The gap between these two columns is where uninsured losses live. A firm like Bloc Cyber reviews coverage at the insuring-agreement level precisely because a bundled checkbox does not reveal these gaps until a claim is filed.
A mid-market company with 200 employees and $40 million in revenue will pay a very different cyber insurance premium than a 15-person professional services firm earning $2 million. The difference is not arbitrary. Underwriters price cyber risk using a specific set of variables: your revenue band, industry classification, policy limits and retentions, the security controls you have in place, and your claims history. Understanding how each factor drives cost gives you the ability to negotiate a better outcome and avoid paying for coverage you do not need, or worse, discovering you are underinsured after a breach. Global cyber insurance rates fell between 4% and 6% in early 2026, though premiums are projected to rise by the end of the year as ransomware frequency ticks upward and regulatory enforcement intensifies across multiple states. That window of relative affordability will not stay open indefinitely. Whether you are purchasing your first cyber policy or renewing an existing one, the pricing mechanics below will help you understand exactly what you are paying for and why.
Understanding the Foundations of Cyber Insurance Pricing
Cyber insurance pricing is not a single calculation. It is a composite of overlapping risk assessments that underwriters weigh differently depending on the carrier and the policy form. Three foundational inputs drive almost every quote: the size of your company measured by revenue, the industry you operate in, and how your sector has performed historically in terms of claims frequency and severity.
These inputs establish a base rate. Everything else, from security controls to retention choices, adjusts that base rate up or down. A company that understands these foundational factors can anticipate where its premium will land before it even receives a quote.
Revenue Bands and Company Size
Underwriters use annual revenue as a proxy for exposure. A company generating $50 million in revenue typically processes more data, maintains more customer records, and operates more digital infrastructure than one generating $5 million. That increased surface area means more potential points of failure.
Most carriers organize pricing into revenue bands. A common structure looks like this: under $5 million, $5 million to $25 million, $25 million to $100 million, and $100 million to $500 million. Each band carries a different rate per million of coverage. Small businesses with revenue under $5 million can often secure $1 million in coverage for $1,500 to $5,000 annually, while mid-market firms frequently see premiums ranging from $10,000 to $50,000 or more depending on the other rating factors discussed below.
Employee count matters too, but revenue remains the primary sizing metric. A 50-person SaaS company with $30 million in ARR will be rated differently than a 50-person manufacturer with $8 million in revenue.
Industry Risk Categories and Rating Factors
Your industry classification is the second major pricing driver. Healthcare organizations, financial services firms, and technology companies consistently pay higher premiums because they handle sensitive data subject to strict regulatory frameworks like HIPAA, GLBA, and state privacy statutes.
Manufacturing and retail have seen premiums climb sharply since 2023 as ransomware groups shifted targeting toward operational technology environments. A manufacturing firm with connected production systems now faces underwriting scrutiny that would have been reserved for healthcare five years ago. Education and nonprofit sectors tend to receive more favorable rates, though that advantage narrows when the organization handles student financial aid data or donor payment information.
Underwriters also look at sub-industry classifications. A fintech startup and a community bank both fall under "financial services," but their risk profiles differ substantially. This is one area where working with a specialist, like Bloc Cyber, matters: a generalist broker may not push back on an overly broad industry classification that inflates your rate.
Historical Claims Data and Loss Ratios
Carriers price policies based on their own loss experience within each industry and revenue band. If a carrier paid out $80 in claims for every $100 in premium collected from healthcare accounts last year, it will raise rates for healthcare accounts this year. The average cyber insurance claim now exceeds $100,000, and that figure continues to climb as business interruption losses grow alongside direct breach costs.
Your own claims history carries weight too. A prior cyber claim, even one that fell below your retention, signals to underwriters that your organization has experienced a security event. Two or more claims in a five-year window can result in premium surcharges of 25% to 50%, or in some cases, declination from certain markets entirely.
Policy Structure: Limits, Retentions, and Premiums
The interplay between your policy limit and your retention is where premium optimization happens. These two choices define how much risk you transfer to the carrier and how much you retain yourself.
Choosing Between $1M and $5M Limits
A $1 million aggregate limit is the standard entry point for small businesses. It covers first-party costs like forensic investigation, notification, credit monitoring, and business interruption, alongside third-party liability for regulatory defense and privacy lawsuits. For a company with under $10 million in revenue and limited data exposure, $1 million may be sufficient.
The jump to $5 million in coverage does not mean a fivefold increase in premium. Excess layers are typically priced at a fraction of the primary layer's cost because the probability of a loss exceeding $1 million is lower than the probability of any loss occurring at all. A $1 million primary policy might cost $8,000, while adding $4 million in excess coverage might add another $6,000 to $12,000. That marginal cost is often worth it, particularly for companies subject to contractual requirements from enterprise clients or regulatory bodies that expect higher limits.
How Retention (Deductibles) Affect Monthly Costs
Your retention is the amount you pay out of pocket before the policy responds. Standard retentions for small and mid-market accounts range from $2,500 to $50,000, with $10,000 being common for companies in the $10 million to $50 million revenue range.
Raising your retention from $10,000 to $25,000 can reduce your annual premium by 10% to 20%. That trade-off makes sense if your organization has the cash flow to absorb the higher retention without financial strain. It does not make sense if a $25,000 unexpected expense would create a liquidity problem. Some policy forms also apply separate retentions to different insuring agreements, so a $10,000 retention on privacy liability might sit alongside a $25,000 retention on business interruption. Bloc Cyber reviews these form-level details before binding so there are no surprises when a claim arises.
