The average cost of a data breach for a small business in 2024 hit $4.88 million, according to IBM’s Cost of a Data Breach Report. Most small businesses don’t survive it. And yet, fewer than 20% of small businesses carry any form of cybersecurity insurance. That’s not a gap — that’s a cliff edge most owners don’t see until they’re already falling.
If you’ve ever wondered whether cybersecurity insurance is worth it, what it actually covers, or whether your existing business insurance has you sorted — this post answers all of it, plainly and practically.
What Is Cybersecurity Insurance?
Cybersecurity insurance (also called cyber liability insurance) is a specialist policy that covers financial losses resulting from cyberattacks, data breaches, and related digital incidents. It’s not bundled into standard business insurance or general liability policies — those typically exclude cyber events entirely. You need a standalone cyber policy or a specific cyber endorsement added to your existing cover.
Think of it like this: your fire insurance covers your building burning down, but it won’t pay a cent when ransomware locks every computer in that building. That’s exactly where cybersecurity insurance steps in.
What Cybersecurity Insurance Typically Covers
Coverage varies between providers and policy tiers, but most comprehensive cyber policies include two main components: first-party coverage (losses your business suffers directly) and third-party coverage (claims made against you by others affected by your breach).
First-Party Coverage — Your Direct Losses
- Ransomware payments and recovery costs: If attackers encrypt your data and demand payment, a cyber policy can cover the ransom and the cost of restoring your systems. This is one of the most common claims filed today.
- Business interruption losses: When your systems go down after an attack, you’re losing revenue every hour. Cyber insurance can compensate for that lost income during recovery.
- Data restoration costs: Recovering or rebuilding corrupted or stolen data takes specialist help. Your policy can cover those forensic IT and recovery costs.
- Notification expenses: In Australia, the UK, the EU, and the US, businesses are legally required to notify affected individuals after a data breach. Those notifications — letters, call centres, credit monitoring services — cost real money.
- Crisis communication and PR: A public breach can devastate your reputation. Many policies cover the cost of a PR firm to manage the fallout.
- Cyber extortion support: Beyond ransomware, policies often cover threats to expose sensitive data or launch DDoS attacks unless paid.
Third-Party Coverage — Claims Against You
- Customer and client lawsuits: If your breach exposes customer data and they sue you, third-party coverage handles legal defence costs and settlements.
- Regulatory fines and penalties: Under laws like the GDPR, Australia’s Privacy Act, or HIPAA in the US, regulators can levy significant fines for mishandling personal data. Some (not all) cyber policies cover these penalties.
- Media liability: If your business accidentally publishes copyrighted content or defamatory material online as part of a cyberattack, this coverage applies.
What Cybersecurity Insurance Does NOT Cover
This is just as important to understand. Policies have exclusions, and assuming you’re covered when you’re not is a costly mistake.
- Pre-existing vulnerabilities: If you knew about an unpatched system or security gap before taking out the policy and didn’t disclose it, your insurer can deny your claim.
- Nation-state attacks: Many policies contain war exclusions. If an attack is attributed to a foreign government (a growing grey area), your claim may be rejected. Lloyd’s of London updated its exclusions specifically around this in 2023.
- Social engineering fraud gaps: Some policies cover social engineering scams (like a staff member being tricked into transferring funds) only up to a sublimit — often far lower than the main policy limit. Check this carefully.
- Bodily injury or property damage: If a cyberattack on your systems causes physical harm (say, in a manufacturing or medical environment), that typically falls outside a standard cyber policy.
- Poor security hygiene: Insurers increasingly require businesses to meet baseline security standards — MFA, endpoint protection, regular backups — to qualify for coverage. Failing to maintain these can void your claim.
How Much Does Cybersecurity Insurance Cost?
For small businesses, premiums typically range from $500 to $5,000 per year depending on your industry, revenue, data volume, and security posture. High-risk industries like healthcare, finance, legal, and e-commerce pay more. Businesses that handle large volumes of personal data also attract higher premiums.
Here’s a rough benchmark to work with:
- Micro business (under 10 staff, low data risk): $500–$1,200/year
- Small business (10–50 staff, moderate data handling): $1,500–$4,000/year
- Medium business or high-risk industry: $5,000–$20,000+/year
The premium is almost always less than the cost of a single incident response engagement from a cybersecurity firm, which alone can run $10,000–$50,000 for a small breach.
Do You Actually Need Cybersecurity Insurance?
The honest answer: if your business stores any customer data, processes payments, or relies on digital systems to operate — yes, you need it. Here’s how to think through it practically:
You Probably Need Cyber Insurance If:
- You store customer names, emails, payment details, or health information
- You use cloud software like Microsoft 365, Xero, Shopify, or any SaaS platform
- Your staff use email for client communication
- A system outage would cost you revenue (which is every business)
- You work in healthcare, legal, finance, real estate, or education
- Your clients or contracts require you to carry it (increasingly common)
Steps to Take Before Applying for a Policy
Insurers will assess your security posture during underwriting. Taking these steps before applying improves your eligibility and reduces your premium:
- Enable multi-factor authentication (MFA) on all business accounts — email, banking, cloud apps. This is now a standard underwriting requirement.
- Implement regular, tested backups stored offline or in an isolated cloud environment.
- Deploy endpoint protection (antivirus/EDR software) on all business devices.
- Patch and update software regularly — unpatched systems are one of the top causes of insurable incidents.
- Train staff on phishing awareness. Human error is involved in over 80% of breaches. Documented training reduces your risk profile.
How to Choose the Right Cybersecurity Insurance Policy
Not all policies are equal. When comparing options, focus on these specifics rather than just the headline premium:
- Check the sublimits: A policy with a $1M limit might only cover $25,000 for social engineering fraud. Know what each coverage bucket actually pays out.
- Look at the incident response panel: The best policies include access to pre-vetted forensic investigators, legal counsel, and PR firms as part of the package — not just reimbursement after the fact.
- Understand the retention (excess/deductible): This is what you pay before the insurer covers the rest. A lower premium with a $50,000 excess may not serve you well as a small business.
- Ask about retroactive cover: Cyber incidents often have a lag — the breach happens months before it’s discovered. Retroactive cover means incidents that occurred before the policy start date (but after a retroactive date) are still covered.
- Read the war and infrastructure exclusions carefully: Given the current threat landscape, these matter more than they used to.
Cybersecurity Insurance Is Risk Management, Not a Safety Net
One critical point: cybersecurity insurance is not a substitute for good security practices. Insurers know this, which is why underwriting requirements are getting stricter every year. Businesses that invest in basic security hygiene — MFA, patching, backups, training — pay lower premiums, qualify for better coverage, and are far less likely to file a claim in the first place.
Think of cybersecurity insurance the way you think about car insurance. You still wear a seatbelt. You still drive carefully. Insurance is for when things go wrong despite your best efforts.
The Bottom Line on Cybersecurity Insurance
A cyberattack is no longer an unlikely scenario for small businesses — it’s a matter of when, not if. Cybersecurity insurance closes the financial gap that no amount of antivirus software can fully eliminate. It covers the ransom, the lawyers, the regulators, the recovery, and the reputational cleanup. For most businesses, the annual premium is a rounding error compared to the cost of a single uninsured breach.
Before your next renewal cycle, talk to a broker who specialises in cyber liability. Get a real quote based on your actual risk profile. And in the meantime, start with the basics: turn on MFA, back up your data, and make sure your team knows how to spot a phishing email.
Because the best cybersecurity insurance claim is the one you never have to make.
