Blog · Business Insurance

Cyber Insurance Calculator for Small Businesses: How Much Exposure Do You Have?

Cyber insurance should start with an inventory of data, revenue dependence, vendors and security controls. This checkup turns “we are too small to be targeted” into a concrete risk conversation.

Updated September 2026 · Built from official/public 2026 sources where available

CyberBusinessCalculator
How we make money: Some links on 30Insure may be affiliate links. If you get a quote or buy through them, 30Insure may earn a commission at no extra cost to you. That should never change the math or the recommendation framework.
The short versionFTC guidance says cyber insurance can address first-party costs such as forensic work, data restoration, notification and business interruption, plus third-party liability depending on the policy. CISA strongly recommends MFA as a baseline control. Insurance does not replace the controls.

Small-business cyber exposure check

First-party vs. third-party

FTC separates first-party costs, such as legal advice, data restoration, customer notification, lost income, crisis management and forensic services, from third-party liability such as claims, settlements and regulatory response. A policy can include one or both; confirm the contract.

Five underwriting questions you should answer before shopping

Where is sensitive customer and employee data stored?
Is MFA required for email, admins and remote access?
Are backups tested and isolated from the primary network?
Which vendors can access systems or data?
Who is called in the first hour of an incident?

The insurance/control loop

Cyber underwriting can make weak controls expensive or ineligible. Instead of seeing MFA, backups and training as insurer paperwork, use the application as a security gap checklist. Better controls reduce loss probability whether or not they reduce premium.

FAQ

Does general liability cover cyber loss?

NAIC notes most commercial property and general liability policies do not cover cyber risks broadly; cyber policies are customized.

Is MFA enough?

No. It is a high-value control, not a complete security program.

Should a two-person business consider cyber?

Size alone is not the right filter. Data sensitivity, online operations, vendor access, revenue dependence and contractual requirements matter.

Sources & methodology

We favor regulators, government agencies and primary insurance-industry data for factual rules and current limits. Calculators use the numbers you enter and clearly labeled illustrative assumptions rather than pretending a national average is your quote.

  1. FTC — Cybersecurity for Small Business
  2. CISA — Require multifactor authentication
  3. NAIC — Cybersecurity insurance topic

Keep reading

Browse all free insurance tools →