Home / Cyber Liability Insurance Cost Calculator

Cyber Liability Insurance Cost Calculator

Estimate your annual cyber liability premium by industry, annual revenue, records stored, and coverage limit.

Details

Results

Estimated annual premium--
Monthly--
Per $1k revenue--

Estimate only. Actual quotes vary by carrier, security controls, and claims history. See SBA.gov for general guidance.

One breach can cost more than a year of revenue

The average cost of a small business data breach in the U.S. now runs well into six figures once you factor in forensic investigation, breach notification letters, regulatory fines, and legal fees. Healthcare, financial services, and legal firms pay more because their records carry higher sensitivity and stricter compliance obligations. A stolen patient record costs significantly more per record to resolve than a stolen retail loyalty account.

Cyber liability insurance covers first-party costs like ransomware negotiation and system recovery, as well as third-party costs like customer lawsuits and regulatory penalties. Coverage limits of $1M are standard for most small and mid-size firms; companies handling sensitive data for large clients often need $2M or more. Businesses that provide professional services should also consider professional liability (E&O) insurance, which covers a separate but related risk: claims that your service or advice caused a client financial harm.

Security controls cut real premiums significantly. Carriers typically discount 10 to 20 percent for businesses with multi-factor authentication and endpoint detection in place. This calculator does not model those discounts, so actual quotes may be lower.

The rates behind this estimate

The calculator layers three multipliers on top of a flat per-revenue base rate: industry, records stored, and coverage limit. These are the 2026 figures coded into the tool above.

InputRate or factor
Base rate$0.90 per $1,000 revenue (floor $500)
General business / retail factor1.0
Healthcare / medical factor1.5
Financial services / fintech factor1.3
Legal services factor1.2
Education / ed-tech factor1.4
IT / software / SaaS factor1.1
Manufacturing / logistics factor0.9
Non-profit / government factor1.2
Under 1,000 records factor1.0
1,000 to 10,000 records factor1.15
10,000 to 100,000 records factor1.35
Over 100,000 records factor1.60
$500K limit factor1.0
$1M limit factor1.25
$2M limit factor1.55
$5M limit factor1.90
Good to know

FAQ

Do I need cyber coverage if I don't store credit card numbers?

Likely yes. Email addresses, employee records, and login credentials are all data a breach can expose, and most state breach-notification laws cover more than payment data.

Does using cloud hosting like AWS or Google Workspace reduce my exposure?

It can reduce some technical risk but does not eliminate liability, since you are still responsible for how that data is accessed, shared, and protected under most vendor contracts.

What is the difference between first-party and third-party cyber costs?

First-party costs are your own recovery expenses, like forensics, notification, and ransom. Third-party costs are claims and lawsuits from people whose data was exposed.

Why does the record count matter more than company size?

Because breach costs scale with how many people you have to notify and monitor, a small business holding 50,000 records can face costs closer to a much larger company's than to a similarly sized peer with fewer records.

Related reading