How Much Does Cyber Insurance Cost? (2024)

  • Cost
  • What Is It?
  • Why Buy It?
  • Purchasing
  • Trends
  • Common Claims

You have home insurance and car insurance. You have insurance for specific events like fires and floods.

Do you have insurance, though, to cover you in case of a cyberattack? What’s your plan for when malware disables your computer, or when hackers breach your network? And what’s it going to cost to protect yourself from these dangers?

In this guide, we’ll get into what you can expect to pay for cyber insurance, what it covers, and how you can keep your costs down.

How Much Does Cyber Insurance Cost?

Bottom line, what does cyber insurance cost? That depends on whether you’re looking to purchase a personal policy or a business policy.

Personal Insurance Policies

Typically, individuals buy cyber insurance as add-ons to their homeowners insurance policies. Of course, every policy is different and prices can vary considerably based on factors like geographic location, customer service, purchaser history, and coverage exemptions. Some insurers charge as little as $10 a month for $25,000 worth of coverage. In general, though, you can expect to pay $25 to $100 per month for cyber insurance, depending on how much coverage you want and which deductible you choose.1

In our own research on personal cyber insurance, we found that people weren’t aware of the real costs of annual premiums.

How much do you think the yearly premium would be to purchase a personal cyber insurance policy with $25,000 coverage?Overall
Less than $5019%
$50 – $9925%
$100 – $14940%
$150 – $19910%
More than $2007%

83 percent of respondents thought annual premiums of $25,000 coverage would cost under $150, while 93 percent thought they would cost less than $200. That explains why for 34 percent of non-users, the cost of personal cyber insurance is the biggest deterrent.

Business Insurance Policies

The costs of business policies vary widely as well. Annual costs can be anywhere from $500 to $5,000.2 Even more than personal cyber insurance, many factors can influence this price, such as these:

  • Type of industry
  • Type of business
  • Size of the company
  • Amount of sensitive information the company maintains
  • Annual revenue
  • Strength of security measures
  • Coverage level
  • Deductible
  • Claims history

Price also varies by state. For example, while the average annual annual premium of a business plan in Georgia was just over $1,450 in 2020, the average cost in New York was $1,616.

FYI: The average cost of business cyber insurance in 2020 was highest in the state of Arkansas, where an annual policy cost on average $1,646.50.

How to Keep Cyber Insurance Costs Down

Cyber insurance is a necessity these days, but you want to keep your costs down as much as possible. Here’s how.

Personal Policies

There aren’t many options for lowering personal cyber insurance premiums. However, some companies offer discounts if you:

  • Pay your premiums upfront
  • Limit your cyber risks by using antivirus software, VPNs, and strong, secure passwords
How Much Does Cyber Insurance Cost? (1)

Business Policies

Normally, insurers don’t advertise business discounts, but most companies will tailor a policy to your particular needs. If that’s the case, you might cut costs by using some best practices to limit your risk.

  • Employee training: Ensure that all of your employees understand the cyber risks your business faces and are well trained in minimizing those risks.
  • Penetration testing: Hire a tech company that specializes in penetration testing to check your system for vulnerabilities.
  • Strict password policies: Follow best practices for passwords, using 12 or more characters and a combination of numbers, letters, and special characters. Consider implementing two- or multi-factor authentication to your online accounts as well.
  • Personal data encryption: Encrypt all sensitive data. Make sure the encryption key is safe, and limit who has access to it.
  • Limited records: Limit the number of records you deal with. If you don’t need access to some records, store them securely so they can’t be compromised.3

What Is Cyber Insurance?

Cyber insurance is a contract between you and an insurer that says the insurer will pay you for any losses you incur related to your computers or network. Cyber insurance covers many types of cyber incidents, from computer damages to data breaches. In fact, the easiest way to explain cyber insurance is to talk about just what kinds of events it covers.

