For Subscribers

Everything You Need to Know About Cyber Insurance What it covers, what it costs and why it matters.

By Mikal E. Belicove

Opinions expressed by Entrepreneur contributors are their own.

Daria Nepriakhina | StockSnap.io

Q: Do I need cyber insurance for my business?

A: You must be asking because you think your business is too small to attract criminals. In fact, when it comes to cyber theft, size doesn't matter, according to Christine Marciano, president of insurance brokerage Cyber Data Risk Managers in Princeton, N.J. She says hackers are looking for businesses of any size with valuable customer data they can steal and sell on the black market.

Hence the need for cyber insurance—coverage that can include data theft or loss, network intrusions, information-security breaches and lost income due to system downtime. It's available for first- and third-party losses, which means that if your business has customer or vendor relationships and processes customer-sensitive (nonpublic) information, you need it.

We asked Marciano to give us the lowdown.

Doesn't my current insurance cover cyber breaches?

Review your policies—especially the exclusions—and you'll likely find that your traditional commercial general liability won't respond to a cyber or data breach claim. And the last thing you want to do is handle a cyber attack or data breach alone. Cyber insurance can provide coverage for regulatory defense, penalties and fines.

Penalties? Fines? How does that happen?

Most states have laws requiring companies to notify individuals of security breaches involving their personally identifiable information. Regulators such as the FCC and FTC can assess fines and penalties against a company for a data-security breach that affects consumers' sensitive, personal information.

An example from April: The FCC handed AT&T a $25 million fine for a data breach that affected 280,000 customers.

Gulp. how much does cyber insurance cost?

Like any insurance, premiums vary by insurer and type of coverage selected. They can start at $850 a year for a $1 million aggregate policy for a small, sole-proprietor business and climb to seven figures for midsize to large companies that require coverage limits of $300 million or more.

Anything I can do to whittle down those premiums?

The Internet Security Alliance, in coordination with insurer AIG, has a helpful guide to best practices that need to become part of a company's culture. Such practices can help reduce the cost of purchasing a cyber insurance policy. Go to AIG.com and download their whitepapers on managing cyber risk and maintaining "good cyber hygiene."

Among the tips: eliminate unnecessary data, regularly change passwords, avoid sharing logins and passwords, update software immediately and audit user accounts on a regular basis. If you can document that these policies are in place and followed consistently, you may see a break on your premiums—it all depends on the value of the data your business holds.

Mikal E. Belicove is a market positioning, social media, and management consultant specializing in website usability and business blogging. His latest book, The Complete Idiot’s Guide to Facebook, is now available at bookstores. 

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Buying / Investing in Business

From a $120M Acquisition to a $1.3T Market

Co-ownership is creating big opportunities for entrepreneurs.

Business News

AI Could Cause 99% of All Workers to Be Unemployed in the Next Five Years, Says Computer Science Professor

Professor Roman Yampolskiy predicted that artificial general intelligence would be developed and used by 2030, leading to mass automation.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.

Buying / Investing in Business

Big Investors Are Betting on This 'Unlisted' Stock

You can join them as an early-stage investor as this company disrupts a $1.3T market.

Leadership

Lead From the Top: 5 Core Responsibilities of a CEO

Knowing exactly what the chief executive's role entails is critical for steering a company to success.