Why Aren’t YOU Buying Cyber Insurance?

Quick Answer

Why Cyber Insurance? The Honest Answer to “Can My Business Survive a Breach Without It?”

TL;DR

The real question behind “why cyber insurance” is not whether cyber risk exists. It is whether your business could write a check for the full cost of a breach tomorrow without borrowing or laying people off. If the answer is no, you have a financial transfer problem, not an IT problem. Cyber insurance moves that cost off your balance sheet and brings a crisis team with it. Your general liability, umbrella, and property policies will not.

For 40 years I have sat across the table from business owners who buy property insurance for a fire they have never had and liability insurance for a lawsuit that never came, then hesitate on cyber. If you have outgrown one-size-fits-all coverage and you are trying to decide whether this line is worth the premium, this page is for you.

Most owners I talk to are not asking me to define cyber risk. They already know attacks happen. What they are quietly weighing is a money question: can I afford to self-insure a breach, or would one incident wipe me out? That is the honest version of “why cyber insurance,” and it deserves an honest answer with real numbers.

The Coyle Group approach

You tell me what a bad day would actually cost your business, and I will tell you whether transferring that risk is worth roughly 3% of your insurance budget. No fear tactics, no jargon. If you want that number for your business, book a call and I will get you a premium indication from three basic questions.

Do you actually need cyber insurance?

Yes, if your business stores customer data, sends or receives payments, or runs on email, you need cyber insurance, and here is the part owners get wrong: size does not make you safe, it makes you a target. In my experience the smallest firms are the most exposed, because attackers know they carry the least defense. That belief that you are too small to bother with is the exposure.

The data backs this up. Roughly 64% of small businesses believe their operation is too small to be an attractive target, while two thirds of attacks now focus on the small and mid-sized market. Hackers chase the “small fish” on purpose, because those firms rarely have the staff or tools to fight an intrusion the way a large enterprise can.

So the question is not whether cyber criminals want your business. It is whether you have decided who pays when they get in.

A few quick tests tell me whether an owner genuinely needs coverage:

  • You hold customer, patient, or employee records of any kind.
  • You move money by wire, ACH, or invoice.
  • You depend on email, a website, or cloud software to operate.
  • A day of downtime would cost you real revenue.
  • A client contract or regulator expects you to protect their data.

If you checked even one box, cyber belongs in your program. You can learn how we structure it on our cyber insurance page.

How much exposure you carry, though, depends on your business model:

  • Professional and financial firms hold sensitive client records and face regulatory and liability fallout if that data leaks.
  • Retail and ecommerce operations process card payments, so payment fraud and PCI obligations dominate their risk.
  • Manufacturers and distributors face operational shutdown and funds transfer fraud on vendor payments.
  • Healthcare and benefits firms hold protected records that carry the steepest notification duties when breached.

There is an honest flip side. If you hold no customer data, take no digital payments, and could comfortably absorb a total loss from cash reserves, cyber may be optional for you, and I will tell you that rather than sell you a policy you do not need.

What a cyber breach really costs a business your size

A cyber breach typically costs a small or mid-sized business six figures, and the range runs far higher than most owners guess. The average event lands around $117,000 according to Kaspersky Labs, but that is only the average. What surprises people is not the headline number, it is how the bill splits across costs they never planned for.

Here is what the research shows once you add up the full incident, not just the ransom:

Cost driver

Typical impact for an SMB

Average cyber event (baseline)

~$117,000 (Kaspersky Labs)

Average total attack cost

~$254,445, up to $7M at the high end (Microsoft)

Downtime while you recover

~$53,000 per hour (industry estimates)

What responds from your other policies

$0 in most cases

The federal government makes the same point plainly. As the Federal Trade Commission notes, recovering from a cyber attack can be costly, and cyber insurance is one option that helps protect your business against those losses. The scale is not abstract either. The FBI logged $12.5 billion in reported cybercrime losses in 2023 alone, according to the Insurance Information Institute.

Now put that next to a premium that averages a few thousand dollars. This is the math that ends most debates. Want to see what a claim actually looks like start to finish? Walk through the anatomy of a cyber breach and then ask whether your business could absorb it alone.

A pattern we see in practice

An employee gets an email that looks like it came from a vendor, updates the “new” bank details, and wires a payment. The money is gone before lunch. There is no fire, no lawsuit, no property damage for another policy to respond to. The cyber policy covers the funds transfer fraud, the forensics to confirm how it happened, and the legal notice if data moved too. That is the difference between a bad week and a solvency event.

