The Policy You Bought Probably Won't Pay What You Think
A landscaping company gets hit with ransomware on a Friday night. The owner opens the cyber insurance policy she bought two years ago, relieved she has coverage. Monday morning, the insurer's forensics team arrives, and by Wednesday she learns the payout will cover barely a third of her losses — the policy's ransomware sublimit was a fraction of the headline coverage number, and the wire fraud that followed the breach fell under a separate, even smaller cap.
This scenario isn't rare. Cybercriminals target small businesses roughly three times more often than large enterprises, and 43% of all cyberattacks now hit small businesses — yet only 14% of those businesses consider themselves adequately prepared. Cyber insurance is supposed to close that gap. For a lot of small business owners, it doesn't, because they never read past the coverage limit on page one.
Why Small Businesses Are Buying — and Still Getting Burned
As of 2026, only about 38% of small businesses carry cyber insurance at all, compared to 78% of mid-market companies and 92% of large enterprises. That's a meaningful protection gap on its own. But the more expensive problem is what happens to the businesses that do buy a policy: an estimated 44% of insured small businesses are underinsured, meaning their coverage limit sits at less than half of their realistic worst-case breach cost.
Part of the confusion is that most owners think their general liability or business owner's policy (BOP) already covers this. It typically doesn't. Standard BOPs either exclude cyber incidents outright or bolt on a thin cyber endorsement with a coverage ceiling far below what an actual breach costs — and the average small business cyber claim now exceeds the limits of most of those embedded BOP add-ons. If your only cyber protection is a rider on a general policy, assume it's a placeholder, not a safety net.
What a Real Cyber Policy Actually Covers
A standalone cyber liability policy is built around two buckets of protection, and understanding the split matters because gaps tend to hide at the seam between them.
First-party coverage pays for costs your business incurs directly after an incident:
- Data recovery and system restoration
- Customer/employee breach notification expenses
- Forensic investigation to determine what happened and what was exposed
- Business interruption losses while systems are down
- Crisis management and PR costs
- Credit monitoring for affected individuals
- Ransom payments (when covered — more on that below)
Third-party coverage handles claims made against you by others:
- Legal defense costs
- Settlements from customers or partners harmed by the breach
- Regulatory fines and penalties (where insurable by law)
- Network security liability if your systems were used to attack someone else
On paper, that looks comprehensive. In practice, three structural features of these policies routinely blindside small business owners.
The Three Gaps That Catch Owners Off Guard
1. Ransomware coverage isn't automatic — even when you have a policy
Ransomware sits at the center of a widely misunderstood gap: 84% of surveyed businesses reported having cyber insurance, but only 64% confirmed their policy actually covered ransomware attacks specifically. That's a 20-point gap between "I have cyber insurance" and "I'm covered for the attack I'm most likely to face," and it matters because the median ransom demand has climbed to roughly $2 million. Even where ransomware is covered, insurers frequently attach a separate ransomware sublimit well below the policy's headline aggregate limit — so a $1 million policy might cap ransom-related payouts at $100,000 or $250,000.
2. Social engineering fraud has its own, much smaller cap
If an employee is tricked into wiring money to a fraudulent account or handing over credentials through a convincing phishing email, that's typically classified as "social engineering" or business email compromise — and most policies sublimit it dramatically. In one instructive case, a Texas builder's insurer enforced a $250,000 social engineering sublimit against more than $874,000 in losses from two fraudulent wire transfers, even though the underlying policy limit was far higher. Since business email compromise and social engineering are among the three most common causes of small business cyber incidents, a policy that caps this coverage at a fraction of its stated limit is effectively underinsuring you for your most likely loss.
3. Claim denials cluster around security controls you didn't know were required
Nearly half of all cyber insurance claims get denied or closed without payment, and the reasons are increasingly predictable: insurers now treat specific security controls — multi-factor authentication (MFA), endpoint detection and response (EDR), offline backups, and a documented incident response plan — as baseline conditions of coverage, not nice-to-haves. Roughly 14% of insured firms have faced a claim denial tied to non-compliance with these requirements, and 82% of those denials involve the simple absence of MFA on critical systems. If you attested to security controls on your application that weren't actually in place, or that lapsed after renewal, the claim can be denied on that basis alone — regardless of how legitimate the breach itself was.
There's also a fourth, quieter exclusion worth knowing about: state-backed or "act of war" cyberattacks. Since 2023, standalone cyber policies are required to exclude losses from state-sponsored attacks, a rule that emerged after insurers initially tried (and failed) to deny a $1.4 billion NotPetya claim on war-exclusion grounds. For most small businesses this exclusion is rarely the deciding factor in a claim, but it's one more reason to read the exclusions section rather than assume "hackers" means "covered."
What Coverage Actually Costs
Pricing varies by industry, revenue, data sensitivity, and security posture, but the ranges are consistent enough to budget around:
- Typical range: $100–$200 per month, or roughly $1,200–$2,400 annually, for a $1 million policy
- Lower-risk industries (e.g., construction, light manufacturing): often $1,000–$2,000 per year
- Higher-risk industries (professional services, healthcare, anything handling sensitive client data): commonly $2,500–$5,000 per year for the same $1 million limit
Premiums actually fell about 6% in 2025 and sit roughly 22% below their 2022 peak, but industry forecasts point to a 15–20% increase in 2026 as insurers tighten underwriting standards and push the security-control requirements described above. Demonstrating MFA, EDR, offline backups, and a written incident response plan isn't just a claims-time formality anymore — it increasingly determines whether you get quoted at all, and at what price.
How to Buy a Policy That Actually Pays Out
- Ask for the ransomware and social engineering sublimits in writing, separately from the aggregate limit. A $1 million policy with a $100,000 ransomware sublimit is not a $1 million ransomware policy.
- Match the coverage limit to a real worst-case estimate, not a round number. Given that 44% of insured small businesses are underinsured by half or more, start from your actual data volume, customer count, and average revenue-per-day (for business interruption) rather than picking $1 million because it sounds sufficient.
- Implement the controls insurers actually require before you apply: MFA everywhere, offline/immutable backups, an EDR tool, and a written incident response plan. This affects both your premium and whether a future claim gets paid.
- Re-verify your application attestations at every renewal. If you told the insurer MFA was enforced on all admin accounts last year, confirm it's still true before you renew — a lapsed control is a common, avoidable reason for denial.
- Treat business email compromise as a training problem, not just an insurance problem. Given how tightly social engineering payouts are capped, staff training on wire transfer verification is often cheaper than the coverage gap it prevents.
Keep Your Financial Records Ready for the Claim You Hope Never to File
If you're ever in the position of filing a cyber insurance claim, the insurer's forensic and financial teams will ask for clean records: what data you hold, what systems touched a transaction, and what your actual losses were. Beancount.io's plain-text accounting gives you a fully version-controlled, auditable ledger — transparent by design, with a complete history of every change — so if you ever need to reconstruct a financial picture during a breach investigation, it's already there. Get started for free and keep your books as resilient as the rest of your security stack.