How Much Does Cyber Insurance Cost? (2)

Personal Policies

Different personal and family policies cover different kinds of cyber dangers, but most offer protection from these incidents:

  • Attacks on equipment: Even if you’ve installed the best antivirus software on your devices, malware can still find ways to infect them. Cyber insurance helps you pay for equipment repairs or replacements.
  • Cyberbullying losses: Cyberbullying statistics are troubling these days. In fact, 44 percent of U.S. parents report that their children have been harassed online at some point. Cyberbullying during the COVID-19 pandemic became even worse. In July of 2020, five months into the pandemic, we conducted our own study of 500 parents of children ages 10 to 18. Of the parents whose children had been bullied, 56 percent said the bullying had occurred within the last six months, as the pandemic had become widespread. Cyber insurance can cover legal costs, private tutoring, or even relocation expenses you incur as a result of cyberbullying.
  • Extortion: Cyber extortion has become one of the most popular forms of cyberattack. Ransomware on your laptop locks down documents and programs, demanding that you pay to regain access. Other attacks gather embarrassing information about you for blackmail purposes. Most cyber insurance covers both types of extortion.
  • Identity theft: Thieves want your personally identifiable information, or PII. Once they’ve committed identity theft, they’ll try to make money from it, either by using the information themselves or by selling it on the dark web. A good identity theft protection service can prevent this problem. Additionally, many identity theft protection services now offer some form of insurance to pay for losses or expenses you accrue because of identity theft. It can pay for fraud specialists, identity monitoring, and legal fees.4 However, identity theft protection services don’t cover things like cyberbullying or ransomware reimbursem*nt. To be completely covered, you need both services — identity theft protection and cyber insurance.

Business Policies

Cyber insurance is more complicated for businesses. In the simplest terms, business cyber insurance covers a company’s liability in cases of data breaches of sensitive customer information such as:

  • Social Security numbers
  • Credit card numbers
  • Account numbers
  • Driver’s license numbers
  • Health records

However, there are two distinct types of cyber insurance for businesses: cyber liability insurance and data breach insurance. Some insurers offer these two types of insurance in combination. Others, such as The Hartford, offer them as separate policies. But what’s the difference between the two?

  • Cyber liability insurance: Typically, cyber liability insurance works well for small businesses that store minimal customer data. If the company should lose any customer PII, this policy will pay for expenses like:
    • Hiring a PR firm
    • Notifying customers, patients, and/or employees of the breach
    • Providing credit monitoring and identity restoration to breach victims

    Businesses can also customize the policies to add services such as:

    • Income replacement
    • Prior act coverage, which protects a company from breaches that may have occurred before the policy started but haven’t yet been detected
    • Extortion payments
  • Cyber breach insurance: Larger companies may need cyber breach insurance, which provides a broader range of coverage in the case of data breaches. For instance, in addition to the costs liability insurance covers, cyber breach insurance pays for:
    • Customer lawsuits relating to breaches
    • State and federal fines
    • Legal insurance to meet state and federal regulations

THE MORE YOU KNOW: Breach insurance is a special type of cyber insurance available to businesses. It protects businesses in case hackers manage to access their customer records.

Why Buy Cyber Insurance?

There are two basic reasons why you need to get a cyber insurance policy. First, cybercrime has become a common problem, and it’s becoming worse every year. Second, cybercrime is expensive, and a policy costs less than what you’re likely to pay if you become a victim.

Personal Policies

Just how widespread is cybercrime these days? In 2020, the FBI’s Internet Crime Complaint Center received a record of 791,790 complaints. That’s a 70 percent increase over 2019. The unfortunate truth is that if you use the internet, you’re vulnerable to cybercrime.

But cybercrime isn’t just widespread; it’s also costly. In total, those 791,790 complaints racked up $4.2 billion in losses to individuals and families. That works out to over $5,300 per attack.5 Cyber insurance ensures you won’t have to pay for those damages yourself.

Business Policies

Every business can benefit from a cyber insurance policy. As with personal policies, the benefits are pretty straightforward. To start with, 58 percent of companies worldwide claim to have experienced a security breach at some point.6 That means the odds are high that your company will suffer a breach eventually as well.

What kind of financial burden will you face if you suffer such a breach? The average cost of a data breach in the U.S. in 2020 was $8.64 million.7 In short, you need cyber insurance because the risk that your company will suffer an attack is high, and the costs are high as well. Having cyber insurance means you won’t be paying those costs by yourself.

Purchasing Cyber Insurance

Not all cyber insurance is created equal. When it comes time to buy a policy, you need to ask the right questions of your agency, such as what kinds of events its policies cover.

