BizQuotedCoverage worksheet · US small businessCheck coverage

Cyber Liability for Small Business: What It Actually Covers

Cyber liability splits into first-party coverage (your costs after an incident) and third-party coverage (claims others bring against you). Here's what small-business cyber policies actually pay for, what drives the price, and an honest look at who can reasonably skip one.

Guide · Maya TrentLast reviewed Aug 2, 20267 min read

Form BQ-102 · Coverage highlights

Editorial record

Coverage topic
Cyber Liability
Type
Guide
Reviewed by
Maya Trent
Last reviewed
Aug 2, 2026
Figures
Sourced & dated inline

Typical published ranges, not quotes. Confirm required-by-law items with a licensed agent in your state.

Disclosure: BizQuoted is reader-supported: some "compare quotes" and "check your rate" links on this page are affiliate links, and if you use them we may earn a commission at no extra cost to you — which never changes our rankings or the ranges we publish.

Cyber insurance is usually sold with horror statistics. We'll skip those. The more useful way in: a cyber liability policy is really two policies in one wrapper — coverage for your own costs after an incident, and coverage for claims other people bring against you because of one. Decide whether each half maps to your business, and the buy-or-skip question mostly answers itself. This guide walks both halves, what actually drives the price, and — the part most articles won't write — who can reasonably skip it.

First-party coverage: your own costs

First-party coverage pays the bills that land on you directly after an incident:

  • Incident response and forensics. The specialists who figure out what happened and shut the door.
  • Notification and credit monitoring. If customer data is exposed, state breach-notification rules generally require you to tell the people affected — the specifics vary by state, so confirm your obligations with a licensed agent in your state. The policy funds the notices and the monitoring services that usually follow.
  • Data restoration. Rebuilding what was corrupted or encrypted.
  • Cyber business interruption. Income lost while systems are down from a covered event.
  • Cyber extortion. Ransomware response, negotiation, and — subject to policy terms — payments. Read this section of any policy closely: extortion coverage commonly carries its own sublimit.
  • Funds-transfer fraud and social engineering. Often a separate endorsement with its own sublimit, and worth singling out: the loss that actually finds small businesses most often isn't an exotic hack, it's a spoofed email that reroutes a real payment — an invoice that looks like your vendor's, with someone else's account number on it.

Third-party coverage: claims against you

Third-party coverage responds when other people come after you because of a cyber incident:

  • Privacy liability. Customers or clients suing over exposed data.
  • Network security liability. Claims that your compromised systems were used to harm someone else.
  • Regulatory defense. Response to regulator inquiries and, where insurable, fines and penalties.
  • PCI assessments. The contractual fines card networks can levy after payment-card incidents — frequently an endorsement, so check for it if you take cards.
First-partyThird-party
Who's harmedYouSomeone else
Typical triggersRansomware, breach, fraud loss, downtimeLawsuits, regulator action, PCI assessments
What gets paidResponse costs, restoration, lost incomeDefense, settlements, covered penalties

What it typically costs — and why we don't post a number

Here's the honest version. BizQuoted publishes a typical cost range only where we have a sourced, dated figure to stand behind, and small-business cyber is a line where we don't yet — pricing swings too widely by data profile, and too fast year to year, for one "typical" number to help more than it misleads. So instead of planting a figure your own quote won't match, here's what actually moves a cyber premium:

  • The records you hold, and how sensitive they are. Volume and sensitivity drive cyber pricing far more than headcount does — a list of names and emails is a different risk from stored card numbers, health data, or identity documents.
  • Revenue and industry. A high-transaction retailer and a data-light service business with the same employee count are not the same risk.
  • Limits and sublimits. The size of the tower, and the sublimits on extortion and social-engineering coverage, move the number as much as the headline limit does.
  • Your security posture. Applications ask about multi-factor authentication and backups because they are rating levers, not paperwork — better controls can earn a better rate.

Ranges, never invented numbers: when we can't cite a sourced figure, we say so rather than manufacture one. To size it for your own profile, compare quotes below and read the sublimits, not just the headline price — and see our methodology page for where the ranges we do publish come from.

