Last year, 63% of small businesses watched their cyber insurance premiums jump 200% or more. This year, the carriers are not just charging more. They are sending applications with a checklist that looks a lot like a security audit. For a lot of small business owners, that checklist is the first time anyone has told them, in writing, what the minimum actually is.
That is the real story right now. Attackers have always known small businesses are softer targets. What is new is that insurance companies have started pricing it that way too, and they are not willing to write checks to companies that cannot prove they are doing the basics.
The numbers have stopped being abstract
A few data points that explain why this is happening:
- Verizon’s 2025 Data Breach Investigations Report logged 2,842 confirmed breaches at small and medium businesses — roughly four times the rate of large organizations.
- 88% of SMB breaches now involve ransomware, per Verizon’s dataset.
- 40% of small businesses say a $100,000 incident would put them out of business, according to VikingCloud’s 2025 research.
- 47% of companies under 50 employees still have no cybersecurity budget at all (StrongDM).
- Only 17% of SMBs carry cyber insurance (StrongDM). Most of the ones that do not are gambling, not budgeting.
These are not theoretical numbers. The $100,000 figure is not a worst-case scenario — it is closer to a median. Average ransomware payments from US small businesses last year ran about $115,000. Add forensic investigation, customer notification, legal fees, and the cost of downtime, and the real bill is usually two or three times the ransom itself.
The companies that survive these events are not the ones with the best security in their peer group. They are the ones that had enough working controls that an underwriter was willing to back them.
What insurers are now actually checking
Cyber insurance used to be closer to a credit-card application. “Do you have a firewall? Yes. Approved.” That era is over. In 2026, carriers verify the answers. They ask for screenshots, logs, and configuration exports. The Coalition and Fisch Solutions renewal checklists for 2026 spell it out:
- Multi-factor authentication everywhere — including VPN, email, and any admin interface. SMS-based MFA is increasingly treated as insufficient. Phishing-resistant MFA (hardware keys, platform passkeys, or push-based authenticator apps) is becoming the default ask.
- Endpoint detection and response (EDR) on every device, not just antivirus. Carriers want to see that someone is monitoring alerts, not just collecting them.
- Tested, offline, or immutable backups, with a documented recovery test in the last 12 months. A backup that has never been restored is not a backup. It is a hope.
- A documented incident response plan, with names, numbers, and a tested escalation. The 24-to-72-hour breach-notification window is real and tight.
- Email security beyond the basics: DMARC, anti-spoofing, and link rewriting at the gateway. Business email compromise is still the most common way small businesses get hit.
If a small business cannot produce those five items, the carrier either declines the policy, charges a deductible that makes the coverage almost pointless, or excludes ransomware from the policy entirely.

The gap is the message
The frustrating part is that almost none of these controls are expensive or exotic. Phishing-resistant MFA is free with Microsoft 365 or Google Workspace for most companies. EDR tools from companies like CrowdStrike, SentinelOne, or even Microsoft Defender for Business run in the low double digits per endpoint per month. Backups to an immutable cloud target with quarterly restore tests are a weekend project, not a quarter-long engagement.
So why is the gap so wide? A few reasons, all familiar:
- The owner is busy and the IT person is also the owner’s nephew.
- The “we passed our audit” trap — compliance frameworks (HIPAA, PCI, SOC 2) measure different things than insurer checklists. Passing one does not automatically satisfy the other.
- Security is invisible until it isn’t, and until recently the consequences were also invisible to most owners because they had not yet been hit.
- Many MSPs sell “managed security” that is mostly antivirus and patching, and the customer has no way to tell the difference.
What to do about it this quarter
If you are a small business owner, here is the practical list. Not the long version, just the one that will get you through an insurance application and meaningfully reduce your real risk.
- Turn on MFA everywhere this week. Start with email, VPN, and any admin console. Push-based authenticators are fine; SMS is a stopgap.
- Move from antivirus to EDR. If you cannot tell whether alerts are being reviewed, you do not have EDR — you have antivirus on autopilot.
- Test a backup restore. Pick one important system, restore it to a clean environment, and time it. That single test will tell you whether your backup story is real.
- Write a one-page incident response plan. Who calls the insurer, who calls legal, who talks to customers, who restores systems. Print it. Tape it to the wall next to the fire escape plan.
- Ask your MSP or IT provider for a written security summary. What is deployed, what is monitored, what is tested. If they cannot produce it in a week, that answer is itself the report.
None of these are fun projects. All of them are cheaper than a bad week.

The honest take
For most of the last decade, small businesses have been told that cybersecurity is “important” in the same vague way flossing is important. The insurance market has finally done what the awareness campaigns could not: it has attached a dollar amount to the gap, and it has started refusing to insure the gap.
That is a painful adjustment, but it is also the first honest market signal small business owners have ever gotten about what the minimum looks like. The companies that take the checklist seriously, even the ones doing it grudgingly while filling out a renewal form, will end up safer than the ones that wait for an incident to teach the lesson.
The 40% who cannot survive a six-figure attack are not going to learn it from a magazine article. They are going to learn it from the next invoice, the next claim denial, or the next morning when a workstation shows a ransom note instead of a desktop. The good news is that the checklist to avoid all three of those mornings fits on one page, costs less than a part-time hire, and does not require a security team to operate.
It just requires the decision to start.
Sources
- Verizon, 2025 Data Breach Investigations Report (DBIR): https://www.verizon.com/business/resources/reports/dbir/
- VikingCloud, Small Business Cybersecurity Statistics 2025
- StrongDM, Small Business Cyber Security Statistics 2025: https://www.strongdm.com/blog/small-business-cyber-security-statistics
- Coalition, 5 Essential Cyber Insurance Requirements: https://www.coalitioninc.com/topics/5-essential-cyber-insurance-requirements
- Fisch Solutions, Cyber Insurance Requirements 2026: MFA, Renewal & Compliance: https://fischsolutions.com/cyber-insurance-requirements-2026/
- Hiscox, Cyber Readiness Report 2025