If you want that exposure quantified for your own numbers, request a coverage-gap review and we will size it with you.

Doesn’t my general liability or BOP already cover this?

No, in almost every case your general liability, umbrella, and property policies will not pay a cyber claim, and this is the single most expensive misunderstanding I see. Owners assume they are covered, skip the dedicated policy, and only learn the truth after a breach when the denial letter arrives. I blame the industry for explaining this poorly, so let me be direct about why those policies stay silent.

General liability responds to bodily injury and property damage. A data breach is neither. Property policies cover physical loss to physical things, and data is not a physical thing under most forms. Umbrella coverage only extends what sits beneath it, so it cannot reach a risk the underlying policy never covered in the first place.

There is one exception worth knowing. Some small business owners policies can be endorsed to add limited cyber coverage. It sounds efficient, but it is usually a trap.

Here is what a bolt-on endorsement typically leaves out:

  • Full breach response and forensics, not a token sublimit.
  • Access to an incident response team the day it happens.
  • Ransom negotiation and payment coverage.
  • Business interruption for lost income during downtime.

I have written before about why you should not simply endorse cyber onto a BOP. It also helps to understand where cyber ends and other coverage begins, which is why the distinction between cyber insurance versus crime insurance matters when someone wires money out the door. A standalone policy is the only reliable answer.

What cyber insurance actually covers (and what it won’t)

Cyber insurance covers the two sides of a breach: the costs your business absorbs directly, and the costs you owe to others. Owners want to know if the premium buys a check after the fact or real help during the crisis, and the honest answer is both, if the policy is structured right. The catch is that coverage varies wildly between forms, so knowing the parts is what protects you.

Cyber coverage splits into first-party and third-party protection. First-party pays for your own losses. Third-party pays for claims others bring against you.

The clean breakdown looks like this:

Coverage side

What it pays for

First-party

Forensics, data restoration, business interruption, ransom payment, notification costs, credit monitoring, PR

Third-party

Lawsuits from affected customers, regulatory fines and defense, liability from a breach of others’ data

For a deeper split of who gets paid and when, the difference between first-party and third-party cyber coverage is worth ten minutes of your time before you buy.

Just as important is what cyber will not do. It is a backstop, not a security program. Common gaps and exclusions include:

  • Losses tied to security controls you claimed to have but did not maintain.
  • Prior incidents you knew about before the policy started.
  • Upgrades to your systems beyond restoring what was lost.

Cyber pays for the damage. It does not replace doing the basics well. Book a call if you want your current form read line by line.

How much does cyber insurance cost?

Cyber insurance usually costs a small or mid-sized business between about $1,000 and $7,500 a year for a $1 million limit, and for most of my clients it lands near the low end of that range. What tends to shock owners is not the price, it is how small the price is next to the exposure it removes. This is where the “it is too expensive” objection usually falls apart.

In our own book, the cyber policies we quoted in this market segment averaged around $4,000, which came to less than 3% of the client’s total insurance spend. I call that the 3% reframe: for roughly three cents on every insurance dollar, you move your single most ruinous risk off your balance sheet.

Here is how pricing generally shapes up:

Business profile

Typical annual premium ($1M limit)

Micro business, low data volume

~$400 to $1,600

Small to mid-sized, moderate risk

~$1,000 to $7,500

Data-heavy or higher-risk operations

Priced individually

What drives your premium up or down comes down to a short list:

  • Your annual revenue and the volume of records you store.
  • Your industry and how attractive your data is to attackers.
  • The security controls you have in place, such as multi-factor authentication, tested backups, and endpoint protection.
  • The coverage limit and the sublimits you select.
  • Your claims history and how cleanly you answer the application.

This is the point where the answer to why cyber insurance is worth it becomes plain: the premium is a rounding error next to the loss. Two things are pushing rates in 2026, so waiting rarely saves money. S&P projects a 15% to 20% rise in cyber premiums after a 126% jump in ransomware incidents. The market is hardening, not softening. My honest read is the same one I have given for years: the cheapest this coverage will be is today. If you want a real indication for your business, contact us and answer three basic questions.

