Buying your first cyber insurance policy: a small business walkthrough
What a 10 to 30 user business needs to know before buying its first cyber policy, from coverage types to the social engineering sub-limit that decides whether a BEC loss is actually covered.
· Jake Schaaf, Founder of Atticus Rowan
A 20-person distributor gets a contract redline from its biggest customer: carry cyber liability insurance with at least $1 million in coverage, provide a certificate within 30 days. The owner calls their business insurance agent, who quotes something in an afternoon. Nobody reads the application questions closely, nobody checks what is actually covered and the certificate goes out on time. The policy then sits in a drawer until the day a fraudulent wire leaves the bank account, which is when everyone learns that the loss falls under a sub-limit worth a tenth of the number on the certificate.
Most of our writing on cyber insurance covers renewals, where underwriters tighten requirements year over year. This post is for the business buying its first policy, because the first purchase is where the most consequential mistakes get made.
Why buy at 10 to 30 users at all
The honest math: a single successful attack outruns the cash reserves of most small businesses.
- A business email compromise loss lands in the tens to hundreds of thousands of dollars in a single transaction. The FBI’s IC3 reported roughly $2.9 billion in BEC losses in 2023 alone, and the median victim is not a Fortune 500 company.
- A ransomware event carries recovery costs well beyond any ransom: forensics, rebuild labor, downtime measured in days or weeks and customer notification obligations. We broke down the components in the true cost of ransomware.
- Even a modest incident involving customer data triggers legal review and notification costs that start in 5 figures.
A business running 15 percent margins does not absorb a $150,000 loss. It borrows, shrinks or closes. Cyber insurance exists to convert that tail risk into a predictable premium, which for a small business with reasonable controls typically runs $1,500 to $5,000 per year for $1 million in limits. Control-dependent, and that dependence is the second half of this post.
First-party and third-party coverage in plain English
Cyber policies bundle 2 different kinds of protection:
- First-party coverage pays for your own losses: incident response and forensics, data restoration, business interruption while systems are down, extortion payments where lawful and notification costs for affected individuals.
- Third-party coverage pays for claims other people bring against you: a customer whose data leaked, a partner harmed by an incident that spread from your systems, regulatory defense costs.
A small business needs both, and nearly all packaged cyber policies include both. The distribution matters though. Read the declarations page and note the per-category limits, because “$1 million policy” is a headline number sliced into smaller buckets underneath.
The sub-limit that decides your BEC outcome
Here is the single most important thing a first-time buyer should check. Fraudulent instruction losses, where an employee is deceived into sending money, are typically not covered under the main cyber limit. They fall under a social engineering or cybercrime endorsement, and that endorsement is routinely sub-limited to $100,000, $50,000 or even $25,000 regardless of the policy’s headline limit.
Since business email compromise is the most probable expensive event for a 10 to 30 user company, a $1 million policy with a $25,000 social engineering sub-limit is shaped backwards for your actual risk. When comparing quotes:
- Ask directly: what is the sub-limit for social engineering fraud and fraudulent funds transfer?
- Ask whether coverage requires that you performed a verification callback before the transfer. Some policies only pay if your documented procedures were followed, which is fair, but you need to know that and actually have the procedure.
- Consider trading a lower headline limit for a higher social engineering sub-limit if the premium is similar.
What the application will ask
Cyber insurance applications have converged on a core control set, and your answers directly move both premium and insurability. Expect questions about:
- MFA on email, remote access and administrative accounts. This is the closest thing to a hard requirement in the market. We covered the mechanics in MFA, EDR and backups: the cyber insurance triage list.
- EDR (endpoint detection and response) on workstations and servers, as opposed to plain antivirus.
- Backups that are offline, immutable or otherwise separated from production, with evidence of restore testing.
- Email filtering and awareness training, sometimes with phishing simulation cadence.
- End-of-life software anywhere in the environment, which underwriters increasingly treat as a red flag.
Answer accurately. An application is a legal document, and a misstatement discovered during a claim (MFA marked “yes” that was enabled for some users, for instance) gives the carrier grounds to deny or rescind. If the honest answer today is “no,” it is usually cheaper to fix the control first and apply after. The full list of what underwriters probe is in the 25 questions you will fail on your next renewal, which doubles as a preparation checklist for a first application.
Questions to ask the broker
A generalist business agent may place 1 or 2 cyber policies a year. Come prepared:
- Is this a standalone cyber policy or an endorsement bolted onto our business owner’s policy? Standalone policies are broader and are usually worth the difference at this risk level.
- Who is the incident response panel and can we use our own IT provider during a claim, or must we use carrier-approved vendors?
- What are the notification requirements? Many policies require carrier notice before you spend money on response, and late notice can jeopardize coverage.
- Does the policy cover funds we hold for others, if that applies to your business?
- What happens at renewal if we have a claim? Ask about typical premium impact and non-renewal practices.
The order of operations
The sequence that gets the best outcome, in our experience:
- Close the big 4 control gaps first: MFA everywhere, EDR, separated backups, awareness training
- Document your money-movement verification procedure in writing
- Apply through a broker who places cyber regularly, with 2 to 3 carrier quotes
- Compare social engineering sub-limits, not just headline limits and premium
- Calendar a controls review 90 days before renewal, because the questions get harder every year
Insurance is the risk you transfer. The controls are the risk you actually reduce, and they are also what makes the insurance affordable and valid. Atticus Rowan helps small businesses stand up the control set, produce the evidence underwriters want and answer applications accurately the first time. If a customer contract or your own risk math has put cyber insurance on your desk, contact us before you sign the application.
Related insights
More on Cyber insurance →April 20, 2026
What actually lowers your cyber insurance premium
The specific control changes, evidence artifacts and broker moves that actually lower cyber insurance premium at renewal, and what does not.
April 19, 2026
MFA, EDR and offline backups, the cyber insurance triage list
The three controls that carry the most weight in modern cyber insurance underwriting, why they became the triage list and how to confirm yours are actually operating.
April 19, 2026
Your cyber insurance renewal questionnaire is getting harder, a walkthrough
A walkthrough of the modern cyber insurance renewal process, why the questionnaire has doubled in length since 2022 and what the underwriter is actually measuring behind each section.