You finally sit down to buy a policy, and the quote gives you a menu of limits. One million dollars. Two million. Five hundred thousand for a little less money. And there you are, with no real way to tell whether you are protecting your business or paying for coverage you will never touch. Pick too low and a single bad week could blow straight through it. Pick too high and you are handing a carrier money you could have kept.
Here is the reassuring part. Sizing your coverage is not a guess, and you do not need an actuary to do it. A handful of plain questions about your data, your revenue, and who you answer to will point you at a number you can trust. Most small businesses land at a one million dollar limit, but plenty need less and some need more, and the point of this guide is to help you tell which one you are.

First, picture what a bad day actually costs
Before you can size a limit, you need a feel for the bill you are insuring against. A cyber claim is rarely one charge. It is a stack of them that lands over a few weeks.
A typical small business incident pulls in a forensics team to find out what happened, a lawyer to tell you who you have to notify, notification letters and credit monitoring for affected customers, and lost income while you are down. If ransomware is involved, add recovery and possibly a ransom decision on top. The average paid cyber claim ran near $116,000 in 2025, and for small businesses specifically the typical claim sat closer to $79,000. But averages hide the tail. Serious breaches at small firms have run well past a million dollars once legal, regulatory, and downtime costs pile up.
That spread is exactly why a single vague number does not work. Your job is not to cover the average. It is to cover the version of a bad day that would actually threaten your business.
How much cyber insurance do I need? The quick answer
For most small businesses, a good starting point is a one million dollar per claim and one million dollar aggregate policy. That is the standard limit carriers write for firms under about 250 employees, and it covers the great majority of incidents at that size.
You can reasonably size down toward $500,000 if you are a very small, low data operation, and you should size up toward two million dollars or more if you hold a lot of sensitive records, work in a regulated field, or have client contracts that demand it. So when you ask how much cyber insurance do I need, the honest answer is that one million is the sensible default, and the four questions below tell you whether to move off it.
The four questions that set your number
Run through these before you look at a single quote. Together they turn a fuzzy worry into a real limit.
1. How much sensitive data do you hold?
Data is the single biggest driver of a breach bill, because notification, credit monitoring, and regulatory exposure all scale with the number of records you lose. A business sitting on tens of thousands of customer records, card numbers, or health files carries far more risk than one that stores almost nothing. In the United States, breach costs have been running in the range of a few hundred dollars per record once you add up response, notification, and legal work. Do the rough math on your own record count and the number gets real fast.
2. What is your annual revenue?
Revenue is a proxy for how much you have to lose and how long you could survive a shutdown. It also drives how carriers price you. A rough field rule many brokers use is to carry a limit somewhere in the neighborhood of your annual revenue for a typical small firm, then adjust up if your data or industry is high risk. A shop doing $800,000 a year with light data might be fine at $500,000 to $1,000,000. A firm doing several million with sensitive records is squarely in two million dollar territory.
3. What industry are you in?
Some fields simply cost more when they break. Medical practices carry protected health information and HIPAA exposure. Law firms and accountants hold client money and confidential files. Online retailers process card data. If you are in one of those higher risk categories, you should lean toward the top of your range, because both the likelihood and the price of a claim run higher.

4. Do any contracts require a minimum limit?
This one quietly decides the answer for a lot of owners. If you sell to larger companies, government bodies, or anyone with a procurement team, your contract may already spell out a required cyber limit, often one million or two million dollars. Vendors and enterprise clients increasingly make coverage a condition of doing business. Check your existing agreements before you buy, because a contract minimum overrides every other rule of thumb here.

