Cyber insurance protects a business when hackers steal data, lock up files for ransom, or knock systems offline

Cyber insurance is a policy that pays for costs when a business faces a cyberattack or data breach. It covers things like the cost to notify customers that their information was stolen, fees to hire forensic investigators to figure out what happened, ransom demands, and lost income while systems are down. Some policies also cover legal bills if the business gets sued over the breach, and the cost to restore or rebuild data.

Unlike general business insurance, which covers physical damage or liability from accidents, cyber insurance is built for digital threats. A ransomware attack that encrypts a company's files, a breach that exposes customer credit card numbers, or a phishing scam that tricks an employee into wiring money—these are the situations cyber insurance is designed to pay for. The policy does not prevent the attack; it covers what happens after.

Key Takeaways

  • Cyber insurance pays for costs after a data breach or cyberattack, including notification of affected people, forensic investigation, and lost business income.
  • Coverage varies widely by policy—some cover ransomware payments and legal defense, while others do not, so the details matter more than the price.
  • Insurers often require basic security measures like multi-factor authentication and regular software updates before they will write a policy.
  • A typical policy costs between $1,000 and $5,000 per year for a small business, though the actual amount depends on the industry, company size, and what is covered.
  • Cyber insurance is separate from general business liability and does not replace the need for strong passwords, employee training, and regular backups.

What a cyber insurance policy actually covers

Cyber policies come in two broad categories: first-party coverage, which pays the business directly, and third-party coverage, which pays for claims brought against the business by others.

First-party coverage includes the cost to notify customers that their data was compromised—this is often required by law and can run thousands of dollars for a large customer list. It covers hiring a forensic firm to investigate what happened and how the breach occurred. It pays for the cost of credit monitoring services offered to affected customers. It covers lost income if the business cannot operate while systems are being restored. Some policies reimburse the cost of paying a ransom to recover encrypted files, though this is becoming less common and some insurers exclude it entirely.

Third-party coverage pays legal defense costs if customers or regulators sue the business over the breach. It covers settlements or judgments if the business is found liable. It can cover regulatory fines in some cases, though this varies by state and policy.

What is not covered is important: most policies exclude attacks that happen because the business ignored obvious security problems, like running outdated software or using weak passwords. They typically do not cover losses from fraud committed by the business's own employees. They do not cover damage to physical equipment, even if caused by a cyberattack—that falls under property insurance.

How much cyber insurance costs and what affects the price

A small business with fewer than 50 employees typically pays between $1,000 and $5,000 per year for a basic cyber policy. A mid-sized company might pay $5,000 to $15,000 annually. These are rough ranges; the actual cost depends on several factors that insurers evaluate.

The industry matters significantly. A healthcare practice or law firm that handles sensitive personal information pays more than a retail store. A financial services company pays more than a manufacturing business. Insurers see some industries as higher risk because they hold more valuable data or face stricter regulations.

Company size affects the price—more employees and more customer data mean higher premiums. The amount of coverage chosen also drives cost: a policy that covers up to $1 million in losses costs less than one covering $5 million. The deductible works the same way as other insurance: choosing a higher deductible (what the business pays out of pocket before insurance kicks in) lowers the premium.

The business's own security practices matter most. Insurers will ask whether the company uses multi-factor authentication (requiring a password plus a second verification step), whether it backs up data regularly, whether it has a written incident response plan, and whether employees receive security training. A business with strong practices pays less than one with weak ones. Some insurers will not write a policy at all if the business does not meet minimum security standards.

What happens when a business files a claim

When a cyberattack or breach occurs, the business contacts the insurance company and describes what happened. The insurer assigns a claims adjuster who will ask for documentation: when the breach was discovered, what systems were affected, how many people's data was exposed, and what steps the business has already taken to respond.

The insurer may require the business to hire a forensic investigator approved by the insurance company. This investigator examines the systems to determine how the attack happened, what data was accessed, and whether the breach is still ongoing. The insurer pays this cost directly, not the business.

