Small businesses with under $10M in revenue typically pay $1,500 to $7,500 per year for a $1M cyber liability policy in 2026 (Source: NAIC Cyber Insurance Market Report, 2026). Mid-market firms in the $10M-$100M band run $7,500 to $35,000 for the same coverage. Premium varies sharply by industry, controls in place, and ransomware sublimit. Carriers now require MFA, EDR, immutable backups, and security training to even quote coverage.
Last verified: Sep 14, 2026.
At a glance
- SMB cyber insurance (under $10M revenue): $1,500-$7,500/yr for $1M limits
- Mid-market ($10M-$100M): $7,500-$35,000/yr
- Ransomware sublimit: typically 25-50% of aggregate limit
- Required controls: MFA, EDR, immutable backups, training, IR plan
- Premium reduction with NIST CSF 2.0: 10-25%
Cyber insurance premium by business size
Cyber insurance premiums depend on revenue, industry, controls, and coverage structure. Small businesses with strong controls in low-risk industries pay under $2,000 per year. Mid-market firms with more complex environments and higher data volumes pay $7,500 to $35,000. Carriers price based on expected loss cost, and ransomware experience through 2020-2023 has reset premiums industry-wide.
| Business Profile | Revenue | Coverage | Premium Range (2026) |
|---|---|---|---|
| Micro / solopreneur | Under $1M | $500K-$1M aggregate, $250K ransomware sublimit | $500 - $2,500 |
| Small business | $1M - $10M | $1M aggregate, $500K-$1M ransomware | $1,500 - $7,500 |
| Mid-market | $10M - $100M | $1M-$5M aggregate, $500K-$2M ransomware | $7,500 - $35,000 |
| Upper mid-market | $100M - $500M | $5M-$25M aggregate, $2M-$10M ransomware | $35,000 - $150,000 |
| Enterprise | $500M+ | $25M-$100M+ aggregate, custom ransomware | $150,000 - $1,000,000+ |
Source: NAIC Cyber Insurance Market Report and carrier broker surveys, 2026.
Coverage components of a cyber insurance policy
A modern cyber policy bundles several coverage parts that should be evaluated together. First-party coverages pay the insured for their own losses; third-party coverages defend against claims from customers, partners, or regulators. The right mix depends on data handling, contractual obligations, and regulatory exposure.
| Coverage Part | What It Pays | Typical Limit |
|---|---|---|
| Breach response | Forensics, legal, notification, credit monitoring | Included up to aggregate |
| Ransomware / extortion | Extortion payment, negotiation, recovery | 25-50% of aggregate |
| Business interruption | Lost income from covered cyber event | $1M-$25M depending on size |
| Data restoration | Cost to restore or recreate data | $1M-$10M |
| Cyber liability (3rd party) | Defense and settlement of customer claims | $1M-$25M |
| Regulatory defense & fines | Defense for GDPR, HIPAA, state AG actions | $1M-$10M |
| Reputation harm | PR firm costs after a covered event | $250K-$2M |
| Social engineering | BEC fraud losses | $250K-$1M sublimit |
Source: AIG, Chubb, Travelers, Coalition cyber policy forms, 2026.
How to reduce cyber insurance premium
Carriers reward documented controls with materially lower premiums. Implementing MFA on email and remote access, deploying EDR on all endpoints, maintaining immutable or offline backups, running security awareness training, and documenting an incident response plan are baseline requirements. Adding SIEM or MDR coverage, vulnerability management, and privileged access management unlocks additional premium tiers. Brokers experienced in cyber placements typically deliver 10 to 25 percent better premiums than generalist commercial agents because they understand carrier appetite and risk-engineering credits.
Ransomware sublimit and exclusions to watch
Ransomware coverage has tightened materially since 2023. Most carriers impose sublimits of 25 to 50 percent of aggregate policy limits for ransomware. Several exclude or surcharge payments to entities on OFAC sanctions lists, which can complicate negotiation. War and state-backed cyber exclusions now routinely exclude losses from nation-state attacks, though attribution disputes remain common during claim handling.
Internal links
See related guides: Cyber insurance application checklist, Ransomware negotiation services cost, and MDR service cost.
Recommended Books for This Topic
FAQs
See the FAQ section above for cyber insurance premium benchmarks, ransomware sublimit guidance, underwriting requirements, and exclusion watchouts.
Cyber insurance claims by attack vector
Cyber insurance claims in 2025-2026 are dominated by ransomware and business email compromise. Understanding the attack vector distribution helps prioritize risk management investments that also satisfy underwriting requirements.
| Attack Vector | % of Claims | Average Claim Size | Most Affected Industries |
|---|---|---|---|
| Ransomware | 35% | $350,000 | Healthcare, manufacturing, government |
| Business Email Compromise | 28% | $125,000 | Real estate, finance, legal |
| Data Breach | 18% | $220,000 | Retail, healthcare, education |
| System Failure | 10% | $95,000 | Technology, financial services |
| Privacy Violation | 9% | $180,000 | Healthcare, education, retail |
Source: NAIC Cyber Insurance Claims Report and carrier loss data, 2026.
FAQ expansion
Q: How long does it take to get cyber insurance? The full application process typically takes 4 to 8 weeks from kickoff to bind. Clean applications with strong controls can bind in 1-2 weeks. Applications with material gaps (missing MFA, weak backups) trigger follow-up questions that extend timelines to 6-8 weeks. Renewal cycles typically run 6-8 weeks before policy expiration.
Q: Can I get cyber insurance without MFA? Most carriers now refuse to quote without MFA on email, remote access, and privileged accounts. A small number of carriers offer policies with MFA-waiver exclusions, but premiums are 50-100% higher and coverage is restricted. Implementing MFA is the single biggest lever for both insurability and premium reduction.
Q: Does cyber insurance cover regulatory fines? Many policies include coverage for regulatory defense costs and some fines, particularly for GDPR, HIPAA, and state AG actions. Coverage for fines is typically subject to indemnity provisions and may exclude intentional or willful violations. Read policy forms carefully for regulatory coverage scope and exclusions.
As an Amazon Associate, Tutorsbot earns from qualifying purchases. Disclosure.