Personal Policies

Before you invest in insurance, you should consider these questions carefully:

  • How much coverage do you need? The biggest concern when you’re deciding how much coverage you need is what kind of risks you face. At most, what do you and your family stand to lose from a cyberattack? Since the average cost of a personal cyberattack is $5,300, $15,000 worth of coverage is plenty for most homeowners. Of course, that maximum can vary by individual situation. If your financial risk is high, you may need to consider a specialty policy from a company that handles high-value insurance, such as Chubb, AIG, or PURE.
  • What events does the policy cover? Different companies and policies cover different cyber events. At a minimum, your policy should cover:
    • Ransomware attacks
    • Viruses and malware
    • Identity theft
    • Cyberbullying
  • What will the policy pay for? Just because a policy covers a specific event, such as identity theft, doesn’t mean it will pay for all the expenses you might incur. Pay close attention to what your policy pays for, and make sure the list includes:
    • Extortion payments
    • Equipment replacement
    • Software replacement
    • Lost wages
    • Identity theft restoration services
    • Legal fees
  • How is the company’s customer service? Too often, customers think only about price and ignore customer service. The cheapest policy in the world, though, won’t be much use if you can’t get your insurance agent on the phone when you’ve suffered a cyberattack. You can start by visiting the Better Business Bureau’s website to read about the company’s reputation. Credit rating agencies such as Moody’s, S&P Global Ratings, and J.D. Power rate insurance companies as well. Find out how each company communicates with customers. Can you contact it 24 hours a day? Does it offer live online help? In general, make sure you can get the help you need when and how you want it.
  • What will it cost? Finally, you should compare the price of plans across companies. As a general guideline, you should be able to purchase $25,000 worth of coverage for $25 to $50 per month, depending on the size of your deductible.

Business Policies

With business cyber insurance, you’ll need to zoom in on the specific types of coverage the policy offers.

  • What are your specific risks? Calculating risk for a business policy is different from calculating risk for a personal policy. You must consider such factors as how many customer records you keep, what kind of data those records contain, how many employees have access to those records, and what security mechanisms you have in place. Often, the insurer helps you to determine these numbers, but you might hire an outside company to make sure you’re getting precisely what you need.
  • Can you get retroactive coverage? Data breaches often go undetected for some time. That means a data breach may happen before your policy starts, but that breach might not cause damage until after the coverage goes into effect. Will your insurance pay for that breach, or not? Look for companies that will pay for it or at least allow you to purchase add-on coverage that will pay for it.
  • Do you need regulatory coverage? Data breaches, in particular, can result in fines for your business. Ask your insurer whether your coverage pays regulatory fines.
  • Does your policy cover equipment? Cyber breach policies cover data breaches, but they often don’t cover damaged equipment. Coverage for damaged equipment may require a separate policy.8

Trends in Cyber Insurance

Cyber insurance has been around for less than 30 years, so it’s an industry that’s still evolving, just as cyber risks evolve over time. Here are a few trends in cyber insurance that predict where the industry is heading:

  • Rising prices: In a recent survey of insurance brokers, more than half of clients reported that their prices rose by 10 to 30 percent in 2020.
  • Lower coverage limits in some business sectors: The growing number of cyberattacks has led insurers to set coverage limits for some business sectors that face greater cyber risks. These sectors include education, which deals with the data of minors, and healthcare, an industry that collects protected health information, or PHI.
  • Cyber-specific policies: More insurers are offering both personal and business cyber insurance as stand-alone policies rather than as part of more comprehensive insurance policies.
  • Increasing popularity of cyber insurance: Insurers report a higher percentage of their clients are now investing in cyber insurance. Where 26 percent of people requested cyber insurance in 2016, 47 percent requested it in 2020.9

The Most Common Cyber Insurance Claims

Cyber insurance covers various types of claims, but a few show up more often than others.

