Cyber Insurance Cost by Company Size: What You'll Actually Pay in 2025
For most U.S. companies, cyber insurance costs somewhere between $1,000 and $7,500 per year for every $1 million in coverage, and the single biggest variable is company size โ measured by annual revenue and employee headcount, not just what industry you're in. A sole proprietor or small business often pays $500โ$2,000 annually for a $1M policy. A mid-market firm with $50Mโ$500M in revenue typically pays $10,000โ$75,000. Large enterprises with complex data footprints routinely spend six or seven figures for layered towers of coverage. But the number on your quote is downstream of something more controllable: whether you meet the security controls underwriters now treat as non-negotiable.
How premiums scale with company size
Insurers price cyber risk primarily off revenue, because revenue correlates with the volume of records you hold, the size of the ransom you could be extorted for, and your capacity to pay a premium. Headcount and data sensitivity fine-tune that base figure. Rough U.S. market bands for a standalone $1M policy look like this:
- Micro business (under $1M revenue, 1โ10 employees): $500โ$1,500/year. Often bundled into a broader business owner's policy.
- Small business ($1Mโ$10M revenue): $1,500โ$5,000/year for $1M in coverage.
- Lower mid-market ($10Mโ$50M revenue): $5,000โ$20,000/year, and many carriers push you toward $2Mโ$5M limits.
- Upper mid-market ($50Mโ$500M revenue): $20,000โ$100,000+/year, frequently across multiple carriers.
- Enterprise ($500M+ revenue): Six to seven figures for a full tower of primary and excess layers.
These are ballpark figures โ a healthcare company holding protected health information or a payments processor handling cardholder data will pay materially more than a manufacturer of the same size, because the per-record breach cost and regulatory exposure are higher. Geography matters too: firms in California tend to see slightly higher premiums than the national average, driven by CCPA/CPRA liability, the density of tech and healthcare firms, and higher litigation costs.
What actually drives your quote up or down
Two companies of identical size can get quotes that differ by 40% or more. The gap is almost always about risk posture, and underwriters evaluate a consistent set of factors:
- Security controls in place โ the biggest single lever, covered in detail below.
- Data type and volume โ PHI, payment card data, and large customer PII pools raise costs; internal-only operational data lowers them.
- Industry โ healthcare, financial services, and public sector sit at the top of the risk curve; manufacturing and professional services sit lower.
- Claims history โ a prior ransomware event or breach can double a renewal or make you uninsurable at your prior limit.
- Coverage limits and sublimits โ a $5M policy with generous ransomware and business-interruption sublimits costs far more than a bare $1M policy with a low ransomware cap.
- Retention (deductible) โ accepting a higher self-insured retention directly lowers your premium. Moving from a $25K to a $100K retention is one of the fastest ways for a mid-market firm to cut cost.
The controls that decide whether you get quoted at all
The cyber insurance market hardened sharply after the ransomware surge of 2020โ2022, and the result is that certain controls are no longer "nice to have" โ they're gating conditions. Cyber insurers commonly require multi-factor authentication (MFA), endpoint detection and response (EDR), immutable backups, email security, and a documented incident response (IR) plan as baseline underwriting conditions before they will even issue a quote. If you can't demonstrate these, you'll either be declined, offered a stripped-down policy with a ransomware exclusion, or priced at the top of your size band.
The practical takeaway for a security leader: these five controls are the highest-ROI premium reductions available to you, because they move you from "declined or surcharged" to "standard rate." A concrete sequence for a mid-market firm that isn't yet compliant:
- MFA everywhere that matters first โ email, VPN, remote access, and privileged admin accounts. This is the control underwriters ask about most bluntly, and partial MFA (say, email only) often isn't enough.
- Deploy EDR across all endpoints and servers, not just workstations. Underwriters increasingly want coverage of your full estate.
- Make backups immutable and test restores โ the ability to recover without paying a ransom is what caps the insurer's downside.
- Add email security (filtering, anti-phishing) because phishing remains the top ransomware entry vector.
- Write and rehearse an IR plan โ a documented plan with named roles and an external forensics/legal retainer signals maturity and shortens claim resolution.
Closing these gaps before renewal, then documenting them clearly in your application, is the difference between a quote and a decline โ and often between the top and bottom of your price band.
Should you trust an online cost calculator?
A cyber insurance cost calculator is useful for one thing: setting a realistic budget expectation before you talk to a broker. Feed in your revenue, industry, and desired limits and you'll get a defensible range. What a calculator can't do is price your actual controls posture โ the very factor that moves your quote most. Use a calculator to answer "is $30K/year plausible for a $75M-revenue services firm?" (yes), then treat the real quote as a function of how well you can evidence MFA, EDR, and the rest. Don't buy on price alone: a cheap policy with a low ransomware sublimit and broad exclusions can be worse than no coverage when you're staring at a $2M extortion demand.
Who the big carriers are, and a note on careers
The largest cyber insurance carriers in the U.S. market include Chubb, AXA XL, Beazley, AIG, Travelers, Zurich, CNA, and Coalition, with insurtech players like Coalition and At-Bay competing hard on the strength of their active-monitoring and risk-scanning models. These newer entrants often reward strong technical controls with better pricing, which reinforces the point above: your security stack is now a pricing input, not just a compliance checkbox.
On the career question that shows up alongside these searches โ yes, it's possible to earn $500,000+ per year in cybersecurity, but it's concentrated in a narrow band of roles: CISOs at large enterprises, principal security architects, senior offensive-security specialists at top firms, and equity-heavy positions at high-growth security startups. For most practitioners, total compensation lands well below that; the half-million tier typically requires either executive scope with P&L or budget responsibility, or deep specialization plus equity. The leadership path is where the compensation ceiling is highest, which is exactly why understanding risk-transfer economics like cyber insurance is part of the CISO skill set.
If you want a fast, realistic estimate before you approach a broker, PlayCISO's free Cyber Insurance Premium Calculator lets you plug in your company size, industry, and control posture to see where your premium is likely to land โ and where closing a control gap could move the number.
Ready to practise the decisions these articles describe?
Run a free War Room โ