What cyber insurance actually covers
First-party costs: forensics, notification, credit monitoring, ransomware payments, business interruption. Third-party: lawsuits from customers, regulatory fines (where insurable), media liability. Social-engineering fraud (wire transfer scams) is usually a sublimit or separate endorsement — read it.
- • War exclusions and 'failure to maintain' clauses are the big denial traps.
- • PCI compliance failures can void payment-card coverage.
- • Document your controls at application time — misrepresentation is grounds for rescission.
Related guides
Long-form playbooks on the same topic, written by the RevenueLab editorial team.
FAQ
How much does cyber insurance cost for a small business?
Typically $750–3,000/year for under $5M revenue with basic controls, scaling to $8,000+ for data-heavy businesses. Healthcare and financial firms pay roughly double.
Does cyber insurance cover ransomware?
Most policies cover ransom payments, negotiation, forensics, and business interruption — but some carriers now sublimit ransomware or require specific controls. Check the ransomware endorsement explicitly.
What controls do insurers require?
Nearly universal: MFA on email and remote access, offline/immutable backups, endpoint detection. Increasingly: security awareness training, patch SLAs, and incident response plans. Lying on the application voids the policy.
How this calculator is built
Independently maintained
Written by Sam Doshi and the RevenueLab editorial team. We don't sell the data feeds this tool is built on.
Sourced from primary data
Benchmarks come from public AdSense / Stripe / IRS disclosures and reader-submitted data — never third-party "$X per view" claims. Full methodology.
Last editorial review
Reviewed on a rolling quarterly cycle. Dated reviews are published on the methodology record for each calculator.
Editorial standards
See our editorial policy and disclaimer. Results are estimates, not advice.