  • Data breaches: A data breach is when a hacker gains access to customers’ PII. Data breaches are the most common business cyber insurance claim, and they have the largest total losses. According to a report by the insurer Willis Towers Watson, for instance, 73 percent of its clients’ claims between 2013 and 2019 involved breach/incident response and crisis management.
  • Cloud hacks: Hackers use phishing attacks to gain access to individual cloud accounts. Once they’re in, they use the cloud infrastructure to jump from one customer account to another.
  • E-commerce shutdowns: Hackers aren’t just about money. Hacktivists are more interested in shutting down your business. If they can hack into a website, they can shut you down completely.
  • Account takeovers: The largest number of personal cyber insurance claims each year involve account takeovers. In these cyberattacks, thieves try to take over your bank accounts or credit card accounts and make fraudulent transactions. Find out more in our guide to protecting yourself from account takeovers.
  • Phishing: The number of phishing scams rises each year, and the attacks are becoming more sophisticated. According to FBI statistics, for instance, phishing attacks more than doubled between 2019 and 2020.
  • Malware: To prevent malware attacks, buy the best antivirus for your business or the best antivirus software for personal use. Antivirus software should protect you from most of these cyberthreats:
    • Ransomware
    • Spyware
    • Trojan viruses
    • Computer worms
    • Adware

    There were 5.6 billion malware attacks in 2020, and no antivirus can stop all hacks. When those threats get through, cyber insurance pays to repair and replace your equipment and software. It will often pay ransoms as well.

How Much Does Cyber Insurance Cost? (3)

Recap

Cyber insurance is a growing industry, and with good reason. There are more cyberthreats out there than ever before. For instance, the FBI reported a 300 percent rise in cybercrime during 2020.

We recommend that you buy cyber insurance whether you’re looking to protect your home or your business. However, consider the costs and the ways you can save money on your protection before you buy a policy.

FAQs

Cyber insurance is a complex topic, and we know you have lots of questions. We’ve taken the time to answer the ones we hear most frequently.

  • What is the average cost of cyber insurance?

    The average annual premium for personal cyber insurance is between $300 and $1,200, depending on the level of coverage and the specific deductible you choose. The average cost of cyber insurance for a business is between $500 and $5,000 per year.

  • Is cyber insurance worth the cost?

    Cyber insurance is worth the cost. The number of cyberattacks in the U.S. rose by 70 percent in 2020. Meanwhile, the average cost of a cyberattack on a personal network was $5,300. With policies as low as $300 a year for $25,000 worth of coverage, it would be over 17 years before a customer paid more in insurance than they would likely save in the event of an attack.

    The cyber risks for businesses are even greater. In fact, 58 percent of businesses worldwide report they’ve been attacked at some point, and the average cost of a single data breach in the U.S. is $8.64 million. On average, a cyber insurance policy with a coverage limit of $1 million costs $1,500 in annual premiums. That price is within reach for even small businesses, and the risks are simply too great not to have cyber insurance.

  • Who offers cyber insurance?

    Many companies offer cyber insurance, including:

    • Acuity
    • Agency Height
    • AIG
    • Alleghany Corporation Group
    • Allianz
    • American International Group
    • AmTrust Financial
    • Arbella
    • Argo
    • Aspen Insurance Group
    • AXA
    • AXIS Capital
    • BCS
    • Beazley
    • Berkshire
    • BlackFire Cyber Insurance
    • Burns & Wilcox
    • Central Insurance
    • Chubb
    • CNA
    • Corvus
    • CoverageSmith
    • CoverWallet
    • Cowbell Cyber
    • CyberPolicy
    • Embroker
    • Fairfax
    • Gannon Associates
    • Hackinsure
    • Hanover Insurance
    • Hathaway
    • Hiscox
    • HSB
    • Liberty Mutual
    • Markel Corporation Group
    • Nationwide
    • Plymouth Rock
    • PURE
    • Resilience
    • Safety
    • Selective
    • Sompo
    • State Farm
    • The Cincinnati Insurance Companies
    • The Hartford
    • The Doctors Company
    • Tokio Marine
    • Travelers
    • Berkley Insurance Group
    • Catlin
    • Reinsurance America Group
    • Zurich
  • Who needs cyber insurance?

    Anyone who uses the internet needs cyber insurance. If you access the internet, you are vulnerable to a variety of cyberattacks, from simple viruses to identity theft to ransom demands. Any business that collects and stores sensitive customer information is especially vulnerable to attacks.

How Much Does Cyber Insurance Cost? (2024)

FAQs

How Much Does Cyber Insurance Cost? ›

The cost of cyber insurance depends on a number of factors, some that you can control and some that you can't. Many businesses can find a policy with a yearly premium between $500 and $1,000. Not a bad deal compared to $1.7M – the average cost of a cyberattack.

