Most small business owners still believe they are too small to attract a cyberattack. In reality, SMBs experienced four times more confirmed breaches than large organizations in 2024, according to Verizon's 2025 Data Breach Investigations Report.
Christiaan Durdaller, national cyber and technology practice director at CRC Group, sees that misconception drive financial harm every day. Here, he explains the underlying barriers to SME cyber insurance adoption and what brokers can do to close the small business cyber insurance gap.
The idea that small businesses are too small to interest cybercriminals is widespread. It is also, Durdaller argues, one of the most expensive assumptions a business owner can make.
"Many small business owners genuinely believe they're not a target, that hackers are only interested in large enterprises with valuable data or deep pockets," Durdaller said. "What we see on the ground is that this couldn't be further from the truth. SMEs are often easier targets precisely because their defenses are thinner."
The protection gap reflects that disconnect. Only 16.8% of global SMEs hold a standalone cyber policy, according to GlobalData's 2025 SME Survey. Those same businesses faced ransomware in 88% of confirmed breaches in 2024, compared to just 39% at large organizations based on Verizon's data.
The economics of cybercrime help explain the targeting shift. Ransomware-as-a-Service platforms have lowered the cost of attacking smaller businesses, while volume campaigns against SMEs now outperform single strikes on large enterprises. Small businesses receive one malicious email in every 323 delivered, the highest targeting rate of any organization size, according to Verizon's 2025 DBIR.
"There's also a trust and literacy gap," Durdaller said. "Cyber insurance isn't something most business owners grew up understanding the way they understand property or other related liability cover. When a policy lands in front of them full of technical language and exclusions, the default response is to set it aside."
That leaves price as the default explanation for low SME cyber insurance uptake. Durdaller pushes back on that framing.
"Price is a factor, but in our experience, it's rarely the primary barrier; it's that the value proposition hasn't been made clear enough, and frankly, that's a challenge we put effort into conquering daily," he said.
Regulatory pressure around cyber insurance has grown, but not all of it reaches the typical small business. In practice, Durdaller notes, CIRCIA's reach is narrower than most brokers assume.
"It's moving the needle for some, but it would be an overstatement to say regulation is driving broad SME uptake," Durdaller said.
"What we tend to see is that regulatory pressure lands hardest on businesses that are already somewhat engaged, those with a compliance function, or those operating in sectors with existing regulatory oversight, such as healthcare, financial services, or organizations supporting critical infrastructure.
"For the typical small business, CIRCIA is still fairly abstract. The incident reporting timelines it mandates feel distant until you're dealing with a breach."
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) generally exempts small businesses under the SBA size standard. It targets covered entities across 16 critical infrastructure sectors. Covered entities must report substantial breaches within 72 hours. As of mid-2026, the Cybersecurity and Infrastructure Security Agency (CISA) had yet to issue the final rule. Its most recent stakeholder town halls ran in June 2026.
According to Durdaller, the more active driver of SME cyber insurance adoption runs through supply chains rather than regulators.
"Larger organizations are increasingly asking vendors to demonstrate cyber maturity and, in many cases, require them to carry cyber insurance as a condition of doing business. That has become a meaningful catalyst for adoption, particularly among SMEs selling into enterprise customers."
That dynamic gives brokers a concrete angle. Durdaller explains that regulation works best not as a direct mandate but as a tool for moving fence-sitting clients.
"It gives us a concrete, external reason to act, not just a risk management argument, but a legal and commercial one," he said.
Nearly nine in 10 C-level executives worldwide said their companies lacked adequate cyber protection, according to Munich Re's Global Cyber Risk and Insurance Survey 2026. Among SMEs, Durdaller notes, that awareness rarely translates into a purchase.
"That gap between awareness and action is something we see regularly, and it's important to distinguish the two," he said. "Knowing you're exposed is not the same as knowing what to do about it."
At the SME level, the "C-suite" is often one person. Durdaller says that business owners must manage cyber risk alongside cash flow pressures, staffing concerns, and supply chain issues. Those priorities compete directly with cyber insurance decisions.
"There's also a degree of fatalism – a sense that if a serious attack happens, the insurance won't really cover it anyway," Durdaller said. The irony, he adds, is that cyber incidents tend to hit smaller businesses harder than large ones. Business interruption, recovery costs, legal expenses, and customer notification can add up to hundreds of thousands of dollars. Many smaller businesses never fully recover.
Durdaller argues that for brokers, the answer lies less in product knowledge and more in process.
"Overcoming that skepticism requires brokers to do more work up front: walking clients through what a real claim looks like, what the policy actually responds to, and what the process feels like in practice," he said. "That's time-intensive, but it's the kind of conversation that genuinely changes minds."
Better products, lower prices, and a simpler buying experience are the three levers most often cited for closing the SME cyber insurance gap. Durdaller says simplicity outweighs the other two.
"All three matter, but the biggest lever is simplicity – in the product, in the language, and in the buying experience," Durdaller said. "The businesses most likely to remain uninsured aren't shopping around and finding the price too high; they're not engaging with the process at all. That points to a distribution and communication problem as much as a product one."
Part of that challenge is reframing what cyber insurance actually covers. Most losses don't come from nation-state attacks.
"They're coming from ransomware, business email compromise, funds transfer fraud, and compromised credentials – risks that every business faces regardless of size," Durdaller said. "The challenge isn't convincing clients that cyber risk exists; it's helping them understand that cyber insurance responds to these everyday events, not just the headline-grabbing incidents."
Underwriting has also become more precise, he adds. Controls such as multi-factor authentication, endpoint detection and response, and tested offline backups now affect both pricing and insurability. Understanding that connection gives brokers a concrete case that stronger security practices lead to better coverage terms.
Durdaller points to one underused opening. Brokers who embed cyber into the broader client relationship tend to get further than those who treat it as a standalone product.
"When clients see you as a long-term risk advisor rather than someone selling another policy, the conversation changes entirely," he said.