Cyber insurance

How Much Cyber Insurance Do I Need?

How much cyber insurance do I need is really two questions, what limit to carry and what the policy should cost. This guide is written for the business owner or IT lead sizing a first cyber policy or questioning a renewal number. It walks through the sizing logic underwriters and brokers actually use, the records you hold, the revenue that stops when systems stop, and the minimums your client contracts set. It then covers what a cyber limit pays for, the factors that drive cyber insurance cost, the published price ranges worth trusting, who needs cyber insurance in the first place, and how to benchmark a limit against what similar businesses carry instead of guessing.

Reviewed by Advocate Insurance Consultants · Last updated August 2026

Key takeaways

  • Size your cyber limit against your worst plausible incident, stacking forensics and legal, notification and credit monitoring, lost revenue from downtime, and the liability claims that follow.
  • Contract minimums from clients, lenders, and vendor portals set a hard floor, so carry the larger of your own incident estimate and the highest active requirement.
  • One incident usually triggers both first-party and third-party coverage from one shared limit, so a limit sized only to notification costs can run out mid-claim.
  • Rather than chase a national average, Advocate benchmarks your cyber premium against real bound transactions for similar businesses, and Coverage Gap Analysis surfaces gaps against required coverage standards.

How much cyber insurance do I need for my business?

Start with the incident, not the policy menu. A cyber limit has to absorb the full cost of your worst plausible event, which usually stacks four components. Forensics and legal response, notification and credit monitoring for every person whose records you hold, the revenue lost while systems are down, and the claims or regulatory action that follows. Price a realistic scenario across all four and you have a defensible starting limit.

Contract requirements can override the math. When a client, lender, or vendor portal names a minimum cyber limit, that number is the floor regardless of your own estimate, and the highest active requirement wins. Between your incident math and your contract floor, carry the larger.

  • Records held. Notification, credit monitoring, and forensics scale with every person whose data you store, so a customer or patient count is a direct input to the limit.

  • Revenue at risk from downtime. Estimate the daily revenue that stops when core systems stop, multiplied across a realistic recovery measured in days or weeks.

  • Contract minimums. Client, lender, and vendor-portal requirements set a hard floor. Carry at least the highest limit any active contract demands.

What a cyber insurance limit covers

A cyber insurance limit sits over two families of coverage that draw down the same pool. First-party coverage pays your own costs after an incident, forensic investigation, breach counsel, customer notification, credit monitoring, data restoration, extortion response, and the income lost while systems are down. The Insurance Information Institute notes that standard business policies offer only limited cyber protection, which is why serious limits are written on a standalone policy.

Third-party coverage pays what you owe others, defense and settlements when customers or partners sue over compromised data, plus regulatory proceedings, with fines and penalties covered where the law allows. One incident routinely triggers both sides, so a limit sized against notification costs alone can run out midway through the liability claims. That is the classic coverage gap on cyber programs, a limit sized to one component of a multi-component loss.

What drives cyber insurance cost

Cyber underwriting is application-driven. These five factors move the premium more than anything else, and some of them are in your control before the quote.

Factor

Why it matters

What you can control

Industry and data volume

Healthcare, finance, and any business holding large volumes of personal records face higher expected breach costs

Purge stale records and collect only the data you actually use

Revenue

A larger operation means more downtime exposure and larger liability claims, so premiums scale with revenue

Little direct control, but accurate revenue reporting keeps the rating basis honest

Security controls

MFA, tested backups, endpoint detection, and phishing training reduce both the odds and the size of a claim

The most controllable factor. Weak answers here raise the price or can block a quote entirely

Limit and retention

A higher limit raises the premium, a higher retention lowers it by keeping small losses on your books

Trade retention against premium after the limit itself is set correctly

Claims history

A prior cyber incident signals elevated risk and raises the price for several renewals

Document the fixes made after any incident, remediation evidence moderates the increase

Weighting varies by carrier and market cycle. The application answers drive the quote.

How much does cyber insurance cost?

There is no single honest number, because the premium is rated on the factors above rather than on a flat schedule. Published figures are hedged for the same reason. Progressive, for example, publishes example annual premiums between about $500 and $5,000 or more for small businesses, and is explicit that an average is hard to give because every business rates differently.

The retention you choose moves the price as much as the limit does. A retention is the amount of each claim you pay before the policy responds, the cyber market's version of a deductible. Raising it lowers the premium and keeps small incidents off your loss history, but it has to be an amount the business can genuinely absorb in a bad month.

The more useful question than any national average is whether your own premium sits in line for your revenue, industry, and controls. That is a price benchmarking exercise, comparing your premium against real transacted prices for similar businesses rather than against a headline figure.

