CapeFear.ai

Your Commercial Clients Think They're Too Small for Cyber Insurance. Most Are Wrong.

An insurance agency book of business being reviewed for missing cyber coverage, illustrated

Ask a small business owner if they need cyber insurance and a lot of them will tell you it's for someone else. A bank, a hospital, a company with a name people recognize. That belief is common, and it is wrong, and it is sitting inside your agency's own book of business right now on accounts nobody has looked at since the policy was first written.

The numbers most agencies haven't seen

MoneyGeek's 2025 analysis of small business cyber risk found that 74% of small businesses carry inadequate cyber coverage, even though 92% carry some form of business insurance. The average cyber claim hit $264,000 in 2025, up from $205,000 the year before, a 30% jump in a single year. The median small business holds about $12,100 in cash reserves. That is a 22-to-1 gap between what a typical claim costs and what a typical business could actually cover out of pocket.

Hiscox's 2025 Cyber Readiness Report puts a number on how often this actually comes up: 59% of small and mid-sized businesses it surveyed had experienced a cyberattack in the past 12 months, and a third of those were hit with fines or penalties afterward. This is not a rare event you can underwrite around. It is a routine one.

Why the gap hides inside a normal book of business

Nobody sells a commercial package and skips cyber on purpose. It usually happens for a quieter reason: the account was written five or six years ago, before cyber was a standard line item on most applications, and it has renewed on autopilot ever since. Or the client has a general liability policy with a thin cyber endorsement bolted on, one that would not come close to covering a real breach response, and nobody has ever walked them through what that sublimit actually means in a $264,000 claim. Or the account manager knows the exposure exists but the account is one of two hundred on their desk and there is no system flagging it, just memory.

None of that is negligence. It is what happens when a real gap depends on someone remembering to check for it, account by account, on top of everything else a book this size requires.

What a proactive review actually catches

Run a straightforward pass across commercial accounts and a few patterns show up almost every time:

  • Accounts with general liability or a BOP but no standalone cyber policy or endorsement at all.
  • Accounts with a cyber sublimit that has not moved in years while claim costs have climbed 30% in the last twelve months alone.
  • Accounts in categories owners assume are low-risk (contractors, medical and dental offices, professional services) that actually handle exactly the payment and patient data attackers go after.
  • Renewals coming up in the next 60 to 90 days, which is the natural moment to raise it before the client is locked in for another year.

None of this requires new carrier relationships or a new product line. It is a review of what is already sitting in the management system, matched against what is already in the client's file.

How to run this without adding headcount

This is the kind of work that is easy to agree with and hard to actually staff. It does not need a person, it needs a process: an agent reads the book of business, flags accounts that show one of the patterns above, and drafts a short, specific note for each one (something closer to "your GL renews in 45 days and the file shows no standalone cyber coverage" than a form letter). The producer reviews every draft, edits or kills the ones that do not apply, and sends the rest. Nothing goes out to a client that a person has not read first. That is the same handoff model that works for renewal reminders and certificate requests: the agent does the reading and the drafting, a person still makes the call. See how a review like this actually runs if you want the mechanics.

Small business owners are not wrong to be busy. They are wrong about being too small to matter to an attacker. An agency that catches the gap before the renewal, instead of after the claim, is doing the part of the job that actually protects the client relationship.

Sources: InsuranceNewsNet, "74% of small businesses underinsured as cyber claims hit $264K" (MoneyGeek analysis, 2025); Hiscox Cyber Readiness Report 2025.

Book a 30-min call →