
You may have seen this claim online:
“60% of small businesses close within six months of a cyberattack.”
I do not recommend publishing that statistic as fact.
It has been repeated widely for years, but there is no strong, current primary source establishing that 60% of small businesses actually close after a cyberattack.
A stronger and more credible introduction for Insurance Guide Book is:
“Cyberattacks can create severe financial and operational disruption for small businesses, which often have fewer resources available for recovery.”
That statement is supported by current evidence. Verizon’s 2026 Data Breach Investigations Report says small organizations are disproportionately affected by ransomware and often have fewer resources available to respond.
Why Cyber Risk Is a Small-Business Problem
Many business owners still picture cybercriminals targeting:
banks + multinational corporations + government agencies.
But small businesses are attractive targets too.
They may store:
- Customer names
- Email addresses
- Payment information
- Employee records
- Login credentials
- Financial information
- Proprietary business data
And smaller organizations don’t necessarily have:
24/7 security teams + dedicated incident-response departments + large cybersecurity budgets.
Verizon’s 2026 DBIR analyzed thousands of incidents affecting small and medium-sized organizations and found ransomware remains a disproportionate problem for smaller organizations.
So the question isn’t simply:
“Could somebody hack us?”
A more useful question is:
“If something happens tomorrow, can we afford the recovery?”
That’s where cyber insurance enters the conversation.
What Is Cyber Liability Insurance?
Cyber insurance is designed to help businesses manage certain financial consequences arising from cyber incidents.
But “cyber insurance” isn’t one single standardized package.
Policies can differ substantially.
The FTC recommends that businesses consider whether they need:
first-party coverage, third-party coverage, or both.
Understanding that distinction is essential before deciding whether:
$1 million is enough.
First-Party Cyber Coverage
First-party coverage generally addresses losses suffered directly by your business.
According to the FTC, this can include costs associated with:
- Legal counsel
- Data recovery
- Customer notification
- Call-center services
- Lost income from business interruption
- Crisis management
- Public relations
- Cyber extortion
- Fraud
- Forensic investigation
- Certain fees, fines and penalties
Imagine your company’s systems are encrypted by ransomware.
Your immediate expenses might include:
Forensic investigation
↓
System restoration
↓
Legal consultation
↓
Customer notification
↓
Business interruption
↓
Public relations
A serious cyber incident can therefore generate multiple expenses simultaneously.
Third-Party Cyber Liability
Now imagine hackers steal customer information.
Customers allege that your company failed to protect their data.
That creates a different category of exposure.
Third-party cyber coverage can potentially address costs associated with:
- Claims from affected individuals
- Lawsuits
- Legal defense
- Regulatory inquiries
- Settlements
- Judgments
- Certain related expenses
The FTC specifically identifies these types of expenses when explaining third-party cyber coverage.
So a good cyber policy may need to protect both:
Your company’s own financial losses
and
Your liability to other people.
Why $1 Million Is a Common Starting Point
A small company shopping for cyber insurance may receive options such as:
$250,000
$500,000
$1 million
$2 million
$5 million
or higher.
Seeing a $1 million limit can feel reassuring.
After all:
$1,000,000 sounds like a lot of money.
For some small businesses, it may indeed provide substantial protection.
For others, it could be inadequate.
The correct question isn’t:
“Is $1 million a good cyber limit?”
It is:
“What could one realistic cyber incident cost my particular business?”
The Anatomy of a Cyber Claim
Consider a hypothetical online retailer.
It has:
25 employees
40,000 customer records
$4 million annual revenue
and relies heavily on its website for sales.
A ransomware attack shuts its systems down.
Potential costs could include:
Forensic Investigation
Cybersecurity specialists need to determine:
- What happened?
- How did attackers enter?
- What systems were affected?
- Was information stolen?
- Is the attacker still inside?
Legal Counsel
Specialist lawyers may need to determine:
- Notification obligations
- Regulatory requirements
- Contractual obligations
- Potential liability
Data Restoration
Servers, databases, applications and backups may need restoration.
Business Interruption
The website may be unavailable.
Orders stop.