Once the investigation is complete, the business submits invoices for covered expenses—notification costs, credit monitoring, lost income, legal fees. The insurer reviews each invoice to confirm it is covered under the policy and that the amount is reasonable. If approved, the insurer pays the bill, minus the deductible. The entire process typically takes weeks to months, depending on the complexity of the breach and how quickly the business submits documentation.

The difference between cyber insurance and other business coverage

General business liability insurance covers accidents and injuries on the business's property, or harm caused by the business's products or services. It does not cover data breaches or cyberattacks. Property insurance covers physical damage to buildings and equipment. It does not cover losses from digital attacks.

Some businesses confuse cyber insurance with business interruption insurance, which pays for lost income when the business cannot operate due to a covered event like a fire. Business interruption insurance may cover some cyberattack losses, but it typically does not cover the investigation, notification, or legal costs that cyber insurance handles. The two can work together: business interruption covers lost income, while cyber insurance covers the other costs of responding to the breach.

Cyber insurance also does not replace the need for strong security practices. It is a financial safety net, not a substitute for passwords, backups, employee training, and software updates. An insurer will not pay a claim if the breach happened because the business ignored basic security measures.

Who needs cyber insurance and who might not

Any business that stores customer information—names, email addresses, payment card numbers, health records—should consider cyber insurance. This includes retailers, healthcare practices, law firms, accounting firms, nonprofits, and any business that accepts online payments or maintains a customer database.

A very small business with no customer data and no online presence may not need it. A sole proprietor who works from home and does not handle sensitive information faces lower risk. But the threshold is lower than many business owners expect: even a small consulting firm that keeps client contact information and project details on a computer is a target for attackers.

Businesses in regulated industries—healthcare, finance, education—often face legal requirements to have cyber insurance or to carry specific amounts of coverage. Some large customers require their vendors to carry cyber insurance as a condition of doing business. A business should check its contracts and industry regulations to see whether coverage is required.

How to choose a cyber insurance policy

Start by listing what the business actually needs covered. Does it handle payment card data? Does it store health information? How many customers does it have? What would it cost to notify them all if their data was breached? What would it cost to hire investigators and restore systems? These numbers help determine how much coverage to buy.

Compare policies from multiple insurers—coverage varies widely, and the cheapest policy may not cover what the business actually needs. Read what is excluded: some policies exclude ransomware, some exclude certain types of attacks, some exclude losses from employee negligence. Understand the deductible and what the policy will actually pay for.

Ask each insurer what security measures they require. If the business does not meet those standards, either upgrade the security first or expect higher premiums. Some insurers offer discounts for specific security practices like multi-factor authentication or annual security training.

Work with an insurance broker or agent who handles cyber policies. They can explain the differences between policies and help match coverage to the business's actual risk. This is more useful than buying online based on price alone.

Frequently Asked Questions

Does cyber insurance cover ransomware attacks?

Some policies cover the cost of paying a ransom to recover encrypted files, but this is becoming less common. Many insurers now exclude ransom payments entirely, or limit them to a small percentage of the total coverage. Read the policy carefully to see whether ransomware is covered and what the limits are.

Will cyber insurance cover losses if an employee falls for a phishing scam?

It depends on the policy. Some cover losses from phishing attacks that trick employees into wiring money or revealing passwords. Others exclude losses caused by employee error or negligence. This is a detail to ask about when comparing policies, since phishing is a common attack method.

Can a business get cyber insurance if it has already had a breach?

Yes, but the insurer will investigate what happened and may require the business to fix security problems before writing a new policy. The breach itself does not automatically disqualify a business, but the insurer will want to know why it happened and what has changed to prevent it from happening again.

Does cyber insurance cover attacks by the business's own employees?

Most policies exclude losses from fraud or theft committed by employees. If an employee steals customer data or embezzles money using access to company systems, cyber insurance typically will not pay. This is considered an internal crime, not a cyberattack.

What if the business does not have cyber insurance and gets hacked?

The business pays all costs out of pocket: investigation, notification, credit monitoring, legal defense, and any settlements. For a large breach, these costs can reach hundreds of thousands of dollars. The business also faces potential fines from regulators if it fails to notify affected people or comply with data protection laws.