The short version
- There is no standard price. Two businesses with the same revenue can get very different quotes, or one can be declined, because of their security controls and data.
- The big rating factors: revenue, industry, records held, security controls, prior claims, and the coverage you choose.
- Controls are pass or fail before they are price. Many insurers will not quote a business without multifactor authentication on email and remote access, or without backups kept separate from the network.
- You control more of the price than you think: fixing gaps before you apply, choosing the right retention, and setting sublimits deliberately all move the number.
- Do not save money by cutting the coverage you are most likely to use. Business interruption and social engineering are where small businesses most often need their policy.
The rating factors insurers use
| Factor | Why it matters | What you can do |
|---|---|---|
| Revenue | A proxy for size, records, and the cost of downtime | Report accurately; revenue drives exposure, not just price |
| Industry | Health care, financial, legal, education, and technology firms hold more sensitive data and draw more attacks | Nothing to change, but strong controls offset it |
| Records held | Notification and liability costs rise with the number of people whose data you hold | Delete records you no longer need; data you do not keep cannot be breached |
| Type of data | Social Security numbers, health, and financial data cost more to handle after a breach | Limit who collects and stores it, and encrypt it |
| Security controls | The single biggest driver of eligibility and price | See the next section |
| Prior incidents and claims | Past breaches, ransomware, or fraud raise rates or narrow terms | Document what you fixed afterward |
| Limits and sublimits | Higher limits cost more, though not proportionally | Size the limit to your exposure; see how much you need |
| Retention | A higher deductible lowers premium | Pick one you could pay from cash in a bad month |
| Coverage options | Social engineering, dependent business interruption, and system failure add cost | Buy the ones your business actually depends on |
The security controls that move price most
Insurers ask about these because they are tied to how attacks succeed. Ransomware and email fraud, two of the most common small business claims, both depend on stolen logins and missing backups.
| Control | What insurers want to see | Why |
|---|---|---|
| Multifactor authentication (MFA) | On email, remote access (VPN, remote desktop), administrator accounts, and cloud apps | Stolen passwords are the most common way in; MFA blocks most of those attempts |
| Backups | Regular, encrypted, kept offline or otherwise separated from the network, and tested by actually restoring | Ransomware targets backups; untested backups often fail when needed |
| Endpoint detection and response (EDR) | Installed on all computers and servers, ideally monitored | Catches attacks traditional antivirus misses |
| Patching | Critical security updates applied within days to weeks; no unsupported software | Attackers exploit known, unpatched flaws |
| Email security | Filtering, plus domain protections (SPF, DKIM, and DMARC) | Reduces phishing and spoofing of your domain |
| Security awareness training | Regular training and phishing simulations | Employees are the target of most attacks |
| Payment verification | Call-back to a known number before changing bank details or sending large payments | Stops most business email compromise losses |
| Privileged access | Separate admin accounts, used only for admin work | Limits what an attacker can do with one stolen login |
| Remote desktop exposure | No remote desktop ports open to the internet | A common entry point for ransomware |
| Encryption | Laptops and portable devices encrypted | Lost devices become non-events; under Washington law, encrypted data generally does not trigger breach notice |
Insurers also scan the internet-facing side of your business, such as your website, email domain, and any open ports, before they quote. Problems they find there can change the price or the terms even if your application looks clean.
Eight ways to lower your premium
- Turn on MFA everywhere before you apply. Email, remote access, admin accounts, banking, and cloud apps. It is the control insurers ask about first.
- Prove your backups work. Keep at least one copy offline or immutable, and do a test restore. Note the date; applications ask.
- Close remote desktop to the internet and remove software that no longer gets security updates.
- Write down a payment verification rule and train everyone who touches money on it. It can also be a condition of social engineering coverage.
- Delete data you do not need. Old customer files, former employee records past their retention period, and scanned IDs all add exposure.
- Choose the retention deliberately. Raising it can lower premium meaningfully; compare two or three options.
- Right-size limits and sublimits. Match the limit to your records, downtime, and contracts rather than buying the largest available.
- Start early and use a broker. Submitting 60 to 90 days before renewal leaves time to fix gaps an underwriter flags and to compare more than one insurer.
Where not to save money
| Tempting cut | Why it backfires |
|---|---|
| Dropping business interruption | Downtime is often one of the largest costs of a ransomware attack for a small business |
| A tiny social engineering sublimit | Fake invoices and payment changes are among the most common business losses; the FBI logged 21,442 business email compromise complaints in 2024 |
| Skipping dependent business interruption | If your scheduling, practice, or ecommerce platform goes down, your income stops too |
| Overstating controls to get a better price | An inaccurate application can give the insurer grounds to deny a claim |
| Relying on a business owners policy endorsement alone | Usually too small and too narrow; see does a BOP cover a breach? |
What happens at renewal
Cyber renewals are rarely automatic. Expect an updated application, a fresh external scan, and questions about any incidents during the year. A control that has slipped, such as MFA turned off for a few users, can change the renewal terms. Keep a short record of your controls and when you tested backups so renewal is quick.