A simple sizing worksheet
Put the four answers together and you get a starting limit. When you are working out how much cyber insurance you need, use this as a first pass, then let your data and contracts push you up.
| Business profile | Sensible starting limit |
|---|---|
| Very small, little sensitive data, under about $500K revenue | $500,000 |
| Typical small business, some customer data, under 250 staff | $1,000,000 |
| Holds lots of records, card data, or health data | $1,000,000 to $2,000,000 |
| Regulated field, enterprise clients, or a contract minimum | $2,000,000 or more |
Notice the ranges overlap. That is on purpose. Two businesses the same size can land in different places depending on their data and their clients, which is why the questions matter more than the head count.
If you want to pressure test your number, you can check what a given limit actually costs and see whether stepping up a tier is cheaper than you expect. It often is, because most of your premium pays for the first dollars of coverage, not the last.
Watch the sublimits, not just the big number
Here is the trap that catches careful owners. You buy a two million dollar policy, feel covered, and then discover the parts you were most worried about are capped far below that.
A sublimit is a smaller cap sitting inside your main limit for a specific kind of loss. Your two million dollar policy might pay only $250,000 toward a ransom, or cap wire fraud and social engineering losses at $100,000 to $250,000. When a scammer tricks your bookkeeper into wiring $300,000 to a fake vendor, that sublimit is the number that pays, not the headline limit. The rest is yours.
The three sublimits worth reading closely are ransomware, social engineering or wire fraud, and business interruption. Business interruption matters because lost income is now one of the biggest drivers of cyber claims, and many policies also add a waiting period of 8 to 12 hours before that coverage even starts. Losses in that first window come out of your pocket. So when you compare quotes, do not just compare the big number. Ask your broker to walk every sublimit, and treat a policy with a healthy main limit but a tiny ransomware or wire fraud sublimit as the gap it really is. Our plain English coverage guide and the glossary break these terms down further if any of them are new.

When more coverage is worth it, and when it is overkill
More limit is not always the smart buy. Once your main limit comfortably clears your realistic worst case, extra millions mostly add premium without adding real protection. The better money is often spent raising a thin sublimit, shortening a waiting period, or buying the security controls that lower your price in the first place.
Lean toward a higher limit when you hold sensitive data at scale, operate in a regulated field, depend on a few systems that would freeze the whole business if they went down, or serve clients who could sue you after a breach. Lean toward a leaner limit when you store little, your revenue is modest, and a bad incident would be painful but survivable out of cash flow.

One more thing that changes the math. Carriers price you partly on your security, so meeting the controls insurers now expect, things like multi factor authentication, tested backups, and an incident response plan, can let you buy a stronger limit for a similar price. Good security does not just lower your risk. It lowers your cost of covering it.
Key takeaways
Sizing your policy comes down to a short, honest look at your own risk.
- One million dollars is the sensible default for most small businesses, with $500,000 for very small low data firms and two million or more for high risk or regulated ones.
- Let four things set your number: how much sensitive data you hold, your revenue, your industry, and any contract minimums.
- Read the sublimits for ransomware, wire fraud, and business interruption. A high main limit means little if the part you need is capped low.
- Beyond your worst realistic case, extra limit adds cost more than protection. Fix thin sublimits and strengthen security instead.
- Review your limit every year, because your data, revenue, and contracts all move.
Frequently asked questions
Is one million dollars enough cyber insurance for a small business?
For most small businesses, yes. A one million dollar per claim and aggregate limit is the standard carriers write under 250 employees, and it covers the large majority of incidents at that size. Step up if you hold a lot of sensitive records, work in a regulated field, or have a contract that requires more.
How do I calculate how much cyber insurance I need?
Start with four questions: how many sensitive records you hold, your annual revenue, your industry risk, and whether any client contract sets a minimum. A typical small firm starts around one million dollars, then moves up if data, industry, or contracts push it there. Your broker can model a limit against your specific exposure.
What is the difference between a limit and a sublimit?
Your limit is the most the policy will pay in total. A sublimit is a smaller cap inside it for a specific loss, like ransomware or wire fraud. A two million dollar policy can still cap a ransom payment at a few hundred thousand, so the sublimit, not the headline number, is what pays for that kind of claim.
Does more coverage always cost a lot more?
Not usually. Most of your premium buys the first layer of coverage, so stepping from one million to two million often costs less than owners expect. Strong security controls can offset the difference, which is why it is worth pricing a higher limit before ruling it out.
How often should I review my coverage?
At least once a year, and any time your business changes in a big way. Growing revenue, new customer data, a move into a regulated service, or a new enterprise contract can all mean your old limit no longer fits.



