Every year, the number and sophistication of cyberattacks increase. While large data breaches get the headlines, small and midsize businesses (SMBs) can face risks too. Cybersecurity insurance helps mitigate the risks by covering the costs of breached computer systems, ransomware, and other cyber events.
You may believe your business is too small to experience cyberattacks. In fact, the opposite is true. According to Verizon’s 2025 Data Breach Investigations Report, 90% of victims have fewer than 1,000 employees. SMBs also typically have weaker defenses and more to lose. Roughly a third of SMBs suffer cyberattacks each year, and one out of five say an attack costing as little as $10,000 would put them out of business, according to VikingCloud’s 2025 SMB Threat Landscape Report.
Cybersecurity insurance won’t prevent cyberattacks or data breaches, but it can help you recover from them more quickly. This article will describe the different types of cyber insurance coverage available to small- and medium-sized organizations, and the cyber risks these policies do and don’t cover. It also outlines what cyber insurance premiums typically cost and the steps small business owners need to take to qualify for coverage.
What is cybersecurity insurance?
As the name implies, cybersecurity insurance—also known as cyber liability insurance, cyber risk insurance, or simply cyber insurance—is a specific type of business insurance designed to mitigate the financial damage caused by cyberattacks and data breaches. Most policies will cover financial losses incurred by your business (first-party liability) and damages suffered by customers, suppliers, or business partners (third-party liability).
Cyber insurance differs from other types of business insurance in one important aspect. While traditional insurance policies deal almost exclusively with losses incurred in the physical world, a cyber liability insurance policy covers digital losses.
For example, if a thief steals a laptop containing all of your customers’ private data, a business insurance policy might pay to replace the laptop. It likely won’t reimburse you for the value of that data, the cost of notifying your customers of the breach, or revenue lost from any downtime your business suffers. It won’t reimburse you for any fines paid for violating data privacy regulations or any legal fees you incur if you get sued.
Most insurers require their customers to implement specific security controls before they qualify for coverage and will deny claims if they determine your business has been negligent. By forcing you to adopt good cybersecurity hygiene, cyber insurance can help reduce your cyber risk and prevent successful attacks. Good cybersecurity hygiene requirements might include:
-
Routinely installing the most current software patches
-
Implementing sophisticated access management systems
-
Encrypting sensitive customer and employee data
-
Creating an incident response plan
Why do ecommerce businesses need cyber insurance?
Operating an ecommerce store opens your business to a vast pool of potential customers, but it also exposes you to attacks from every corner of the globe. Without security and financial safeguards in place, any business that relies on websites, cloud apps, or digital payments is vulnerable to an attack.
Companies whose customer, employee, or financial data has been breached may also be forced to pay penalties for compliance violations. No SMB is too small to be attacked or to take appropriate measures to prevent cyberattacks from putting them out of business.
What does a cyber insurance policy cover?
Most cyber insurance policies offer coverage for losses resulting from the following six categories:
-
Data breach response and notification. This may include hiring investigators to determine the cause and severity of the breach, notifying every party whose data may have been leaked, and setting up call centers and/or credit monitoring services for affected customers.
-
Business interruption and revenue loss. If a cyber incident disables your ability to generate income, the policy may cover some or all of those losses, as well as any extra expenses incurred in getting your business back up and running.
-
Cybercrime and fraud. Some policies will cover money lost to business email compromise (BEC) exploits, where employees are tricked into wiring funds to attackers posing as company executives, as well as other forms of social engineering attacks.
-
Legal defense and regulatory response. Data breaches can result in lawsuits or regulatory violations, especially in highly regulated industries. Cyber insurance can help mitigate losses from attorneys’ fees, fines, judgments, and other legal expenses.
-
Crisis management services. When a business loses customer data, its reputation takes a hit. Cyber coverage may include the cost of hiring a public relations firm to manage how information about the breach is communicated and to help restore brand identity.
-
Cyber extortion. If ransomware attacks take your data hostage, many insurers will cover the ransom payments when legally permissible. They may even negotiate directly with cyber criminals on your behalf, as well as reimburse you for system restoration and data recovery costs.
What cyber insurance does not cover
There are several types of cyber incidents that most cyber insurance policies do not cover, especially when the losses are caused by employee negligence, poor security processes, preexisting vulnerabilities, or insider attacks. Here are some other common exclusions and limitations to cyber insurance coverage:
-
State-sponsored activities. Attacks by adversaries acting on behalf of nation-states may be considered acts of war, and thus not covered by some cyber policies.
-
Breaches of trusted third parties. Coverage for damages suffered from attacks on suppliers, service providers, or other third-party vendors varies significantly by policy. It may be excluded, limited, or available for an additional cost.
-
Attacks on critical infrastructure. Losses from catastrophic breakdowns in power, water, or telecommunications systems caused by a cyberattack are generally excluded from business policies.
-
Theft of intellectual property. If attackers break into your systems and steal your intellectual property, that loss is usually not covered by your cyber policy, but can be covered by IP insurance.
-
Ineffective security processes. Failure to implement commonly accepted security safeguards, such as encrypting personally identifiable information (PII) or keeping software up to date, can impact your coverage. For example, if an attacker exploited a critical software vulnerability you were aware of and did nothing to fix, the insurer may deny your claim.
How does cyber insurance work?
There are two fundamental types of cyber liability insurance coverage—first party and third party—and many policies bundle them together. Here’s how they both work.
First-party coverage focuses on the losses your business incurs directly. If you suffer a data breach, any losses associated with notification, business interruption, fraud, and so on are handled by your cyber insurance carrier. They pay for remediation services on your behalf or reimburse you later for expenses you incur.
