Cyber insurance isn't a substitute for security — it's the backstop. And insurers now ask hard questions before they'll cover you. Here's how to be ready.
What underwriters want to see
- MFA on email and remote access (often mandatory now)
- Tested backups and a recovery plan
- Endpoint protection / EDR
- Staff security training and a written policy
Controls that lower your premium
Each of the above reduces risk — and risk is what you're priced on. Our website security tools guide and antivirus guide map the tooling.
Questions to ask before buying
Does it cover ransomware and extortion? Business interruption? Breach notification and legal? Is there a retainer for forensics? Read the exclusions — many exclude "human error" or missing MFA.
Pair coverage with our ransomware guide and the security checklist so you both qualify and recover.
Frequently Asked Questions
How much does cyber insurance cost for a small business?
Costs vary by coverage amount, industry, and risk profile. Small businesses typically pay $500-$2,500 annually for $100,000-$1 million coverage. High-risk industries (healthcare, finance) pay more. Compare quotes from multiple insurers and look for policies that cover: breach response, legal fees, regulatory fines, business interruption, and recovery costs.
Do I need cyber insurance if I have good security?
Yes. Even the best security can't prevent all attacks. Cyber insurance covers costs that security measures can't prevent: forensic investigation, legal fees, customer notification, credit monitoring, regulatory fines, and business interruption. It's insurance - you hope you never need it, but you're protected if you do.