Kinro

Kinro

Blog

Coverage Decisions · September 24, 2026

How much cyber insurance should a small tech startup buy?

Estimate a startup's cyber insurance needs using customer contracts, incident costs, policy sublimits, security controls, and questions for a licensed agent.

Kinro Team
How much cyber insurance should a small tech startup buy?

A small tech startup should start by comparing the cyber insurance limit required by its most demanding customer contract with the estimated cost of a serious cyber incident. Then review available policy limits and terms with a licensed agent. The amount the market will offer is a constraint to evaluate, not a measure of how much coverage the startup needs. A common entry point may be useful for getting quotes, but it is not a recommendation by itself. Data volume, payment handling, regulated information, downtime, contractual liability, security controls, and policy sublimits can make the right limit higher or change the policy structure entirely.

Use the framework below to build a starting number, then have a licensed agent review the assumptions, available limits, exclusions, and carrier requirements. Cyber insurance is not a guarantee that every loss will be covered.

Start with the requirement that can stop the deal

If a customer, lender, investor, landlord, or partner requires cyber insurance, write down the exact wording before choosing a limit. A contract may specify:

  • A minimum limit or aggregate limit.
  • First-party coverage, third-party coverage, or both.
  • A certificate of insurance or specific endorsement.
  • Data security, breach notification, or vendor obligations.
  • Additional insured or waiver language.
  • A required limit that applies to cyber, technology errors and omissions, or another policy.

Treat the contractual limit as a floor to investigate, not proof that the business is fully protected. Share the contract with the agent and, where the language affects legal obligations, counsel. The policy and the contract should be reviewed together.

Kinro’s startup insurance guidance notes that customer contracts can drive E&O, cyber, general liability, limits, and certificate wording. Its cyber liability coverage page also lists contractual cyber limits as a common trigger for review.

Estimate the cost of one serious incident

Build a simple exposure worksheet. Use your own operating numbers where possible, and label estimates clearly. The purpose is not to predict the next claim. It is to avoid choosing a limit without testing the loss categories that matter to the business.

ExposureWhat to estimateWhy it affects the limit
Breach responseForensics, legal review, notification, call-center support, credit monitoring, public relations, and data restorationResponse costs can start before a liability claim exists. The FTC identifies legal counsel, notification, data recovery, crisis management, forensic services, and related costs as first-party considerations.
Business interruptionDaily gross revenue or contribution margin multiplied by a realistic recovery period, plus extra expense needed to keep operatingA startup that cannot deliver its service, access its systems, or process transactions may lose revenue while recovery is underway.
Third-party liabilityCustomer claims, defense, settlements, judgments, and contractual obligations that the policy may addressA SaaS or technology company can face claims from customers that rely on its software, systems, or data handling.
Regulatory and payment exposureLegal defense, investigations, assessments, and other costs connected to regulated data or payment processing, subject to what is insurable and coveredHealth, financial, payment, and personal data can add obligations and affected parties. Coverage varies by policy and jurisdiction.
Restoration and extra expenseSpecialists, temporary systems, replacement equipment, expedited services, and other recovery costsA low revenue number does not necessarily mean a low recovery bill.

A simple starting calculation

Add the reasonable estimates for a serious incident:

Response costs + interruption loss + extra expense + third-party exposure + regulatory and payment exposure = preliminary exposure number

Then compare that number with the highest contractual requirement and the policy options available to the business. Round the working number up to the next available limit only after checking the policy’s sublimits, waiting periods, aggregate, defense-cost treatment, and exclusions.

This calculation is a discussion tool, not a quote or a coverage recommendation. A licensed agent should test the assumptions against carrier underwriting and the policy form.

Use these five startup facts to adjust the estimate

1. The records you hold and where they live

Count the sensitive information the startup stores, processes, or can access, including customer, employee, payment, health, and authentication data. Include information held in email, cloud storage, customer-support systems, accounting tools, analytics platforms, and vendor systems.

Ask:

  • How many records could be affected by one incident?
  • Which records contain personal, health, financial, or payment information?
  • Are you storing the data, processing it, or handling it for another business?
  • Which vendors can access it?
  • Can you identify and restore the affected data?

A startup that holds little sensitive data may have a different first-party exposure from one that stores customer data for enterprise clients. The company’s role in the data flow matters as much as its employee count.

2. The revenue and systems that stop when technology stops

Estimate how much revenue depends on the product, cloud environment, payment system, email, or other digital tools being available. Use a recovery period that reflects the startup’s actual backup, restoration, vendor, and customer-support arrangements.

Ask:

  • What stops working if the production environment is unavailable?
  • How much revenue or margin is tied to one day of downtime?
  • What would it cost to operate manually or use a temporary system?
  • How quickly can the team restore from a tested backup?
  • Does a key cloud or technology vendor create concentration risk?

CISA advises small businesses to maintain an incident response plan and test backups and restores. Those controls can affect recovery assumptions, but they do not eliminate the need to model downtime.

3. The customer contract with the highest consequence

Review the startup’s largest customer and vendor obligations, not only the standard contract template. Enterprise customers may require a particular limit, indemnity, security standard, notification timeline, or coverage combination.

Ask:

  • What is the largest contractual limit or indemnity obligation?
  • Does the contract make the startup responsible for a customer’s data or systems?
  • Does it require technology E&O as well as cyber?
  • Does it require worldwide coverage or a particular response process?
  • Can one incident affect several customers at once?

