Cyber Insurance for Small and Medium-Sized Businesses: Costs, Coverage, and Pitfalls to Avoid



Cyber insurance for small and medium-sized businesses (SMEs) is designed to cover a portion of the costs following a cyberattack: system restoration, expert fees, notification, and business interruption. It is not a substitute for security measures. With 16 % of French microbusinesses and SMEs reporting a cyber incident in 2025, according to Cybermalveillance.gouv.fr, it is becoming primarily a risk management tool—provided one understands its limitations, prerequisites, and true cost.


Cyber Insurance for Small and Medium-Sized Businesses: Costs, Coverage, and Pitfalls to Avoid

Cyber Insurance for Small and Medium-Sized Businesses: Why the Trend Is Gaining Momentum in France

Interest in cyber insurance for small and medium-sized businesses is growing because cyberattacks no longer target only large corporations. SMEs often have less segmented systems, rarely tested backups, and a heavy reliance on a few software applications: accounting, e-commerce, ERP (enterprise resource planning), and email services such as Microsoft 365 or Google Workspace.

The available figures confirm growth in the insurance market. In its LUCY 2026 study, AMRAE reports 20,996 standalone cyber insurance policies in France in 2025 among its panel of brokers, compared to 14,124 in 2024, representing a 49% increase. Small businesses accounted for 5,547 policies, up 45 %, and microbusinesses for 9,360, up 35 %.

Another figure that’s often cited is that 68 % of French SMEs are projected to be insured in 2026, compared to 45 % in 2024. Caution: This data comes from a single commercial source identified in the research, not from a public agency or a trade association. It likely reflects a real trend, but it should not be interpreted as a benchmark statistic.

The strongest indicator lies elsewhere: the number of policies is increasing alors while total premiums are falling slightly. AMRAE reports €305.9 million in cyber premiums written in 2025, compared to €316.8 million in 2024. France Assureurs, for its part, estimates approximately 302 million euros in standalone cyber premiums in 2025, excluding coverage included in multi-risk policies. In other words, more companies are gaining access to coverage, but with widely varying coverage amounts, deductibles, and terms.

What does cyber insurance cover?

Cyber insurance generally covers the financial consequences of a cyber incident. The 2025 French Guide to Public Procurement lists three main categories: the costs of managing and reporting a data breach, the costs of restoring the IT system, and business interruption losses.

Specifically, following a ransomware attack (software that locks your files in exchange for a ransom), the insurer may cover the costs of an incident response expert, server restoration, legal assistance related to the GDPR, crisis communication, or a portion of the revenue lost during the outage. The scope of coverage depends on the policy. The devil is in the details.

A “business interruption” policy may, for example, exclude the first 12, 24, or 48 hours of downtime through a deductible of this amount. A clause may limit coverage if the failure stems from a service provider, outdated software, or a lack of usable backups. This is often when business leaders discover that “being insured” does not mean “being reimbursed no matter what happens.”

Read also  The 7 best free online translation sites in 2026

In fact, in 2024, the ACPR, the banking and insurance supervisory authority, asked insurers to clarify whether cyber risk was actually covered or excluded in their policies. The issue is very specific: some companies believe they are protected by a comprehensive business insurance policy, even though cyber coverage is limited or even absent.

How much does cyber insurance for small and medium-sized businesses cost?

The cost of cyber insurance for small and medium-sized businesses depends on revenue, industry, coverage level, deductible, incident history, and the security measures already in place. Rates published by brokers in 2026 provide a useful ballpark figure: around 1,000 to 5,000 euros per year for an SME with 10 to 250 employees and 2 to 50 million euros in revenue, with coverage limits of approximately 1 to 5 million euros. This is not an official average, but it is consistent with the ranges observed in the market.

With this budget, it’s best not to compare policies based solely on the annual premium. Two policies costing 2,500 euros each can be very different if one includes a 10,000-euro deductible, a 24/7 hotline, and coverage for business interruption, while the other strictly limits appraisal costs and excludes certain automatic coverage providers.

Company Profile Estimated annual bonus A Popular Ceiling Option Current Subscription Period
Small Business with a Showcase Website and Cloud-Based Email A few hundred to 1,500 € 250,000 to 1 million euros 1 to 2 weeks for a simple questionnaire
SMEs with 10–50 employees, customer data €1,000 to €3,000 1 to 2 million euros 2 to 4 weeks with minimal analysis
SMEs with 50–250 employees, more complex IT systems €3,000 to €5,000 and up 2 to 5 million euros 3 to 6 weeks; an audit may sometimes be required
E-commerce SMEs or sensitive businesses Variable, often capitalized Based on revenue and reliance on the web 4 to 8 weeks if requirements are met

Good risk assessment involves comparing the premium to the cost of a business interruption. If your business loses 8,000 euros per day without access to the ERP system or e-commerce site, a high deductible and a ceiling that’s too low can render the policy largely useless. To put these figures into perspective, here’s a detailed breakdown of the The Actual Cost of a Ransomware Attack for an SME It often helps to have the right figures ready before requesting a quote.

Requirements Set by Insurers

Insurers no longer sell cyber insurance for small and medium-sized businesses as a mere administrative formality. They are increasingly requesting proof: procedures, screenshots of system settings, audit reports, and backup policies. The goal is simple: to avoid insuring a company whose risk is already under control.

