Why Does Cyber Insurance Cost So Much? (2024)

While the cyber insurance market is showing some signs of stabilization, those who have purchased commercial cyber insurance over the past five years likely experienced double-digit cyber insurance premium increases. Risk managers and other organizational leaders are asking why is cyber insurance so expensive and is cyber insurance worth it.

What Is Cyber Insurance?

Cyber liability insurance, also referred to sometimes as cyber risk insurance, cyberattack insurance or cybersecurity insurance coverage, helps companies respond to and recover from the financial impacts of cyber-related events. In addition to data breaches, these events could include malware infestation, email compromise and denial of service/ransomware attacks.

Learn more by reading “What Is Cyber Insurance?

Who Needs Cyber Insurance?

Every organization is at risk of cyberattacks today. Any organization with an email address or a bank account should invest in cyber insurance. If a company stores credit card numbers, customer data, personally identifiable information (PII) or protected health information (PHI), the company should invest in cyber liability coverage. If an organization has a website, processes online payments or is part of an industry with many regulations around customer data, it should secure a cyber insurance policy.

Further, no business is too small for cybercriminals to target. Data security and networking company Barracuda Networks reports that small businesses with less than 100 employees are three times more likely than larger companies to be targets of social engineering attacks. A social engineering attack occurs when a threat actor tricks an employee into sharing sensitive information or making a security mistake.

Learn more by reading "Understanding Common Types of Cyberattacks."

Why Buy Cyber Insurance?

It’s a cliché, but it’s true. It’s not if a cyberattack will impact an organization; it’s when. Recovery takes time and money.

Consider some of the losses cyber insurance can help protect against:

  • The cost of repairing systems and recovering data
  • The cost of paying a ransom
  • The cost of business interruption while systems are being restored
  • The cost of engaging forensics experts to determine what happened and how
  • The cost of notifying clients and offering credit monitoring
  • The cost of hiring legal counsel to defend against lawsuits
  • The cost of engaging media experts to minimize reputational damage
  • The cost of paying federal and municipal fines

Cyber insurance may be what keeps the business afloat after an attack. Learn more by reading “Cyber Insurance Coverages 101.”

How Much Does Cyber Insurance Cost?

The cost of cyber liability insurance for a small business generally starts at $2,500. For medium- and large-size businesses, the yearly premium could be a few thousand dollars to tens of thousands of dollars per $1 million in coverage. However, every organization is unique, and the cost will vary for each business.

Companies with shareholders should especially consider cyber coverage and limits carefully. Recently stakeholders brought suit against a company’s board members after a cyberattack. They alleged mismanagement because the company had not secured enough cyber insurance coverage, thinking it was too expensive.

Learn more by reading "Nine Cyber Risk Questions Every Board Should Ask."

Why Are Cyber Insurance Prices Rising?

This year alone, data from 5.4 million Twitter accounts, social security numbers of 2.5 million student loan borrowers, and the PII of 9.7 million current and past Medibank healthcare and insurance clients was breached. The severity and cost of cyberattacks like these, especially where ransomware is involved, have been key drivers of cyber insurance costs. The average data breach cost is now $4.35 million, a 12.7% increase since just 2020, according to IBM Security’s Cost of Data Breach 2022 Report.

Business email compromise (BEC) scams have also been on the rise. According to the FBI, between July 2019 and December 2021, actual and attempted BEC losses (U.S. dollars) increased by 65%. It’s no wonder, then, that cyber insurers have adjusted premium rates dramatically in recent years.

What Affects Cyber Liability Insurance Costs?

When considering cyber liability insurance premiums, insurers look at several factors, including what is happening in the market overall and the prospective client’s risk profile and claim history. Carriers also consider the following elements when determining whether to insure an organization and the cost of cyber liability insurance.

Industry

Some industries, such as healthcare, higher education, retail and manufacturing organizations, are targeted by cybercriminals more often than others. Organizations in these sectors store the types of data (e.g., social security numbers, credit card information, bank account numbers, etc.) most prized by threat actors, putting them at greater risk for a cyber event. In the case of manufacturers, cybercriminals know that companies lose a lot of money every hour a line is down and that chaos can quickly erupt, pressuring the organization to pay a high-dollar ransom quickly.

Number of Employees

The greater the number of employees, the more opportunities cybercriminals have to access a company’s sensitive information and infrastructure. Unfortunately, employees are the most significant cyber weakness in any organization.

Revenue

The more money an organization has, the more attractive it becomes to cybercriminals. However, smaller organizations are typically easier targets because they don’t usually have the in-house cybersecurity resources that larger organizations have. This makes small companies attractive, too.

Deductibles and Limits

As with most types of insurance, the deductible or retention (the amount a company will pay before its insurance kicks in) and the limits (the maximum amount the insurer will pay for a claim) impact the cost of the premium. Generally, the more risk an insured is willing to assume, the lower the premium. When a company is willing to assume more risk, it signals to the carrier that the organization is confident in its cybersecurity measures.

How to Manage Cyber Insurance Costs

While organizations cannot control all the factors driving the cost of cyber insurance, they can make themselves more attractive to insurers compared to others competing for available coverage and the best rates.

Insurers want proof that a company has done everything possible to prevent cyber events. These actions include developing an effective cyber incident response plan, training employees to recognize phishing scams, implementing multifactor authentication and endpoint detection and response, and regularly patching software.

Learn more by reading "Manage Cyber Risks and Limit Financial Losses."

