

Size cyber limits to your incident math, not your revenue: what a multi-week outage costs you in lost income and payroll, what notifying and monitoring every person in your records would cost, and the largest wire an attacker could talk your team into sending. For many small and mid-size businesses that math lands at $1M to $5M in cyber limits; businesses holding regulated data (health, financial, payment-card) or dependent on always-on systems frequently justify more. The waiting period and the sublimits inside the form matter as much as the headline limit.
The most common catastrophic cyber loss for an operating business is interruption: ransomware or a destructive attack takes systems down, and for two or three weeks you cannot invoice, schedule, or ship while payroll continues. Multiply your weekly gross profit by a realistic restoration window, add incident-response professionals billing by the hour, and you have the floor for your business-interruption agreement. Then read the waiting period, the hours of downtime you absorb before coverage starts, and any sublimit: a $50,000 interruption sublimit against a three-week outage is decoration.
Notification, call-center, and credit-monitoring obligations scale with the number of people in your systems: customers, patients, employees, applicants. Per-person incident costs, studied annually by IBM and others, run high enough that even a modest database implies six-figure response costs, and regulated data (health information, financial records, card data) adds investigations and penalties on top. A business holding 50,000 records is carrying a materially different exposure than one holding 500, whatever their revenues say.
Funds-transfer fraud has a property no other loss shares: the money is usually unrecoverable within hours. Size the social-engineering endorsement to the largest payment your controls would plausibly release on a convincing instruction. In the era of deepfaked executives, that is the largest wire your bank would honor, not the largest one you consider normal. Endorsement sublimits commonly run well below the main policy limit, which is precisely why they need to be chosen deliberately rather than accepted as written.
Cyber premium varies more than any established commercial line because underwriters price your actual controls: multi-factor authentication, backups, endpoint monitoring, employee training. Well-run smaller businesses commonly see four-figure annual premiums for $1M limits; weaker controls, sensitive data, or prior incidents move pricing and insurability quickly. The controls conversation cuts both ways: the same measures that reduce premium are the ones that keep an incident small, which is why a serious quote process starts with what you have, not with a number pulled from revenue.
For a business with modest records, short tolerable downtime, and strong controls, commonly yes. For anyone holding regulated data, running always-on operations, or moving large wires, the incident math frequently outruns $1M before the third-party claims even start.
Increasingly, yes. Enterprise customers, lenders, and public-sector contracts now routinely require specific cyber limits and endorsements as a condition of doing business. Check contracts before renewals, because the requirement often exceeds what you carry.
Ninety days before it, you get one market read for your industry, from me. Nothing else happens without you.
Sixty seconds of questions, or upload your current policies. ARIA shows what it finds, cited to the page, with no obligation attached.
In writing, within 48 hours, free. If the read shows your current program is right, I will tell you to stay put, in writing. You lose nothing either way.
Nothing binds until a licensed Risk Strategist signs the placement
ARIA · live across every page