AdvisorPortal
← Learn·✎ ArticleΒ·CommercialΒ·2026-06-18

Cyber insurance for SMEs: what a breach actually costs

A cyber incident costs more than the ransom or the IT fix. Here is what typically drives the bill up, and what a cyber policy is built to cover for a small business.

Small and mid-sized businesses tend to assume cyber insurance is for banks and large tech companies, not a ten-person operation running on email and a point-of-sale system. In practice, the businesses with the least in-house IT resilience are often the ones a cyberattack hits hardest, precisely because they have no dedicated team to contain it.

Why the risk has grown for smaller businesses

The Monetary Authority of Singapore has repeatedly flagged that digitalisation is expanding the attack surface across the financial sector and, by extension, the businesses that depend on digital payments, cloud tools and online services to operate. This is not a risk unique to large enterprises: an SME using cloud accounting software, an online store, or even just email for invoicing carries meaningful exposure to phishing, ransomware and data compromise. Industry bodies in Singapore have also begun partnering directly with cybersecurity groups specifically to strengthen protection for SMEs, a sign that insurers see this segment as under-protected relative to its actual risk.

What actually drives up the cost of a breach

The headline cost people picture, a ransom demand or the fee to fix a hacked system, is usually only one part of the bill. The costs that tend to add up around it include:

  • Business interruption. If systems are down, the business may not be able to take orders, process payments, or operate normally for days, and that lost income is often larger than the technical remediation cost.
  • Forensic investigation. Establishing what happened, what data was accessed, and whether the vulnerability has actually been closed usually requires a specialist, not just the existing IT vendor.
  • Notification and legal obligations. Depending on what data was involved, a business may need to notify affected customers or regulators, and get legal advice on those obligations, which carries its own cost.
  • Third-party liability. If a breach exposes customer or partner data, the business can face claims from those affected, separate from its own recovery costs.
  • Reputational and recovery costs. Rebuilding customer trust, PR support, and credit monitoring offered to affected customers are common add-on costs after a serious breach.

Because actual breach costs vary enormously depending on the size of the business, the type of data involved, and how quickly the incident is contained, treat any specific dollar figure you see quoted elsewhere as illustrative rather than a number you can plan a sum insured around; ask your insurer or broker for current claims experience relevant to a business your size.

What a cyber insurance policy typically covers

Cyber policies aimed at SMEs generally bundle first-party costs (what happens to your own business) with third-party liability (claims from others affected). Common components include incident response and forensic costs, business interruption, data restoration, ransomware and extortion payments (subject to policy terms and increasingly subject to regulatory guidance), notification costs, and legal liability to third parties. Some policies also include access to a panel of specialists, so that when an incident happens, the business is not searching for a forensic firm at the same time it is trying to contain the breach.

What is often excluded or limited

Cyber policies commonly exclude losses arising from known, unpatched vulnerabilities that the business failed to address after being notified, and many require a baseline level of security practice, such as multi-factor authentication or regular backups, as a condition of cover. Some also limit or exclude cover for acts of war or state-sponsored attacks, a distinction that has become more contested as attribution of major attacks has grown murkier. Read the security requirements in the policy carefully, since a claim can be reduced or declined if the business was not meeting the baseline it agreed to at the point of purchase.

Sizing cover for a small business

Rather than picking a sum insured off a template, work from your own numbers: how many days of lost revenue would a full systems outage cost you, how much customer or payment data do you actually hold, and what would notification and legal support realistically cost given that volume. A business with minimal customer data and a simple website has a very different exposure from one processing payment card data at scale, even if both are similarly sized by revenue.

Talk to an advisor

Cyber insurance for SMEs is priced and structured differently across insurers, and the right sum insured depends on your data exposure and how much downtime your business could absorb. An advisor can help translate your operations into the specific covers that matter. Compare commercial cover at /compare/singapore/commercial or find an advisor through our directory.

Sources

This content is educational information from a licensed advisor, not financial advice. Product details vary by insurer β€” verify specifics with an advisor.

Daniel Lim profile photo
Daniel Limβœ“ Verified advisor
Motor Β· Property
View profile & ask a question β†’