Skip to content
GM Calculator

Cyber Insurance Calculator | SMB Premium Estimate & Coverage Sizing

Estimate what cyber insurance will cost your business — and see how MFA, EDR, and tested backups cut the price — then size your limit with the 3-bucket exposure method instead of guessing at $1M.

💰 Premium estimate by industry & revenue🔐 Control discounts (up to ~30% off)🪣 3-bucket limit sizing📊 2026 SMB benchmarks
Learn How It Works

What Cyber Insurance Actually Costs in 2026

Cyber insurance is priced on your risk profile: industry, revenue, data footprint, security controls, and claims history. Unlike most business insurance, there's no standard rate card — two similar-sized companies can pay very different premiums. Published 2026 data shows:

💵 Small business (<$1M revenue), $1M limit: $1,200–$2,400/yr

📊 National SMB average, $1M limit: ~$1,000–$1,750/yr ($83–$145/mo)

🏢 Mid-size ($10M–$50M revenue), higher limits: $5,000–$15,000/yr

🛰️ Mid-market ($20M–$200M revenue), $2M–$10M limits: $8,000–$50,000/yr

The spread within each band is mostly security controls. Two identical 25-person companies can receive quotes 30% apart — the difference is MFA, EDR, and who has tested backups.

How Underwriters Price Your Policy

The calculator above models the same factors an underwriter weighs:

Premium ≈ Industry base × Revenue factor × Employee factor × Limit × Retention − Control discounts

Industry base: healthcare and finance run 60–70% above professional services; restaurants and nonprofits run below.

Revenue & headcount: bigger attack surface, bigger notification liability, bigger BI exposure.

Limit: premium scales sub-linearly — doubling from $1M to $2M adds roughly 60%, not 100%.

Retention: $25K deductible vs $2.5K saves roughly 20% in premium.

Security Controls That Cut Premiums (and Which Are Required)

Underwriting in 2026 is a technical audit, not a questionnaire. These are the controls carriers check, the discounts they typically reward, and what evidence you'll need to show.

ControlTypical discountStatus at most carriersEvidence underwriters request
🔐 MFA (email, VPN, admin)~10%Required to quoteScreenshot of MFA enrollment / conditional-access policies
🖥️ EDR on all endpoints~8%Required to quoteEDR console export showing coverage %
💾 Immutable, tested backups~7%Required to quoteRestore test logs from the last 6 months
🎓 Awareness training + phishing sims~4%Strongly expectedTraining completion reports, phishing failure rates
🩹 30-day patch cadence~3%Strongly expectedPatch policy + critical-vulnerability SLA documentation
📋 Incident response planTerms, not priceRequired by manyIR plan document with named contacts and retention counsel
The 2026 claims risk: over 40% of cyber claims faced denial scrutiny last year, and the most common reason wasn't fraud — it was misrepresented controls. If your application says MFA is everywhere but one executive account has SMS-only fallback, that gap can void the claim. Only check the boxes you can prove.

The 3-Bucket Method for Sizing Your Limit

Most SMBs buy $1M because it's the first number on the quote form. Size it properly instead — the calculator's Size Your Limit tab runs this exact method:

Bucket 1 — Downtime exposure

Daily gross profit × expected recovery days + extra recovery expense. Example: a $5M revenue distributor at 30% margin loses $4,100/day; a realistic 21-day ransomware recovery plus $50K of forensics and overtime = ~$136K. Owners consistently underestimate this — one manufacturer assumed 3 days and was down 18 because backups hadn't been tested in 14 months.

Bucket 2 — Data exposure

Records × per-record cost: notification runs $50–$200 per record, credit monitoring $10–$30 per person per year, plus regulatory defense ($50K–$250K+ for HIPAA or PCI actions). 10,000 basic PII records ≈ $600K; the same count of health records ≈ $2M.

Bucket 3 — Fraud exposure (BEC / wire)

Your largest single wire transfer. This is where SMBs are dangerously underinsured: most policies cap social engineering at $100K–$250K while average BEC losses run $200K–$300K+. The FBI logged ~$2.77B in BEC losses in 2024. If your largest wire is $250K, your sublimit needs to match it.

