How Much Does Cyber Liability Insurance Cost?
Published on | Written by Alec Pow
This article was researched using 14 sources. See our methodology and corrections policy.
Cyber liability insurance covers breach response, privacy liability, ransomware response, forensic investigation, notification, legal defense, and business interruption after a covered network or data event. Insureon, TechInsurance, Hiscox, Progressive Commercial, The Hartford, and Embroker publish small-business cyber pricing examples or quote ranges, while NAIC, IBM, Verizon, Coalition, and Marsh frame the policy around sensitive records, breach severity, ransomware, software vulnerabilities, remote access, and security controls.
How Much Does Cyber Liability Insurance Cost?
Jump to sections
For a small U.S. business, cyber liability insurance cost can run from the low hundreds per year to several thousand dollars per year. One 2025 pricing page puts the average at $129 (equivalent to 4.3 hours at $30 per hour, or about $52 in 1990 dollars) per month, or about $1,552 a year, and shows annual premiums from $400 to over $8,000 through premium and annual range data.
The quote is built from the limit, deductible or retention, industry class, revenue, data volume, security controls, prior incidents, and coverage parts. Exact pricing is often private because underwriters need application answers before they bind coverage.
A small retailer, SaaS vendor, consultant, or medical office is priced per policy year, then adjusted by the limit, deductible, data type, contract requirement, and add-ons such as breach response or extortion coverage. A buyer comparing quotes should read the coverage form, not just the premium line.

Important numbers
- Entry, Hiscox shows sample cyber security premiums of $26.91 (about $11 in 1990 dollars) to $33.90 per month for three small-business profiles with a $250,000 limit and $10,000 deductible in a sample quote chart.
- Mid, a $129 monthly premium equals $1,548 over 12 months, which is $4 below the $1,552 annual figure listed in 2026 customer premium distribution.
- All-in, Progressive says some annual cyber policies might cost around $500, and others can cost $5,000 or more, depending on limits and risk factors in its annual policy range.
Who this cost makes sense for
Cyber liability coverage makes the most sense when a business cannot operate without email, cloud accounts, online payments, client portals, or stored customer records. ERGO NEXT’s 2026 small-business page says cyber events can create downtime, lost income, cleanup costs, legal action, and loss of trust for companies using common digital tools such as cloud apps, POS systems, contracts, invoices, and CRMs in a small-business cyber discussion.
Cyber insurance also sits beside other risk-control costs. A restaurant might budget for a kitchen hood fire suppression system, then use cyber coverage for payment systems and payroll records. A building owner might pay for a commercial roof inspection, then buy cyber coverage for tenant portals and accounting software.
Makes sense if
- Your client contract requires a cyber liability certificate before work starts.
- You store customer, employee, health, financial, or login records.
- Your revenue would drop if email, POS, billing, or cloud software went down.
- You use vendors or remote access that could expose your systems.
Doesn’t make sense if
- Your business is truly offline and has no stored customer data.
- The policy excludes the event you are trying to insure.
- The deductible is higher than the small loss you are trying to transfer.
- You are buying coverage instead of fixing MFA, backups, and access controls.
What you’re actually buying
Cyber liability insurance is business insurance for losses tied to data breaches, network attacks, privacy claims, and digital extortion. It can pay the insured company’s own response expenses and can defend the company when a customer, client, regulator, or partner claims the business failed to protect information.
It is not security software, employee training, a backup system, or a managed IT contract. It also differs from general liability insurance, which is built around bodily injury and property damage, and from technology errors and omissions coverage, which centers on claims that a tech service or product failed. NAIC’s May 2024 cybersecurity topic page ties the issue to sensitive consumer financial and health information collected in underwriting and claims through its consumer data background.
Coverage parts
A policy can look cheap because it covers only a narrow slice of the problem. First-party cyber coverage pays the insured business for breach response, data recovery, cyber extortion, business interruption, notification, and other response costs. Third-party cyber liability can pay defense costs and settlements when clients or customers bring claims after a breach. Some tech companies also need tech E&O because the allegation may be that their software, hosting, consulting, or managed service failed.
Line items matter. The Hartford lists an average annual small-business data breach premium of about $320 (about $130 in 1990 dollars), then breaks related core coverages into $140 for response expense, $128 for defense and liability, $9 for an extortion sublimit, and $43 for other options in its coverage cost split. Those parts add back to $320, since $140 plus $128 plus $9 plus $43 equals $320.
Limits, deductibles, and retentions
The limit controls how much the insurer may pay for covered losses, and the deductible or retention controls how much the business must absorb before insurance responds. Higher limits cost more because the insurer is taking on more possible loss. Higher deductibles can reduce the premium, but they also leave the buyer holding more cash risk at claim time.
Embroker’s 2026 article says businesses spent between $1,200 and $7,000 annually on cyber insurance in 2024, with a median around $2,000 per year, and it describes coverage limits from $500,000 to $5 million per occurrence in a limit and premium guide. A firm moving from a contract-required low limit to a seven-figure limit should expect underwriting questions about revenue, records, backup status, admin access, prior claims, and vendor exposure.