Who genuinely needs it

  • You take card payments. Even with processing fully outsourced, your merchant agreement can leave you holding contractual PCI exposure after an incident.
  • You store meaningful customer data. Names and emails on a list are one thing; payment details, health information, or identity documents are another. The more sensitive the records, the stronger the case.
  • You hold client files. Consultants, bookkeepers, and IT shops carrying client data pair cyber with their errors and omissions coverage — the lines meet in the middle. Our professional liability explainer covers that half.
  • Your revenue lives on connected systems. For an e-commerce operation, downtime is the whole loss — see our e-commerce seller insurance roundup for how sellers stack it.

An honest look at who can skip it

No state requires small businesses to carry cyber insurance as of this writing — the real requirements, where they exist, come from client and vendor contracts. That makes cyber a judgment call for most owner-operators, and the judgment can honestly go either way.

The skippable profile looks like this: you don't touch card data (cash, check, or a processor that never hands you numbers), you store no meaningful customer records, no contract demands the coverage, and a week without your laptop would be an annoyance rather than a revenue hole. A solo landscaper who books by phone and invoices by text sits squarely in that profile — in our coverage checker's tiers, that's "worth considering," not "required."

One honest counterpoint before you close the tab: if you invoice by email, you carry the one exposure that reliably finds small businesses — payment-diversion fraud. If that's the risk that worries you, the specific piece to price is funds-transfer fraud coverage, not necessarily a full standalone cyber tower. Ask for that coverage by name and check its sublimit.

Buying it without buying the wrong thing

  • Size the limit to your records and your downtime cost, not to a round number.
  • Standalone beats endorsement when the exposure is real. Some carriers bolt thin cyber endorsements onto a business owner's policy; they're better than nothing and thinner than they look — sublimits do the quiet work. Read the declarations page.
  • Answer the security questions accurately. MFA and backup answers move your rate, and misstating them is the kind of thing that surfaces during a claim.
  • Check the social-engineering endorsement and its sublimit — for many small operations it's the most likely coverage to actually get used.

When you're ready to price it, Compare quotes through a marketplace that includes cyber among its lines and returns several carriers' numbers from one application. Hiscox writes cyber on its own paper for very small operations, so a direct number is a fair second data point — Check your rate at Hiscox and read its sublimits next to the marketplace quotes. And if you're still deciding whether cyber belongs on your list at all, our coverage checker sorts it against your trade, state, and data exposure — with typical published ranges attached.

Last reviewed: August 2026. The figures on this page are typical published ranges, not quotes; our methodology explains where each one comes from and how often we recheck it.

Frequently asked

Is cyber insurance required by law?

No state statute requires small businesses to carry cyber insurance as of this writing. Requirements, where they exist, come from client and vendor contracts. Breach-notification duties after an incident are a separate legal matter and vary by state — confirm your obligations with a licensed agent in your state.

Does general liability cover data breaches?

No. General liability responds to bodily injury and property damage — physical harm. Data exposure, fraud losses, and downtime are financial harm from digital events, which is exactly the gap cyber liability exists to fill.

Do online-only businesses need cyber insurance?

They tend to have the strongest case: payments, customer records, and revenue all live on connected systems, so a single incident touches all three. For e-commerce sellers, cyber usually sits in the worth-considering-to-commonly-required band, and some marketplace and vendor contracts push it higher.

What's the difference between first-party and third-party cyber coverage?

First-party coverage pays your own costs after an incident — response, notification, restoration, lost income, extortion. Third-party coverage pays claims others bring against you because of one — privacy lawsuits, regulatory defense, PCI assessments. Most small-business cyber policies package both, with sublimits that deserve a close read.

How much does cyber insurance cost for a small business?

BizQuoted doesn't publish a typical cyber range, because small-business cyber pricing varies too much by the records you hold, your revenue, industry, limits, and security controls for a single figure to mean much without a sourced, dated basis — and we only publish ranges we can cite. What moves it most is the volume and sensitivity of the data you store, not your headcount. The most reliable way to see a real number is to compare quotes for your own profile and read the sublimits.

Compare quotes

We only link where a partner exists, and we never reorder these for a commission.

  • Simply Business

    A marketplace that shops multiple carriers in one flow — the fastest way to line up quotes side by side, and strong for same-day COIs.

  • Hiscox

    A direct writer (not a marketplace) with a strong appetite for consultants and service firms; professional liability is its bread and butter.

See what your business actually needs

Two minutes in the coverage checker turns this guide into a checklist for your trade and state.

Open the coverage checker