Quick Answer
Cyber insurance cost for most small and mid-size businesses runs between $500 and $5,000 per year for $1M in coverage, according to the Cyber Readiness Institute. Your exact premium depends on revenue, industry, the sensitivity of the data you hold, your policy limits and retention, and the security controls you can prove, such as MFA and tested backups.
If you have shopped for a cyber policy lately, you already know the frustration: the prices are all over the place. One business owner recently shared that a quote for cyber insurance came in at $18,000 a year and “seems pretty spicy.” Another reported a premium increase of 350% for identical coverage compared to the prior year. Others hear premiums that appear steep compared to the actual coverage provided, and quietly decide to go without. That confusion is exactly why understanding cyber insurance cost matters before you buy, not after. The Coyle Group is a commercial insurance agency that handles the complex, high-value risks other agencies don’t know how to structure, where the details in the policy are the difference between a paid claim and a denied one.
What Happens to Businesses That Skip Cyber Insurance?
Businesses that skip cyber insurance pay for incidents entirely out of pocket, and those bills are getting bigger every year. The FBI’s Internet Crime Complaint Center logged $20.9 billion in reported losses in 2025, a 26% increase over 2024. What surprises most owners is that their other policies almost never pick up these costs, and that gap is where the real damage happens.
IBM’s 2025 Cost of a Data Breach Report puts the average US breach at a record $10.22 million. Your business is not average, but scaled-down versions of the same expenses hit small firms just as hard:

Those three claim scenarios, paraphrased from Travelers Insurance cyber sales literature, appear in more detail later in this article, because where the money goes explains what you are actually buying. Without cyber insurance, none of these events would be covered by any other policy those companies bought.
Want to know what cyber insurance cost looks like for your firm specifically? Contact us for a no-pressure review.
How Much Does Cyber Insurance Cost in 2026?
Most small and mid-size businesses pay between $500 and $5,000 per year for cyber insurance, a range published by the Cyber Readiness Institute in its small business cyber insurance FAQ. The catch is that this range assumes roughly $1M in limits and a clean risk profile, and both assumptions move the number substantially.
Gordon answers how much cyber insurance costs and how to get it
Here is how cyber insurance cost typically scales by revenue for a business with standard controls in place.
Annual Revenue |
Typical Annual Premium (about $1M limit) |
|---|---|
|
Under $1M |
$500 to $1,500 |
|
$1M to $10M |
$1,000 to $3,000 |
|
$10M to $50M |
$3,000 to $10,000 |
|
$50M to $100M+ |
$10,000 to $50,000+ |
Treat these cyber insurance cost ranges as planning numbers, not quotes. A tech firm holding client data will land at the top of its band. A landscaping company with no stored payment data will land near the bottom. And a firm that cannot show MFA or tested backups may pay double, or get declined entirely.
What is cyber insurance, in simple terms?
Cyber insurance is a policy that pays the costs of a hacking incident, ransomware attack, or data breach: the forensics team, the lawyers, customer notification, lost income while systems are down, and lawsuits or fines that follow. If you want the full breakdown of coverage parts, our guide to what cyber insurance covers walks through each one.
What Drives Cyber Insurance Cost Up or Down?
Seven factors determine almost all of the movement in cyber insurance cost: revenue, industry, data type and volume, policy limits, retention, security controls, and claims history. Underwriters weight them differently, which is the honest reason two carriers can quote the same business thousands of dollars apart.
The seven pricing factors
The Hartford notes in its cyber insurance cost overview that carriers have eased rates for companies demonstrating strong security measures, while ransomware exposure keeps upward pressure on everyone else. That split, tightening for weak controls and softening for strong ones, has defined the market since the hard-market spike that produced those 350% renewal stories. The NAIC’s 2025 Cybersecurity Insurance Report shows the US market at $9.14 billion in direct written premiums for 2024, down 7% from the prior year as pricing softened.
Watch the fine print, not just the premium.
