Cyber Insurance Calculator for Small Businesses: How Much Exposure Do You Have?
Cyber insurance should start with an inventory of data, revenue dependence, vendors and security controls. This checkup turns “we are too small to be targeted” into a concrete risk conversation.
Small-business cyber exposure check
First-party vs. third-party
FTC separates first-party costs, such as legal advice, data restoration, customer notification, lost income, crisis management and forensic services, from third-party liability such as claims, settlements and regulatory response. A policy can include one or both; confirm the contract.
Five underwriting questions you should answer before shopping
The insurance/control loop
Cyber underwriting can make weak controls expensive or ineligible. Instead of seeing MFA, backups and training as insurer paperwork, use the application as a security gap checklist. Better controls reduce loss probability whether or not they reduce premium.
FAQ
Does general liability cover cyber loss?
NAIC notes most commercial property and general liability policies do not cover cyber risks broadly; cyber policies are customized.
Is MFA enough?
No. It is a high-value control, not a complete security program.
Should a two-person business consider cyber?
Size alone is not the right filter. Data sensitivity, online operations, vendor access, revenue dependence and contractual requirements matter.
Sources & methodology
We favor regulators, government agencies and primary insurance-industry data for factual rules and current limits. Calculators use the numbers you enter and clearly labeled illustrative assumptions rather than pretending a national average is your quote.