A cyberattack doesn't just mean restoring your systems. It can mean paying forensic investigators, notifying customers, hiring breach counsel, responding to regulators, defending lawsuits, and covering lost revenue while your business is offline. Cyber Insurance exists to pay those costs.
In 2025, the FBI's Internet Crime Complaint Center reported nearly $21B in cybercrime losses, a 26% increase over the prior year. Ransomware and phishing remain the most common loss types for small and mid-size companies, and both trigger Cyber Insurance. When an incident hits, the financial and operational fallout can be significant. For ecommerce businesses, SaaS platforms, and any company running on digital infrastructure, Cyber Insurance is what allows you to investigate, respond, and recover without derailing growth or damaging customer trust.
Most enterprise customers now require Cyber Insurance before a contract executes. If you're in a sales cycle with a larger company, you've probably already seen this requirement in the contract. If you haven't yet, you likely will.
Key Takeaways
- Cyber Insurance covers digital risks that traditional policies don't: breach response, ransomware, regulatory fines, and legal defense.
- Median annual premium is $2,755 based on 2,034 Vouch clients, with premiums scaling by revenue, data exposure, and security posture.
- Coverage includes both first-party protection (your direct costs) and third-party liability (claims from customers, partners, or regulators).
- AI-powered threats, deepfake fraud, and agentic system exposures are an active and growing part of the current threat environment.
- The right coverage limits depend on your revenue, PII volume, industry, and contract requirements, not just what a customer put in their template.
What Cyber Insurance Covers
Cyber Insurance covers the financial and operational fallout from cyberattacks and data incidents. Coverage splits into two components: first-party coverage and third-party coverage, which together protect your business from both directions of a cyber event.
1. First-Party Coverage: Your Direct Costs
First-party coverage pays for what happens to your business during and after an incident:
- Breach Response and Notification: The cost to notify affected customers and regulators as required by state breach notification laws. This includes hiring notification vendors and providing credit monitoring to affected individuals.
- Digital Forensics and Data Recovery: Hiring experts to investigate how the breach happened, what was accessed, and how to restore affected systems.
- Business Interruption: Revenue loss and ongoing operating expenses when a cyberattack takes your systems offline.
- Cyber Extortion and Ransomware Response: Negotiation support, ransom payments (where legally permitted), and recovery assistance after a ransomware attack.
- Fraud, Social Engineering, and Funds Transfer Losses: Financial losses from phishing attacks, business email compromise, and fraudulent wire transfers.
2. Third-Party Coverage: Claims From Others
Third-party coverage responds when customers, partners, or regulators hold you responsible for a cyber event:
- Legal Defense and Liability: Attorney fees, court costs, and settlements when third parties sue over data exposure or service failures.
- Privacy Liability: Claims tied to mishandling personal, financial, or health-related data.
- Regulatory Penalties: Fines and investigation costs from regulators like HIPAA, CCPA, and GDPR following a breach.
- Media and Content Liability: Liability for copyright infringement, defamation, or privacy violations through online content.
Because modern attacks are so frequent and technically sophisticated, insurers see an increasing volume of both types of claims. Understanding the two core components of your Cyber policy helps you evaluate whether your limits are adequate for the actual exposures your business carries.
Learn more about what Cyber Insurance covers.
What Cyber Insurance Doesn't Cover
Cyber Insurance is designed for digital losses. It doesn’t cover:
- Bodily Injury and Property Damage: Physical injuries and property losses belong under General Liability and Property Insurance.
- Hardware Replacement: The cost to replace physical devices falls under Property Insurance.
- Technology Upgrades or Betterments: Coverage restores your systems to their pre-incident state. It can't fund improvements or upgrades.
- Long-Term Lost Revenue or Reputational Damage: Coverage applies to measurable losses during the incident period, not speculative future damage to your brand or customer relationships.
- Incidents Already in Progress Before Coverage Begins: Known or suspected incidents at the time of binding are excluded. Disclose any known circumstances when you apply.
- Nation-State Attacks or Cyber Warfare: Attacks attributed to sovereign governments may be excluded under war exclusion clauses.
- Intentional or Criminal Acts by the Insured: Coverage doesn't apply when a loss is caused by deliberate actions from the policyholder.
Learn more about what Cyber Insurance doesn't cover.
Types of Cyber Insurance
Policies can be structured in different ways depending on your business model, data exposure, and contract requirements.
Standalone
Standalone Cyber coverage is a dedicated policy covering only cyber risks. It provides the highest coverage limits and the most specific terms. This is the right structure for any company with meaningful data exposure, enterprise client relationships, or explicit contractual coverage requirements.
Bundled
Bundled Cyber coverage sometimes appears as a small sublimit inside a Business Owners Policy (BOP). These sublimits are typically $100K or less. That's not adequate for most tech companies. Notification costs, forensic fees, and legal defense in a data breach routinely exceed $100K before any regulatory fines or third-party claims are factored in. If your current Cyber coverage lives in a BOP, review the sublimit carefully.
Combined
Combined Cyber and Tech E&O coverage is the most common structure for technology companies. When these two coverages are written on the same policy form, there's no dispute about which responds when a software error leads to a security incident. Real incidents frequently involve elements of both an errors and omissions claim and a cyber event.
The CrowdStrike outage in 2024 is a clear example. What began as a software update error cascaded into a massive operational failure for thousands of downstream customers, raising questions about both Professional Liability and Cyber coverage simultaneously. Having both on the same form eliminates that ambiguity. Buying them separately from different carriers creates a gap that neither policy will volunteer to fill.
How Cyber Insurance Works
From applying for coverage to filing a claim, here's how a Cyber Insurance policy works in practice.
1. Apply for Coverage
You'll complete an application covering your revenue, employee count, industry, data types, and security practices. The application typically takes 20 to 40 minutes. Underwriters are primarily interested in four controls: multi-factor authentication (MFA), endpoint detection and response (EDR), encrypted backups, and whether you have an incident response plan. Strong answers can reduce your premium. See the next section on what insurers look for.
2. Underwriting and Binding
Once your application is submitted, underwriting evaluates your risk profile and returns a quote with coverage limits, deductibles, and sublimits for each coverage type. Cyber policies are written on an annual basis. If your revenue or data exposure changes materially during the policy year, you can typically request a mid-term adjustment.
3. File a Claim
Report a suspected incident to your insurer as soon as possible. Most Cyber policies include a breach response hotline and access to pre-approved forensic firms, legal counsel, and notification vendors. Early notification matters: delays in reporting can affect coverage, and the first 24 to 72 hours after discovery are critical for containing the incident and preserving evidence.
What Insurers Look For
Underwriters evaluate Cyber Insurance risk by examining your security controls, data practices, and history of incidents. The areas that affect your quote most significantly:
- Multi-Factor Authentication (MFA) is the single most important underwriting question. MFA on all remote access, email, and administrative systems qualifies you for better rates and broader terms. Companies without MFA may be declined by some carriers or face significant surcharges.
- Endpoint Detection and Response (EDR) tells underwriters you're running active threat detection on company devices, not just traditional antivirus software. EDR tools detect behavioral anomalies before they become full breaches.
- Encrypted Backups Stored Offline protect your ability to restore systems without paying ransom. Ransomware typically targets connected backups. Encrypted, air-gapped backups are what give a company real recovery options after an attack. Underwriters ask about backup frequency and restoration testing.
- Incident Response (IR) Plan signals security maturity. You don't need a lengthy document. You need named contacts, a communication protocol, and a clear decision tree for the first hours after discovery.
- Patch Cadence matters because delayed patching is one of the most common attack vectors. Underwriters ask about your patch cycle for critical systems and operating environments.
- Vendor Risk Management is an increasingly common underwriting question. If key vendors have access to your data or systems, your exposure extends beyond your own controls. Underwriters ask about your third-party vendor posture, particularly for cloud infrastructure and SaaS tools.
SOC 2 certification in progress is generally acceptable to note on your application and typically qualifies for a premium discount. Compliance tools like Vanta, Thoropass, and Secureframe integrate with the Vouch application process.
How Much Does Cyber Insurance Cost
Based on data from 2,034 Vouch clients, here are the median annual premiums by company revenue:
Median Annual Cyber Premium by Revenue
Annual premiums reflect median pricing for standalone Cyber Insurance Policies. Premiums may be rounded. Actual pricing varies based on industry, location, claims history, company stage, and selected coverage limits.
What Affects Your Premium
- Coverage Limits: Higher limits cost more. Most early-stage companies start at $1M and increase limits when revenue growth or contract requirements call for it.
- Data Sensitivity: Companies handling PHI, payment card data, or financial records pay more than companies with limited PII exposure.
- Industry: Healthcare, fintech, and companies serving regulated industries carry higher data sensitivity and regulatory exposure. Tech startups in SaaS and AI typically pay rates at the lower end of the market relative to their risk profile.
- Security Controls: MFA, EDR, encrypted backups, and SOC 2 compliance all reduce premium. Strong controls improve your risk profile and can meaningfully affect your quote.
- Prior Incidents: A history of claims increases your premium. Undisclosed prior incidents can void coverage. When in doubt, disclose with context rather than omit.
- Company Size and Revenue: Revenue is the primary underwriting variable. Cyber policies are priced off projected next-12-month revenue.
- Remote Work and Distributed Teams: More endpoints and more access vectors create more exposure, which is reflected in pricing.
- Vendor Dependencies: Companies with deep integrations to third-party systems face more supply chain exposure, which underwriters factor in.
Learn more about how much Cyber Insurance costs.
How Much Cyber Insurance Do You Need?
The right coverage amount depends on your data exposure, industry, technology dependence, and contract requirements. Use this table as a starting point:
Recommended Coverage Limits by PII Records, Industry, and Revenue
Limits expressed as First-Party / Third-Party
Use this as a starting point. Contract requirements, regulatory exposure, and your growth trajectory all affect the right number.
Learn more about how much Cyber Insurance you need.
What Drives Your Limits Decision
Industry and Threat Environment
Tech, financial services, and healthcare companies face the most targeted attacks. If you handle PHI, payment data, or proprietary financial models, set limits with the realistic cost of a breach in mind. According to IBM's 2025 Cost of Data Breach Report, breaches involving data across multiple environments (public clouds, private clouds, and on-premises systems) cost an average of $5.05M.
Data Exposure and Record Volume
Breach costs scale with the number of records affected. Notification, credit monitoring, legal defense, and regulatory penalties all multiply when you've exposed a million records versus ten thousand. The matrix above reflects this: as PII volume grows, recommended limits rise.
Technology Dependence
The more your revenue depends on digital systems being available, the more business interruption exposure you carry. A SaaS company operating under uptime SLAs has far more to lose from a 72-hour outage than a company where technology is a supporting function.
Contractual Requirements
Many enterprise customers now require $1M to $5M in Cyber coverage before a contract executes. These requirements are worth reviewing before you simply comply. Enterprise contracts often copy-paste insurance requirements from templates that may not reflect your actual risk profile.
Learn more about Cyber Insurance for startups.
Third-Party Responsibilities
If you process or store data on behalf of customers, you may face liability for incidents in their data even if the breach originated elsewhere in your supply chain.
Geographic Footprint and Legal Obligations
GDPR, HIPAA, CCPA, and other regulations impose mandatory notification requirements and potential fines. If you're serving customers in Europe, California, or regulated industries, your limits should reflect the regulatory exposure.
Scale and Growth Trajectory
Limits that are right today may be inadequate after your next fundraise, a significant product launch, or a new enterprise contract. Build a habit of reviewing Cyber Insurance limits at least annually and whenever a meaningful milestone changes your risk profile.
AI-Era Cyber Threats
Artificial intelligence has expanded the attack surface in ways that most standard Cyber Insurance explainers haven't addressed. These threats are active today. For a broader look at AI's impact on business liability, see Understanding AI Risks for High-Growth Companies.
AI-Powered Phishing and Social Engineering
Traditional phishing attacks are detectable by trained employees. AI-generated phishing is harder to catch, and AI-powered ransomware has emerged as a related threat category growing at a similar pace. Attackers now use large language models to craft highly personalized messages that replicate the writing style of specific executives, reference real internal projects, and arrive at psychologically optimal moments. The result is a new class of business email compromise attacks with significantly higher success rates than prior-generation phishing. Cyber Insurance covers funds transfer losses and legal defense costs that result from these attacks, subject to sublimits.
Deepfake Fraud
Synthetic audio and video of executives are being used to authorize fraudulent wire transfers and impersonate leadership on video calls with finance teams. Cases involving seven-figure losses have been documented at mid-market companies. A CFO receives what appears to be a video call with their CEO authorizing an urgent transfer. The call is fabricated. Cyber Insurance covers the resulting funds transfer losses under social engineering coverage, subject to sublimits. Review your social engineering sublimit. It's often set lower than the main policy limit.
Model and Data Poisoning
Companies that build or deploy AI models face a distinct threat: adversarial manipulation of training data or model weights. A poisoned model may behave normally under standard conditions while producing subtly incorrect outputs in targeted scenarios. This can damage customers, create regulatory exposure, or compromise the integrity of outputs your clients rely on for business decisions. Cyber Insurance can cover the forensic investigation and first-party costs of detecting and remediating a poisoned model.
Agentic System Exposures
AI agents that take autonomous actions on behalf of users create new liability questions at the boundary between Cyber and Tech E&O. When an AI agent causes a data exposure through unauthorized access, Cyber Insurance responds. When an AI agent causes a financial loss through an error in its decision-making, Tech E&O responds. When both happen in the same incident, which is increasingly common, having both coverages on the same policy form is what eliminates the gap.
What Your Cyber Policy Covers for AI Threats
Standard Cyber Insurance covers the financial consequences of AI-enabled attacks against your business: forensic investigation, breach notification, third-party claims, and business interruption.
What it doesn't automatically cover is liability specifically arising from errors in your own AI products. For AI product liability, Tech E&O with an AI endorsement is required. The AI endorsement explicitly extends E&O coverage to include errors, hallucinations, and harmful outputs from AI algorithms. Without it, standard E&O policies may exclude AI-generated errors entirely. For any company building or deploying AI products, reviewing your E&O coverage in light of this exclusion is important.
Common Misconceptions About Cyber Insurance
"We're Too Small to Be Targeted."
Attackers don't profile companies by revenue. They profile by vulnerability. Small companies are frequently targeted precisely because they have less security infrastructure than large enterprises while still holding customer data, payment credentials, and employee records. Ransomware operators in particular prefer smaller targets because recovery capacity is lower and the probability of payment is higher.
"Our General Liability or Property Insurance Will Cover Cyber Incidents."
General Liability Insurance covers physical injuries and property damage. Business Property Insurance covers physical assets. Neither is designed to cover forensic investigations, customer notifications, data recovery, or legal defense from a data breach. These are distinct exposures that require a separate Cyber policy.
"We Don't Have Sensitive Data, So We're Not at Risk."
This is the most common misconception in advisor conversations with tech companies. Even companies that don't store PII face ransomware, which encrypts your systems and demands payment regardless of what data you hold. Business interruption is a real exposure: a 72-hour system outage has financial consequences for any company dependent on uptime. And most companies touch customer data in transit through APIs, third-party integrations, or SaaS connections, even if they don't store it.
"Our Cloud Provider Handles Security for Us."
AWS, Google Cloud, and Azure secure the underlying infrastructure. They don't secure your applications, access controls, employee credentials, or how your team configures their services. Cloud misconfigurations and compromised credentials are among the leading causes of data exposures in cloud environments, and none of those incidents are covered or indemnified by your cloud provider.
"Strong Security Means We Don't Need Cyber Insurance."
Good security reduces the likelihood of an incident. It doesn't eliminate exposure when a vendor is breached, when an employee falls for a sophisticated AI-generated phishing attack, or when a zero-day vulnerability is exploited before your team can patch it. Security and insurance address different parts of the risk equation: one reduces probability, the other limits the financial impact when prevention fails.
"Cyber Insurance Just Pays Ransom, So It Encourages Attacks."
Cyber Insurance provides forensic support, legal counsel, and system recovery resources alongside any extortion response. Whether to pay a ransom is a decision made with legal and operational guidance from the insurer's response team. Most policies prioritize recovery over payment, and many ransomware resolutions don't involve ransom payment at all.
"Incidents Are Rare, So Coverage Isn't Necessary."
Cyber incidents are not rare. The 2025 Verizon Data Breach Investigations Report found that the median time to detect that leaked credentials are being actively exploited is approximately 94 days. Companies are being compromised and don't know it for months. According to the 2026 Verizon Data Breach Investigations Report, ransomware was present in 48% of all breaches in the prior year. FBI cybercrime losses have grown every year since reporting began, reaching nearly $21B in 2025.
Cyber Insurance vs. Other Types of Insurance
Cyber Insurance complements your existing coverage rather than replacing it. Here's how it compares to other lines you may already carry:
*Wire fraud and funds transfer losses can trigger both Cyber and Crime Insurance. The specific policy language determines which responds.
Cyber Insurance vs. General Liability Insurance
General Liability Insurance covers physical injuries, property damage, and advertising injury. It doesn’t cover breach notification, forensic investigation, regulatory fines, or legal defense from a data incident. These are distinct exposures requiring a Cyber policy.
Cyber Insurance vs. Business Property Insurance
Business Property Insurance covers physical damage to equipment. It doesn’t cover intangible losses: corrupted data, lost access to cloud systems, or the cost of restoring a compromised application. If your business interruption risk is primarily digital, Property Insurance alone isn't adequate.
Cyber Insurance vs. Crime Insurance
Crime Insurance covers employee theft, forgery, and certain wire fraud. Cyber Insurance covers external threats, breach costs, and regulatory exposure. For social engineering and business email compromise losses, both policies can be relevant. If your business has significant payment flows or cash management exposure, having both policies written to work together is recommended.
Cyber Insurance vs. E&O Insurance
This is the most important comparison for technology companies. Errors & Omissions (E&O) Insurance covers claims arising from errors in your software or services. Cyber Insurance covers claims arising from unauthorized access to data or systems. These are different triggers, but the line between them has blurred significantly as interconnected software makes it possible for a software error to cascade into a data breach, or for an AI agent action to trigger both simultaneously. Vouch advisors recommend purchasing these together on the same form to ensure there's no gap when an incident involves elements of both.
Learn more about Tech E&O vs. Cyber Insurance.
Cyber Insurance vs. D&O Insurance
Directors and Officers (D&O) Insurance covers your directors and officers against personal liability for business decisions. It doesn’t respond to cyber incidents unless the claim specifically alleges that a director or officer was negligent in overseeing cybersecurity practices. That's a real but distinct exposure, and it doesn't substitute for a standalone Cyber policy.
Cyber Insurance vs. Media Liability Insurance
Media Liability Insurance covers claims related to content you publish: copyright infringement, defamation, and privacy violations in media. Cyber Insurance addresses data security incidents. Some Cyber policies include media liability components. Review your policy form for specifics.
How Vouch Helps You Navigate Cyber Insurance
Cyber Insurance isn't one-size-fits-all. The right policy depends on what data you handle, how your product works, the contracts you sign, and how quickly your business is growing. Two companies with the same revenue can have very different coverage needs depending on their customers, security posture, and regulatory exposure.
Vouch helps companies evaluate those risks before they become expensive mistakes. Advisors review customer insurance requirements, explain how Cyber and Tech E&O interact, and identify where standard policy forms may leave gaps.
For companies building AI products, fintech platforms, and other technology businesses, those conversations increasingly focus on newer exposures like AI-generated outputs, agentic systems, and evolving contractual requirements. Where appropriate, Vouch can recommend policy forms and endorsements designed to address those risks.
Finding the Right Cyber Insurance for Your Business
Cyber threats have become a routine business risk, whether you're building software, processing payments, storing customer data, or deploying AI. The right Cyber Insurance policy gives your company access to breach response experts, legal counsel, and financial protection when an incident occurs, helping you recover without disrupting your business.
The right policy isn't determined by revenue alone. Your data exposure, industry, security practices, contractual obligations, and growth plans all influence the coverage and limits you need. As your business evolves, your Cyber Insurance should evolve with it.
If you're evaluating Cyber Insurance for the first time or reassessing an existing policy, Vouch can help you compare coverage options, review customer insurance requirements, benchmark appropriate limits, and identify potential gaps. Whether you're preparing for an enterprise contract, pursuing SOC 2, or launching a new product, reviewing your coverage before those milestones can help you avoid costly surprises later.
Frequently Asked Questions
What is Cyber Insurance?
Cyber Insurance is a policy that covers the financial and operational costs of a cyberattack or data breach: investigation, notification, legal defense, regulatory fines, and business interruption losses that General Liability and Property Insurance don't address.
Do small and midsize businesses really need Cyber Insurance?
