๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

Cyber Insurance Cost by Company Size in the USA: What You'll Actually Pay

September 25, 2026 ยท PlayCISO

In the USA, cyber insurance cost scales roughly with your revenue, data volume, and industry risk โ€” not with employee headcount alone. A small business (under ~$10M revenue) typically pays $500 to $5,000 per year for a $1M policy, a mid-market firm ($10Mโ€“$100M revenue) commonly lands in the $5,000 to $50,000 range, and enterprises with large regulated data footprints can pay six or seven figures annually. But the single biggest variable isn't size โ€” it's whether you meet the security controls insurers now demand before they'll even issue a quote. Skip those, and you either can't buy coverage at any price or pay a heavy surcharge. This post breaks down what drives cost at each company size, what the policy actually covers, and how to move your premium in the right direction.

What actually drives your premium โ€” beyond company size

Company size is a proxy, not the real input. Underwriters price four things:

  • Revenue and record count. More revenue and more stored personal records (PII, PHI, payment data) mean a larger potential breach-response bill, which drives premium up faster than headcount does.
  • Industry. Healthcare, financial services, and any business processing card data pay materially more than, say, a manufacturer of the same revenue โ€” because their breach exposure and regulatory penalties are higher.
  • Security controls in place. This is now the make-or-break factor. Insurers commonly require MFA, EDR, immutable backups, email security, and a documented incident response plan as baseline underwriting conditions before quoting at all. Missing controls don't just raise price โ€” they can make you uninsurable.
  • Coverage limits and retention. A $1M limit costs a fraction of a $10M limit, and choosing a higher deductible (retention) lowers your annual premium in exchange for more out-of-pocket exposure per claim.

Two companies with identical revenue can see premiums differ by 3โ€“5x based on controls and industry alone. That's why "cost by company size" is only a starting range.

Cost ranges by company size in the USA

Use these as planning brackets, not quotes โ€” your actual number depends on the factors above.

  • Small business (under ~$10M revenue, up to ~50 employees): Roughly $500โ€“$5,000/year for a $1M policy. A low-risk consultancy with clean controls sits near the bottom; a small medical practice or e-commerce shop handling card data sits near the top or higher.
  • Mid-market ($10Mโ€“$100M revenue): Roughly $5,000โ€“$50,000/year, often for $2Mโ€“$5M limits. At this size underwriters scrutinize your control posture closely and will require security questionnaires and sometimes external scans.
  • Enterprise ($100M+ revenue): $50,000 into the millions, with layered "tower" structures โ€” a primary insurer plus excess carriers stacking additional limits above them.

A useful rule of thumb: expect to pay somewhere in the range of 1% to 3% of your desired coverage limit annually if your controls are solid. Weak controls push that ratio higher or eliminate the option entirely.

What cyber liability insurance actually covers

Before you shop on price, know what you're buying. Most cyber liability policies split into two halves:

  • First-party coverage โ€” your own costs after an incident: forensic investigation, breach notification and credit monitoring, data restoration, business interruption losses, cyber extortion / ransomware payments, and PR/crisis response.
  • Third-party coverage โ€” liabilities to others: regulatory fines and defense costs, lawsuits from affected customers or partners, and payment card industry (PCI) assessments.

Read the exclusions carefully. Policies increasingly carve out losses from "known vulnerabilities" left unpatched, acts of war, or failure to maintain the controls you attested to on your application. That last one matters: if you claimed you had MFA everywhere and a breach traces to an account without it, your claim can be denied. The application isn't paperwork โ€” it's a warranty.

How to lower your premium (and become insurable at all)

The fastest way to cut cost is to close the gaps underwriters penalize. Work down this list in order โ€” it maps directly to what insurers require:

  • MFA everywhere, especially email, VPN, and admin accounts. This is the number-one question on most applications. Enforce it phishing-resistant where you can.
  • EDR on all endpoints and servers. Legacy antivirus alone increasingly fails to satisfy underwriting.
  • Immutable, tested backups. Insurers want backups that ransomware can't encrypt or delete, plus evidence you've tested restoration.
  • Email security. Anti-phishing filtering and DMARC reduce the most common breach entry point.
  • A documented, exercised incident response plan. Having the document isn't enough โ€” carriers increasingly ask whether you've run a tabletop exercise against it.

Beyond the baseline five, offering a higher retention, bundling with an existing broker relationship, and demonstrating a formal patch-management cadence and privileged access controls all move price. A mid-market firm that implements MFA and EDR before renewal frequently sees both a lower quote and access to more carriers competing for the business โ€” competition itself lowers price.

Who the biggest US cyber insurers are โ€” and why it matters

The largest cyber insurers in the US market include Chubb, AXA XL, Travelers, AIG, Beazley, and Coalition, alongside insurtech-led providers like At-Bay. Why should a buyer care about the carrier list? Because these firms differ meaningfully in appetite: some specialize in small business with fast, automated quoting; others focus on complex enterprise towers. Insurtech carriers like Coalition and At-Bay pair the policy with active security monitoring and will alert you to exposed assets before they become claims โ€” effectively bundling risk reduction with coverage. Getting quotes from at least three carriers across different models is the single most reliable way to avoid overpaying.

A quick word on the salary question

Readers researching cyber insurance often also ask whether you can earn $500,000 a year in cybersecurity. The short answer: yes, but it's the exception, not the norm. Total compensation at that level is generally reserved for CISOs at large enterprises, specialized security architects at major tech firms, or top-tier consultants โ€” often with equity or bonus making up a large share. A typical senior security engineer in the US earns well into six figures but below that mark; the $500K tier requires leadership scope, scarce expertise (cloud security, appsec, offensive security), or a company willing to pay for retention. It's a genuine ceiling for the field โ€” just not an average.

Getting to a real number

Company-size brackets get you a planning range; only a quote gets you a price. Before you talk to a broker, inventory your controls against the five baseline requirements above โ€” that assessment alone will predict whether you're looking at the low or high end of your bracket. If you want a ballpark before you engage carriers, try PlayCISO's free Cyber Insurance Premium Calculator to estimate your annual cost based on your revenue, industry, and current security posture.

Ready to practise the decisions these articles describe?

Run a free War Room โ†’