Two market trends change what a quote is really worth: co-insurance provisions that require you to retain 10 to 20 percent of every loss, and ransomware sub-limits that cap that coverage at a fraction of the overall policy limit. A low cyber insurance cost with both provisions can deliver half the protection of a slightly pricier policy without them. Ask for both numbers on every quote.
Curious where your controls put you? Take our cyber risk assessment scorecard, then book a call to review the results.
Anatomy of a Cyber Breach: Where the Money Actually Goes
Every cyber claim breaks into the same expense buckets: investigation, restoration, lost income, notification, and legal fallout. Seeing a real breach unfold line by line explains why cyber insurance cost is trivial next to the cost of an uninsured event, and why premiums vary with the data you hold.
Years ago, A.M. Best reported that cyber premiums grew over 32% in 2017, with most of that growth in the Fortune 500 world while SME penetration sat in the low teens. That gap has narrowed, but the pattern remains: the large corporate buyers purchase as much cyber protection as they can get, while smaller firms hesitate. Do decision makers in the SME market think it will not happen to them? Do they forget that large firms have teams of experts defending their networks, yet still get hacked? Whatever the reasoning, these claim scenarios from Travelers cyber literature show what an uninsured event looks like:
Ransomware: $2M+ uninsured
A $100M manufacturer lost several days of production to malware in its production system. Forensics, restoration, and overtime were substantial, but nothing compared to the lost production. Total costs exceeded $2,000,000, and the property policy paid nothing. A $2M cyber policy would have cost less than $15,000 a year.
Phishing: $300K+ uninsured
One phishing email exposed PII for 5,000 customers at a firm under $10M in revenue. Forensics, notification, credit monitoring, and multi-state fines ran upwards of $300,000. A cyber policy would have been about $3,000 a year. Pay $3,000 in premiums or $300,000 out of pocket: you tell me which is the better deal.
HIPAA breach: $440K uninsured
A home healthcare employee emailed 750 patient records to his home computer, breaching company policy and the HIPAA Privacy Rule. Notification, federal investigations, and the PR fallout cost about $440,000. At roughly $40M in revenue, premiums would have been around $7,000 a year.
Scenario 1: Ransomware at a manufacturer
A server at a manufacturing plant with $100M in revenues was infected with undetectable malware.
Hackers gained access to the plant’s production system and caused a shutdown lasting several days. A computer forensic expert was hired to investigate and help the IT team restore systems. The outside experts and internal overtime were substantial, but nothing compared to several days of lost production.
Total estimated costs exceeded $2,000,000. You may think business interruption insurance covers this, but the shutdown was not caused by a covered peril, so the property policy paid nothing. A $2M cyber policy would have probably cost less than $15,000 a year, less than 2 percent of that firm’s total insurance budget. Our ransomware coverage guide explains how these claims get paid.
Gordon explains whether cyber insurance covers ransomware attacks
Scenario 2: Spear phishing at a small company
An employee opened a phishing email that looked legitimate and infiltrated the network in a split second. Anti-virus software had not been updated, and hackers accessed names, addresses, social security numbers, and financial data for 5,000 customers. A forensics investigator determined the scope, customers were notified, and each received a year of credit monitoring. Costs ran upwards of $300,000, and several states levied fines for failure to protect personally identifiable information. For a company under $10M in revenue, a cyber policy would have been about $3,000 a year. Pay $3,000 in premiums or $300,000 out of pocket: you tell me which is the better deal. Training is the cheapest defense here, and our cybersecurity awareness training guide shows where to start.
Scenario 3: Innocent negligence at a healthcare firm
An employee of a home healthcare provider emailed a spreadsheet to his home account to finish that evening. The file contained names, insurance data, and private medical records for 750 patients, breaching both company policy and the HIPAA Privacy Rule. The employee was terminated, the employer was forced to notify all 750 patients, and the public relations fallout damaged the company’s reputation, costing about $440,000 in notification and defense expenses tied to federal investigations. At roughly $40M in revenue, premiums would have been around $7,000 a year. Human mistakes like this drive most incidents, which is why we wrote about how 95% of data breaches are caused by human error.
