Pricing guide

How much does cyber insurance cost in 2026

Most small companies pay between 1,200 and 7,500 dollars a year for a 1 million dollar limit. Here is why the spread is so wide and where you are likely to land.

Updated August 2026. About a 9 minute read. Written by the Cost of Cyber Insurance editorial desk.

Cyber insurance pricing settled down in 2026 after several volatile years. Rates rose sharply through the ransomware surge, then fell as capacity returned to the market. Buyers with clean controls are now renewing flat or slightly down, while buyers with gaps are still paying a premium for those gaps or being declined outright.

Typical annual premiums by company size

The figures below assume a 1 million dollar aggregate limit, a standard retention for the size band, and a company with multi factor authentication, tested backups and no losses in the last five years.

  • Under 1 million in revenue. Roughly 800 to 2,200 dollars a year. Many carriers write this band through a simple application with fewer than a dozen questions.
  • 1 to 10 million in revenue. Roughly 1,800 to 7,500 dollars a year. This is where the security questionnaire starts to matter.
  • 10 to 50 million in revenue. Roughly 7,000 to 25,000 dollars a year, and most buyers move to a 2 million or 5 million limit here.
  • Over 50 million in revenue. Usually 25,000 dollars and up, often built as a tower with a primary layer and excess layers above it.

What actually moves your premium

Security controls

Controls carry more weight than any other single factor in 2026. Multi factor authentication on email, remote access and privileged accounts is effectively a condition of entry. Tested offline or immutable backups come next, followed by endpoint detection and response, email filtering and a documented incident response plan. A company that can evidence all five will see quotes 25 to 40 percent below an identical company that cannot.

Industry and data

Healthcare, education, public sector and financial services attract the highest loads. Breach response cost scales with the number of records you hold, because notification, forensics and credit monitoring are all priced per record.

Claims history

A prior ransomware event typically adds 25 to 40 percent, and often comes with a higher retention or a ransomware sublimit until you can show two clean years.

Where the money goes inside the policy

A modern cyber form bundles several covers into one premium. First party covers pay your own costs: incident response, forensics, business interruption, data restoration and, where legally permitted, extortion payments. Third party covers pay other people: privacy liability, regulatory defence and fines where insurable, and payment card penalties. Most of the premium sits in the first party side, because that is where the frequency is.

How to reduce what you pay

  • Close the control gaps before you go to market, not after the quote comes back.
  • Prepare a short security narrative. Underwriters reward a clear story about what you do and how you would respond to an incident.
  • Test whether a higher retention pays for itself. Going from 5,000 to 25,000 dollars often cuts 10 to 15 percent off the premium.
  • Start the renewal 60 days out so you have time to market the risk properly.

Run your own numbers with the cyber liability insurance cost calculator and read the methodology for the assumptions behind every figure on this page.