August 12, 2026
Cybersecurity insurance for small business: what it costs, what it covers, and what carriers won't pay for anymore
You bought a cyber policy three years ago, checked a few boxes on the application, and moved on. Now your renewal quote just tripled, the questionnaire is eight pages long, and your broker is asking whether you have EDR deployed on every endpoint. If you're wondering what changed and whether the policy will actually pay out if something bad happens, this post is for you.
Cyber insurance in 2026 looks nothing like it did in 2020. Carriers got burned during the ransomware boom, tightened underwriting, and started denying claims for reasons that would have been unthinkable a few years ago. Here's what you need to know before you renew — or file a claim.
What actually happened to the market between 2020 and 2026
Around 2019–2021, cyber insurance was easy money for carriers. Premiums were cheap, applications were short, and most small businesses never filed a claim. Then ransomware groups industrialized. Payouts exploded. Carriers like AIG, Chubb, and Travelers hemorrhaged money on cyber lines and reacted the way any insurance market reacts: they raised prices, tightened underwriting, and rewrote exclusions.
For small businesses, three things changed:
Premiums went up 3–5x. A policy that cost $600/year in 2020 is $2,400–$3,000 in 2026 for comparable coverage. Some segments saw even sharper increases.
Underwriting got real. You now fill out a detailed security questionnaire. Some carriers run external scans of your infrastructure before quoting. If your MX records show no SPF/DKIM/DMARC, if your RDP is exposed to the internet, or if your WordPress admin login is at /wp-admin with no MFA, they see it.
Exclusions got aggressive. Ransomware sublimits, nation-state exclusions, and "failure to maintain" clauses now show up in most SMB policies. The policy will still say "cyber coverage" on the cover page. What's underneath has changed a lot.
The upshot: cyber insurance is still worth having, but you have to earn it, and you have to keep earning it every year.
Baseline controls carriers now require
If you can't check these boxes on the application honestly, you'll either be denied, priced out, or handed a policy with so many carve-outs it's not worth the paper.
Multi-factor authentication on email and admin access. This is non-negotiable in 2026. Every carrier asks. If a breach happens on an account without MFA, expect the claim to be denied on the grounds that you misrepresented your controls or failed to maintain them.
Tested backups with proven recovery time. Not "we have backups." Tested backups. Carriers want to know when you last did a restore test and how long recovery took. Backups that exist but have never been restored are the number-one reason ransomware victims end up paying anyway.
EDR or a modern anti-malware solution. Legacy antivirus (Norton, McAfee consumer editions) doesn't count. They want to see a real endpoint detection product — Microsoft Defender for Business, SentinelOne, CrowdStrike, Huntress, Bitdefender GravityZone — something with behavioral detection and central logging.
Documented patch cadence. How quickly do you patch critical vulnerabilities? "When we get around to it" is a wrong answer. Carriers expect critical patches within 14 days, sometimes 7. If you got breached through a CVE that had a patch available for 90 days, the claim is dead.
Email security controls. SPF, DKIM, and DMARC properly configured. A basic DMARC record looks like this:
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100
If you're on p=none forever with no monitoring, carriers notice.
Employee security awareness training. Documented. Annual at minimum. Phishing simulations preferred.
Privileged access controls. Who has domain admin? Are those accounts separate from daily-use accounts? Are they using MFA? "Everyone's an admin because it's easier" is a claim denial waiting to happen.
Some carriers also now require an incident response plan on file, a documented vendor management process, and evidence that you review access rights quarterly. The bar keeps rising.
What a small business policy typically covers
Assuming you qualify, here's what a standard SMB cyber policy pays for:
Incident response costs. When you discover a breach, you call the carrier's incident response hotline. They dispatch a forensics firm and a breach coach (usually a specialized attorney). These people are expensive — $400–$800/hour — and the policy covers them.
Forensics and root cause analysis. Someone digs through your logs, endpoints, and cloud tenants to figure out what happened, how, and what data was accessed. This is where you find out whether the attacker had access for 3 hours or 8 months.
