top of page

How to Buy Cyber Insurance?

May 18, 2022
7 min read

Updated: Aug 18

Infographic: How to Buy Cyber Insurance; man at laptop reviews papers, with 3-step guide and Kosh Solutions logo.
Updated August 18, 2026

Many customers ask us, “Where can I buy cyber insurance?”, “How much cyber insurance do I need?”, or simply, “Is there insurance for cyberattacks?”


To help answer those questions, we originally asked insurance brokers in New Mexico and Orange County to walk us through what purchasing cyber insurance looks like.

Cyber insurance still isn't as standardized as something like auto insurance, but the basic buying process is fairly familiar.


There are three main steps:

  1. Determine your risks and how much coverage you may need

  2. Have your insurance broker obtain and compare coverage options

  3. Have your IT or cybersecurity provider verify that your technology matches the application and underwriting requirements


We'll walk through each step below.


Related Articles


Before You Start: Get the Cyber Insurance Application

Nickie Tran, President of IQ Risk Insurance Services, gave us useful advice when we originally developed this article:

Start with the cyber liability application.

The application can act as a mini risk-assessment exercise because it forces the business to answer questions about its data, technology, security controls, previous incidents, backups, employees, and other exposures.


It also tells you what that particular insurer is actually interested in.


Cyber insurers may use different applications and supplemental questionnaires depending on the organization and the type of risk. Travelers, for example, currently publishes separate application materials addressing areas including MFA, social-engineering fraud, payment cards, healthcare, and renewals.


Get the application from your broker early, rather than waiting until renewal is due.

Then involve your IT provider in the technical questions.


Step 1 – Determine How Much Coverage You Need

Cyber insurance isn't only for large businesses.


The more useful question is:

What could a serious cyber incident realistically cost your organization?

There are two broad categories to think about:

  1. First-party costs — losses your own business incurs

  2. Third-party costs — claims or liabilities involving customers, employees, vendors, or others


First-Party Costs

These are costs your organization may experience directly following a cyber incident.

They can include:


Cybersecurity and forensic response

You may need specialists to:

  • Determine how the attacker gained access

  • Contain the incident

  • Determine which systems or data were affected

  • Remove malicious software or attacker access

  • Restore systems and data


Business interruption

This may be one of the largest exposures for many businesses.

Ask yourself:


How much would one day without your critical technology cost?

Consider:

  • Lost revenue

  • Employee downtime

  • Delayed projects

  • Missed customer appointments

  • Lost sales opportunities

  • Overtime and recovery expenses

  • Customer churn

  • Reputational impact


A business that can function manually for several days has a very different exposure from one whose operations stop completely when its systems go offline.


Data restoration

What would it cost to recreate or restore critical files, applications, databases, or systems?


Breach response

A privacy incident may require:

  • Legal counsel

  • Forensic investigation

  • Customer notification

  • Credit or identity monitoring

  • Regulatory response

  • Crisis communications


Cybercrime and fraudulent transfers

Business email compromise and funds-transfer fraud deserve particular attention today.

An attacker may impersonate an executive, compromise a vendor's email account, change payment instructions, or trick an employee into wiring money to a fraudulent account.


Coalition's 2026 claims data found that business email compromise and funds-transfer fraud together represented 58% of its claims.


Ask yourself:


What is the largest payment our company could realistically send based on fraudulent instructions?

That number may help guide your conversation about social-engineering and funds-transfer limits.


Third-Party Costs

A cyber incident can also create liability to others.


Examples include:

  • A customer claiming your breach exposed their personal information

  • An employee alleging sensitive information was mishandled

  • A customer suffering financial loss after fraudulent messages were sent from a compromised company account

  • Regulatory investigations

  • Lawsuits related to privacy or security

  • Attorney's fees and defense costs


For companies in healthcare, finance, professional services, technology, and other data-sensitive industries, these exposures can be particularly important.


How Much Does Cyber Insurance Cost?

Our original version of this article gave a rough formula for calculating premiums based on the amount of coverage purchased.


We no longer recommend using a formula like that.


Cyber insurance pricing can vary considerably based on factors such as:

  • Revenue

  • Industry

  • Type and amount of sensitive information

  • Coverage limits

  • Retention or deductible

  • Previous cyber incidents and claims

  • Security controls

  • Geographic exposure

  • The specific coverage being purchased


At the time of this 2026 update, the cyber insurance market is relatively favorable for buyers. Marsh reported that global cyber insurance rates declined 4% in the second quarter of 2026, marking the twelfth consecutive quarter of rate decreases. It also reported that buyers were often able to pursue broader coverage, higher limits, and reduced retentions.


But averages don't tell you what your business will pay.


The most useful pricing information will come from actual quotes based on your organization's risk profile.


Step 2 – Receive and Review Quotes

Once you have a better understanding of your potential exposure, your insurance broker can shop the market and obtain coverage options.


Our original recommendation was to get at least three quotes.


That's still a reasonable goal when appropriate, but the more important point is to compare multiple viable options rather than simply accepting the first premium presented.


Nickie Tran explained the value of having the broker, business, and IT provider work together:

“We work together with the business and IT security professionals to determine what kind of coverage is best and get quotes that meet those needs.”

