What Cyber Insurance Covers
Cyber insurance pays the costs of a covered digital incident — a data breach, ransomware attack, business email compromise, or network outage caused by a malicious actor. Coverage breaks into two categories.
First-party coverage pays for your own costs:
- Breach response and forensics: Hiring a cybersecurity firm to determine what happened, what data was accessed, and how the attacker got in.
- Customer notification: Under state breach notification laws — all 50 states now have them — you are legally required to notify affected customers when their personal information is exposed. Notification costs include letter preparation, mailing, and call center staffing.
- Credit monitoring for affected customers: Many state laws and regulatory settlement agreements require offering affected individuals free credit monitoring for a defined period after a breach.
- Ransomware response: Costs to recover encrypted data, negotiate with attackers, and restore systems. Some policies cover ransom payments subject to OFAC compliance review.
- Business interruption loss: Revenue lost while your systems are offline during investigation or recovery. This specifically covers network outages caused by a cyber event — it is separate from business interruption insurance for physical property losses.
- Data restoration: Cost to rebuild or recover corrupted or encrypted data from backup systems.
Third-party coverage pays for others' claims against you:
- Customer lawsuits from a breach of their personal data
- Regulatory defense costs and penalties from HHS, FTC, or state attorneys general
- Media liability from defamation or copyright claims on your digital properties
Policy structure matters: most cyber policies are issued on a claims-made basis, covering incidents reported during the policy period — not necessarily when the incident first occurred.
Who Needs Cyber Insurance
No federal law universally mandates cyber insurance for small businesses. But several regulatory frameworks create financial exposure significant enough that coverage is effectively necessary for any business that handles customer data digitally.
Healthcare businesses: HIPAA's Breach Notification Rule requires covered entities to notify affected patients and the Department of Health and Human Services within 60 days of discovering a breach. For breaches affecting 500 or more individuals in a state, the entity must also notify prominent media outlets within 60 days. HHS Office for Civil Rights enforcement penalties have reached as high as $1.9 million per violation category. Cyber insurance covers the legal defense, notification costs, and mitigation these investigations require.
Businesses that process payment cards: PCI DSS requires businesses accepting credit cards to maintain specific security controls. A breach triggering forensic investigation fees, card reissuance costs billed by card brands, and potential fines from your payment processor — all of which a cyber policy can cover.
Financial services businesses: The FTC Safeguards Rule requires non-bank financial institutions — tax preparers, auto dealers, mortgage brokers, and accountants — to implement a formal information security program. A breach triggers notification requirements and regulatory scrutiny. Cyber insurance covers the response costs.
Any business that stores customer personal information digitally: All 50 states now have data breach notification laws. A breach exposing names combined with financial account numbers, Social Security numbers, medical information, or login credentials triggers mandatory notification. The SBA's cybersecurity guidance identifies small businesses as high-value targets because they hold customer data, financial account access, and supply chain connections while dedicating fewer resources to security than enterprise organizations. The FBI's Internet Crime Complaint Center recorded more than 880,000 cybercrime complaints in 2024, the highest single-year total since the program launched in 2000.
What Cyber Insurance Does NOT Cover
Exclusions matter as much as what's included. Standard exclusions in 2026 cyber policies:
- Nation-state and war exclusions: Following litigation over several large-scale state-sponsored cyberattacks, most cyber carriers now explicitly exclude losses attributed to nation-state operations, war, or hostile government actors. Review the exclusion language itself — not just the marketing summary.
- Pre-existing incidents: Policies don't cover breaches that began before the policy inception date, even if you didn't know about them. A forensic investigation revealing a months-old intrusion can create a coverage dispute if it predates the policy start.
- Failure to maintain warranted security controls: Many policies include warranties that you maintain specific controls — multi-factor authentication on email, encrypted backups, endpoint detection software. A misrepresentation can void a claim.
- Physical hardware replacement: Cyber policies cover lost data and income, not replacing stolen or destroyed hardware. Commercial property insurance covers physical assets.
- Social engineering and funds transfer fraud (sometimes): Business email compromise — where an attacker tricks an employee into wiring funds — falls into a coverage gray zone. Some policies cover it under a social engineering rider; many exclude it without that specific endorsement.
How Much Cyber Insurance Costs
For a small business with revenue under $5 million, standalone cyber insurance typically costs $1,000 to $3,500 per year for a $1 million policy limit. The main variables:
- Revenue and data volume: More revenue typically means more customer data and larger exposure — premiums scale accordingly.
- Industry: Healthcare and financial services face higher premiums because regulatory breach costs are elevated. Retail and food service businesses typically pay less.
- Security controls in place: Businesses with multi-factor authentication, encrypted offsite backups, and active endpoint monitoring qualify for better rates. Some carriers require specific controls as a condition of coverage.
- Deductible: A higher deductible lowers the premium, but verify your business can absorb the deductible in a real incident before accepting one.
Compare standalone policies against the cyber endorsements bundled into most business owner's policies. A typical BOP endorsement caps cyber coverage at $10,000 to $50,000 — well below the cost of a real breach with forensics, notification, and legal defense involved. A standalone policy with a $1 million limit is the floor for most businesses that store any meaningful volume of customer data.
How to Evaluate a Policy
Ask these specific questions before binding coverage:
- First-party, third-party, or combined? A combined policy covers both your breach response costs and customer claims against you. A first-party-only policy leaves you exposed to lawsuits.
- What security controls are warranted? Get the specific list in writing. Verify your business actually meets each control before the policy inceptions — and document it.
- Does the policy cover ransomware payments? If yes, is payment subject to OFAC compliance verification (required under U.S. sanctions law)?
- What do the nation-state and war exclusions say exactly? Read the exclusion language, not the policy summary.
- Who are the breach response panel vendors? Most policies require using approved forensic firms and law firms. Know who they are before an incident — not during one.
- Is social engineering fraud covered or excluded? If your business regularly wires funds or makes vendor payments, this specific coverage matters.
Cyber Insurance and Business Funding
An increasing share of business lenders treat cyber insurance as part of insurance due diligence, particularly for businesses that operate primarily online or handle significant volumes of customer data. What lenders actually review in your business financial statements covers the broader documentation picture — but insurance verification is standard on both SBA and working capital applications.
The FTC's Start with Security guidance recommends the same security controls cyber insurers use as underwriting criteria: multi-factor authentication, data minimization, encrypted backups, and a documented incident response plan. A business that can demonstrate both active coverage and documented security practices signals to lenders that digital risk is being managed systematically.
If a funding application is on the horizon, confirm that cyber coverage is in force before applying. For lenders that require evidence of coverage, a gap in coverage discovered at closing creates friction that delays funding.
Related reads: