Quick Answer
Cyber insurance covers: data breach response, ransomware attacks, business interruption from cyber events, regulatory fines, and legal defense against privacy lawsuits. Average cost: $1,000-$5,000/year for small businesses. Leading carriers include Hartford (competitive pricing for small-mid businesses) and Chubb (premium coverage with $5M+ limits).
Coverage includes: Data breaches, ransomware payments, business interruption, BEC fraud, regulatory fines (HIPAA, GDPR, CCPA), customer notification costs, forensic investigation, credit monitoring, and legal defense.
Cyber insurance protects your business from the financial devastation of cyber attacks and data breaches. With the average breach costing $4.44 million globally — and $10.22 million in the U.S. (IBM Cost of a Data Breach Report 2025), this coverage has become essential for businesses of all sizes.
Get instant quotes from top carriers →
Table of Contents
- Coverage Overview: First-Party vs Third-Party
- First-Party Coverage (Your Direct Costs)
- Third-Party Coverage (Claims Against You)
- Real Claim Examples
- What's NOT Covered
- How Much Coverage You Need
- Top Carriers: Hartford vs Chubb
Coverage Overview: First-Party vs Third-Party
Cyber insurance has two main components:
| Coverage Type | What It Covers | Examples |
|---|---|---|
| First-Party | Your direct losses and costs | Breach response, ransomware, business interruption, data recovery |
| Third-Party | Claims made against you by others | Customer lawsuits, regulatory fines, payment card liability |
First-Party Coverage: Your Direct Costs
1. Data Breach Response
The most frequently used cyber coverage. When customer, employee, or patient data is compromised, your policy pays for:
- Forensic investigation: Hiring experts to determine what happened ($200-$500/hour)
- Notification costs: Legally required notices to affected individuals ($1-$3/person)
- Credit monitoring: 1-2 years of monitoring for affected individuals
- Crisis management/PR: Protecting your reputation after a breach
- Legal counsel: Breach coaches who guide your response
- Call center: Handling inquiries from affected individuals
Important: Breach response costs add up fast. Even a small breach affecting 5,000 records can cost $25,000-$75,000 just for notifications, credit monitoring, and legal counsel.
2. Ransomware Coverage
Ransomware is the fastest-growing cyber threat. Coverage includes:
| Component | What's Covered | Typical Sub-Limit |
|---|---|---|
| Ransom payment | Actual ransom payment (if authorized by carrier) | $100K-$1M+ |
| Ransom negotiation | Expert negotiators to reduce payment | Included |
| System restoration | Rebuilding systems, restoring backups | Full policy limit |
| Business interruption | Lost income during downtime | Full policy limit |
3. Business Email Compromise (BEC) / Social Engineering Fraud
BEC fraud is the #1 cyber loss for small businesses. Attackers impersonate executives or vendors to trick employees into sending money. Coverage includes:
- Funds transfer fraud: Money stolen through social engineering
- Invoice manipulation: Vendor payment redirected to attacker
- Typical sub-limit: $100K-$250K (often lower than main policy limit)
Get instant quotes from top carriers →
4. Business Interruption
Covers lost income and extra expenses when a cyber incident disrupts operations:
- Lost revenue during system downtime
- Extra expenses to maintain operations (temporary systems, overtime)
- Dependent business interruption (when a vendor's breach affects you)
- Waiting period: typically 8-12 hours before coverage kicks in
Third-Party Coverage: Claims Against You
1. Regulatory Fines & Penalties
Data privacy regulations carry severe penalties. Cyber insurance covers defense costs and fines (where legally insurable):
| Regulation | Potential Fines | Coverage |
|---|---|---|
| HIPAA | $100-$50,000 per record | Defense + fines |
| GDPR | Up to 4% of global revenue | Defense + fines |
| CCPA/CPRA | $2,500-$7,500 per violation | Defense + fines |
| PCI DSS | $5,000-$100,000/month | Card brand assessments |
| State breach laws | Varies by state | Defense + penalties |
2. Privacy Liability
Covers lawsuits from individuals whose data was compromised, including class action defense, settlements, and judgments.
3. Payment Card Liability
If payment card data is compromised, your policy covers PCI DSS fines, card reissuance costs, and assessments from Visa/Mastercard.
4. Media Liability
Some cyber policies include coverage for website content claims — defamation, copyright infringement, or invasion of privacy through your online presence.
Real Claim Examples
Example 1: Ransomware Attack on Accounting Firm
Incident: Hackers locked all client files and demanded $75,000 ransom.
Costs covered: $45,000 ransom payment (negotiated down from $75,000), $28,000 system restoration, $35,000 business interruption (14 days downtime), $12,000 forensics.
Total claim: $120,000 paid by cyber insurance.