These are only a few examples of how a cyber event can deal a crushing blow to any sized company. More are collected in our cyber insurance claims examples library.
How Do You Lower Your Cyber Insurance Cost?
You lower cyber insurance cost by proving the security controls underwriters care about: MFA everywhere, tested backups, patched software, filtered email, managed access, and trained employees. The Cyber Readiness Institute lists these as the minimum controls carriers want to see. What most owners miss is that the same controls also decide whether a claim gets paid. Budget note: these basics typically cost a small business far less per year than the premium credit and claim protection they unlock, so security spend and cyber insurance cost should be planned together.
Six controls that cut premiums

Is Cyber Insurance Worth the Cost?
Yes. For most businesses, cyber insurance cost runs 1 to 2 percent of what a single uninsured incident would take out of pocket, and the policy buys you an emergency response team, not just a check. The part buyers underestimate is the breach coach, and it deserves its own explanation.
If a cyber event hit your firm tonight, who would you call? Your attorney? Your outsourced IT firm? Your CPA? As the panic sets in that your network is compromised or your data is locked by ransomware, who is the first person you call? If you have purchased cyber insurance, you likely have a 24/7 emergency number. On the other end is a breach coach who understands what you are experiencing and what steps to take immediately to limit the damages and consequential damages.
Gordon on whether you really need cyber insurance
A real morning, a real breach coach
“This breach coach, in my opinion, is worth every penny you could spend on cyber insurance.”
Gordon recently had a client call early one morning in a panic: their network was compromised and he did not know the extent of the intrusion. Because the firm had purchased cyber insurance, Gordon gave him the 1-800 number. A half hour later the client called back with an update. The breach coach had given him specific instructions and people to reach out to. By mid-day the situation was under control and in the hands of experts. That is the real value of cyber insurance. Weigh cyber insurance cost against a morning like that, and the math gets easy. Still skeptical? We wrote an honest answer to is cyber insurance BS for small business owners asking exactly that.
How Do You Get an Accurate Cyber Insurance Quote?
An accurate cyber insurance quote requires three inputs: your revenue and record counts, your current security controls, and the limits and retention you want. Get those right and quotes converge fast, and your cyber insurance cost estimate becomes a number you can trust. Get them wrong and you either overpay or set up a claim dispute later.
What to have ready before you ask for pricing:
Two buying mistakes inflate cyber insurance cost or gut the coverage. First, quick-quote tools that skip underwriting produce numbers that rarely survive contact with a real application, which is why our cyber insurance cost calculator page explains what online estimates get wrong. Second, bolting a cyber endorsement onto a BOP looks cheap but leaves gaping holes, and we explain why in endorsing cyber insurance to a BOP. Our 9 tips for buying cyber insurance covers the rest of the process.
Gordon on why cyber insurance cost calculators get it wrong
Why Work With The Coyle Group on Cyber Insurance Cost?
The Coyle Group treats cyber insurance cost as an engineering problem, not a rate sheet. We benchmark your exposure, structure limits and retention around your actual worst case, and present your security posture to carriers in the language that earns credits. That is different from an agency that emails you three quotes and lets you pick the cheapest.
Gordon B. Coyle, CPCU, ARM, AMIM, PWCA, has spent more than 40 years solving insurance problems for businesses across the US, from small business cyber insurance placements to complex programs for technology companies and financial firms. Every review starts with what you are actually exposed to, not what a carrier wants to sell.
Ready for a number you can budget against? Book a call and we will build your cyber insurance cost estimate together.
Frequently Asked Questions About Cyber Insurance Cost
Author’s Expertise
This article was written by the CEO of The Coyle Group, Gordon B. Coyle, CPCU, ARM, AMIM, PWCA, who has over 40 years of experience working with business owners of all sizes and industries across the US, solving their insurance challenges.