How much does cyber insurance cost? ›

How much does cyber insurance typically cost? For small businesses, annual cyber insurance premiums can range from $1,000 to $7,500. This range is dependent on several factors, which we discuss below. A recent survey found that the majority of cyber insurance underwriters expect rates to increase slightly in 2024.

How much does cyber security protection cost? ›

How Much Do Managed Cybersecurity Services Cost? Minimum costs for outsourced cybersecurity services start around $2,000 - $3,500 per month and go up from there. On a per-user basis, that breaks down to a range between $195 and $350 per user, including support and maintenance.

How do you determine how much cyber insurance you need? ›

Consider the worst-case scenario: a major cyber attack. Estimate insurance costs by the direct costs (like system repairs and data recovery) and indirect costs (like business interruption, legal fees, and reputational damage). This estimation is crucial for determining the amount of coverage you need.

Is cyber insurance enough? ›

Businesses should consider cyber insurance a risk management tool, but it's not a comprehensive solution to all cybersecurity challenges. It also may be beyond some small businesses' financial means, and the cost is increasing.

Does cyber insurance pay out? ›

Cyber insurance covers the liability actions that might be brought against you, arising out of a cyber event (third party loss), such as investigation and defence costs, civil damages, compensation payments to affected parties.

How much does cybersecurity services cost? ›

What is the Real Cost of Hiring a Cybersecurity Company? The average cost of hiring a cybersecurity service provider on Clutch is between $100-$149 an hour.

Is cybersecurity insurance worth IT? ›

Today, the average cost of cyber claims is substantial, far exceeding the average cost of cyber premiums. And considering the proactive and reactive services on offer, it's clear that cyber insurance is more than worth the money.

How much budget for cybersecurity? ›

That would represent a major increase over the $11.8 billion pegged for civilian agency cybersecurity spending in fiscal 2024 and the $11.3 billion spent on the same activities in fiscal 2023, according to the White House's analysis of IT and cybersecurity spending.

What isn t covered by cyber insurance? ›

Potential future lost profits

But they won't cover profits lost after an incident as a direct or indirect result. Devaluation of affected data, a company's diminished market share, profits lost due to reputation damage—most policies exclude such potential losses.

Can I buy cyber insurance? ›

You can buy cyber risk insurance directly from an insurer or from a broker. You can find brokers specialising in cyber insurance through the British Insurance Brokers' Association (BIBA).

Can individuals buy cyber insurance? ›

Personal cyber insurance covers individuals for their personal online security risks and financial loss due to cybercrime. Cybercrimes and risks include: Online account takeover or compromise. Expenses incurred or financial loss due to identity theft or social engineering scams.

What is the average cost of cyber security insurance? ›

What is the average cost of cyber insurance? The average annual premium for personal cyber insurance is between $300 and $1,200, depending on the level of coverage and the specific deductible you choose. The average cost of cyber insurance for a business is between $500 and $5,000 per year.

Why is cyber insurance so expensive? ›

There's a simple and a complicated answer to this question. You could probably figure out the simple answer on your own: cyber insurance costs more because of the huge rise in data breaches and hacks in the post-COVID world.

What is the average payout for cyber insurance? ›

According to a report by Beazley, the average cost for a cyber insurance claim stands at $600,000. The financial services sector experiences the highest average cost per claim, which is $1.2 million.

Is cyber protection insurance worth it? ›

Today, the average cost of cyber claims is substantial, far exceeding the average cost of cyber premiums. And considering the proactive and reactive services on offer, it's clear that cyber insurance is more than worth the money.

What does cyber insurance typically cover? ›

A cyber insurance policy helps an organization pay for any financial losses they may incur in the event of a cyberattack or data breach. It also helps them cover any costs related to the remediation process, such as paying for the investigation, crisis communication, legal services, and refunds to customers.

References

Top Articles
Latest Posts
Article information

Author: Trent Wehner

Last Updated:

Views: 5668

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Trent Wehner

Birthday: 1993-03-14

Address: 872 Kevin Squares, New Codyville, AK 01785-0416

Phone: +18698800304764

Job: Senior Farming Developer

Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.