How to Buy Cyber Insurance?
Updated: Aug 18

Many customers ask us, “Where can I buy cyber insurance?”, “How much cyber insurance do I need?”, or simply, “Is there insurance for cyberattacks?”
To help answer those questions, we originally asked insurance brokers in New Mexico and Orange County to walk us through what purchasing cyber insurance looks like.
Cyber insurance still isn't as standardized as something like auto insurance, but the basic buying process is fairly familiar.
There are three main steps:
Determine your risks and how much coverage you may need
Have your insurance broker obtain and compare coverage options
Have your IT or cybersecurity provider verify that your technology matches the application and underwriting requirements
We'll walk through each step below.
Related Articles
Before You Start: Get the Cyber Insurance Application
Nickie Tran, President of IQ Risk Insurance Services, gave us useful advice when we originally developed this article:
Start with the cyber liability application.
The application can act as a mini risk-assessment exercise because it forces the business to answer questions about its data, technology, security controls, previous incidents, backups, employees, and other exposures.
It also tells you what that particular insurer is actually interested in.
Cyber insurers may use different applications and supplemental questionnaires depending on the organization and the type of risk. Travelers, for example, currently publishes separate application materials addressing areas including MFA, social-engineering fraud, payment cards, healthcare, and renewals.
Get the application from your broker early, rather than waiting until renewal is due.
Then involve your IT provider in the technical questions.
Step 1 – Determine How Much Coverage You Need
Cyber insurance isn't only for large businesses.
The more useful question is:
What could a serious cyber incident realistically cost your organization?
There are two broad categories to think about:
First-party costs — losses your own business incurs
Third-party costs — claims or liabilities involving customers, employees, vendors, or others
First-Party Costs
These are costs your organization may experience directly following a cyber incident.
They can include:
Cybersecurity and forensic response
You may need specialists to:
Determine how the attacker gained access
Contain the incident
Determine which systems or data were affected
Remove malicious software or attacker access
Restore systems and data
Business interruption
This may be one of the largest exposures for many businesses.
Ask yourself:
How much would one day without your critical technology cost?
Consider:
Lost revenue
Employee downtime
Delayed projects
Missed customer appointments
Lost sales opportunities
Overtime and recovery expenses
Customer churn
Reputational impact
A business that can function manually for several days has a very different exposure from one whose operations stop completely when its systems go offline.
Data restoration
What would it cost to recreate or restore critical files, applications, databases, or systems?
Breach response
A privacy incident may require:
Legal counsel
Forensic investigation
Customer notification
Credit or identity monitoring
Regulatory response
Crisis communications
Cybercrime and fraudulent transfers
Business email compromise and funds-transfer fraud deserve particular attention today.
An attacker may impersonate an executive, compromise a vendor's email account, change payment instructions, or trick an employee into wiring money to a fraudulent account.
Coalition's 2026 claims data found that business email compromise and funds-transfer fraud together represented 58% of its claims.
Ask yourself:
What is the largest payment our company could realistically send based on fraudulent instructions?
That number may help guide your conversation about social-engineering and funds-transfer limits.
Third-Party Costs
A cyber incident can also create liability to others.
Examples include:
A customer claiming your breach exposed their personal information
An employee alleging sensitive information was mishandled
A customer suffering financial loss after fraudulent messages were sent from a compromised company account
Regulatory investigations
Lawsuits related to privacy or security
Attorney's fees and defense costs
For companies in healthcare, finance, professional services, technology, and other data-sensitive industries, these exposures can be particularly important.
For a deeper explanation, see What Does Cyber Insurance Cover? And Not Cover?.
How Much Does Cyber Insurance Cost?
Our original version of this article gave a rough formula for calculating premiums based on the amount of coverage purchased.
We no longer recommend using a formula like that.
Cyber insurance pricing can vary considerably based on factors such as:
Revenue
Industry
Type and amount of sensitive information
Coverage limits
Retention or deductible
Previous cyber incidents and claims
Security controls
Geographic exposure
The specific coverage being purchased
At the time of this 2026 update, the cyber insurance market is relatively favorable for buyers. Marsh reported that global cyber insurance rates declined 4% in the second quarter of 2026, marking the twelfth consecutive quarter of rate decreases. It also reported that buyers were often able to pursue broader coverage, higher limits, and reduced retentions.
But averages don't tell you what your business will pay.
The most useful pricing information will come from actual quotes based on your organization's risk profile.
Step 2 – Receive and Review Quotes
Once you have a better understanding of your potential exposure, your insurance broker can shop the market and obtain coverage options.
Our original recommendation was to get at least three quotes.
That's still a reasonable goal when appropriate, but the more important point is to compare multiple viable options rather than simply accepting the first premium presented.
Nickie Tran explained the value of having the broker, business, and IT provider work together:
“We work together with the business and IT security professionals to determine what kind of coverage is best and get quotes that meet those needs.”