Requirements vary by contract, but the most common requests tend to be fairly consistent:

  • multi-factor authentication (MFA) (two-step verification) for email, administrator access, and sensitive tools;
  • Standalone, restorable, and tested backups, ideally with an Hors copy as a line of defense against ransomware;
  • Regular updates to servers, workstations, CMS platforms such as WordPress, extensions, and frameworks;
  • advanced endpoint protection, such as EDR (behavioral detection) rather than just antivirus software;
  • raising employee awareness about phishing, as email remains a common point of entry.
Read also  5 no-code web and mobile project ideas to create in 2025

In the projects we work on, we often see the same disconnect: the company thinks it’s “covered” because it has an automatic backup, but no one has tested a full restore in six months. But a backup that can’t be restored isn’t worth much when everything gets encrypted.

This point is in line with regulatory recommendations. For entities subject to NIS2, ANSSI states in ReCyF v2.5, published in 2026, that backup and restore processes must be tested at least once a year, and that backups must be protected against incidents that would render them unusable—for example, through off-site storage. Even if your small or medium-sized business is not subject to NIS2, this is a sound practice.

Web and mobile applications also deserve special attention. A poorly secured API (an interface that allows two software programs to communicate) can expose customer data even if the main server remains uncompromised. Before signing up, check the application security features, particularly those related to Invisible vulnerabilities in mobile APIs and the publication review process for a secure mobile app.

Exclusions That Make All the Difference When a Claim Is Filed

Cyber insurance should be viewed as a risk-based contract, not as a promise of unlimited coverage. Exclusions may include acts of war, certain systemic events, uninsurable fines, indirect losses, lack of maintenance, or failure to comply with the measures specified in the questionnaire.

The most common pitfall is filling out the application form too quickly. If you check “MFA enabled on all sensitive accounts” alors even though only executives use it, the insurer may dispute the coverage after an incident. The same applies if you declare that backups have been tested alors there are no minutes, tickets, or reports alort to prove it.

Another point is often overlooked: Under Article L12-10-1 of the Insurance Code, which applies to cyberattack clauses, the victim must file a complaint with the competent authorities within 72 hours of becoming aware of the attack in order to be eligible for compensation. In the panic following an incident, this timeframe passes very quickly.

Honestly, cyber insurance is only worthwhile if you’re willing to take a minimally professional approach to risk management. Otherwise, you’re paying a premium for a policy that’s not very robust. The right approach is to prepare an insurability dossier: a simple system map, a list of service providers, backup procedures, emergency procedures, and crisis contacts.

When Cyber Insurance Is a Good Choice—and When It Isn't encore

Cyber insurance for small and medium-sized businesses is a good fit if your company relies heavily on digital technology, processes personal data, sells online, manages connected manufacturing, or cannot operate for several days without email or business software. It is also useful if your large corporate clients require contractual guarantees.

It’s less of a priority if you have no cybersecurity budget. In that case, spending between 3,000 and 8,000 euros on basic measures may be more cost-effective than a premium: widespread MFA, a password manager, 3-2-1 backups, Windows hardening, updates, monitoring, and a disaster recovery plan. An insurance policy comes next, built on a more solid foundation.

Read also  Webflow agency, no-code agency: optimize your website quickly and without coding

The NIS2 Directive is putting additional pressure on certain organizations. According to ANSSI’s MonEspaceNIS2, “significant entities” include, in particular, organizations with at least 50 employees or with revenue and total assets exceeding 10 million euros, unless they are classified as critical entities. For these companies, insurance is not a substitute for compliance, but it can supplement the financial framework.

From the agency’s perspective, the instinct is to treat insurance as a consequence of architecture: where is the data, who manages what, how is it restored, and how long can operations continue? On an e-commerce site, for example, securing access, updates, payments, OVH or Cloudflare hosting, and backups directly impacts insurability.

Modern authentication methods can also reduce the risk of account compromise. Passkeys (passwordless login based on a cryptographic key) are becoming a serious option for exposed web services; this topic is discussed in more detail here for Websites that want to replace passwords.

Addressing these types of projects early on helps avoid most unpleasant surprises: inaccurate disclosures, insufficient coverage, unusable backups, and unrealistic recovery timelines following an incident. This is often where an outside perspective can save time, especially when insurance, hosting, security, and business continuity intersect.

FAQ on Cyber Insurance for Small and Medium-Sized Businesses

Is an SME required to purchase cyber insurance?

No, there is no general requirement for cyber insurance for French SMEs. However, certain clients, requests for proposals, or contracts may require it, and NIS2 indirectly reinforces expectations regarding risk management.

Does cyber insurance cover ransom payments?

It depends on the contract, the applicable legal framework, and the circumstances. Even when coverage is provided, paying a ransom remains a risky decision, subject to oversight by the authorities, the insurer, and incident response experts.

How long does it take to get cyber insurance?

A small business can receive a quote within one to two weeks if its application is straightforward. For an SME with higher risk, expect it to take three to six weeks, especially if the insurer requests supporting documentation or an audit.

Does a comprehensive business insurance policy already cover cyber risks?

Sometimes, but often with low coverage limits or exclusions. You need to ask for it in writing to confirm whether restoration costs, notification costs, expert assessment costs, and cyber business interruption losses are included.

What should you do before requesting a quote for SME cyber insurance?

Prepare your documentation: MFA enabled, backups tested, software inventory, updates, service providers, incident procedures. A well-organized file improves communication and minimizes ambiguity in the event of an incident.

English