A cyber quote
A usable quote should show the annual premium, policy limit, retention or deductible, covered events, sublimits, exclusions, retroactive date if used, and any required security conditions. The buyer should also ask whether breach counsel, digital forensics, customer notification, credit monitoring, PR support, data recovery, and business interruption are inside the limit or subject to their own caps.
| Quote line | What to check | Budget effect |
|---|---|---|
| Premium | Annual amount and whether monthly billing adds fees | Cash flow |
| Limit | Per-claim and aggregate caps | Upper protection |
| Retention | Amount paid before coverage responds | Out-of-pocket loss |
| Sublimits | Extortion, forensics, notification, or interruption caps | Claim gap risk |
That table is also where add-ons show up. A quote with a lower premium can be the worse buy if it excludes ransomware, limits breach response, or leaves defense costs inside a small aggregate. Ask the broker to mark which costs are first-party, which are third-party, and which remain uninsured.
Three buyer cases
Budget case. A solo consultant with no card processing and a contract requirement for cyber coverage may choose a modest limit and a higher deductible. The main driver is the client certificate, not a large database. The buyer should still check whether phishing, cloud email compromise, and breach response are covered because those risks fit a consulting practice.
Typical case. A retailer using POS software, online orders, customer email lists, and vendors has more access points. The premium can rise because the policy may need first-party breach response, business interruption, privacy liability, and payment-related coverage. The insurer will care about who can access the POS system and whether third-party IT vendors use secure access.
High case. A software vendor, MSP, or IT consultant may need cyber coverage tied to tech E&O because a client could claim the vendor caused or failed to prevent a breach. This buyer often faces contract limits, vendor risk reviews, and longer security questionnaires. A low premium is less useful if the policy fails to answer the exact contract language.
Hidden costs
The premium is only one part of the budget. After an incident, the business may still owe the deductible or retention, uncovered forensic work, uncovered legal time, notification expenses above a sublimit, credit monitoring beyond policy terms, replacement hardware, emergency IT labor, and lost income during downtime. The policy form decides which of those costs are covered.
Hidden-cost range to watch includes deductibles around $1,000 to $2,500 in some small-business cyber policies, sample quote deductibles at $10,000, and attack losses that can reach several thousand dollars before any reputation or downtime effect is counted.
Hiscox reported in 2023 that the median annual cyber-attack cost for surveyed U.S. small businesses fell from about $10,000 in 2022 to about $8,300 in 2023, with the median number of attacks rising from 3 to 4 in its readiness report release. That older figure is useful historical context, not a carrier quote.
Worked annual total
A small professional firm might build an annual budget from a $1,552 premium, a $2,500 deductible reserve, and $300 for basic staff security training. That totals $4,352 because $1,552 plus $2,500 plus $300 equals $4,352. The premium and reserve are the insurance budget, and the training line is a risk-control cost that may support the application.
- Annual cyber premium, $1,552.
- Deductible reserve, $2,500.
- Basic training allowance, $300.
- Worked annual planning total, $4,352.
Underwriters also test the controls behind that budget. TechInsurance says first-party coverage can pay for investigation, customer notification, crisis management, and business interruption expenses. Coalition reported in March 2025 that 58% of 2024 ransomware claims started with compromised perimeter security appliances, and remote desktop products were second at 18%, in its ransomware entry-point report. That is why MFA, patching, backups, VPN controls, vendor access, and endpoint monitoring can affect whether a quote is offered and how strict the terms are.
Article Highlights
- Small-business cyber coverage can start under $500 a year, but higher-risk profiles can reach several thousand dollars.
- The limit, deductible, data type, contract requirement, and security controls drive the quote.
- A cheap policy can be weak if it excludes ransomware, business interruption, or breach response.
- Budget for the deductible and response work, not just the annual premium.
- MFA, backups, patching, and remote-access controls can shape underwriting terms.
Answers to Common Questions
Is cyber liability insurance paid monthly or annually?
Many carriers and brokers can show monthly and annual payment options. Annual payment may reduce billing friction, but the quote should state whether installment fees apply.
How much coverage does a small business need?
Start with contract requirements, customer record count, revenue at risk during downtime, and the cost of breach response. A business with client systems access may need higher limits than a local firm with only basic email records.
Does general liability insurance cover cyber claims?
General liability is built for bodily injury and property damage. Cyber events need a policy that addresses data, privacy, network security, response expenses, and digital liability.
Can security controls lower the premium?
They can help the application and may improve terms. Underwriters may ask about MFA, backups, endpoint protection, patching, admin access, vendor access, and prior incidents before quoting.
Disclosure: Educational content, not financial advice. Insurance pricing depends on underwriting, coverage limits, deductibles, and region. Confirm quotes and policy terms with a licensed insurer. See our methodology and corrections policy.