Revenue falls.
Customer Notification
Affected customers may need to be notified depending on applicable laws and circumstances.
Crisis Management
Customers may begin asking:
“Is my information safe?”
The business needs a coordinated response.
Third-Party Claims
Customers or business partners may pursue claims.
Regulatory Response
Regulators may become involved depending on the data, jurisdiction and incident.
Suddenly:
$1 million doesn’t look quite as enormous.
Don’t Use IBM’s Average as Your Insurance Limit
IBM reported that the global average cost of a data breach in its 2025 research was approximately:
$4.44 million.
For the United States, the reported average was:
$10.22 million.
Those are striking numbers.
But they do not mean the average small business needs a $10 million cyber policy.
IBM’s study covers organizations and incidents of different sizes and characteristics.
Using a broad breach average as your personal insurance-limit recommendation would be misleading.
Instead, use your company’s actual exposure.
Start With Your Data
Ask:
How much sensitive information do we hold?
Consider:
- Customer records
- Employee records
- Payment information
- Health information
- Financial information
- Login credentials
- Confidential client files
A company storing:
500 relatively basic customer records
may have a very different exposure from one holding:
500,000 sensitive records.
Then Consider Your Revenue Dependency
This is often overlooked.
Suppose your business generates:
$30,000 per day.
A cyberattack takes your systems offline for:
10 days.
Potential lost revenue:
$300,000.
And that’s before considering:
forensics + legal fees + restoration + notification + PR + liability.
For a company highly dependent on technology, business-interruption exposure can consume a large portion of a cyber limit.
Ask How Long You Could Operate Offline
This is a powerful question.
Could your company function for:
1 hour?
Probably.
1 day?
Maybe.
1 week?
Problem.
30 days?
Potentially catastrophic.
Businesses especially vulnerable to downtime include:
- E-commerce stores
- SaaS companies
- Online marketplaces
- Medical practices
- Professional-services firms
- Payment processors
- Logistics companies
- Digital agencies
- Technology businesses
For these companies, cyber insurance shouldn’t be evaluated only as:
data-breach insurance.
Downtime may be equally important.
Ransomware Remains a Major Concern
Verizon’s 2026 DBIR reported that ransomware appeared in 48% of breaches in its dataset, up from 44% the previous year. It also found continued disproportionate effects on smaller organizations.
This makes ransomware coverage an important area to review.
But don’t ask only:
“Does my policy cover ransomware?”
Ask:
“Exactly which ransomware-related expenses are covered?”
Those are different questions.
Cyber Extortion Coverage
A cyber policy may potentially address expenses associated with an extortion event.
But check:
- Extortion sublimit
- Consent requirements
- Incident-response requirements
- Sanctions-related restrictions
- Exclusions
- Waiting periods
- Deductible or retention
The FTC specifically recommends asking whether a cyber insurer will help pay ransom demands in ransomware situations.
Coverage remains subject to policy terms and applicable law.
Business Interruption May Be More Important Than Ransom
Imagine:
Ransom demand: $100,000
but:
Lost income during recovery: $450,000.
The ransom isn’t necessarily the largest financial problem.
That’s why businesses should carefully examine:
Cyber business interruption coverage.
The FTC lists lost income from business interruption among expenses that first-party cyber insurance may cover.
Check how your policy defines:
Waiting period
Covered interruption
Period of restoration
Net income
Continuing expenses
Dependent business interruption
Your Vendor Can Be Hacked Instead of You
Here’s another scenario.
Your company’s network is secure.
But your:
cloud provider
or
payment processor
or
software vendor
gets compromised.
Your business stops operating.
Verizon’s 2026 DBIR reported that breaches involving third parties rose 60% from the previous year’s dataset and reached 48% of breaches.
The FTC also specifically recommends checking whether cyber insurance covers attacks involving data held by vendors and other third parties.
This makes third-party dependency increasingly important.
Ask About Dependent Business Interruption
Suppose your website depends on a cloud provider.
The cloud provider suffers a covered cyber event.
Your systems are fine.
But:
your website goes offline anyway.
