Quick Answer: Data Breach Insurance
Data breach insurance — also called cyber liability insurance or cyber insurance — covers the financial losses and response costs of a data breach or cyberattack. A typical policy bundles first-party coverage (your own losses: forensics, notification, credit monitoring, ransom, business interruption) with third-party coverage (claims from affected customers: legal defense, settlements, regulatory fines). Annual premiums for small businesses range from $1,000 to $5,000 for $1 million in coverage; mid-market companies pay $5,000 to $25,000; large enterprises pay $50,000 to $500,000+. Top providers include Coalition, At-Bay, Cowbell, Chubb, Tokio Marine HCC, AIG, Beazley, and Travelers.
What Data Breach Insurance Covers
Modern cyber policies bundle coverage across two categories. First-party coverage pays for losses you suffer directly:
- Forensic investigation — costs to determine how the breach happened, what was accessed, and who is affected.
- Breach notification — costs to mail notices to affected individuals (postage alone for a large breach can run into six figures).
- Credit monitoring — typically one to three years of free monitoring for affected customers.
- Public relations — costs to manage reputational fallout and restore customer trust.
- Business interruption — lost revenue when systems are down due to a covered attack.
- Ransom payments — costs to pay (or negotiate down) a ransomware demand, including cryptocurrency and advisor fees.
- Data restoration — costs to rebuild or recover compromised or destroyed data.
Third-party coverage pays for claims brought against you by others:
- Legal defense — attorney fees to defend against lawsuits from customers, partners, or shareholders.
- Settlements and judgments — payouts to plaintiffs in class actions or individual lawsuits.
- Regulatory fines and penalties — HIPAA, FTC, state AG, and PCI DSS fines where insurable by law.
- Media liability — claims related to defamation, copyright infringement, or privacy violations in published content.
What Data Breach Insurance Does Not Cover
Standard exclusions to watch for in any policy:
- Prior known breaches — incidents that occurred before the policy's retroactive date.
- Acts of war or nation-state attacks — many policies have war exclusions that have been tested against major events like NotPetya.
- Intellectual property theft — IP loss is usually covered under a separate policy.
- Reputational harm not tied to a covered event — general brand damage from negative press typically requires a separate media liability policy.
- Future profits lost — lost business opportunities that cannot be tied directly to the covered event.
- Intentional violations — fines for deliberate lawbreaking are rarely insurable.
- Unencrypted devices — many policies reduce or deny payouts if the breached device was not encrypted.
- Known unpatched vulnerabilities — failure to apply critical patches can void coverage.
How Much Data Breach Insurance Costs
Premiums depend on company revenue, industry, data volume, security controls, and coverage limits. Industry benchmarks for 2026:
| Company Size (Annual Revenue) | Annual Premium for $1M Coverage | Typical Coverage Limits |
|---|---|---|
| Under $1M | $800 – $3,000 | $500K – $1M |
| $1M – $10M | $1,500 – $7,000 | $1M – $3M |
| $10M – $50M | $5,000 – $20,000 | $2M – $10M |
| $50M – $250M | $15,000 – $60,000 | $5M – $25M |
| $250M – $1B | $40,000 – $150,000 | $10M – $50M |
| Over $1B | $100,000 – $500,000+ | $25M – $500M+ |
Industries with the highest premiums: healthcare, financial services, retail with payment card data, and SaaS handling regulated data. Industries with lower premiums: professional services, manufacturing, and non-customer-facing B2B.
Who Needs Data Breach Insurance
You need data breach insurance if any of the following apply to your business:
- You store or process customer PII (names, SSNs, addresses, dates of birth).
- You process payment cards or ACH transactions.
- You handle protected health information (PHI) subject to HIPAA.
- You rely on online systems for revenue or operations.
- You contract with enterprise customers who require cyber insurance as a vendor prerequisite.
- You operate in a regulated industry (financial services, healthcare, education).
If you are a small business without a security team or dedicated IT staff, cyber insurance is increasingly non-optional — it provides access to a 24/7 incident response hotline, breach coach attorneys, and pre-approved vendors that small businesses cannot otherwise maintain on retainer.






