Cyber Insurance Cost by Company Size: What You'll Actually Pay in 2024
Cyber insurance cost scales roughly with revenue, data sensitivity, and industry โ not headcount alone โ but as a working baseline: a small business (under $10M revenue) typically pays $1,000โ$7,500 per year for $1M in coverage; a mid-market company ($10Mโ$100M revenue) commonly lands in the $10,000โ$50,000 range; and enterprises above $100M revenue negotiate custom programs starting in the six figures. Those bands move dramatically based on one thing you control: your security posture. Insurers now require specific technical controls before they'll even issue a quote, and having them or lacking them can swing your premium by 30โ50% โ or make you uninsurable. This post breaks down cost by company size and shows you exactly what to fix to move your quote in the right direction.
How much cyber insurance costs by company size
The single biggest driver of premium is revenue, because revenue is a proxy for how much a breach could cost the insurer to pay out. Business interruption losses, notification costs, and regulatory fines all scale with the size of your customer base and transaction volume. Here's a realistic breakdown for the USA market for a standalone cyber policy with $1M in coverage:
- Micro business (under $1M revenue, 1โ10 employees): $500โ$2,000/year. Often bundled into a broader business owner's policy (BOP).
- Small business ($1Mโ$10M revenue): $1,500โ$7,500/year for $1M in coverage. This is where most searches for "cyber insurance cost for a small business" land.
- Mid-market ($10Mโ$100M revenue): $10,000โ$50,000/year, with coverage limits typically scaling to $3Mโ$10M.
- Enterprise ($100M+ revenue): $100,000 to several million per year, built as layered towers with multiple carriers.
Two companies of identical size can pay wildly different amounts. A 40-person e-commerce firm processing credit cards will pay more than a 40-person landscaping company, because it holds regulated payment data (PCI DSS scope) and has higher business-interruption exposure. Industry matters: healthcare, financial services, and managed service providers consistently pay premium rates because they're prime ransomware and supply-chain targets.
The controls that decide your premium (and whether you get quoted at all)
Since 2021, the underwriting market has tightened sharply. Carriers stopped competing purely on price and started competing on risk selection. In practice, that means cyber insurers commonly require MFA, EDR, immutable backups, email security, and a documented incident response plan as baseline underwriting conditions before quoting. If you can't attest to these on the application, you'll either be declined or offered a sublimited, expensive policy.
Here's what each control actually buys you at the underwriting table:
- Multi-factor authentication (MFA): The single most-scrutinized control. Underwriters want MFA on remote access, email, VPN, and privileged/admin accounts โ not just the front door. Missing MFA on privileged accounts is a common reason for declination.
- Endpoint Detection and Response (EDR): Legacy antivirus no longer satisfies most carriers. They want to see a modern EDR/XDR platform with active monitoring, because it directly reduces ransomware dwell time and payout size.
- Immutable backups: Backups that ransomware can't encrypt or delete. This is the control that lets you recover without paying a ransom, which is why insurers weight it heavily โ it caps their loss.
- Email security: Filtering and anti-phishing, since email remains the top initial access vector for both ransomware and business email compromise.
- A documented IR plan: Not a binder on a shelf โ a tested plan showing you can detect, contain, and notify quickly. Faster response means smaller claims.
The actionable takeaway: before you request a single quote, run your environment against this five-item list. Closing even two gaps โ say, extending MFA to admin accounts and moving backups to immutable storage โ can be the difference between a decline and a competitive renewal. Underwriters reward demonstrable controls with lower premiums and higher limits.
A worked example: how posture changes the number
Take a $25M-revenue professional services firm seeking $3M in coverage. With MFA everywhere, EDR deployed, immutable backups, email filtering, and a tested IR plan, they might see a quote around $18,000/year. Strip out immutable backups and leave admin accounts on password-only login, and the same firm faces one of three outcomes: a quote near $32,000 with a ransomware sublimit (meaning ransomware claims are capped well below the $3M policy limit), a coinsurance clause forcing them to absorb 20โ50% of any ransomware loss, or a flat decline.
This is why a generic "cyber insurance cost calculator" only gets you halfway. The number it produces is a starting band; your controls determine where inside โ or outside โ that band you actually land. If you're in a high-cost state market like California, where data-breach notification obligations under the CCPA raise potential claim severity, the posture premium matters even more.
Who the biggest cyber insurance carriers are
If you're shopping, you'll encounter the major players repeatedly. The largest cyber insurers by market presence include Chubb, AXA XL, Beazley, AIG, Travelers, CNA, Coalition, and At-Bay. Coalition and At-Bay are worth calling out because they operate as "active insurers" โ they pair the policy with continuous scanning of your external attack surface and will alert you to exposures mid-term. For smaller businesses, that active-monitoring model can be more valuable than a marginally cheaper premium from a traditional carrier, because it helps you avoid the claim in the first place.
Work through an independent broker who specializes in cyber rather than going direct to one carrier. A specialist broker knows which carriers are hungry for your industry and size segment this quarter, and market appetite shifts constantly.
And yes โ can you make $500,000 in cybersecurity?
Readers researching this topic often ask this alongside it, so directly: yes, but it's the exception, not the rule. Base salaries for senior security engineers and architects at large tech and financial firms run $180,000โ$300,000. Total compensation crossing $500,000 generally requires a CISO or VP-level role at a large enterprise, where equity and bonus stack on top of base โ or a highly specialized niche like offensive security research, cloud security architecture at a FAANG-tier company, or independent consulting with a strong client book. The controls discussed above are exactly what these professionals are hired to implement, and demonstrable expertise in reducing insurable risk is increasingly a resume differentiator, not just a compliance chore.
How to lower your quote before renewal
Concrete steps, in priority order: (1) enforce MFA on all remote, email, and privileged access โ this is the highest-leverage single fix; (2) deploy EDR and retire standalone legacy antivirus; (3) move at least one clean backup copy to immutable, offline, or air-gapped storage and test the restore; (4) document and tabletop-test your IR plan so you can attest it's exercised, not theoretical; (5) tighten email security with anti-phishing and DMARC. Each of these maps directly to a question on the underwriting application, and each one you can honestly check "yes" on pulls your premium downward.
To turn these variables into a specific number for your organization, try PlayCISO's free Cyber Insurance Premium Calculator โ it factors in your revenue, industry, and which of these baseline controls you actually have in place, so you can see the premium impact before you ever talk to a broker.
Ready to practise the decisions these articles describe?
Run a free War Room โ