Comparison: Cyber Liability vs. General Liability Coverage
Many business owners assume their general liability policy provides some protection against cyber events. It does not, at least not in any meaningful way. General liability policies contain broad electronic data exclusions and are not designed to respond to breach notification costs, ransomware payments, or regulatory investigations.
Coverage Comparison Table
| Coverage Element | General Liability | Cyber Liability |
|---|---|---|
| Breach notification costs | Not covered | Covered |
| Forensic investigation | Not covered | Covered |
| Ransomware / extortion | Not covered | Covered (with sublimits) |
| Business interruption from cyber event | Not covered | Covered (after waiting period) |
| Regulatory defense and fines | Not covered | Covered (where insurable by law) |
| Third-party privacy lawsuits | Typically excluded | Covered |
| Bodily injury / property damage | Covered | Not covered |
| Advertising injury | Covered | Not covered |
The distinction is clear. A general liability policy protects against physical-world risks. A cyber liability policy protects against digital risks. They are complementary, not interchangeable. Businesses subject to breach-notification statutes in all 50 states need dedicated cyber coverage to fund the mandatory response obligations those laws impose.
Lowering Costs Through Security Control Credits
Underwriters reward organizations that reduce their attack surface. Specific security controls can earn premium credits ranging from 5% to 25%, and in some cases, the absence of these controls will result in declination rather than a surcharge.
Multi-Factor Authentication (MFA) Discounts
MFA on email, VPN, and privileged accounts is no longer optional for cyber insurance eligibility. Most carriers require it as a baseline condition of coverage. Organizations that have MFA deployed across all remote access points and administrative consoles meet the minimum threshold most insurers now demand and may qualify for credits of 5% to 10% on their premium.
The key detail: partial MFA deployment does not count. If your finance team uses MFA but your IT administrators do not, underwriters will flag that gap.
Endpoint Detection and Response (EDR) Requirements
EDR tools that provide real-time monitoring, automated threat containment, and forensic logging have become a second non-negotiable control. Carriers want to see EDR deployed on all endpoints, not just servers. Organizations running legacy antivirus without EDR capabilities face higher premiums or outright coverage restrictions.
Premium credits for full EDR deployment typically range from 5% to 15%. The investment in EDR often pays for itself through insurance savings alone within the first policy year, before even considering the direct security benefits.
Employee Training and Incident Response Planning
Phishing remains the most common initial attack vector. Carriers ask whether your organization conducts regular security awareness training and simulated phishing exercises. Annual training is the minimum; quarterly training earns stronger credits.
A documented and tested incident response plan signals to underwriters that your organization can contain a breach quickly, reducing the carrier's expected loss. Companies that can demonstrate tabletop exercises conducted within the past 12 months often receive an additional 5% to 10% credit. The combination of MFA, EDR, training, and incident response planning can reduce a quoted premium by 20% to 30% in aggregate.
Frequently Asked Questions About Cyber Costs
How much does a small business typically pay for cyber insurance? A company with under $5 million in revenue and fewer than 25 employees can generally expect to pay between $1,500 and $5,000 annually for $1 million in coverage, assuming no prior claims and basic security controls in place.
Does my industry affect my premium more than my revenue? Both matter, but industry classification often has a larger impact on rate-per-million. A $10 million healthcare company will almost always pay more than a $10 million consulting firm because the data exposure and regulatory environment differ significantly.
Can I lower my premium by increasing my retention? Yes. Moving from a $5,000 retention to a $25,000 retention can reduce annual premium by 10% to 20%. Make sure your organization can absorb that amount comfortably if a claim occurs.
Will a prior claim disqualify me from coverage? Not necessarily, but it will affect pricing. A single claim with a clear remediation narrative is manageable. Multiple claims or an open claim at renewal time will narrow your market options and increase costs.
Do I need cyber insurance if I already have tech E&O? Tech E&O covers claims arising from your professional technology services. Cyber liability covers your own data breach and network security failures. They overlap in limited areas but protect against different exposures. Most technology companies need both.
Making the Right Choice for Your Business
Cyber insurance pricing is driven by measurable factors you can influence. Your revenue band and industry set the starting point, but your retention choice, security posture, and claims history determine where you land within that range. Investing in MFA, EDR, employee training, and a tested incident response plan does more than reduce premiums: it reduces the likelihood you will need to file a claim at all.
The policy form itself matters as much as the price. Sublimits on ransomware, waiting periods on business interruption, and exclusions for unencrypted data can all erode coverage in ways that a premium comparison alone will not reveal. If you are evaluating cyber coverage for the first time or questioning whether your current policy actually responds to the risks you face, request a review with a specialist who will walk through the insuring agreements, retentions, and exclusions specific to your policy form. That conversation costs nothing and can prevent a costly gap from surfacing during a claim.
ABOUT THE AUTHOR
Caden Braly
— Founder, Bloc Cyber
I'm Caden Braly, founder of Bloc Cyber, the specialty cyber insurance arm of Braly Insurance. I built Bloc Cyber around one idea: businesses deserve coverage that actually responds when a cyberattack happens. I work closely with clients to understand their exposure, place the right policy through specialty carriers, and stand with them through the claim. My goal is simple — give every business straight answers and protection they can trust.
Full profile → caden@bloccyber.com LinkedIn




