How Much Cyber Insurance Should I Buy: Records, Limits, Sublimits

Most businesses need between $1 million and $5 million in cyber insurance, and the way to answer “how much cyber insurance should I buy” is to add up your worst realistic loss across five categories rather than picking a round number off an industry chart. A company holding 50,000 customer records faces a fundamentally different risk than one holding 500, and a healthcare provider under HIPAA faces a different floor than a retailer with no regulated data. The gap between adequate and dangerously underinsured usually comes down to a handful of calculations buyers skip.

The Five Numbers to Add Up

The right limit is the sum of your worst realistic scenario across each of these:

  • Breach notification, credit monitoring, and call center costs based on your actual record count
  • The maximum regulatory penalty under the most aggressive law that applies to you
  • Revenue lost over a realistic system recovery timeline, plus fixed costs that keep running
  • Forensic investigation and legal defense fees
  • Contractual penalties you’d owe clients for missed service levels or deadlines

Add them, then match the total to a policy tier. If the math points to $4 million and you buy $1 million because the premium is cheaper, you are self-insuring the $3 million gap whether you intend to or not.

Start With a Hard Count of Your Records

Sort the electronic records you hold by sensitivity. Social Security numbers and financial account data carry the highest breach costs, followed by medical records, then general contact information. Each category triggers different notification obligations and different levels of legal exposure.

Breach response costs per affected person vary with what was exposed and what services you provide afterward. Credit monitoring, notification mailings, call center staffing, and forensic work all feed the per-person figure. The global average total cost of a data breach reached $4.44 million in 2025, while breaches at U.S. companies averaged $10.22 million due to heavier regulatory penalties and slower detection times. A business storing 50,000 customer files with sensitive financial or health data can easily face seven-figure response costs from notification and monitoring alone, before any fine or lawsuit enters the picture.

The Regulatory Floor That Applies to You

Certain laws impose penalties steep enough that they essentially dictate a minimum coverage level. Identify which apply to your business and use the worst-case fine as a floor the rest of your coverage sits on top of.

HIPAA

Any organization handling protected health information must notify affected individuals within 60 days of discovering a breach. Breaches affecting more than 500 people in a single state also require notice to prominent media outlets and the Secretary of Health and Human Services within that same window.1Health and Human Services (HHS). Breach Notification Rule Penalties are tiered by negligence and adjusted for inflation. As of 2024, tiers range from $141 per violation when the entity genuinely didn’t know about the problem, up to a minimum of $71,162 per violation for willful neglect uncorrected for more than 30 days, with annual caps exceeding $2.1 million per tier.2Federal Register. Annual Civil Monetary Penalties Inflation Adjustment Because each affected individual can count as a separate violation, a single breach involving thousands of patients can generate penalties in the tens of millions.

CCPA

The California Consumer Privacy Act applies to any business handling California residents’ data, regardless of where the business is located. Following the 2025 inflation adjustment, statutory damages range from $107 to $799 per consumer per incident.3California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties A breach exposing 100,000 California residents could generate up to $79.9 million in statutory damages alone. Even at the low end, $10.7 million in potential liability from one incident dwarfs a $1 million policy.

GDPR

If your business collects data from anyone in the European Union, the General Data Protection Regulation applies. Maximum fines reach 20 million euros or four percent of global annual revenue, whichever is higher.4General Data Protection Regulation (GDPR). Art. 83 GDPR – General Conditions for Imposing Administrative Fines For a company with $200 million in annual revenue, the four-percent threshold creates $8 million in potential exposure from a single enforcement action.

Business Interruption Math

Revenue loss during an outage is where cyber claims get expensive fast. Calculate your average gross profit per hour of operation, add the fixed costs that keep running while systems are down (payroll, rent, utilities), and multiply by a realistic recovery timeline. A company earning $10,000 per hour in gross profit faces $240,000 per day in lost revenue. If full restoration takes two weeks, that’s $3.36 million before you’ve paid a single forensic investigator.

Digital forensic teams that investigate breaches and restore systems charge premium rates, and a complex investigation can stretch across several weeks. If the outage causes you to miss contractual deadlines, those penalties stack on top.

One detail buyers routinely overlook: most cyber policies impose a waiting period before business interruption coverage activates, functioning as a time-based deductible. The typical waiting period runs 6 to 12 hours, with some policies stretching to 24 hours or more. Any revenue lost during that initial window comes out of your pocket. You can negotiate a shorter waiting period for a higher premium. Build this gap into your coverage math, especially if your business generates significant revenue per hour.

Policy Structure Can Shrink the Number You Think You Bought

Three features commonly reduce effective coverage well below the headline limit. Account for each before you decide a given policy tier is enough.