Add the three buckets, then a 20–30% buffer. That's your target limit range — and if a client contract specifies a minimum, start there and check that sublimits don't hollow it out.

Coverage Limits Businesses Like Yours Buy

Common limit ranges by industry, and the exposure that drives them.

IndustryCommon limitTypical annual costWhy
💼 Professional services$1M–$2M$1,200–$2,500Client data, contractual requirements
🛒 Retail / e-commerce$1M–$3M$1,300–$3,000PCI compliance, transaction volume
🏥 Healthcare / medical$2M–$5M$2,000–$5,000HIPAA penalties, PHI exposure
🏭 Manufacturing / logistics$1M–$3M$1,150–$3,500OT systems, business-interruption exposure
☁️ SaaS / technology$2M–$10M$1,600–$8,000+Third-party liability, enterprise contract demands
🏦 Financial services$3M–$10M$2,100–$10,000+Regulatory scrutiny, fiduciary exposure

Real-World Premium Estimates

💼 12-person marketing agency, $1.8M revenue

$1M limit, $2.5K retention, all 5 controls in place → ≈ $850–$1,100/yr. The client contracts requiring "$1M cyber" are the real reason to buy; the controls discount is a bonus for doing security right.

🏥 30-person dental practice, $4M revenue

$2M limit (PHI exposure), $10K retention, MFA + EDR + backups → ≈ $2,400–$3,200/yr. 20,000 patient records × ~$200/record = $4M of data exposure alone — $1M would be badly thin.

🏭 45-person precision manufacturer, $12M revenue

$3M limit, $25K retention, partial controls → ≈ $4,500–$7,000/yr. The business-interruption bucket dominates: $12M × 28% margin = $9,200/day of lost gross profit — 21 days down is $193K before any recovery costs.

What Cyber Insurance Pays For (and What It Won't)

✅ Typically covered

  • • Breach counsel & digital forensics ($50K–$150K typical)
  • • Notification & call center ($50–$200/record)
  • • Credit monitoring ($10–$30/person/yr)
  • • Ransomware payment & system restoration
  • • Business interruption (after 8–24h waiting period)
  • • Regulatory defense (HIPAA, PCI, state AG actions)
  • • Third-party liability lawsuits

❌ Commonly excluded or sublimited

  • • Employee theft (needs crime policy)
  • • War / nation-state attacks (broad language — read it)
  • • BEC above the $100K–$250K social-engineering sublimit
  • • Dependent BI (your cloud vendor's outage) unless endorsed
  • • Incidents caused by unpatched known vulnerabilities
  • • Long-tail IP/patent claims (that's E&O territory)
  • • Future profits beyond the BI period

Common Cyber Insurance Mistakes

Mistake 1: Buying the default $1M without sizing exposure

For data-heavy or high-downtime businesses, $1M can be exhausted by day 12 of a month-long recovery. Run the 3-bucket method — it takes five minutes and is the difference between a claim that saves the business and one that doesn't.

Mistake 2: Overstating controls on the application

The fastest way to a denied claim. Underwriters verify — and claims adjusters verify harder. A single un-MFA'd service account can unravel the whole policy. Honest applications with real gaps get better long-term outcomes than padded ones.

Mistake 3: Ignoring sublimits and the waiting period

A $2M policy with a $100K ransomware sublimit and an 24-hour BI waiting period protects less than a $1M policy with full sublimits and an 8-hour wait. Compare policies on the sublimit table, not the headline number.

Mistake 4: Treating insurance as the security plan

Insurance reimburses losses; it doesn't prevent downtime, reputational damage, or the client you lose after a breach. The controls that earn your premium discount also happen to be the ones that stop the incident in the first place — do both.

Shahid

Reviewed by Shahid

Content Reviewer & Calculator Specialist

Content reviewer specializing in marketing, finance, health, and math calculators on GM Calculator.

