# Cyber insurance for SMEs: what it takes to be covered

**Cyber insurance for SMEs** has shifted from a discretionary purchase to a precondition inside several supply chains. The Italian market collected EUR 182 million in premiums in 2023, the last consolidated figure, up 41% on the previous year. Only 8% of Italian small and medium businesses hold cover against cyber risk, compared with 35% in the United Kingdom and 28% in Germany. The gap reflects perceived cost, the security standards insurers now enforce, and a weak link between the premium paid and the exposure carried.

## The real cost of an uninsured breach

The IBM Cost of a Data Breach 2024 report puts the average cost of a data breach for an Italian SME at EUR 138,000. The figure covers forensic consultants, mandatory GDPR notifications, operational downtime and legal costs. It leaves out the indirect damage: customers who do not return, contracts lost, management time absorbed by an emergency that lasts months.

A mid-market policy for a company of 50 to 200 employees costs between EUR 2,500 and EUR 8,000 a year, with deductibles between EUR 5,000 and EUR 15,000. On arithmetic alone, the trade-off looks favourable. The arithmetic hides the real constraint: not every SME qualifies on the same terms, and some do not qualify at all.

## The security floor insurers now enforce

Insurers no longer sell cyber cover to anyone who asks. After the losses of the 2020-2022 ransomware wave, they tightened acceptance criteria across Europe. Multi-factor authentication has become a precondition on critical systems. The 3-2-1 backup rule, three copies of data on two different media with one stored offline, is checked through technical questionnaires. Endpoint protection must be current and configured. Annual staff training on phishing and security must be documented.

These requirements set the minimum hygiene level below which the risk becomes statistically unsustainable for the underwriter. The Generali and Confindustria Cyber Index PMI 2024 measured the average cyber maturity of Italian small businesses at 52 points out of 100, below the 60-point sufficiency threshold. The result is a trap: the companies that most need cover are the ones least able to obtain it, or they obtain it at prohibitive cost with heavy exclusions.

## What a standard policy actually covers

Four areas define the core of a cyber policy. Breach response covers the incident response team, forensic analysis, mandatory notifications to the data protection authority and to affected people, and legal defence. Business interruption covers lost revenue during the operational standstill, with limits that vary widely between providers. Ransomware management covers negotiation through specialised mediators and, within pre-agreed limits, the ransom itself. Cyber extortion covers threats to publish stolen data or to launch denial-of-service attacks.

The exclusions weigh as much as the cover. A known vulnerability left unpatched voids the claim automatically: where a fix was available for months and the company did not apply it, the policy does not pay. Missing multi-factor authentication on critical systems invalidates cover on those assets. Untested or inadequate backups cut the indemnity for data loss. Cyber war and acts of terrorism are excluded from most standard policies, a clause that produced litigation during the Russia-Ukraine conflict over what counted as an act of war in cyberspace.

## How the main European providers differ

Allianz Cyber Protection PMI offers limits up to EUR 1 million for both third-party liability and business interruption, with retroactive cover up to two years in the top tier. Its strength is financial capacity and a consolidated claims service; its weakness is a cost slightly above the market average.

Generali Cyber Lion comes in three tiers, from Basic to Top, and includes a free security assessment before the contract. The strength is a dense agency network across Italy and service in Italian; the weakness is lower limits than international competitors at the entry level.

AXA Cyber Protection PMI focuses on recovery costs and business interruption and bundles prevention services into the base package. It suits companies below 100 employees on price; underwriting on technical requirements is stricter.

Zurich leads with prevention and assessment included and an advisory approach before the insurance one. It demands more initial involvement from the company, and returns a deeper preliminary analysis and continuous support.

## The moral hazard question

A well-designed policy can weaken the incentive to prevent. Where a company knows the ransom will be covered, it may invest less in keeping attackers out. This dynamic, known in insurance economics as moral hazard, concerns both regulators and insurers. Their answer has two parts: increasingly strict minimum requirements, which turn underwriting into a security improvement process, and deductibles structured so the company always retains a significant share of the risk. Some European countries are debating a ban on cover for ransomware payments, on the grounds that it feeds the criminal market. Italy has not taken a firm position.

## A three-step assessment before buying

The assessment starts with the critical digital assets: which systems would stop operations if compromised. The second step quantifies the impact of one, three and seven days of downtime in lost revenue, fixed costs that continue and possible contractual penalties. The third estimates the likelihood of an attack from the sector, the company's online presence and its public visibility.

A gap analysis then compares the current posture against the insurer requirements described above. Where the gap is wide, the first euro belongs to security, not to a premium. A three-year cost-benefit comparison puts the cumulative premium against the expected cost of an incident weighted by its probability. Cyber policies typically renew annually, and the insurer can change the terms unilaterally at renewal.

## When the policy is not enough

Insurance integrates prevention; it does not replace it. A company with obsolete systems, untrained staff and no security procedures does not become protected by signing a policy. It transfers part of the financial risk and often discovers at claim time that the exclusions leave the cover far narrower than expected. The value of a well-structured policy appears when it sits on top of a solid security posture: at that point it covers the residual risk that the best defences cannot remove. The question for an Italian SME is whether it meets the minimum conditions to be insurable at a reasonable cost. Where the answer is no, the first step is not a broker quote; it is stronger authentication, tested backups, staff training and systematic patching.

Cover also depends on the technology in use: [the risks Italian SMEs weigh before investing in AI](/en/ecorner/2025/ai-investment-risks-smes.html) increasingly enter the insurer's assessment.

## Frequently asked questions

**Is cyber insurance compulsory for Italian SMEs?**
Cover is not compulsory for every business. It becomes a practical requirement for companies inside the NIS2 perimeter or in supply chains where larger customers transfer security obligations to suppliers through contracts.

**What happens to a claim if a known vulnerability was not patched?**
The claim is normally rejected. Where a fix was available for months and the company did not apply it, insurers treat the omission as gross negligence and exclude the loss.

**How much does a policy cost for a company of 50 to 200 employees?**
Premiums run between EUR 2,500 and EUR 8,000 a year, with deductibles between EUR 5,000 and EUR 15,000. The final price depends on sector, revenue and the security measures documented during underwriting.

**Can a policy replace investment in prevention?**
No. A policy transfers part of the financial risk and leaves the operational and reputational damage with the company. Prevention determines whether the company is insurable and on what terms.

## Sources

IBM — Cost of a Data Breach Report 2024, average breach cost by company size and sector — https://www.ibm.com/reports/data-breach
Generali and Confindustria — Cyber Index PMI 2024, cybersecurity maturity of Italian small and medium businesses — https://www.generali.it/iniziative/iniziative-commerciali/cyber-index-pmi
Munich Re — cyber insurance risks and trends, European and North American market data — https://www.munichre.com/en/insights/cyber/cyber-insurance-risks-and-trends-2025.html
EIOPA — Understanding Cyber Insurance, supervisory dialogue with insurers — https://www.eiopa.europa.eu/document/download/7cec5eef-4b6d-4cd7-ad0f-b4add0a3fe17_en?filename=Understanding+Cyber+Insurance+-+Report
Howden — European cyber insurance market outlook and penetration gap — https://www.howdengroupholdings.com/news/cyber-insurance-entering-a-new-phase-of-development-as-non-us-territories-set-to-capture-54-of-growth-up-to-2030
