Insureon reports a $129 monthly median for cyber insurance among its small-business customers, while its published annual range runs from about $400 to more than $8,000.
- Separate first-party response from third-party liability
- Verify ransomware and social-engineering terms
- Document controls truthfully
Cyber insurance customer distribution
Checked by us August 13, 2026
| Coverage | Monthly | Annual orientation | Context |
|---|---|---|---|
| Median policy cost | $129 | $1,552 | Policies purchased through the cited marketplace |
| Lower-cost segment | Under $100 | 41% of customers | Share of cited customers below this monthly amount |
| Middle segment | $100–$200 | 26% of customers | Share within this monthly band |
| Published range | Varies | About $400–$8,000+ | Industry, data and controls create a wide range |
The source says these are median costs from 100,000 Insureon customers, mostly businesses with fewer than five employees and revenue below roughly $200,000. Technology E&O and some specialist cyber risks are not equivalent to a standard cyber policy.
Data sources: Insureon — Cyber insurance cost ↗
Cyber insurance applications connect price with both digital exposure and security practices. The amount and sensitivity of data, dependence on technology, revenue, contractual duties, and potential interruption can all matter.
Important: This guide provides general educational information, not legal, tax, or insurance advice. Requirements and policy terms vary. Consult a licensed professional about your situation.
Map the exposure before the quote
Document the personal, financial, health, or confidential information the business stores or accesses. Identify critical systems, cloud vendors, payment processing, remote access, backups, and the operational effect of an outage.
Controls insurers commonly examine
Applications may ask about multi-factor authentication, endpoint protection, patching, backups, email security, employee training, privileged access, vendor management, and incident response. Answer precisely; an inaccurate application can create serious problems later.
- MFA for email, remote, and privileged access
- Tested offline or isolated backups
- Endpoint detection and response
- Security awareness and phishing controls
- Written incident-response contacts
Compare more than the limit
Review first-party and third-party coverages, waiting periods, sublimits, panel vendors, ransomware conditions, business interruption calculations, prior acts, and exclusions. Coordinate cyber insurance with crime, professional liability, and technology policies where exposures overlap.
Cyber applications ask operational questions for a reason
Multi-factor authentication, backups, patching, endpoint protection, email controls, and vendor access are not boxes to tick casually. They influence both eligibility and the chance that an incident becomes severe. An incorrect answer can create a difficult coverage dispute later.
Answer with the person who actually manages the systems. Define which users and systems have MFA, how backups are isolated and tested, who can grant administrative access, and how departing staff are removed. If a control is planned but not implemented, say so.
Separate your own loss from liability to others
A ransomware event may involve forensic work, restoration, notification, legal advice, business interruption, extortion, and claims from customers. Policies organize these costs differently and use sublimits, waiting periods, retentions, and vendor panels. A single overall limit does not describe all of that.
Technology E&O may also matter when the company provides technology services. Ask how a security incident arising from professional work is allocated and whether one policy coordinates with the other. The answer should fit the firm's contracts and data responsibilities.
Cyber proposal questions
Read the incident-response provisions before an emergency, not during one.
- Which events trigger first-party and third-party coverage?
- Are social engineering and funds transfer addressed?
- What waiting period applies to business interruption?
- Which services have sublimits?
- Must panel vendors or breach counsel be used?
- How are dependent systems and cloud providers treated?
Separate cyber controls from policy terms
Review evidence for operational controls and generate questions about breach, interruption, extortion, vendors and defense.
Open the worksheetSources and further reading
We prioritize government, regulatory, and established consumer-education sources. External pages may change after our review.
Research reviewed on August 2, 2026. Prices and requirements can change; this page does not provide a quote.