How Hylant Can Help You

Hylant’s dedicated cyber risk and insurance team works with organizations to help them understand and address their cyber risks from an insurance perspective. We provide risk profiling, exposure quantification, insurance procurement and negotiation, risk readiness and incident response planning services. Working with our clients, we minimize cyber events’ potential financial and reputational impacts on their organizations.

To discuss your cyber insurance and risk management needs, contact Hylant today.

The above information does not constitute advice. Always contact your insurance broker or trusted advisor for insurance-related questions.

Why Does Cyber Insurance Cost So Much? (2024)

FAQs

Why is cyber insurance so expensive? ›

You could probably figure out the simple answer on your own: cyber insurance costs more because of the huge rise in data breaches and hacks in the post-COVID world. When the pandemic hit and employees started working remotely en masse, it created a cybersecurity crisis.

How much does cybercrime insurance cost? ›

How much does cyber insurance typically cost? For small businesses, annual cyber insurance premiums can range from $1,000 to $7,500. This range is dependent on several factors, which we discuss below. A recent survey found that the majority of cyber insurance underwriters expect rates to increase slightly in 2024.

What are the problems with cyber insurance? ›

However, the cyber insurance industry faces significant challenges, including a lack of historical data, a lack of ability to predict the future of cyber risk, the possibility of large cascading loss events, uncertainties among market participants about what is specifically covered under such policies, and legal ...

How do you explain cyber insurance? ›

Cybersecurity insurance (cyber insurance) is a product that enables businesses to mitigate the risk of cyber crime activity like cyberattacks and data breaches.

Is cyber security expensive? ›

Outsourced cybersecurity services typically begin at a minimum cost of $2,000 to $3,500 per month, with prices increasing depending on scope and complexity of services.

Is cyber insurance worth it? ›

Today, the average cost of cyber claims is substantial, far exceeding the average cost of cyber premiums. And considering the proactive and reactive services on offer, it's clear that cyber insurance is more than worth the money.

Does cyber insurance pay out? ›

Cyber insurance covers the liability actions that might be brought against you, arising out of a cyber event (third party loss), such as investigation and defence costs, civil damages, compensation payments to affected parties.

What is the cost of cyber crime? ›

cybersecurity as the single greatest threat to the global economy over the ensuing decade. Analysis from cybersecurity industry groups suggests that cyber attacks have a great impact on the global economy. According to one estimate, the global cost of cybercrime is estimated to top $8 trillion in 2023.

Will cyber insurance pay ransom? ›

Cyber insurance is an effective way to reduce cyber risk, protecting against financial loss, business interruption and cyber extortion—with ransomware having the potential to cause all three. As such, a good cyber policy does cover ransomware.

What cyber insurance doesn t cover? ›

Also, most cyber liability insurance policies don't cover your business for a decrease in company value. For example, your intellectual information could be stolen through digital crime. Without that information, your company becomes less valuable overall, but insurance providers will not cover that loss of value.

What are the advantages and disadvantages of cyber insurance? ›

Pros and Cons of Cyber Liability Insurance: A Quick Look
PROSCONS
Protection against financial lossesHigh cost
Legal protectionCoverage exclusions and limitations
Mitigates reputational damageFalse sense of security
Compliance with industry standards
Jul 14, 2023

Why purchase cyber insurance? ›

Cyber insurance, also known as cybersecurity liability insurance, allows businesses to manage the potential impact and cost of cyberattacks. By purchasing cybersecurity insurance and paying premiums, organizations transfer some of the risks associated with cyberattacks to the insurance company.

How much does cyber insurance cost? ›

The average cost of cyber insurance for a business is between $500 and $5,000 per year. The average annual premium for personal cyber insurance is between $300 and $1,200, depending on the level of coverage and the specific deductible you choose.

Are cyber insurance claims made? ›

However, many other types of business insurance policies are usually claims-made. For instance, errors and omissions, professional liability, directors and officers liability, employment practices liability and cyber coverage are typically claims-made policies.

Is cyber insurance mandatory? ›

Companies will be required to have cyber insurance policies in place to protect against cyber threats. Cyber insurance will be a mandatory requirement for businesses that want to do business with other companies. The cyber insurance market will continue to grow in 2024.

What is the average payout for cyber insurance? ›

The average cost of a cyber insurance claim for an SME is approximately $345,000.

Is cyber insurance going away? ›

The majority, 64%, agreed that the cyber insurance market will harden over the next 12 months, while 57% also expect cyber underwriting standards to rise. A significant 80% predict that cyber risks will increase over the next year, with 31% anticipating a significant surge.

How much cyber liability insurance do you need? ›

A data breach costs a business an average of $150 per lost or stolen record of customer PII. Most small businesses purchase a cyber liability insurance policy with a $1 million per-occurrence limit, a $1 million aggregate limit, and a $1,000 deductible.

Why do companies buy cyber insurance? ›

At a minimum, cyber liability insurance helps companies comply with state regulations that require a business to notify customers of a data breach involving personally identifiable information. Policies can also cover: Indemnification for legal fees and expenses. Customer notifications in the event of a breach.

Top Articles
Latest Posts
Article information

Author: Arielle Torp

Last Updated:

Views: 6347

Rating: 4 / 5 (41 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Arielle Torp

Birthday: 1997-09-20

Address: 87313 Erdman Vista, North Dustinborough, WA 37563

Phone: +97216742823598

Job: Central Technology Officer

Hobby: Taekwondo, Macrame, Foreign language learning, Kite flying, Cooking, Skiing, Computer programming

Introduction: My name is Arielle Torp, I am a comfortable, kind, zealous, lovely, jolly, colorful, adventurous person who loves writing and wants to share my knowledge and understanding with you.