Does your cyber policy respond?
Potentially—but don’t assume.
Look for coverage commonly described as:
Dependent Business Interruption
or similar terminology.
Check the actual wording.
Social Engineering Is Another Major Gap
Consider this example.
Your finance employee receives an email appearing to come from the CEO:
“Urgent. Transfer $175,000 to this supplier today.”
The employee complies.
Later, everyone discovers:
the email was fraudulent.
Is that covered?
Maybe.
But cyber policies and crime policies may treat social-engineering losses differently.
You need to check:
- Social engineering coverage
- Funds transfer fraud
- Computer fraud
- Crime coverage
- Applicable sublimits
- Verification requirements
Don’t assume:
“It involved a computer, so cyber insurance covers it.”
Watch the Sublimits
This is one of the biggest traps.
Your declarations page says:
Cyber Liability Limit: $1,000,000.
Excellent.
Then you read further:
Social Engineering: $100,000
Cyber Extortion: $250,000
PCI Expenses: $100,000
Reputational Loss: $50,000
The headline:
$1 million
doesn’t necessarily mean every type of cyber loss has $1 million available.
Always review:
sublimits.
Does Defense Cost Reduce Your Limit?
This can make a huge difference.
Suppose your policy has:
$1 million limit.
A cyber liability lawsuit generates:
$300,000 legal defense costs.
If defense costs are:
inside the limit,
you may have only:
$700,000
remaining for covered settlements or other amounts subject to the same limit.
Ask:
Are defense costs inside or outside my policy limit?
Never assume.
Understand Your Retention
Cyber policies often have a:
retention
similar in concept to a deductible.
Suppose:
Covered claim: $150,000
Retention: $25,000
Your business may need to absorb the first:
$25,000
before applicable insurance responds according to the policy.
Choose a retention your company could realistically fund during a crisis.
Is $1 Million Enough for a Freelancer?
Potentially.
Imagine an independent marketing consultant who:
- Has no employees
- Holds relatively little sensitive information
- Has modest revenue
- Uses reputable cloud services
- Maintains good cybersecurity
- Has limited contractual cyber exposure
A $1 million limit could potentially be substantial relative to the company’s exposure.
But even here:
review the policy rather than relying on the number.
Is $1 Million Enough for an E-Commerce Business?
The answer becomes more complicated.
An online retailer may have:
- Large customer database
- Payment-related exposure
- Heavy website dependency
- Third-party vendors
- Business-interruption risk
- Privacy obligations
- International customers
For such a company, $1 million may or may not be sufficient.
You need a realistic loss scenario.
Is $1 Million Enough for a Medical Practice?
Potentially sensitive exposure can be much greater.
A medical practice may hold:
- Patient identities
- Health information
- Insurance information
- Billing information
- Employee records
It may also face industry-specific privacy and regulatory requirements.
A generic:
“Every small business needs $1 million”
recommendation would therefore be inappropriate.
Is $1 Million Enough for a SaaS Company?
Again, perhaps—but not automatically.
A SaaS business may have relatively few employees while supporting:
thousands of customers.
If a cyber event causes customer downtime, potential claims can extend beyond the company’s own recovery costs.
Contractual obligations become extremely important.
Review:
customer contracts + limitation-of-liability clauses + service-level agreements + cyber policy.
Revenue Isn’t the Only Measure
A company with:
$2 million revenue
could potentially have more cyber exposure than another company with:
$10 million revenue.
Why?
Because cyber exposure depends on:
data + operations + contracts + technology dependency + industry + customers.
Revenue is only one factor.
Build a Realistic Worst-Case Scenario
Instead of randomly selecting:
$1 million
try this exercise.
Estimate a serious but plausible incident.
| Potential Expense | Example |
|---|---|
| Forensics | $100,000 |
| Legal & Privacy Response | $100,000 |
| Data Restoration | $150,000 |
| Notification & Monitoring | $100,000 |
| Business Interruption | $300,000 |
| Crisis Management | $50,000 |
| Third-Party Claims | $300,000 |
| Potential Total | $1,100,000 |
These numbers are illustrative only, not industry averages.