Who needs cyber insurance?

Any business that stores personal data, takes payments, or depends on its systems to operate has the exposure cyber insurance covers, which is a wider net than most owners assume. A dental practice holds patient records. An online retailer processes cards. A contractor runs scheduling and billing in the cloud, and a week without either is a week without revenue. None of these is a technology company, and all three carry a real cyber exposure.

Security controls reduce the exposure but do not remove it. The Small Business Administration lists multifactor authentication and regular backups among its core cybersecurity practices for small businesses, and cyber underwriters ask about the same controls on the application. Good controls earn a better price. The residual risk that remains is what the policy is for.

Cyber limits in client and vendor contracts

Cyber limits increasingly arrive as someone else's requirement. Enterprise clients, lenders, and vendor onboarding portals now write a minimum cyber limit into contracts the same way they long have for general liability, and they verify it with a certificate before work starts. When a contract on your desk names a cyber limit, that number becomes the floor of your sizing decision.

If you are the one imposing requirements on vendors, the same logic runs in reverse. Decide what limit a vendor incident could realistically cost you, write that limit into the contract, and verify it.

FAQ

Frequently asked questions

How much cyber insurance do I need?

Enough to absorb your worst plausible incident. Add the cost of notifying every person whose records you hold, the revenue lost across a realistic recovery period, and the legal or regulatory claims that follow, then compare the total against the minimum limits your contracts require. The larger number sets the floor. Benchmarking against the limits similar businesses carry turns that estimate into a defensible decision.

How much does cyber insurance cost?

It depends on industry, revenue, the volume of records held, security controls, the limit and retention chosen, and claims history. Published carrier examples for small businesses run from a few hundred dollars a year to several thousand, and carriers caution that averages mislead because every business rates individually. The reliable way to judge a cyber premium is to benchmark it against businesses with a similar profile.

How much is cyber insurance?

There is no flat rate. Progressive, one of the few carriers publishing figures, shows example small business policies from about $500 a year to $5,000 or more, and states that an average is hard to give because every business rates differently. A data-heavy operation, a prior claim, or weak security controls can push a premium well past any published example.

Who needs cyber insurance?

Any business that stores personal information, takes payments, or depends on its systems to operate. That includes medical and dental practices holding patient records, retailers processing cards, professional firms holding client files, and contractors running scheduling and billing in the cloud. The exposure follows the data and the downtime, not the industry label, which is why businesses that never think of themselves as technology companies still carry it.

Show 6 more questions
Do I need cyber insurance?

If exposing your customer records or losing your systems for a week would genuinely hurt, the exposure is real and worth insuring. If a client, lender, or vendor portal contract already requires a cyber limit, the decision is made and the question becomes how much to carry. The cyber insurance guide covers what the policy actually pays for so you can judge the fit.

What does a cyber insurance limit cover?

The limit caps what the policy pays across first-party and third-party coverage combined, usually as one aggregate for the policy period. First-party coverage pays your own response costs, forensics, notification, credit monitoring, data restoration, extortion response, and lost income. Third-party coverage pays defense and settlements when others sue over the incident. One event typically draws on both, which is why a limit sized to notification costs alone runs out.

What security controls lower cyber insurance cost?

Multifactor authentication, tested backups kept separate from the network, endpoint detection and response, patching discipline, and employee phishing training are the controls cyber applications ask about most. Underwriters price directly off these answers, and missing MFA or backups can raise the premium sharply or block a quote altogether. The same controls reduce claim frequency and severity, which protects the price at every renewal after this one.

What is a retention in cyber insurance?

A retention is the amount of each claim you pay before the policy starts paying, the cyber market's equivalent of a deductible. Raising it lowers the premium and keeps small incidents off your claims history, but it has to be an amount the business can absorb without strain. Sizing the retention is a cash-flow decision, while sizing the limit is a worst-case decision, and the two are best set separately.

Is cyber insurance required by law?

Generally no. No broad federal law requires a business to carry cyber insurance. The requirements that bite in practice are contractual, enterprise clients, lenders, and vendor portals that set minimum cyber limits before work starts. Separately, state breach notification laws require telling affected individuals when their data is exposed, and that notification bill is one of the costs a cyber policy exists to pay.

What is the difference between first-party and third-party cyber coverage?

First-party coverage pays your own costs after an incident, investigation, notification, credit monitoring, data restoration, extortion response, and income lost to downtime. Third-party coverage pays what you legally owe others, defense and settlements from claims by customers or partners and from regulatory proceedings. Most standalone cyber policies include both under one aggregate limit, so a serious incident draws the two coverages from the same pool.

See what businesses like yours actually carry

14 days of Premium, free. No credit card. Value in 10 seconds.