Don't Compare Cyber Policies on Price Alone

This is probably the biggest improvement I would make to the buying process today.

A cheaper policy is not necessarily a better policy.


When reviewing cyber insurance quotes, ask your broker to help compare:


  • Total Policy Limit

    • How much protection is available for the overall policy period?

  • Sublimits

    • Does the policy provide smaller limits for particular losses?


  • Pay particular attention to areas such as:

    • Social-engineering fraud

    • Funds-transfer fraud

    • Cyber extortion

    • Business interruption

    • Dependent business interruption

    • Data restoration

  • Cyber-policy wording is not universal, and Coalition specifically cautions that social-engineering coverage can have narrow definitions, different triggers, or separate sublimits between carriers.


  • Retention or Deductible

    • How much does the business need to absorb before coverage responds?

  • Business Interruption

    • What events trigger the coverage?

    • Is there a waiting period before the policy begins paying?

    • How is lost income calculated?

  • Dependent Business Interruption

    • What happens if your technology is fine, but an important cloud provider, software vendor, or other dependent provider suffers an outage or cyber incident?

  • Ransomware and Cyber Extortion

    • What response expenses are included?

    • What conditions apply?

  • Data Restoration

    • Does the policy help pay to restore damaged systems, software, or electronic data?

  • Social Engineering and Funds-Transfer Fraud

    • Does the policy cover employees being tricked into sending money?

    • What limit applies?

    • Is there a separate endorsement?

  • Breach Response Resources

    • What happens when you call the insurer after an incident?

    • Some cyber policies provide access to specialized forensic investigators, breach counsel, crisis-management services, and other response resources in addition to financial reimbursement. Travelers currently lists forensic investigations, litigation expenses, regulatory defense, crisis management, business interruption, cyber extortion, and betterment among its CyberRisk coverage options.

  • Exclusions

    • Have your broker explain important exclusions rather than simply handing you the policy.

  • Technology Errors and Omissions

    • If your company provides technology, software, consulting, or related professional services, ask whether you also need Technology Errors and Omissions coverage.


For many businesses, the structure of the coverage matters as much as the headline limit.


A $2 million policy with a small social-engineering sublimit could behave very differently from another $2 million cyber policy.


Step 3 – Verify Your Technology Before the Policy Is Bound

This step has changed slightly from our original article.

We previously described it as something to do after selecting the policy.

In reality, your IT or cybersecurity team should be involved during the application and underwriting process, before the coverage is finalized.


Insurers may ask about controls such as:

  • Multi-Factor Authentication (MFA)

  • Endpoint Detection and Response (EDR)

  • Backups

  • Vulnerability and patch management

  • Email security

  • Security awareness training

  • Administrator and privileged accounts

  • Incident response

  • Remote access

  • Security monitoring

Your job isn't to give the insurer the answer it wants.

Your job is to give the insurer an accurate answer.


For example:

  • Your company may use MFA, but does it protect administrator accounts too?

  • You may have backups, but have they actually been tested?

  • You may have EDR, but is it installed on all workstations and servers?

  • You may provide employee security training, but are employees actually completing it?



Before submitting the application or binding coverage, have your IT provider verify the technical answers and address any gaps that need remediation.

To help guide that process, Kosh created a useful cybersecurity checklist covering many of the controls insurers commonly ask about.



You can also see our more detailed guide:


Can Companies Add Cyber Insurance to Their Existing Business Insurance?

Sometimes.


Cyber coverage may be available as a stand-alone policy, as part of a broader management-liability package, or as an add-on to another commercial insurance policy, depending on the carrier and business.


Travelers, for example, offers CyberRisk as a stand-alone policy or as part of a broader management-liability suite. Other carriers offer cyber or data-breach coverage that can be added to a Business Owner's Policy.


The important point is that an endorsement or add-on should not automatically be assumed to provide the same protection as a dedicated cyber policy.


Ask your broker to compare:

  • Coverage types

  • Limits

  • Sublimits

  • Business interruption

  • Ransomware

  • Social engineering

  • Funds-transfer fraud

  • Incident-response services

  • Third-party liability

  • Exclusions


A small data-breach endorsement may be perfectly appropriate for one organization and inadequate for another.


The Three People Who Should Be Involved

Buying cyber insurance works best when three perspectives come together.

  1. The Business You understand your operations, revenue, customers, contractual obligations, and what downtime would actually mean.

  2. The Insurance Broker Your broker understands coverage, insurers, policy language, limits, exclusions, and the insurance marketplace.

  3. Your IT or Cybersecurity Provider Your IT team understands whether the technical controls described on the application are really in place.


Each person is answering a different part of the same question:

What risks does this business face, how much of that risk should be transferred to insurance, and are the cybersecurity protections described on the application accurate?

That is ultimately the best way to buy cyber insurance.


Disclaimer

The information contained in this communication is intended for limited use for informational purposes only. It is not considered professional advice, and instead, is general information that may or may not apply to specific situations. Each case is unique and should be evaluated on its own by a professional qualified to provide advice specifically intended to protect your individual situation. Kosh is not liable for improper use of this information.

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page