A cyber limit cannot replace technology E&O when the claim concerns a failed product, service, implementation, or professional obligation. Ask the agent how the policies interact.

Identify whether the startup handles protected health information, payment card data, financial information, or personal information subject to privacy and breach-notification requirements. The FTC separates first-party costs from third-party liability and recommends checking whether a policy addresses defense of lawsuits or regulatory investigations, business interruption, fraud, forensic services, and notification-related costs.

Do not assume that a policy covers every fine, penalty, assessment, or contractual payment. Review the wording, applicable law, sublimits, and exclusions with a licensed agent and legal counsel where needed.

5. The controls the carrier will underwrite

Your limit calculation may describe the exposure, but the market decides what it will offer based on the application and risk profile. Gather the controls a carrier is likely to ask about:

  • Multifactor authentication for email, remote access, and administrator accounts.
  • Tested backups and a documented recovery process.
  • Software patching and endpoint protection.
  • Access controls and privileged-account management.
  • Vendor and cloud-provider oversight.
  • An incident response plan and current response contacts.
  • Prior incidents, claims, or known vulnerabilities.

CISA recommends an incident response plan, leadership involvement, MFA, patching, and tested backups for small businesses. These controls reduce operational risk and make the underwriting discussion more useful, but they are not a promise of coverage or claim payment.

Do not stop at the headline limit

Two policies with the same headline limit may not respond the same way. Before comparing quotes, ask the agent to identify:

  • Sublimits for ransomware, funds transfer fraud, social engineering, business interruption, or notification costs.
  • Whether defense costs reduce the available limit.
  • The waiting period before business interruption coverage begins.
  • Whether the limit is an annual aggregate shared across multiple incidents.
  • Deductibles or self-insured retentions for each major coverage part.
  • Retroactive dates and any prior-acts limitations.
  • Conditions that require specific security controls or vendors.
  • Whether technology E&O, crime, D&O, or another policy is needed for a separate exposure.

The FTC specifically recommends checking first-party and third-party coverage and asking whether the insurer will defend a lawsuit or regulatory investigation. Kinro’s existing cyber liability guide also recommends reviewing what is included, excluded, and subject to separate limits.

Illustrative starting points, not Kinro recommendations

The following categories are a way to organize the conversation. They are not quotes, guarantees, or a statement of the limits Kinro can place. Actual limits depend on the business, state, carrier appetite, policy wording, contracts, and underwriting.

Startup profileWhat to discuss first
Low data exposure, low downtime sensitivity, and no special contract requirementA standard entry quote, tested against the incident worksheet and the cash the company could absorb.
Customer data, payment processing, meaningful downtime exposure, or security questionnairesA higher limit or stronger sublimits may be worth evaluating, alongside the customer and vendor contracts.
Healthcare, financial, or other regulated dataReview regulatory defense, notification, payment, and third-party exposures separately. Do not rely on a generic startup benchmark.
SaaS or technology provider with enterprise customersCompare the largest contractual requirement with the modeled loss, and review cyber alongside technology E&O.
Multiple products, cloud concentration, or a customer base that could be affected at onceModel aggregation and recovery time. Ask whether the available limit and sublimits respond to one event affecting several customers.

When should a startup revisit its cyber limit?

Review the limit when the business changes, not only at renewal. Revisit it after:

  • A major increase in revenue, customers, or stored records.
  • A new healthcare, financial, payment, or enterprise customer.
  • A new contract with a higher insurance requirement.
  • A product launch, acquisition, international expansion, or material cloud change.
  • A ransomware event, breach, near miss, or major control failure.
  • A change in backup, MFA, incident response, or vendor arrangements.

Questions to take to an agent

Bring these answers to the quote conversation:

  1. What is the largest loss category in our worksheet?
  2. Which customer contract sets the highest insurance requirement?
  3. Are the required limits available for our business and state?
  4. Which important coverages have sublimits or waiting periods?
  5. Do defense costs erode the limit?
  6. Is the limit shared across the policy year?
  7. What security controls are required for the quoted coverage?
  8. Should cyber be reviewed with technology E&O, crime, D&O, or another policy?
  9. Which assumptions in our application need confirmation from IT, a security provider, or counsel?
  10. What changes should trigger a limit review before renewal?

Kinro can help compare coverage questions and available carrier options. Start with the Cyber Liability product page, or use the startup insurance page if the business needs to review several coverage lines together.

Sources

  • Federal Trade Commission: Cyber Insurance, accessed September 24, 2026. The FTC distinguishes first-party and third-party coverage and lists response, interruption, forensic, legal, fraud, and liability considerations.
  • CISA: Cyber Guidance for Small Businesses, accessed September 24, 2026. CISA recommends role-based security ownership, incident response planning, MFA, patching, and tested backups.
  • Kinro: Cyber Liability, accessed September 24, 2026. Kinro’s public page identifies data, payment, cloud, vendor, security-control, and contractual-limit inputs.
  • Kinro: Startup Insurance, accessed September 24, 2026. Kinro’s public page identifies startup contract, data, product, and related coverage questions.

This guide is general information, not legal, cybersecurity, or insurance advice. Policy terms, coverage, limits, exclusions, deductibles, and availability vary. Work with a licensed insurance professional and legal or security advisers where appropriate.