But the exercise reveals something important.
A $1 million limit could be exhausted without the incident becoming a spectacular multinational breach.
Another Business Could Need Far Less
Consider a small local contractor.
The company:
- Stores minimal customer data
- Doesn’t process online payments
- Can operate manually for several days
- Has 5 employees
- Has limited contractual exposure
Its realistic cyber loss scenario might be significantly lower.
That’s why cyber limits should be:
exposure-based
rather than:
headline-based.
A Simple Cyber Limit Formula
There’s no universal formula, but businesses can start with:
Incident response costs
Data restoration
Business interruption
Potential customer notification
Potential legal liability
Regulatory exposure
Contractual obligations
Vendor-related exposure
=
Estimated severe cyber loss
Then compare that estimate with:
policy limit + sublimits + retention + exclusions.
Don’t Forget Aggregates
Your policy may have an:
aggregate limit.
Suppose you experience:
Incident 1 — $400,000
and later:
Incident 2 — $750,000.
If both draw from a:
$1 million annual aggregate,
you may encounter a coverage problem.
Businesses should understand both:
per-incident limit
and
aggregate limit.
Cyber Insurance Isn’t a Substitute for Cybersecurity
Buying $5 million of insurance while using:
password123
is not a risk-management strategy.
Insurers increasingly expect businesses to maintain cybersecurity controls.
Common controls may include:
- Multi-factor authentication
- Regular backups
- Software patching
- Endpoint protection
- Access controls
- Employee training
- Incident-response planning
- Vendor-risk management
The FTC recommends regular software updates, backups, cybersecurity policies and third-party risk assessments as part of small-business cybersecurity.
MFA Matters
Multi-factor authentication adds another verification step beyond a password.
This can make stolen credentials less useful to attackers.
Businesses should prioritize MFA for:
- Remote access
- Cloud systems
- Administrator accounts
- Financial systems
A strong cyber-insurance application should accurately describe your controls.
Never claim you have a security measure that isn’t actually implemented.
Backups Need to Be Recoverable
A company says:
“We’re safe. We have backups.”
Then ransomware strikes.
The company discovers:
the backups were also encrypted.
A backup strategy should consider:
- Frequency
- Isolation
- Access control
- Testing
- Restoration procedures
A backup you cannot restore isn’t much of a backup.
Create an Incident Response Plan
Imagine discovering ransomware at:
2:00 AM Saturday.
Who gets called?
Your:
IT provider?
Cyber insurer?
Attorney?
CEO?
Forensics company?
Don’t decide this during the attack.
The FTC recommends checking whether your cyber insurer provides a 24-hour breach hotline.
Save that number somewhere accessible even if your systems are offline.
Know Your Insurer’s Response Requirements
Some policies may require you to contact the insurer before hiring:
lawyers + forensic investigators + PR firms + negotiators.
The insurer may have an approved vendor panel.
If you hire outside providers without authorization, reimbursement could potentially become complicated depending on the policy.
Know the process before an incident.
Questions to Ask Before Buying Cyber Insurance
Ask your broker:
- Does the policy cover both first-party and third-party losses?
- What is the total aggregate limit?
- What sublimits apply?
- What is the retention?
- Are defense costs inside the limit?
- Is ransomware covered?
- What cyber-extortion limit applies?
- Is social engineering covered?
- Is funds-transfer fraud covered?
- Is business interruption covered?
- What waiting period applies?
- Is dependent business interruption covered?
- Are cloud-provider outages covered?
- Are third-party vendor breaches covered?
- Are regulatory investigations covered?
- Are notification expenses covered?
- Are forensic expenses covered?
- Is data restoration covered?
- Is reputational harm covered?
- Is there a 24/7 incident-response hotline?
The FTC specifically recommends evaluating first-party and third-party protection, data breaches, third-party data incidents, litigation/regulatory defense and breach-response support.
