – National Conference of State Legislatures: https://www.ncsl.org/technology-and-communication/data-security-breach-notification-laws
PCI DSS compliance for small businesses – PCI Security Standards Council: https://www.pcisecuritystandards.org/small-merchants/
Cyber insurance market trends and requirements – CISA guidance for small businesses: https://www.cisa.gov/topics/cybersecurity-best-practices/small-and-medium-businesses


