Why claims get denied, and how to make sure yours pays

Cyber claims get denied most often because the business did not maintain a security control it attested to on the application, and this is exactly the fear I hear owners voice out loud. One told me it plainly: they worry the policy will be invalid because there is some control claimed in it they do not actually have, so the insurer will not pay. That fear is valid, and it is also fixable.

Industry reporting puts the cyber claim denial rate above 40% in some segments, and the pattern behind those denials is consistent. Insurers now gate coverage behind real controls, then check whether you kept your word.

The usual culprits:

  • Multi-factor authentication that was promised but not enforced everywhere.
  • Backups that existed on paper but were never tested.
  • Endpoint protection or employee training that lapsed after binding.

The application itself has become brutal. One owner described today’s process as filling out what used to be a one-page form and now feels like applying for a top-secret government clearance. Fourteen-page questionnaires are common, and answering them wrong is how good businesses end up uninsured when it counts.

This is where a broker earns the fee. In practice, we prep clients before they ever answer the questionnaire, so the controls you attest to are controls you actually have. That is the difference between a policy that pays and a policy that argues. Book a call and we will pressure-test your application before an underwriter does.

Are you required to carry cyber insurance?

Cyber insurance is rarely mandated by law the way workers compensation or auto liability is, but “not legally required” is not the same as “optional.” More and more, owners come to me because someone is effectively forcing the issue, and that someone is usually a customer, a regulator, or a lender. The requirement is real even when the statute is not.

Here is where the pressure typically comes from:

  • Client contracts. Enterprise customers increasingly require vendors to carry cyber limits before they sign.
  • Regulators. Data-protection and breach-notification rules impose costs and duties that a policy is built to fund.
  • Lenders and partners. Financing and partnership agreements can name cyber coverage as a condition.

Most forms of insurance we buy are mandated somewhere, by government or by contract. Cyber is often the exception, and owners read that gap as permission to skip it. That is the wrong read. The absence of a mandate does not make the risk smaller, it just means no one is forcing you to protect against the one exposure most likely to end your business. If a client is already asking for proof of coverage, contact us and we will get you compliant fast.

The four reasons owners skip cyber insurance, and the honest answer to each

Owners skip cyber insurance for four predictable reasons, and every one of them dissolves under a close look. In the national research, roughly 59% of businesses still carry no cyber coverage, and industry surveys keep finding the same top reasons: owners think their risk profile does not warrant it, premiums cost too much, or they handle the risk internally. Those are the same four objections I have answered for years, so here they are with the honest reply.

  • “I have not had an incident yet.” Neither had you when you bought property and liability coverage. We insure risks before they hit, not after. Waiting for the first breach to prove the point is the most expensive way to learn it.
  • “My other insurance covers it.” It does not. As covered above, general liability, umbrella, and property forms stay silent on cyber, and a BOP endorsement is thin at best.
  • “My IT controls handle it.” Controls reduce the odds, and they are worth every dollar. But humans click links, and one mistake can expose your whole network. Insurance is the backstop when the controls fail.
  • “It is too expensive.” At roughly 3% of your insurance spend to remove a six or seven figure exposure, the cost objection is really a valuation error. You are comparing the premium to zero instead of to the loss.

“Business owners buy property and liability insurance when they’ve not had a fire or experienced a lawsuit, why is there such reluctance to purchase cyber insurance?”

That is the question I keep coming back to. Insurance becomes the backstop to financial ruin the moment an employee unwittingly clicks a link that wreaks havoc on your systems. If you have watched the CrowdStrike outage or seen how fast a small business gets hit, you already know the risk is not theoretical.

The Absorb-It Test: one question that settles the decision

If you take one thing from this page, take this. I call it the Absorb-It Test, and it is the fastest way to know whether you need to transfer cyber risk:

Could your business write a check tomorrow for the full cost of a breach, six figures or more, without borrowing, without missing payroll, and without laying anyone off?

If the answer is yes, you can self-insure with your eyes open. If the answer is no, and for most businesses it is no, then you do not have an IT question, you have a financing question, and cyber insurance is the answer. That is the whole case for why cyber insurance, in one sentence.

Ready to run the numbers for your business? Book a call and we will get you a premium indication and a straight recommendation.

What to look for in a cyber insurance policy

Look first for real breach response services, not just a limit, because the answer to why cyber insurance earns its keep is the crisis team it brings, not the check it eventually cuts. Most owners compare price and stop there. In my experience the cheapest policy is usually the one that fights you hardest at claim time, so read the structure before the premium.