✓ Content Reviewer✓ Calculator Accuracy Specialist

Cyber Insurance Calculator Pros & Cons

Pros

  • ✅ Interactive premium estimator (competitors are static tables)
  • ✅ Control-by-control discount modeling
  • ✅ 3-bucket limit sizing method built in
  • ✅ Compares against 2026 SMB benchmarks
  • ✅ Free forever — no lead form, no broker contact required

Cons

  • ✗ Directional estimate — real quotes vary by carrier appetite
  • ✗ Doesn't model claims history or vendor-risk questionnaires

Frequently Asked Questions

How much does cyber insurance cost for a small business?

Published 2026 benchmarks put the average small-business cyber premium at roughly $1,000–$1,750 per year for $1 million in coverage — about $83–$145 per month. Premiums range from around $400/yr for tiny low-risk businesses to $8,000+ for data-heavy or higher-revenue firms. Your actual quote depends mostly on industry, revenue, the data you hold, and which security controls you have in place.

How much cyber insurance do I need?

Size your limit to your exposure, not to the quote form default. The 3-bucket method: (1) downtime exposure = daily gross profit × expected recovery days + recovery expenses; (2) data exposure = number of sensitive records × per-record breach cost ($60–$200 depending on data type); (3) fraud exposure = your largest single wire transfer. Add the three buckets plus a 20–30% buffer. Most SMBs land at $1M–$2M; healthcare, finance, and SaaS typically need $2M–$5M.

Is $1 million of cyber insurance enough?

It can be — if revenue is under about $3M, you hold minimal sensitive data, have tested backups, and process no large wires. It's usually thin if daily gross profit exceeds $5,000, you store health or payment card data, you send wires over $100K, or a client contract requires higher limits. Also check sublimits: a $2M policy with a $100K ransomware sublimit protects less than a $1M policy with full limits.

What security controls lower cyber insurance premiums?

The controls underwriters reward most: MFA on email, VPN, and admin accounts (~10% discount and a de-facto requirement), EDR/managed endpoint protection (~8%), immutable backups with tested restores (~7%), security awareness training (~4%), and a documented 30-day patch cadence (~3%). Stacked, these can cut premiums 15–30% — and in 2026 most carriers won't quote at all without MFA, EDR, and tested backups in place.

What are the cyber insurance requirements in 2026?

Underwriting has shifted from questionnaires to proof. Carriers typically require: MFA across email/VPN/admin, EDR on endpoints, immutable and tested backups, security awareness training, a documented patch cadence, an incident response plan, and offline (isolated) backup copies. Expect to provide evidence — screenshots, policy exports, and restore-test logs. Weak or missing controls lead to declined applications, restricted terms, or denied claims.

Does cyber insurance cover ransomware and wire fraud?

Ransomware: most standalone policies cover extortion payments, negotiation, system restoration, and business interruption — subject to your sublimit. Wire fraud and business email compromise (BEC): usually covered but sublimited to $100K–$250K on many policies, while average BEC losses run $200K–$300K+ (FBI IC3 logged ~$2.77B in BEC losses in 2024). Employee theft falls under crime insurance, not cyber — many businesses layer a crime policy on top.

What is a cyber insurance retention (deductible)?

The retention is what you pay out of pocket before coverage kicks in — typically $2,500–$10,000 for SMBs, with $25,000+ common on larger policies. Higher retentions lower your premium (roughly 10–20% moving from $2.5K to $25K) but make small incidents fully self-funded. Also check the business-interruption waiting period: most policies impose an 8–24 hour waiting window before downtime coverage begins.

What does cyber liability insurance actually cover?

First-party costs: breach counsel and forensics ($50K–$150K typical), notification and call centers ($50–$200 per record), credit monitoring ($10–$30 per person/year), ransomware payments and restoration, and business interruption losses. Third-party costs: privacy liability lawsuits, regulatory defense ($50K–$250K+ for HIPAA/PCI/state AG actions), and network security failures. Watch exclusions: war/nation-state language, unpatched-system exclusions, and dependent business interruption (your cloud provider going down) are common friction points.