2026 market benchmarks

Cyber Insurance Cost Calculator

Cyber liability premiums are rated on a handful of variables: how many people you employ, what sector you trade in, how much revenue passes through the business, the limit you buy, and — increasingly decisive — whether your baseline security controls are actually in place. This tool models a plausible annual premium band from published market benchmarks.

Your business

The primary rating variable for small commercial cyber policies.

Sector loss history moves the premium more than most buyers expect.

Proxies for records held, transaction volume and business-interruption exposure.

Assumes a $1,000 deductible. Higher limits cost less per dollar of cover.

Security controls

Underwriters ask about these on every application. Answering "no" to the first three raises the price — or ends the conversation.

Estimated annual cyber insurance premium

$5,071$8,240

Roughly $423$687 per month · $1M limit · $1,000 deductible assumed

How each input moves the premium
Rating factorEffect
Headcount — 5–19 employeesEmployee count is the primary rating variable for small commercial cyber policies; a 20–49 person firm runs roughly 4x a sole trader.+150%
Industry — Tech / ITSector loss experience. Technology, healthcare and financial services all price above the all-industry average.+88%
Revenue — $1M – $5MRevenue proxies for records held, transaction volume and business-interruption exposure.+35%
Coverage limit — $1MHigher limits cost less per dollar of cover, so $5M is roughly 2.3x the $1M premium rather than 5x.baseline
Security controlsMFA, EDR and tested backups in place. Training and a documented incident-response plan earn further credits.baseline

Methodology: how this estimate is built

These are educational estimates derived from published market benchmarks, not quotes. Cyber insurance is individually underwritten: two businesses with identical headcount and revenue can be priced 50% apart because of claims history, the states or countries they operate in, the data they hold, the deductible they accept, and the appetite of the carrier reading the application that week. Nothing on this page is an offer of insurance or a binding indication.

The model starts from a baseline of roughly $999 per year for a small business buying a $1M limit with a $1,000 deductible — the figure repeatedly reported in 2025–2026 small-business cyber market surveys. Four multipliers are then applied:

  • Headcount. The single strongest rating variable at the small end of the market. A firm of 20–49 people pays in the order of four times what a sole trader pays for the same limit, because employee count drives both the phishing attack surface and the number of accounts an attacker can compromise.
  • Industry. Technology and IT services run roughly 88% above the all-industry average, healthcare around 40% above, and financial services around 37% above. Those sectors hold regulated or highly monetisable data and attract targeted attacks; retail and e-commerce sit modestly above average on card and fulfilment exposure.
  • Revenue. Used as a proxy for records held and for the business-interruption limit that would actually be claimed. It moves the premium less sharply than headcount at the micro end and more sharply above $5M.
  • Coverage limit. Limits are not priced linearly. Moving from $1M to $5M typically multiplies the premium by roughly 2.3, not 5, because the excess layers are far less likely to be exhausted.

Security controls are applied last and are the part most under your control. Missing multi-factor authentication, endpoint detection and response, or tested offline backups raises the estimate by 25–50% in this model — and in the real market frequently results in a declination rather than a loaded premium, particularly for ransomware cover. Conversely, documented staff security training and a tested incident-response plan trim 5–15%, and carriers increasingly ask for evidence rather than a checkbox.

The output is shown as a band (80% to 130% of the modelled midpoint) because a point estimate would imply a precision that does not exist in this market. Use it to sanity-check a broker's number, to budget before you go to market, or to work out whether closing a control gap is cheaper than insuring around it. Then get at least three quotes: spread between carriers on identical submissions remains wide.

What the premium is not the whole story

Two policy terms matter as much as price. The deductible (or retention) is what you pay before cover responds; moving from $1,000 to $5,000 or $10,000 can cut the premium materially and is often the cheapest lever available to a business with healthy cash reserves. The sublimits matter even more: ransomware, social-engineering fraud, and business-interruption waiting periods are commonly capped well below the headline limit. A $5M policy with a $250k ransomware sublimit is not a $5M ransomware policy.

If you are buying cyber insurance at the same time as pursuing an attestation, the two programmes overlap heavily — the controls an underwriter wants evidence of are largely the controls a SOC 2 auditor tests. Model that side of the budget with the SOC 2 cost calculator, and see the methodology page for how every figure on this site is sourced and maintained.