Signs $1 Million May Be Too Low
Consider evaluating higher limits if your business:
- Stores large amounts of sensitive data
- Processes significant online transactions
- Depends heavily on digital systems
- Could lose substantial revenue during downtime
- Serves large corporate clients
- Has contractual cyber requirements
- Operates in a regulated industry
- Depends heavily on cloud providers
- Has significant third-party liability exposure
- Would face expensive customer notification
- Has operations across multiple jurisdictions
None automatically means you need more than $1 million.
They mean:
run the numbers.
Signs $1 Million Might Be Reasonable
A $1 million limit may deserve consideration when:
- The business is relatively small
- Sensitive-data volume is limited
- Downtime exposure is modest
- Contractual liabilities are limited
- Strong cybersecurity controls are in place
- Your realistic loss modelling falls comfortably within the limit
Again, that’s not a recommendation that $1 million is sufficient.
Your broker or insurance professional should evaluate your actual exposure.
Cyber Insurance Checklist for 2026
Before renewing:
- Inventory sensitive data.
- Estimate daily revenue dependency.
- Calculate realistic downtime exposure.
- Identify critical vendors.
- Review customer contracts.
- Review regulatory obligations.
- Confirm first-party coverage.
- Confirm third-party liability coverage.
- Review ransomware protection.
- Review social-engineering coverage.
- Check business interruption.
- Check dependent business interruption.
- Review sublimits.
- Review retention.
- Check whether defense costs reduce the limit.
- Confirm incident-response procedures.
- Enable MFA where appropriate.
- Test backups.
- Patch critical systems.
- Train employees.
- Compare several coverage-limit options.
Frequently Asked Questions
Do 60% of small businesses really close after a cyberattack?
There isn’t strong current primary-source evidence supporting the widely repeated claim that 60% of small businesses close within six months of a cyberattack. Avoid presenting it as an established statistic.
There is, however, strong evidence that cyberattacks present substantial risks to smaller organizations. Verizon’s 2026 DBIR specifically reports that small organizations are disproportionately affected by ransomware.
Is $1 million of cyber insurance enough?
It can be enough for some businesses and insufficient for others. Consider data volume, business-interruption exposure, regulatory obligations, customer contracts, third-party liability and applicable sublimits.
What does small-business cyber insurance cover?
Depending on the policy, first-party coverage may address forensics, legal assistance, data recovery, notification, business interruption, crisis management and cyber extortion. Third-party coverage can address claims and lawsuits from others.
Does cyber insurance cover ransomware?
Some policies provide ransomware-related protection, but coverage terms, sublimits, exclusions and legal restrictions vary. Review the actual contract.
Does cyber insurance cover lost income?
Cyber business-interruption coverage can potentially cover qualifying lost income following a covered cyber incident. The FTC identifies lost income from business interruption as a potential first-party cyber coverage.
Does cyber insurance cover a hacked vendor?
Some policies may provide relevant coverage for incidents involving third-party vendors or dependent businesses. The FTC specifically recommends checking protection for cyberattacks involving data held by vendors and third parties.
Does cyber insurance cover phishing?
Potentially, but don’t assume it does. Social-engineering and funds-transfer fraud losses can have separate coverage provisions and relatively low sublimits.
How much cyber insurance should a small business buy?
There is no universal amount. Estimate a severe but realistic cyber incident and compare the potential total cost with available limits, sublimits, deductibles/retentions and exclusions.
Final Thoughts
The biggest mistake a small business can make isn’t necessarily buying:
$1 million instead of $2 million.
It’s choosing a number without understanding the exposure behind it.
Your cyber limit should reflect:
How much data do you hold?
How long could you survive offline?
How much revenue could you lose?
What could customers claim against you?
What do your contracts require?
What sublimits exist inside the policy?
A $1 million policy could be substantial protection for one small company and dangerously inadequate for another.
And don’t build the article—or your insurance decision—around the questionable:
“60% of small businesses close after a hack”
statistic.
The current evidence is compelling enough without it: Verizon’s 2026 research shows ransomware continues to disproportionately affect smaller organizations, while the FTC warns that recovering from a cyberattack can be costly.
The better strategy is:
Strong cybersecurity + realistic loss modelling + appropriate insurance coverage + a tested incident-response plan.