Don't Compare Cyber Policies on Price Alone
This is probably the biggest improvement I would make to the buying process today.
A cheaper policy is not necessarily a better policy.
When reviewing cyber insurance quotes, ask your broker to help compare:
Total Policy Limit
How much protection is available for the overall policy period?
Sublimits
Does the policy provide smaller limits for particular losses?
Pay particular attention to areas such as:
Social-engineering fraud
Funds-transfer fraud
Cyber extortion
Business interruption
Dependent business interruption
Data restoration
Cyber-policy wording is not universal, and Coalition specifically cautions that social-engineering coverage can have narrow definitions, different triggers, or separate sublimits between carriers.
Retention or Deductible
How much does the business need to absorb before coverage responds?
Business Interruption
What events trigger the coverage?
Is there a waiting period before the policy begins paying?
How is lost income calculated?
Dependent Business Interruption
What happens if your technology is fine, but an important cloud provider, software vendor, or other dependent provider suffers an outage or cyber incident?
Ransomware and Cyber Extortion
What response expenses are included?
What conditions apply?
Data Restoration
Does the policy help pay to restore damaged systems, software, or electronic data?
Social Engineering and Funds-Transfer Fraud
Does the policy cover employees being tricked into sending money?
What limit applies?
Is there a separate endorsement?
Breach Response Resources
What happens when you call the insurer after an incident?
Some cyber policies provide access to specialized forensic investigators, breach counsel, crisis-management services, and other response resources in addition to financial reimbursement. Travelers currently lists forensic investigations, litigation expenses, regulatory defense, crisis management, business interruption, cyber extortion, and betterment among its CyberRisk coverage options.
Exclusions
Have your broker explain important exclusions rather than simply handing you the policy.
Technology Errors and Omissions
If your company provides technology, software, consulting, or related professional services, ask whether you also need Technology Errors and Omissions coverage.
For many businesses, the structure of the coverage matters as much as the headline limit.
A $2 million policy with a small social-engineering sublimit could behave very differently from another $2 million cyber policy.
Step 3 – Verify Your Technology Before the Policy Is Bound
This step has changed slightly from our original article.
We previously described it as something to do after selecting the policy.
In reality, your IT or cybersecurity team should be involved during the application and underwriting process, before the coverage is finalized.
Insurers may ask about controls such as:
Multi-Factor Authentication (MFA)
Endpoint Detection and Response (EDR)
Backups
Vulnerability and patch management
Email security
Security awareness training
Administrator and privileged accounts
Incident response
Remote access
Security monitoring
Your job isn't to give the insurer the answer it wants.
Your job is to give the insurer an accurate answer.
For example:
Your company may use MFA, but does it protect administrator accounts too?
You may have backups, but have they actually been tested?
You may have EDR, but is it installed on all workstations and servers?
You may provide employee security training, but are employees actually completing it?
Before submitting the application or binding coverage, have your IT provider verify the technical answers and address any gaps that need remediation.
To help guide that process, Kosh created a useful cybersecurity checklist covering many of the controls insurers commonly ask about.
You can also see our more detailed guide:
Can Companies Add Cyber Insurance to Their Existing Business Insurance?
Sometimes.
Cyber coverage may be available as a stand-alone policy, as part of a broader management-liability package, or as an add-on to another commercial insurance policy, depending on the carrier and business.
Travelers, for example, offers CyberRisk as a stand-alone policy or as part of a broader management-liability suite. Other carriers offer cyber or data-breach coverage that can be added to a Business Owner's Policy.
The important point is that an endorsement or add-on should not automatically be assumed to provide the same protection as a dedicated cyber policy.
Ask your broker to compare:
Coverage types
Limits
Sublimits
Business interruption
Ransomware
Social engineering
Funds-transfer fraud
Incident-response services
Third-party liability
Exclusions
A small data-breach endorsement may be perfectly appropriate for one organization and inadequate for another.
The Three People Who Should Be Involved
Buying cyber insurance works best when three perspectives come together.
The Business You understand your operations, revenue, customers, contractual obligations, and what downtime would actually mean.
The Insurance Broker Your broker understands coverage, insurers, policy language, limits, exclusions, and the insurance marketplace.
Your IT or Cybersecurity Provider Your IT team understands whether the technical controls described on the application are really in place.
Each person is answering a different part of the same question:
What risks does this business face, how much of that risk should be transferred to insurance, and are the cybersecurity protections described on the application accurate?
That is ultimately the best way to buy cyber insurance.
Disclaimer
The information contained in this communication is intended for limited use for informational purposes only. It is not considered professional advice, and instead, is general information that may or may not apply to specific situations. Each case is unique and should be evaluated on its own by a professional qualified to provide advice specifically intended to protect your individual situation. Kosh is not liable for improper use of this information.





Comments