Notification costs. Most US states have breach notification laws. If personally identifiable information was exposed, you're legally obligated to notify affected individuals. Printing, mailing, and call center costs add up fast. The policy covers this.
Credit monitoring for affected customers. Standard is 12–24 months of credit monitoring offered to anyone whose data was exposed. Also covered.
Business interruption. If your systems are down for four days because of ransomware, the policy pays for lost revenue during the outage. There's usually a waiting period (8–12 hours) before coverage kicks in, and you'll need to document the loss.
Ransomware payments — sometimes, sometimes not. This is the most volatile part of the market. Many policies now have a sublimit specifically for ransomware (say, $50K on a $1M policy), require carrier approval before payment, and won't pay if you paid a sanctioned entity. Some policies exclude ransom payments entirely and only cover recovery costs.
Regulatory fines and defense costs. Depending on the policy, defense against regulatory action (FTC, state attorneys general, HIPAA) may be covered. Actual fines are often excluded because most jurisdictions don't allow fines to be insurable.
Third-party liability. If your customers sue you because their data leaked, the policy defends and pays settlements up to policy limits.
What carriers increasingly won't pay for
This is the section people skim, then regret skimming.
Nation-state attacks (the attribution loophole). After the Merck/NotPetya case, "act of war" exclusions got teeth. If the carrier's forensic team attributes the attack to a nation-state actor — even loosely — they can invoke this exclusion. Given that many ransomware groups have known ties to Russia, this is a live risk.
Unpatched known-CVE incidents. If you got breached through a CVE that had a patch available for more than 30–90 days (varies by carrier), coverage may be denied under a "failure to maintain" clause. This is why patch cadence matters.
Missing-MFA breaches. If the compromised account didn't have MFA and you told the carrier on your application that all accounts did, the claim is dead and the policy may be voided entirely for misrepresentation.
Social engineering / business email compromise. Historically the biggest source of SMB cyber losses — someone impersonates your CEO or a vendor and tricks accounting into wiring money. Most standard cyber policies exclude this. You need a separate "social engineering fraud" or "funds transfer fraud" rider, and even then coverage is often capped at $50K–$250K.
Prior known vulnerabilities. If you knew about a security weakness (say, a pentest flagged it) and didn't fix it, and that weakness was exploited, coverage is denied.
Contractors and vendors. If the breach came through a vendor's system, coverage gets messy fast. Some policies exclude vendor-caused incidents entirely.
Read the exclusions section of your policy before you file a claim, not after. Better yet, have your broker walk you through them at renewal.
What it actually costs in 2026
Rough pricing for small businesses in the US market, assuming you meet baseline underwriting requirements:
Under $1M annual revenue: $500–$2,000/year for a $1M policy limit. Retention (deductible) usually $2,500–$5,000.
$1M–$10M annual revenue: $2,000–$8,000/year for a $1M–$3M policy limit. Retention $5,000–$25,000.
$10M–$50M annual revenue: $8,000–$30,000+/year, with retentions climbing to $25,000–$100,000.
Higher-risk industries — healthcare, financial services, anything handling PCI data, MSPs, and law firms — pay a premium above these bands. If you've had a prior claim, expect a 30–100% surcharge and shorter list of willing carriers.
These are ballpark numbers. Your actual quote depends on revenue, industry, data types you handle, and your security posture. A business with strong controls and a clean history pays the low end; a business with weak controls and prior claims pays the high end, if they can get quoted at all.
Application red flags: don't lie on the questionnaire
The application is a legal document. If you check "yes" for MFA on all accounts and it turns out one admin account didn't have it, the carrier can void the policy — meaning they refund your premium and walk away from the claim.
Common places people lie (or "optimistically interpret"):
- MFA coverage. "Most" accounts is not "all" accounts. If the questionnaire says "all," you'd better mean it.
