Quick Answer: Cybersecurity Insurance
Cybersecurity insurance covers financial losses from data breaches, ransomware, and other cyber incidents. A typical policy bundles first-party coverage (forensics, notification, credit monitoring, ransom, business interruption) with third-party coverage (legal defense, settlements, regulatory fines, media liability). Annual premiums range from $1,200–$7,000 for small businesses to $100,000–$1,000,000+ for large enterprises. Top providers include Coalition, At-Bay, Cowbell, Chubb, AIG, Beazley, Tokio Marine HCC, and Travelers.
Why Cybersecurity Insurance Matters in 2026
Cyber incidents are now ranked among the top three business risks globally, alongside extreme weather and supply-chain disruption. According to Allianz Risk Barometer 2025, cyber incidents rank as the #1 business risk in the United States for the fourth consecutive year. The cost of a single breach for a small business averages $120,000–$300,000 — more than 60% of small businesses close within six months of a major cyber incident.
For most businesses, the question is no longer whether to carry cyber insurance — it is which policy, which limits, and what the prerequisites are.
What Cybersecurity Insurance Covers
First-Party Coverage (Your Own Losses)
- Forensic investigation — costs to determine the cause, scope, and impact of an incident.
- Breach notification — costs to mail notices to affected individuals; for a large breach, postage alone can reach six figures.
- Credit monitoring — typically one to three years of free monitoring for affected customers.
- Public relations — costs to manage reputational fallout and restore trust.
- Business interruption — lost revenue when systems are down due to a covered attack.
- Ransom payments — costs to pay or negotiate down a ransomware demand, including cryptocurrency and advisor fees.
- Data restoration — costs to rebuild or recover compromised data.
Third-Party Coverage (Claims From Others)
- Legal defense — attorney fees for defending against customer, partner, or shareholder claims.
- Settlements and judgments — payouts in class actions or individual lawsuits.
- Regulatory fines and penalties — HIPAA, FTC, state AG, and PCI DSS fines where insurable by law.
- Media liability — claims related to defamation, copyright infringement, or privacy violations in published content.
What Cybersecurity Insurance Does Not Cover
Standard exclusions across most policies:
- Prior known breaches — incidents that occurred before the policy's retroactive date.
- Acts of war or nation-state attacks — many policies have war exclusions tested against major events like NotPetya.
- Intellectual property theft — IP loss is covered under separate policies.
- Future profits lost — opportunities that cannot be tied directly to a covered event.
- Intentional violations — fines for deliberate lawbreaking.
- Unencrypted devices — many policies reduce payouts if the breached device was not encrypted.
- Known unpatched vulnerabilities — failure to apply critical patches can void coverage.
How Much Cybersecurity Insurance Costs (2026)
| Company Size | Annual Premium ($1M Coverage) | Typical Limits |
|---|---|---|
| Under $1M revenue | $1,200 – $4,500 | $500K – $1M |
| $1M – $10M revenue | $2,000 – $9,000 | $1M – $3M |
| $10M – $50M revenue | $6,000 – $25,000 | $2M – $10M |
| $50M – $250M revenue | $18,000 – $75,000 | $5M – $25M |
| $250M – $1B revenue | $50,000 – $180,000 | $10M – $50M |
| Over $1B revenue | $100,000 – $1,000,000+ | $25M – $500M+ |
The most expensive industries: healthcare, financial services, retail with payment card data, education, and SaaS handling regulated data. The least expensive: manufacturing, professional services, and non-customer-facing B2B.
Top Cybersecurity Insurance Providers (2026)
| Provider | Best For | Standout Feature |
|---|---|---|
| Coalition | Small and mid-market | Active attack-surface monitoring included |
| At-Bay | Small and mid-market | Security insights included with policy |
| Cowbell | Small business | AI-driven risk scoring and flexible limits |
| Tokio Marine HCC | Mid-market and large | Strong ransomware sublimits |
| Chubb | Large enterprise | Customized coverage and global claims handling |
| AIG | Large enterprise | Broad international coverage and breach response network |
| Beazley | Mid-market and large | Specialized healthcare and financial services policies |
| Travelers | Mid-market | Strong vendor management coverage |
| AXA XL | Large enterprise | Strong international network |
| Liberty Mutual | Mid-market | Bundled with other commercial lines |
Sublimits and Retention: What Matters Most
The headline coverage amount is misleading. Sublimits and retentions matter far more for actual risk transfer:
- Ransomware sublimit: The cap on ransomware payments and related costs. Common ranges: 25%–50% of policy limit, or $250K–$5M.
- Social engineering sublimit: Often $100K–$500K. Email-based fraud losses can be excluded from first-party coverage entirely.
- Regulatory fines sublimit: Often separate from general liability, sometimes not insurable by state law.
- Retention (deductible): Ranges from $2,500 for small businesses to $1M+ for large enterprises. Lower retention means higher premium.
Prerequisites Most Insurers Require
Almost every modern cyber policy requires the insured to maintain baseline controls:
- Multi-factor authentication on email and remote access. The single most common underwriting question.
- Offline backups of critical data, tested quarterly.
- Security awareness training with annual phishing simulations.
- Endpoint detection and response (EDR) on all managed devices.
- Patch management with defined SLAs for critical vulnerabilities.
Failure to maintain these controls can void coverage even after a claim is filed.
How to Choose the Right Policy
Five questions before you sign:
- What are the sublimits? Sublimits can be more binding than the headline coverage.
- What is the retention? Reflects the insurer's risk tolerance for your business.
- Who is on the breach response panel? Most insurers require you to use approved counsel and forensic vendors.
- What is the consent provision? Can you pay a ransom unilaterally, or do you need insurer consent?
- What are the security prerequisites? Confirm your current controls meet the underwriting bar.
For a closer look at first-party vs third-party coverage, what data breach insurance covers, and how it differs from broader cyber liability, see our complete data breach insurance guide. For the regulatory frameworks that drive most cyber insurance requirements, see our compliance frameworks guide. To build the in-house risk and compliance skills that keep premium costs down, explore the TutorsBot Governance, Risk & Compliance course.