When we place coverage, we hold every quote up to the same checklist:

  • A named incident response team you can call the hour a breach hits, not a phone tree.
  • Both first-party and third-party coverage, so your losses and the claims others bring are both funded.
  • Business interruption that pays for lost income during downtime, not only data restoration.
  • Ransomware and funds transfer fraud included, since those are the claims we see most.
  • Sublimits you can live with, because a headline limit means little if the parts that matter are capped low.

Get those parts right and the policy does its job. Miss them and you own a certificate, not protection. That is why cyber insurance should be structured by someone who reads the form, not sold by a checkout button. If you want a second set of eyes, request a second opinion on your current coverage.

Quick answers and buying considerations

Here is the whole decision in one scannable block, so you can act without rereading the page. Cyber insurance comes down to one thing: whether your business could survive a breach it cannot pay for out of pocket. If it could not, you transfer the risk, and everything below follows from that single call.

  • What it is: coverage that pays the direct and third-party costs of a cyber incident and brings a response team the day it hits.
  • Who needs it: any business that stores data, takes payments, or runs on email; exposure scales with your data volume and industry.
  • Who may not: a firm with no data, no digital payments, and reserves large enough to absorb a total loss.
  • What it covers: forensics, data restoration, business interruption, ransom, notification, legal, and PR (first-party), plus lawsuits, fines, and defense (third-party).
  • What it excludes: losses from controls you claimed but did not maintain, prior known incidents, and system upgrades beyond restoration.
  • What drives cost: revenue, data volume, industry, security controls, and the limit you choose; typical small and mid-sized premiums run about $1,000 to $7,500 for $1M.
  • Why standard policies fail: general liability, property, and umbrella forms do not respond to data loss, and BOP endorsements are thin.
  • Strategic considerations: size the limit to your worst realistic day, check the sublimits, and confirm any contract or regulatory requirement.
  • Why a specialist broker matters: we prep your application so the controls you attest to are real, which is how claims get paid instead of denied.

If you want this turned into a straight recommendation for your business, book a call.

Frequently asked questions

Yes. Small businesses are targeted precisely because they defend less, and two thirds of attacks now hit the small and mid-sized market. If you store data, send invoices, or run on email, one incident can cost six figures your other policies will not pay. For a company that could not easily absorb that loss, cyber insurance is the difference between a setback and a shutdown.

Yes, when the policy is applied for honestly and the controls you attest to are real. Denials cluster around misrepresented security controls, such as multi-factor authentication that was promised but not enforced, or backups that were never tested. Work with a broker who preps your application so what you claim matches what you run. That is how you land on the paying side of the more than 40% denial statistic.

The benefits of cyber insurance go beyond a payout. A good policy funds forensics, legal counsel, customer notification, public relations, ransom negotiation, and lost income during downtime, and it brings an incident response team the day the breach happens. In practice, that means you get help managing the crisis, not just a check after the dust settles.

For most small and mid-sized firms, yes. In our book, cyber runs around $4,000 a year, less than 3% of total insurance spend, to remove an exposure that averages six figures and can reach millions. Run the Absorb-It Test: if your business could not write a check for a full breach tomorrow, that is your answer to why cyber insurance is worth it.

Rarely by law, but often in practice. Unlike workers compensation or auto liability, no broad statute requires cyber coverage for most businesses. Client contracts, data-protection regulators, and lenders increasingly require it, so many owners are effectively mandated to carry it even when the government does not force the issue.

It depends on your data volume, revenue, and contractual requirements, but a $1 million limit is a common starting point for small and mid-sized firms. The right limit reflects what a realistic breach would cost you, not a round number. We size it by estimating your worst realistic day, then matching the limit and coverage parts to that exposure.

No, in almost all cases. General liability covers bodily injury and property damage, property policies cover physical loss, and umbrella coverage only extends what sits beneath it. Data is not physical property, so a breach falls into the gap. A standalone cyber policy, not a bolt-on endorsement, is the reliable way to close it.

Author’s Expertise

This article was written by the CEO of The Coyle Group, Gordon B. Coyle, CPCU, ARM, AMIM, PWCA, who has over 40 years of experience working with business owners of all sizes and industries across the US, solving their insurance challenges.

Check Out Our Blogs