Do I need cyber insurance?

Applies nationally Technology & SaaS
Direct answer

No law requires it, but three facts decide the question: every U.S. state obligates you to notify individuals after a breach of their personal information, standard property and liability policies don't cover cyber events, and client contracts increasingly require the coverage. If you hold personal data, move money electronically, or sign those contracts — yes.

“Do we need cyber insurance?” is the highest-volume cyber question small businesses ask, and it’s usually asked defensively — am I being paranoid, or being sold something? Strip the fear and the sales pitch and the decision reduces to what data you hold, how money moves through your systems, and what your contracts say. No statute requires the coverage; three structural facts do the requiring instead.

The three drivers

  1. Breach obligations are already yours. All 50 states, DC, and U.S. territories have laws requiring businesses to notify individuals when a breach exposes their personally identifiable information. Those duties — notification, and commonly credit monitoring and legal guidance to navigate per-state rules — arrive regardless of company size, and they’re first-party costs you incur even if nobody sues.
  2. Your existing policies don’t respond. The NAIC states it flatly: most commercial property and general liability policies do not cover cyber risks. Owners who assume their BOP has this handled are the ones financing incident response out of operating cash.
  3. Your counterparties are starting to require it. Enterprise customers write cyber coverage into vendor contracts; IT providers and MSPs increasingly require or strongly push it onto their clients. For a growing share of buyers, the trigger isn’t a risk calculation at all — it’s a contract they want to sign. (If your work is building or running technology for others, the adjacent question is cyber vs tech E&O — contracts often demand both.)

A decision framework by data and attack surface

If you…Your exposureWeight
Store customer PII — even just an email list with namesState notification duties on breachCore reason to buy
Take payment cardsBreach costs plus card-brand assessmentsCore reason to buy
Hold health, financial, or other regulated dataNotification plus regulatory actionStrongest case of all
Send or receive wires, ACH, vendor paymentsFunds-transfer fraud and social engineering — the small-business loss that actually happensBuy, and check how the policy sublimits it
Depend on systems to operate (bookings, e-commerce, SaaS)Downtime is direct income lossSignificant
Sign contracts specifying cyber coverageRequirement, not a choiceDecides it for you

The honest skip case is narrow: a business holding no personal data, taking no electronic payments, and depending on no systems it can’t work without. Few businesses now fit that description — operating online at all usually forecloses it.

What’s at stake, in numbers someone stands behind

We don’t quote premium averages — published figures conflict. Loss data from a named authority is a different matter: Aon’s market report puts the average global ransomware claim at $713,200 in 2025, nearly double the prior year, with reported U.S. cyber and tech E&O incidents up 38% year over year. Set that against your balance sheet, not against the premium: the question a quote answers is whether transferring a six-figure tail risk is worth the certain annual cost.

If you buy: what underwriting expects

Cyber underwriting is unusually intrusive because controls determine losses. Expect application questions about multifactor authentication, backups, and endpoint protection — and treat them as warranty-grade: carriers have rescinded policies over inaccurate MFA attestations, a coverage-defining detail worth understanding before you sign anything. The practical sequence: fix the basic controls first (they’re required anyway), then apply, with your IT person reviewing every security answer.

Questions people actually ask

Is cyber insurance required by law? No U.S. law mandates buying it. The mandates that do exist are breach-notification duties — which are a reason to buy, not a requirement to.

Do small businesses really need cyber insurance? Size doesn’t exempt you from notification laws, and attackers automate — they don’t hand-select large targets. The data-and-contracts framework above answers it better than headcount does.

Is cyber insurance worth it? Weigh the certain premium against the tail loss: a six-figure average ransomware claim against a policy that also buys you an incident-response bench you couldn’t assemble yourself at 2 a.m.

How much cyber insurance do I need? Let the drivers size it: the records you hold (notification scales per record), your revenue’s dependence on uptime, and the limits your contracts specify — contracts frequently set the floor for you.


Sources are linked below. Statistics are quoted only from named authorities; premium averages are deliberately absent because published figures conflict.

Thanks — your question is in. If it's public, the best ones become a page here. If it's private, an editor will follow up by email.

Ask us

Ask publicly The best questions become new pages here — sourced, anonymized, never with your email.

Questions may be published in anonymized form. No mailing list, no quotes, no follow-up sales.

Ask privately Confidential — for a policy-specific read, answered by an editor, never published.

Sources

  1. NCSL — Security breach notification laws — All 50 states, DC, and U.S. territories have laws requiring businesses to notify individuals of breaches involving personally identifiable information
  2. NAIC — Cybersecurity (insurance topic) — Regulator association's framing: most commercial property and general liability policies do not cover cyber risks; catalogs the loss categories cyberattacks cause
  3. Aon — Cyber and Tech E&O market report — Reported U.S. cyber and tech E&O incidents up 38% in 2025 vs 2024; average global ransomware claim $713,200 in 2025
  4. r/msp — 'Do you require your customers to have cyber insurance?' — Evidence of the contract-driven channel: IT providers pushing cyber insurance requirements down to their small-business clients