For a small business (under 50 employees, under $5M revenue), cyber insurance typically costs between $1,000β$3,000 per year for $1M in coverage. But costs vary hugely based on industry, size, security posture, and claims history.
A micro business (1β10 employees) might pay as little as $500β$1,500 annually, while an enterprise with 1,000+ employees could pay $50,000β$500,000+ per year. Think of cyber insurance pricing like any other insurance: the bigger and riskier you are, the more you pay.
Your company size is one of the strongest predictors of premium. Below is what typical annual premiums look like:
| Company Size | Employees | Typical Annual Premium | Typical Coverage |
|---|---|---|---|
| Micro | 1β10 | $500β$1,500 | $500Kβ$1M |
| Small | 11β50 | $1,000β$3,000 | $1Mβ$2M |
| Mid-market | 51β250 | $3,000β$15,000 | $2Mβ$5M |
| Upper mid-market | 251β1,000 | $15,000β$50,000 | $5Mβ$10M |
| Enterprise | 1,000+ | $50,000β$500,000+ | $10M+ |
These figures are for standard coverage with a $10,000β$25,000 deductible. Prices vary by country, local regulation, and underwriter appetite.
Some industries face significantly higher premiums because they handle sensitive data or are frequent targets. Insurers apply industry-specific multipliers to base rates. Here's how they compare:
| Industry | Risk Level | Premium Multiplier | Why |
|---|---|---|---|
| Healthcare | Very High | 2β3Γ | HIPAA data, patient records, ransomware target |
| Financial Services | High | 1.5β2.5Γ | Regulatory exposure, high-value data |
| Technology | High | 1.5β2Γ | IP, customer data, SaaS liability |
| Retail/E-commerce | Medium-High | 1.3β1.8Γ | Payment card data, PCI DSS compliance |
| Professional Services | Medium | 1β1.5Γ | Client confidential data |
| Manufacturing | Medium | 1β1.5Γ | OT/IT convergence, supply chain risk |
| Education | Medium | 1β1.3Γ | Student data, limited budgets |
| Non-profit | Low-Medium | 0.8β1.2Γ | Limited data, smaller targets |
Example: A small healthcare practice with 20 employees might see a 2.5Γ multiplier applied to base rates. If the base premium is $1,500, they'd pay around $3,750 instead.
Insurance underwriters assess dozens of variables when setting your rate. Here are the main ones:
Your premium isn't set in stone. Improving your security posture can yield significant savings β and many insurers offer discounts for implemented controls:
Many businesses find that the cost of implementing these controls (often $5,000β$20,000) pays for itself through lower premiums within 12β24 months.
The average cost of a data breach is now $4.9 million globally and $165 per compromised record. Even a small breach affecting just 1,000 records would cost you $165,000 in recovery, notification, credit monitoring, and legal fees β far more than your annual insurance premium.
Beyond direct breach costs, cyber insurance covers:
For most businesses, cyber insurance is not just worth the cost β it's essential risk management.
Get matched with a specialist broker who'll find a policy that fits your risk profile and budget.
Get a personalised quote β