How Much Cyber Insurance Does a Small Business Need?

Size a cyber limit from four numbers: how many people's sensitive data you hold, how much income you would lose in one to two weeks offline, your largest single payment exposure, and any contract minimum. Add the response and downtime costs, compare the total with available limits, then check that sublimits for wire fraud and regulatory claims are not far below the main limit.

By Trella Commercial · Updated October 4, 2026

The short version

  • Start with records. Count every person whose sensitive data you hold: customers, patients, clients, and current and former employees. Breach response costs scale with that number.
  • Then downtime. Estimate the gross profit you would lose, plus extra expenses, for one to two weeks without your systems.
  • Then money movement. Your largest single wire or ACH payment is the floor for social engineering and funds transfer coverage.
  • Then contracts. A client or landlord minimum is a floor, not a target.
  • Most reported Washington breaches are mid-sized. In Attorney General filings, 40% of breaches affected 1,001 to 5,000 Washington residents and 29% affected 501 to 1,000. Size for the records you actually hold, not for the median.

Step 1: Count the records you hold

Breach response costs (the attorney, forensics, letters, call center, and credit monitoring) rise with the number of people you must notify. Count everyone whose name sits alongside sensitive data in your systems, email, and files:

Record typeWhere it hidesInclude it?
Customer or patient records with birth dates, ID numbers, health, or financial detailsPractice management, CRM, booking, accounting softwareYes
Current and former employeesPayroll exports, I-9s, W-2s, HR foldersYes, including former employees
Clients' tax, financial, or legal documentsShared drives, email attachments, scanned filesYes
Card numbersOnly if you store them; hosted payment pages usually mean you do notYes, if stored
Names and emails onlyNewsletter listsLower risk, but a username plus password is personal information in Washington

Then compare your count with what Washington breaches actually look like. Among notices filed with the Attorney General, which only receives breaches affecting more than 500 residents:

Washington residents affectedShare of notices
501 to 1,00029%
1,001 to 5,00040%
5,001 to 10,0009%
10,001 to 50,00014%
More than 50,0008%

Source: Trella Commercial's analysis of Washington Attorney General breach notices. Breaches under 500 Washington residents are not filed and do not appear here.

To turn the count into dollars, ask your broker or a breach response provider for current per-person notification and monitoring pricing, and add the attorney and forensic costs, which do not shrink much for a small breach.

Step 2: Estimate downtime

Business interruption pays lost net income plus continuing expenses and extra costs while your systems are down from a covered event. A simple worksheet:

LineHow to estimate
Daily gross profitRevenue per working day minus the costs that stop when you stop
Continuing expensesPayroll you would keep paying, rent, loan payments, software subscriptions
Extra expenseOvertime, temporary equipment, outside IT, manual workarounds
Days offlineRansomware recovery often takes days to weeks; use one to two weeks as a starting assumption, longer if your backups are not tested
Waiting periodThe policy pays only after this many hours; subtract it

Multiply daily loss by days offline. If you depend on one cloud system, such as scheduling, practice management, or ecommerce, ask whether the policy includes dependent business interruption for that vendor's outages.

Step 3: Find your largest payment exposure

Social engineering and funds transfer fraud coverage is usually a sublimit, often much smaller than the main limit. Size it from:

  • Your largest single outgoing payment: a supplier invoice, a payroll run, a property or equipment purchase
  • Client funds you move, for example a trust or escrow account
  • Customer payments that could be redirected by a fake invoice from your email

If your largest payment is larger than the sublimit offered, ask for more, look at a crime policy to sit alongside, or tighten verification procedures so a fake request cannot get through.

Step 4: Check your contracts

Client agreements, leases, vendor contracts, and grants often set a minimum cyber or technology errors and omissions limit, and sometimes require specific coverages such as privacy liability or regulatory coverage. Read the insurance clause for:

  • The minimum limit and whether it is per claim or aggregate
  • Required coverage parts, such as privacy liability, network security, or media
  • Whether the other party must be an additional insured
  • How long coverage must stay in place after the work ends

A contract minimum is the least you can carry, not a measure of your exposure. If Steps 1 to 3 add up to more, the higher number wins.

Step 5: Put the number together

ComponentYour estimate
Breach response for your record count (Step 1)
Downtime for one to two weeks (Step 2)
Liability and regulatory defense, if data is exposedDiscuss with your broker; it rises with record count and data type
Total first-party and liability exposureSum of the above
Largest payment exposure (Step 3)Set the social engineering sublimit from this
Contract minimum (Step 4)The floor

Compare the total with the limits insurers offer. Small business cyber policies are commonly written at limits such as $1 million, $2 million, or higher, with each coverage part either sharing that aggregate or carrying its own sublimit.

Sublimits, retentions, and the details that change the answer

  • Aggregate limit: everything the policy pays in a year. A ransomware event can draw on five coverage parts at once, so the aggregate must cover them together.
  • Sublimits to check: social engineering and funds transfer fraud, regulatory fines and penalties, PCI assessments, dependent business interruption, and reputational harm.
  • Breach response inside or outside the limit: some policies pay breach response costs in addition to the aggregate; others erode it.
  • Retention: a higher retention lowers premium. Pick one you could pay from cash in a bad month.
  • Coinsurance: some ransomware coverage makes you share a percentage of the loss.

Example: how the steps play out

Illustrative only. The business is invented, and the figures stand in for your own estimates, not market benchmarks.

A physical therapy clinic with 12 employees holds records for about 6,000 current and former patients, plus 40 current and former employees. It cannot schedule or bill without its practice software, which is hosted by a vendor. Its largest outgoing payment is about $60,000 for equipment.

  • Records: about 6,000 people, which puts a breach in the 5,001 to 10,000 band that 9% of Washington notices fall into. The clinic asks its broker for per-person response pricing at that count.
  • Downtime: two weeks of lost gross profit plus payroll it would keep paying. Dependent business interruption matters because the practice software is a vendor's.
  • Money movement: the social engineering sublimit should be at least $60,000, and the clinic adds a call-back rule for payment changes.
  • Contracts: a hospital referral agreement requires $1 million of cyber coverage.
  • Data type: some patient data is HIPAA data; its website and marketing data may fall under Washington's My Health My Data Act, so privacy liability wording matters.

The clinic ends up comparing $1 million and $2 million quotes, with the response, downtime, and privacy exposure, not the contract minimum, deciding between them.

Common questions

How much cyber insurance does a small business typically carry?

Small businesses commonly buy limits such as $1 million or $2 million, but the right number depends on how many records you hold, how long you could operate offline, your largest payment exposure, and any contract minimum. Size from those four inputs rather than from what is typical.

Is $1 million of cyber insurance enough?

It can be for a business with a modest number of records, short tolerable downtime, and small payments. Check the sublimits as well: a $1 million policy with a small social engineering sublimit may leave your largest payment exposure uncovered.

Do I need more cyber coverage if I store health information?

Usually. Health information makes a breach more costly to handle and more likely to draw claims, and in Washington it can raise privacy issues under the My Health My Data Act. Look closely at privacy liability, regulatory coverage, and any sublimits.

How do I choose a cyber insurance deductible?

Choose a retention you could pay from cash in a bad month without disrupting operations. A higher retention lowers premium, but some policies apply different retentions to different coverage parts, so compare them across quotes.

Does my contract's required limit tell me how much I need?

It tells you the minimum you must carry to satisfy that contract. Your actual exposure, from records, downtime, and payments, may be higher, and the higher number should decide your limit.

Sources

This page is general information, not a recommendation of a limit for any specific business. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.