"Many business owners assume their insurance covers everything until a claim, a lender or a contractual requirement prompts a closer look. The declarations page is the first place to see what protection is in place and where gaps may exist."
Laura Barker, client service supervisor, Gallagher
Talk to an advisor
What does cyber insurance for small businesses cover?
"Cyber coverage" is a broad term rather than a single protection. It incorporates multiple coverage elements designed to address different types of loss.
One detail worth paying close attention to is the named insured: The specific individual(s) and company(s) listed in the policy. Businesses can sometimes assume affiliated companies, separate legal entities or related operations are automatically covered. However, coverage applies only to named insureds.
Most policies are organized around two broad categories: First-party coverage and third-party coverage.
Understanding your cyber insurance policy limits, sublimits and deductibles
Business owners focus on the policy limit because it's usually the largest number on the declaration page. However, sublimits, deductibles and any cost-sharing requirements also play an important role in determining how coverage applies when a claim occurs.
- Sublimits: A sublimit is a separate cap for a specific type of loss. For example, a policy may have an overall limit of $2 million but only $250,000 available for ransomware-related claims. With such a policy, if you raise a claim for your ransomware loss, it would be limited to the lower amount; that's the sublimit. According to Barker, this is one of the most common areas of confusion because business owners assume the full policy limit applies to every cyber event.
- Deductibles (or retentions): This is the portion of the loss the business pays before insurance begins to pay. The amount varies depending on the organization and the selected coverage.
- Coinsurance and cost-sharing provisions: Some policies require the business to pay a percentage of certain losses after the deductible is met. For example, if a policy includes a ransomware cost-sharing provision, the policy holding business may have to pay a part of the loss while the insurer covers the remainder.
An additional consideration is that, if businesses collect payment card information, store customer records, maintain healthcare data or manage other sensitive information, they may require different levels of cyber risk than businesses with limited data exposure.
Talk to an advisor
What's not on the declarations page
The declarations page provides a snapshot of what's covered, but some important details appear later in the policy, where exclusions set out where coverage may not apply.
Common exclusions and limitations include:
- War and state-sponsored cyberattacks: Many cyber policies exclude losses linked to state-backed cyber operations or acts of cyber warfare. Small businesses may not be directly targeted by a foreign government, but they can still get caught up in a widespread cyber event later attributed to a state-sponsored group.
- Social engineering and funds transfer fraud: Social engineering involves manipulating employees into sharing sensitive information or sending money through fraudulent emails, messages or other communications. For example, an employee may receive a phishing email that appears to come from a trusted vendor and unknowingly transfer funds to a criminal's account. While cyber policies often address the data breach aspect of these incidents, the financial loss may be covered separately and subject to lower limits, often ranging from $100,000 to $250,000.4
- AI risks: As businesses increasingly adopt AI tools, insurers are introducing new policy language that may limit coverage for certain AI-related incidents. Coverage varies by carrier and policy form, making it important to understand how AI-related risks are addressed.
- Unencrypted devices and personal devices used for work: Some policies limit coverage if an incident originates from an unsecured laptop, mobile device or personal device used for business purposes. Businesses with remote or hybrid workforces may want to clarify how these situations are addressed within their policy.
- Prior acts and known vulnerabilities: If a security weakness was known before coverage was purchased or renewed, and remained unresolved, a claim related to that issue may not be covered. Insurers scrutinize the business's system maintenance and security control measures during the application process.
Why claims get denied
Claims can be rejected for a variety of reasons, but the most common issues are:
- Misrepresentation on the application: A business stated that multi-factor authentication (MFA) was enabled across all systems, but an accounting platform or other critical system wasn't protected in the same way. So, claims arising to cover any breach on that accounting platform or email may not be covered, because the information provided during the application process did not clearly mention the security lapses.
- The incident wasn't reported quickly enough: Most policies require notice within 48-72 hours of discovering an incident. Waiting too long to notify the insurer about the incident may result in claim rejection.
- The loss wasn't covered: For example, a business experiences a phishing attack and loses money through a fraudulent wire transfer, but then discovers that the policy covers the breach itself, but not the transfer of funds.
- A sublimit was reached: The loss may be covered, but a specific coverage category may have reached its maximum payout limit. Therefore, the remaining costs become the responsibility of the business.
"My advice is straightforward: Be accurate when completing the application. The goal isn't to look more secure than you are. The goal is to make sure the coverage reflects the business as it operates today."
Laura Barker, client service supervisor, Gallagher
What insurers expect before providing coverage
Cyber insurance applications have become more detailed as cyber threats continue to evolve. Insurers strongly prefer clients with appropriate security measures in place and may request documentation and evidence of key controls before agreeing to provide coverage. These measures include:
- Multi-factor authentication (MFA): MFA has become one of the most important controls insurers look for today, particularly for email, remote access, cloud applications, administrative accounts and other systems that provide access to sensitive information.
- Endpoint monitoring and protection tools: Insurers evaluate how devices across the organization are monitored and protected against cyber threats.
- Backup and recovery processes: Businesses are increasingly asked about how data is backed up, where it's stored and whether recovery procedures are tested regularly.
- Incident response planning: Insurers look for evidence that the organization has documented procedures for responding to a cyber event, including key contacts and communication plans.
- Employee cybersecurity training: Since many incidents begin with a phishing email or other forms of social engineering, insurers favor organizations that have employee awareness programs in place to help reduce exposure.
- System maintenance and patch management: Keeping software and systems updated remains a foundational part of cyber risk management.
Talk to an advisor
Practical steps: A quick checklist
A few practical steps can help businesses better understand their cyber coverage and prepare for potential incidents:
- Review your declarations page and confirm you understand your coverage, limits, sublimits, deductibles and endorsements.
- Enable MFA across email, remote access tools, cloud applications, administrative accounts and accounting systems.
- Review sublimits for ransomware, business interruption, social engineering and funds transfer fraud — not just the overall policy limit.
- Confirm whether social engineering and wire fraud losses are covered and understand any limits that apply.
- Test backup and recovery procedures regularly to verify that critical systems and data can be restored if necessary.
- Maintain an incident response checklist in an offline or externally accessible location that includes key contacts, insurer information, reporting procedures and recovery steps.
- Confirm that the information provided during the application process accurately reflects your current security controls and business operations.
- Schedule a cyber coverage review with your advisor to discuss changes in technology, operations, vendors or data exposure.
Connect with a Gallagher advisor
Cyber insurance is not just a technology consideration — it's a business decision. Whether a business is evaluating cyber insurance for the first time or reviewing existing coverage, understanding how a policy is structured provides valuable insight into what protection is in place, where limits apply and where potential gaps may exist.
Gallagher's small business advisors work with clients to review their cyber exposures, identify potential coverage gaps and evaluate the financial impact a cyber incident may have on their business. These conversations help business owners better understand their options and make informed coverage decisions.
Talk to an advisor today
Sources
1Thrift, Mike. "Cyber Insurance for Small Businesses in 2026: MFA Requirements, Ransomware Coverage, and Premium Benchmarks," Beancount.io, 10 May 2026.
2Kopp, Andreas. "Small Business Ransomware Statistics," Wifitalents, 12 Feb 2026.
3"Cyber Insurance: Risks and Trends 2026," MunichRe, 25 Mar 2026.
4Efros, Stefan. "What Changed in 2026 Cyber Insurance," Efros, 17 Jun 2026.