Third-party cyber coverage handles claims that other parties make against you as a result of your cyber incident. For example, say attackers breach your system and steal data for all of your customers. Those customers file a class action suit against you, claiming you failed to adequately protect their information. Your third-party insurance carrier will defend your interests and, if necessary, pay any settlements or judgments on your behalf.
Third-party coverage may also include protection against privacy lawsuits, regulatory fines, claims of intellectual property infringement or defamation. It may also include liability for network security failures that impact other businesses.
If you buy a cyber insurance policy that includes both first- and third-party liability, sublimits may apply to certain categories of coverage. For example, a policy that offers $1 million in total coverage may cap ransomware payments or third-party privacy liability at $250,000.
Factors that affect how cyber policies are underwritten
- The size of your company
- The industry you’re in
- The type and amount of data you collect
- The cyber incidents you’ve experienced
- The security controls you have in place
Depending on the size and sophistication of your business, applying for a cybersecurity insurance policy may be as simple as filling out a brief questionnaire or as complex as a full security assessment involving third-party auditors and onsite reviews. In either scenario, insurance providers look at a similar set of factors:
The size of your company
The more revenue you generate, the more potential risk you represent. Company size exerts the greatest influence on the cost of the insurance.
The industry you’re in
Certain industries, such as health care, financial services, and retail, are considered higher risks due to the sensitive nature of data they handle and their attractiveness as targets.
The type and amount of data you collect
If your business collects data that is highly regulated—such as payment card data, Social Security numbers, financial account information, or protected health information—you may be held to higher standards for customer notification and be more exposed to claims from consumers. The amount of data you collect also matters. A business with 500,000 customer records represents a greater risk than one with 5,000.
The cyber incidents you’ve experienced
If your business already has a history of data breaches or ransomware attacks, the severity of the incidents and how your business responded to them will impact the cost and availability of coverage.
The security controls you have in place
Companies with robust cybersecurity and risk management practices are more likely to qualify for more expansive coverage and/or lower premiums. Security controls have become an increasingly important factor in determining your ability to obtain cyber liability coverage.
Security controls insurers look for before offering coverage
- Multifactor authentication
- Data encryption
- Endpoint protection
- Patch management
- Employee training
- Regulatory compliance
Maintaining good security hygiene has become a de facto requirement for obtaining cyber insurance. When evaluating your business for risk, insurers look for the following:
Multifactor authentication
The first rule of cybersecurity is to make it harder for attackers to get in. That’s why insurers increasingly require businesses to take additional steps to authenticate employees with access to sensitive data.
Shopify’s two-step authentication, for example, adds an extra security layer to prevent unauthorized access. Even if attackers obtain or guess an employee’s password, they will still be unable to access your store’s admin accounts. To use Shopify Payments to accept payments requires you to activate two-step authentication on your Shopify account.
Data encryption
Encrypting customers’ personal data means that even if you suffer a breach, attackers can’t easily access the data or do anything with it.
Shopify encrypts personal data both in transit and at rest, using industry-standard encryption methodologies.
Endpoint protection
Using up-to-date endpoint detection and response (EDR) software on your business’s desktops, laptops, and mobile devices is crucial. EDR can monitor every system for suspicious activity and contain cyber threats before they spread.
Patch management
Outdated software and missed security updates are two of the leading causes of data breaches. Insurers will look to see whether you’ve implemented a formal process for applying security patches.
Employee training
Whether it’s clicking links inside phishing emails or accidentally misconfiguring security settings, human error is another leading cause of cyber incidents. Insurers may evaluate whether you provide adequate training to avoid the most common mistakes.
Regulatory compliance
Businesses in regulated industries such as retail (which handle vast amounts of consumer data and payment information) need to take security precautions to ensure data compliance.
All Shopify stores are compliant with the Payment Card Industry Data Security Standard (PCI DSS), which means they use industry-standard protections for cardholder data. Shopify also undergoes regular Security Organization Control (SOC) compliance audits to ensure that its security controls adequately protect merchant and customer data.
If you also store customer or merchant data in a spreadsheet or third-party application, it may not be PCI DSS compliant. That could affect your coverage.
How much does cybersecurity insurance coverage cost?
Figuring out how much you should pay for cyber insurance is an inexact science. Premiums vary depending on the factors listed above, as well as the amount of coverage you need and where your business is located.
For example, a policy offering $1 million in coverage with a $10,000 deductible might cost around $2,000 annually. A midsize company in a higher-risk category, such as health care or finance, might pay $5,000 to $10,000 annually for $3 million to $5 million in liability coverage.
Consult with experts to find the right balance of cost and coverage for your business.
Cybersecurity insurance FAQ
What does cybersecurity insurance cover?
Cybersecurity insurance protects your small business from the financial impacts of a data breach or a cyberattack. While it can’t prevent such attacks, it can greatly reduce the damage from a successful breach and help get your business back up and running more quickly, while also indirectly fortifying your cyber defenses against future attacks.
Is cybersecurity insurance worth it?
According to Coalition’s 2025 Cyber Claims Report, average insurance claims for businesses with less than $25 million in revenue were just under $80,000. The average claim for companies in the $25 million to $100 million range was roughly $150,000. The odds of an SMB being attacked are roughly one in three.
How much does cybersecurity insurance cost?
A lot of different factors go into how cyber insurance policies are priced, but the average for a small business with $1 million of coverage is around $2,000 a year. Larger companies that need broader coverage likely will pay more.