- Backup testing. "We have backups" is not the same as "we test restores quarterly." Only claim what you actually do.
- Prior incidents. If you had a breach or ransomware event in the last 3–5 years, disclose it. Carriers share data, and misrepresenting prior incidents is grounds for rescission.
- Endpoint coverage. If you say EDR is on all endpoints, that includes the owner's laptop, the receptionist's computer, and the warehouse tablet — not just the servers.
- Patch cadence. "We patch regularly" is vague enough to be dangerous. Only commit to timelines you can prove.
If you don't know the answer, find out before submitting. If the true answer is uncomfortable, fix the gap and then submit. The premium savings from lying are trivial compared to a denied claim.
The pattern behind denied claims
Talk to any incident response firm and the same claim denial stories come up over and over:
"They paid the ransom without carrier approval." Almost every modern policy requires you to notify the carrier and get approval before any payment. Panic-paying a ransom to get your data back voids the coverage. Call the hotline first, always.
"The breached account didn't have MFA." Application said all accounts had MFA. One account didn't. That's the one that got phished. Claim denied for misrepresentation.
"No backup had been tested in over a year." Backups existed but hadn't been verified. When ransomware hit, restore failed. Business interruption claim denied because the loss was preventable.
"The exploited vulnerability was patched three months ago." Windows Server or a VPN appliance running an old version. Patch was available. Wasn't applied. Failure-to-maintain exclusion invoked.
"The wire was authorized by an employee, not stolen credentials." BEC/wire fraud claim denied because there was no social engineering rider on the policy — the standard cyber section doesn't cover voluntary transfers, even if voluntary was based on a fake email.
The pattern: claims get denied when the insured didn't maintain the controls they claimed to have, or violated the policy's procedural requirements after the incident started. Both are preventable with basic security hygiene and a documented IR plan.
I saw this play out on a WordPress incident earlier this year: a Southern California contractor had a self-healing backdoor a prior developer never fully cleaned, plus 115+ injected spam posts. Nothing sophisticated — just missed. If that business had filed a cyber claim, the carrier's forensics would have found the incomplete prior remediation and the lack of ongoing monitoring, and had ample grounds to reduce the payout. Coverage is only as good as the controls behind it.
What to do before your next renewal
A short checklist to get your posture in shape before the questionnaire lands:
- Turn on MFA everywhere — email, admin panels, VPN, cloud consoles, banking. No exceptions.
- Verify your backups by actually restoring something. Document the test.
- Deploy EDR on every endpoint, including the owner's laptop.
- Patch known critical CVEs within 14 days. Document your process.
- Configure SPF, DKIM, and DMARC on all your domains. Move DMARC toward
p=quarantineorp=reject. - Do a phishing simulation and security awareness training. Document it.
- Write a two-page incident response plan. Include the carrier's hotline number.
- Review the exclusions on your current policy. Ask your broker specifically about social engineering, ransomware sublimits, and failure-to-maintain clauses.
Do these things and you'll qualify for coverage, pay closer to the low end of the pricing bands, and — most importantly — actually get paid when you file a claim.
The bottom line
Cyber insurance in 2026 is a real safety net, but only if you treat it like one. The days of buying a cheap policy and hoping for the best are over. Carriers expect you to run a competent security program, and they will check. If you've been coasting on a policy you bought years ago, dig it out and read the exclusions this weekend. If the answer to "do we have MFA on everything?" or "when did we last test a backup restore?" is a shrug, you've got work to do before your next renewal.
The controls that keep your policy valid are the same controls that make you less likely to file a claim in the first place. That's not a coincidence — it's how insurance is supposed to work.
If you want help getting your controls in order before your next renewal, or you want an outside set of eyes on what your policy actually covers, reach out through the contact form at thewizrdz.io or take a look at the Security Retainer and Site Hardening options. These are exactly the services designed to keep your posture at the level carriers now demand — and to make sure your claim gets paid the day you need it to.