Ransomware Sublimits

Carriers have added ransomware-specific sublimits that can be dramatically lower than the overall policy limit. A policy with a $5 million aggregate limit might cap ransomware-related losses at $1 million or less. Some sublimits run as low as $25,000 to $250,000, which is a problem when extortion demands routinely reach seven figures. The sublimit typically covers not just the ransom payment but all first-party and third-party losses stemming from the event: system restoration, business interruption, legal fees. Some carriers also impose roughly 25 percent co-insurance on ransomware losses, meaning you pay a quarter of every dollar even within the sublimit.

There is a separate legal tripwire worth knowing about before you count on ransom coverage at all. The Treasury Department’s Office of Foreign Assets Control has warned that paying ransom to a sanctioned entity can violate federal sanctions law, and OFAC imposes strict liability, meaning you can be penalized even if you had no idea the attacker was on a sanctions list.5Office of Foreign Assets Control. Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments Your insurer may refuse to authorize payment altogether, which makes robust recovery infrastructure and business interruption coverage more important than the extortion sublimit itself.

Defense Costs Inside the Limits

When defense costs sit “inside the limits,” every dollar your insurer spends on lawyers, expert witnesses, and regulatory defense reduces the money available to pay settlements, fines, or recovery costs. A $3 million policy can shrink to $1.5 million in effective coverage after a lengthy regulatory investigation generates $1.5 million in legal fees. Policies with defense costs “outside the limits” treat legal expenses as a separate pool, leaving your full policy limit available for indemnity payments. Outside-the-limits policies cost more. If your regulatory exposure is high, this distinction alone can determine whether your coverage is adequate.

Per-Occurrence vs. Aggregate

Every policy has a per-occurrence limit (what the insurer pays for any single event) and an aggregate limit (total payouts across all events during the policy period, usually one year). A $1 million per-occurrence, $3 million aggregate policy will cover up to three separate $1 million incidents, but nothing beyond. If multiple smaller incidents are realistic in your industry, such as retail, healthcare, or financial services, the aggregate limit matters as much as the per-occurrence cap.

Standard Coverage Tiers

Carriers package cyber insurance in roughly standardized brackets. Small businesses with limited digital footprints typically start at $1 million, which handles basic breach notification, legal costs, and modest regulatory defense. Mid-sized companies usually land in the $3 million to $5 million range to accommodate larger data sets, more regulatory exposure, and greater revenue at risk during an outage. Organizations above that threshold often stack excess layers or umbrella policies on top of a primary cyber policy to reach $10 million or more.

Underwriting Requirements That Can Void the Coverage

Coverage limits are only half the equation. Carriers have tightened underwriting significantly, and failing to meet their requirements can result in denied applications, coverage exclusions, or voided claims. Most underwriters now treat the following as baseline:

  • Multi-factor authentication on remote access, email, and privileged admin accounts
  • Endpoint detection and response tools that monitor behavior and isolate suspicious activity, not just signature-based antivirus
  • Automated offline or offsite backups on a regular schedule, with periodic restore testing
  • A documented incident response plan assigning roles, communication protocols, and escalation procedures
  • Regular employee training on phishing, social engineering, and credential hygiene

Misrepresenting your security posture on an application is a fast path to a denied claim. If you tell the underwriter MFA is deployed enterprise-wide and an attacker gets in through an unprotected admin account, the carrier has grounds to dispute coverage. Answer honestly, close the gaps the underwriter identifies, and keep documentation that proves your controls are operational.

Watch the Retroactive Date When Switching Carriers

Nearly all cyber insurance is written on a claims-made basis. The policy only responds if the claim is reported during the active policy period. If you cancel or switch carriers and a claim surfaces afterward for a breach that happened while you were covered, the old policy will not pay, and the new policy may exclude events that predate its start.

The retroactive date controls how far back the policy will reach. If your retroactive date is January 1, 2024, and an attacker was inside your network starting in November 2023, the insurer can argue the loss predates coverage. Cyber attacks often unfold over months before anyone notices, so a restrictive retroactive date creates a real gap. When switching carriers, negotiate to keep your existing retroactive date rather than resetting it to the new policy’s start.

Factor Taxes Into Your Target Limit

Cyber insurance payouts that replace lost business income are generally taxable. Federal tax law includes income from all sources unless a specific exclusion applies, and no exclusion exists for commercial insurance proceeds that compensate for lost revenue.6Internal Revenue Service. Tax Implications of Settlements and Judgments What matters is what the payment was intended to replace. A payout covering lost profits during a network outage replaces business income, which makes it taxable. A payout reimbursing expenses you already incurred (forensic investigation, notification costs) offsets deductible business expenses, and the tax treatment depends on whether you deducted those expenses in the same year.

Premiums you pay for cyber insurance are deductible as an ordinary business expense. If a $2 million business interruption payout nets closer to $1.4 million after taxes, you may need a higher limit than your initial calculation suggested.

Run the five-category sum, apply the tax haircut to the business interruption piece, then size the policy against the result. Ransomware sublimits, defense-cost erosion, and waiting-period gaps are the three places coverage most often falls short of what buyers expect, so check each against your own total before you sign.