If you asked ten business owners how they landed on their cyber insurance limit, most would give you some version of the same answer: "That's what our broker recommended," or "That's what similar companies in our industry carry." Neither answer is wrong, exactly. But neither one starts from your actual exposure, and that gap is where a lot of underinsured companies find themselves after a real incident.
Start with financial exposure, not a rule of thumb
A cyber insurance limit should be a reflection of what a serious incident would actually cost your specific business: incident response and forensics, legal counsel, regulatory notifications, credit monitoring for affected customers, business interruption while systems are down, and in some cases, ransom negotiation and payment. Those costs scale with things that are unique to you: how much sensitive data you hold, how dependent your revenue is on systems staying online, and which regulations apply to your industry.
Two companies with similar revenue can have wildly different exposure. A regional retailer processing card payments carries different risk than a professional services firm holding client financial records, even if their top-line revenue is identical. A benchmark based on revenue alone misses that entirely.
Where "peer benchmarking" goes wrong
Peer comparisons are a useful sanity check, but they're often applied too loosely. "Companies our size carry $2M in coverage" tells you what the market is doing on average, not what your business needs. If your peer group skews toward companies with lighter data footprints or better security postures than yours, following their lead can leave you underinsured. The reverse is also true: you may be paying for more coverage than your actual exposure justifies.
The more useful benchmark is sector-specific and grounded in real loss data, not a rough headcount-and-revenue match.
A better process
- Quantify your financial exposure. Model what a realistic worst-case incident costs your business specifically, using your data volume, systems, and industry.
- Compare against real industry indicators. Look at how your sector's actual incidents and losses trend, not just what similarly-sized companies happen to be buying.
- Stress-test your current limit. If your existing policy caps out well below your modeled exposure, that gap is where you're exposed even with a policy in place.
- Revisit annually. Your exposure changes as your data footprint, revenue, and systems change, and your coverage should move with it.
The bottom line
A cyber insurance limit isn't something to set once and forget. It's a number that should be recalculated as your business changes, grounded in what an incident would actually cost you rather than what a peer group happens to be buying. Getting that number right is the difference between a policy that protects your business and one that just checks a box.
If you want a clear, evidence-based read on your own exposure before your next renewal, that's exactly what our limits threshold and financial exposure assessments are built for.