Calculator
Cyber liability insurance cost calculator
Answer eight questions and see a realistic annual premium range for a standalone cyber liability policy, broken into the line items an underwriter actually prices.
Your business
Gross revenue for the coming policy year.
Count every record you store or process, including customer data held on behalf of clients.
Security posture
Estimated annual premium range
$3,850 to $7,600
Ranges are wide on purpose. Two similar companies can be quoted 40 percent apart depending on the carrier appetite that week.
Pursuing SOC 2 or ISO 27001? Estimate those separate costs at Cost of Compliance.
| Line item | Range |
|---|---|
| Base premium for revenue and industrySoftware and SaaS at $5,000,000 in annual revenue | $3,375 to $5,725 |
| Headcount exposure25 employees on the network | $100 to $175 |
| Data volume load10,000 to 100,000 records | $0 to $0 |
| Security control adjustmentMFA in place, tested backups, no EDR | $425 to $700 |
| Claims history loadNo prior claims | $0 to $0 |
| Limit and sublimit load$1,000,000 aggregate limit | $0 to $0 |
| Policy fees, taxes and surchargesBroker fee, surplus lines tax and stamping | $275 to $450 |
Assumptions behind this number
- Retention assumed at $25,000, which is typical for this revenue band.
- Full first party and third party cyber form, including ransomware and business interruption with a waiting period of 8 to 12 hours.
- United States domiciled buyer, no operations in sanctioned territories, and no critical infrastructure exposure.
- Pricing anchored to 2026 renewal data in a soft to flat market. Rates move with loss activity and can change quickly.
How we estimate this
The model starts with a rate per million of revenue and then adjusts it. Rate per million falls as revenue rises, because larger accounts buy limits that are small relative to their size. A company at 2 million in revenue often pays close to 1,200 dollars per million of revenue, while a company at 50 million pays a fraction of that rate.
What moves the number most
- Industry. Healthcare, public sector and financial services carry the highest loads because the regulatory cost of a breach is higher and ransomware actors target them.
- Data volume. Breach response cost scales with record count. Notification, credit monitoring and forensics all price per record.
- Security controls. Missing multi factor authentication is the single most expensive gap. Many carriers will decline the risk outright rather than load the premium.
- Claims history. A prior ransomware event usually adds 25 to 40 percent and can force a higher retention.
- Limit. Moving from 1 million to 5 million does not cost five times more. Higher layers price at a discount because they are less likely to be reached.
Where the data comes from
Rate curves are anchored to published 2026 market commentary from brokers and rating agencies, plus a set of anonymised quotes shared with us by buyers. We refresh the curves quarterly and publish the change log on the methodology page.
What this is not
This is an educational estimate, not a quote. Only a carrier can bind coverage. We do not sell leads, we do not accept broker sponsorships and we take no referral fees from anyone in the insurance chain.