Example 2: Healthcare Data Breach
Incident: Laptop stolen containing 12,000 patient records (unencrypted).
Costs covered: $36,000 notification costs ($3/patient), $24,000 credit monitoring (2 years), $45,000 legal counsel, $8,000 call center, $125,000 HIPAA penalty defense.
Total claim: $238,000 paid by cyber insurance.
Example 3: Business Email Compromise (BEC)
Incident: CFO received fake email from "CEO" requesting urgent wire transfer to new vendor.
Costs covered: $185,000 fraudulent wire transfer (recovered $35,000, insurance paid $150,000 balance).
Total claim: $150,000 paid by cyber insurance.
Example 4: E-commerce Site Hack
Incident: Attackers installed malware to steal payment card data from 8,500 customers.
Costs covered: $180,000 PCI DSS fines, $42,000 forensics, $51,000 notifications, $35,000 PR/crisis management, $220,000 legal defense (class action lawsuit).
Total claim: $528,000 paid by cyber insurance.
Get instant quotes from top carriers →
What Cyber Insurance Does NOT Cover
Common Exclusions:
- Prior known incidents: Breaches you knew about before buying the policy
- Intentional acts: Deliberate data theft by you or your employees
- Infrastructure failures: Power outages or ISP downtime (not cyber-caused)
- Bodily injury/property damage: Covered by general liability, not cyber
- Future improvements: Upgrading your security systems after an incident
- War/nation-state attacks: State-sponsored attacks may be excluded (check your policy)
- Unencrypted devices: Some policies exclude theft of unencrypted laptops/devices
- Software failure: Bugs or technical failures (not malicious attacks)
How Much Coverage Do You Need?
Coverage needs vary based on business size, industry, and data sensitivity:
| Business Size | Records Held | Recommended Limit | Annual Cost |
|---|---|---|---|
| Micro (under 10 employees) | Under 10,000 | $500K-$1M | $1,000-$2,000 |
| Small (10-50 employees) | 10K-100K | $1M-$2M | $2,000-$4,000 |
| Medium (50-250 employees) | 100K-1M | $2M-$5M | $4,000-$8,000 |
| Large (250+ employees) | 1M+ | $5M-$10M+ | $8,000-$25,000+ |
Industry tip: Healthcare, finance, and e-commerce businesses should aim for higher limits due to regulatory exposure and sensitive data handling. Consider $2M minimum for HIPAA-covered entities.
Top Carriers: Hartford vs Chubb
| Carrier | Best For | Limit Range | Key Advantage |
|---|---|---|---|
| Hartford | Small-mid size businesses | $500K-$5M | Competitive pricing, fast binding, excellent small business support |
| Chubb | Mid-large businesses, high-risk industries | $2M-$50M+ | Premium coverage with higher limits, comprehensive incident response |
Hartford: Ideal for businesses seeking competitive cyber insurance pricing without sacrificing quality. Strong reputation for small-mid business support with limits up to $5M. Fast underwriting and claims processing.
Chubb: Premium carrier offering cyber coverage with limits up to $50M+. Best for larger businesses, healthcare systems, financial institutions, and companies with significant regulatory exposure. Higher premiums but comprehensive coverage and world-class incident response teams.
Get instant quotes from top carriers →
Frequently Asked Questions
Does cyber insurance cover ransomware payments?
Yes, most cyber policies cover ransomware payments if authorized by the carrier. Typical sub-limits range from $100K to $1M+. The policy also covers ransom negotiation, system restoration, and business interruption from the attack.
Is cyber insurance required by law?
Not federally, but some states and industries require it. New York (DFS Cybersecurity Rule) requires cyber coverage for financial institutions. Many contracts and vendor agreements now require proof of cyber insurance.
What's the difference between cyber insurance and E&O?
E&O (Errors & Omissions) covers professional mistakes and negligence. Cyber insurance covers technology failures, data breaches, and cyber attacks. Tech companies typically need both — E&O for software bugs/mistakes, cyber for breaches/attacks.
Does cyber insurance cover social engineering fraud?
Yes, but typically with lower sub-limits ($100K-$250K). Business Email Compromise (BEC) coverage is included in most policies but may require additional endorsements for higher limits.
Related Guides
- How Much Does Cyber Insurance Cost? (2026 Pricing Guide)
- Compare Cyber Insurance Carriers: Top 7 for Small Business
- Cyber Insurance for Healthcare & HIPAA Compliance
- Complete Cyber Insurance Guide
Get instant quotes from top carriers →
Related Coverage Pages
- Cyber insurance — See pricing and coverage for business cyber policies
- Data breach insurance — First-party breach response, forensics, and notification coverage
- Cyber security insurance — Protection against ransomware, phishing, and cyber attacks
Ready to protect your business? Compare cyber insurance quotes in under 2 minutes →