Yes. Small businesses are disproportionately targeted by ransomware because their security infrastructure is easier to penetrate than large enterprises. Most enterprise customers now require Cyber Insurance before a contract executes. Median annual premium for a company under $1M in revenue is $2,082 based on Vouch client data.
What does Cyber Insurance cover?
Cyber Insurance covers breach response and notification, digital forensics and data recovery, business interruption from system outages, ransomware and extortion response, legal defense and settlements, regulatory fines, and fraud losses from phishing and business email compromise.
What types of cyber incidents are most common for small businesses?
Ransomware, phishing, and business email compromise are the most common claim types for small businesses. AI-generated phishing has increased significantly in frequency and sophistication. Cloud misconfigurations and compromised credentials are also leading causes of data exposures.
Does Cyber Insurance cover ransomware payments?
Yes, subject to policy terms. Cyber Insurance typically covers ransom negotiation support, the ransom payment itself (where legally permitted), and system recovery costs. Policies include access to ransomware response specialists who evaluate whether payment is advisable before any funds are transferred.
Does Cyber Insurance cover phishing and social engineering?
Yes, subject to sublimits. Social engineering coverage applies to funds transfer fraud, business email compromise, and related phishing losses. Review your policy's social engineering sublimit, which is often lower than the main policy limit.
Does General Liability or Property Insurance cover cyberattacks?
No. General Liability covers physical injuries and property damage. Property Insurance covers physical assets. Neither covers data breaches, ransomware, forensic costs, customer notifications, or regulatory investigations.
Does Tech E&O replace Cyber Insurance?
No. Tech E&O covers errors in your software or services. Cyber Insurance covers unauthorized access to data or systems. These are different triggers, and both are typically needed for technology companies. Buying them on the same form eliminates the coverage gap when an incident involves elements of both.
Is Cyber Insurance required by law?
No federal law requires it for most industries. Some regulated sectors (healthcare, financial services) have cybersecurity standards that effectively require it. Many enterprise clients contractually require it as a condition of doing business.
How much Cyber Insurance do I need?
Start with your revenue, PII volume, and industry. Companies under $1M in revenue with limited data exposure typically start at $1M in limits. Companies with significant PII or $5M+ in revenue should evaluate $3M to $5M in coverage. The limits table in this article provides a starting point by revenue, PII, and industry combination.
Does Cyber Insurance cover AI-related incidents?
Standard Cyber Insurance covers the financial consequences of AI-enabled attacks against your business, including deepfake fraud, AI-powered phishing, and agentic system intrusions. Liability from errors or hallucinations in your own AI products requires Tech E&O with an AI endorsement. Without the endorsement, AI-generated errors from your own product may be excluded from standard E&O coverage.
What do insurers look for when underwriting Cyber Insurance?
The primary controls are multi-factor authentication (MFA), endpoint detection and response (EDR), encrypted offline backups, and a documented incident response plan. SOC 2 certification or in-progress compliance typically qualifies for a premium discount. Companies without MFA on all remote access may face higher premiums or be declined by some carriers.
Does Cyber Insurance help with regulatory compliance?
Yes. Cyber Insurance covers the cost of regulatory investigations, mandatory notifications, and fines associated with privacy regulations like HIPAA, CCPA, and GDPR. It doesn't make you compliant, but it covers the financial consequences when a compliance gap leads to an incident or regulatory action.
Will Cyber Insurance cover me if a vendor causes the incident?
Cyber policies typically cover incidents that originate from a third-party breach if your customers' data was affected, depending on your policy's definitions. Review your contingent business interruption and dependent systems coverage language for specifics.
Does Cyber Insurance cover hardware replacement?
No. Hardware replacement falls under Business Property Insurance. Cyber Insurance covers data recovery, system restoration, and the operational costs of responding to an incident, not the physical cost of replacing equipment.
Vouch Specialty Insurance Services, LLC (CA License #6004944) is a licensed insurance producer in states where it conducts business. A complete list of state licenses is available at vouch.us/legal/licenses. Insurance products are underwritten by various insurance carriers, not by Vouch. This material is for informational purposes only and does not create a binding contract or alter policy terms. Coverage availability, terms, and conditions vary by state and are subject to underwriting review and approval.

.png)




