The cost of cyber insurance for a French SME in 2026 sits between €1,000 and €3,000 a year for a company of 10 to 50 employees, and between €3,000 and €10,000 a year for 50 to 250 employees, for a policy limit of €500,000 to €2 million. Those orders of magnitude match the average premiums that can be derived from AMRAE's LUCY study: roughly €1,600 for a small company insured in 2025, a little over €5,000 for a medium-sized one. At equal size, the gap between two quotes comes first from the security maturity you can demonstrate, then from your sector, your deductible and your limit.
How much does cyber insurance cost by turnover?
Insurers price first on turnover and headcount, which measure the surface to protect and the potential business interruption loss. AMRAE's LUCY 2026 study, which compiles data from the main French brokers, publishes premiums and the number of insured companies per segment for 2025, from which an average premium can be derived.
| Segment (French INSEE categories) | Average premium 2025 (derived from LUCY) | Market range 2026 | Average deductible | Average limit |
|---|---|---|---|---|
| Micro-enterprise (< 10 employees, < €2M turnover) | ≈ €640 | €300 to €800 | €1,076 | €627,000 |
| Small company (10 to 49 employees, €2M to €10M) | ≈ €1,640 | €1,000 to €3,000 | €2,360 | €701,000 |
| Medium company (50 to 249 employees, €10M to €50M) | ≈ €5,040 | €3,000 to €10,000 | €10,600 | €1.4M |
| Mid-cap (250 to 4,999 employees) | ≈ €33,900 | €15,000 and above | €91,200 | €4.2M |
The market ranges are orders of magnitude observed on SME offers in 2026 and depend on the covers included.
Why do two SMEs of the same size pay very different premiums?
Because the cyber premium is a function of your demonstrated maturity, not only of your size. The underwriting questionnaire, that is the one-to-four-page form in which the insurer asks you to describe your security measures, decides three things: whether it agrees to quote, at what price, and with which exclusions. The same file, presented with dated evidence, can cost 30 to 40% less than presented with boxes ticked and nothing to back them. An anonymised example: a SaaS vendor with 45 employees and €6 million in turnover, MFA everywhere, EDR, immutable backups and a response plan, pays about €3,200 for a €2 million limit including business interruption; the same file without EDR had been quoted €4,600 the year before.
Sector matters too. A company handling health data or payments, or hosting its customers' data (SaaS, fintech, e-health), is classed among the most exposed activities, where the rate can be 1.5 to 2 times that of a manufacturer with no sensitive data. Finally, a claim declared in the last three years closes some doors and makes the others more expensive.
What impact do MFA, EDR and backups have on the premium?
Three measures condition access to the market before price is even discussed. Multi-factor authentication (MFA) requires, in addition to a password, a second proof of identity: a one-time code, a hardware key or a phone confirmation. It neutralises most intrusions based on stolen credentials, which matters when account hijacking accounted for 21% of business assistance requests in 2025 according to Cybermalveillance.gouv.fr, up 52%. Without MFA on email, remote access and administrator accounts, most insurers refuse to quote or exclude losses arising from account compromise.
EDR (Endpoint Detection and Response) is software deployed on every workstation and server that monitors abnormal behaviour rather than known malware signatures, and automatically isolates a compromised machine. Offline or immutable backups are copies of your data disconnected from the network or write-locked for a set period, the only guarantee you can restart without paying.
| Security measure | Status with cyber insurers in 2026 | Effect on the quote |
|---|---|---|
| MFA on email, VPN, admin accounts | Near-universal prerequisite | Without MFA: refusal or exclusion of access-related losses |
| EDR or MDR across the whole estate | Expected from 50 employees, rewarded below | Best pricing, lower deductible |
| Tested offline backups | Prerequisite for ransomware covers | Condition of the "own damage" cover |
| Written incident response plan | Differentiator | Unlocks crisis management and business interruption covers |
No single measure is "worth" a fixed percentage: the insurer scores an overall profile, and missing MFA cancels the benefit of EDR being present.
The cyber premium is not the price of a product; it is the price of what you have not yet proven to the insurer.
What does the premium you pay actually cover?
An SME cyber policy usually combines five blocks. First-party incident response costs: forensics, restoration, legal assistance, notification of affected individuals and of the data protection authority. Business interruption, meaning the gross margin you fail to earn during the outage plus the extra costs of getting back up. Extortion: negotiation and, depending on the policy, reimbursement of the ransom. Third-party liability towards those affected by your incident. Finally, often as an option, social engineering fraud such as fake payment orders, which accounted for 13.5% of business assistance requests in 2025, up 93%.
Two quotes at the same price can therefore cover very different things: a €1,800 policy without business interruption or fraud is not worth a €2,400 policy that includes them. If you are a software vendor, our article on liability for code errors details the boundary with professional indemnity.
How do the deductible and the limit change the price?
The deductible is the share of a loss you keep for your own account. Moving from €1,000 to €5,000 cuts the premium by about 15% with several SME market players; going up to €15,000 cuts it by about 25%. The trade-off comes down to one question: how much can your cash position absorb without pain?
The limit, conversely, costs little at the margin: multiplying capacity by five, from €100,000 to €500,000, raises the premium by 50 to 66%, not by 400%. Under-insuring the limit to save a few hundred euros is rarely rational.
Will cyber insurance prices fall or rise in 2026?
Both, depending on your segment. LUCY 2026 records a drop in average premium rates of 32% for large companies and 23% for mid-caps in 2025, in a market of €306 million in premiums, down 3%. The number of insured companies jumped 49% (from 14,124 to 20,996 policies), driven by SMEs. But indemnified claims rose from €54.5 million to €83.2 million, and the mid-cap loss ratio went from 13% to 42%.
That deterioration is the signal to watch. The 2025 cyber threat overview by ANSSI, the French cybersecurity agency, reports that micro, small and medium companies and mid-caps accounted for 37% of the ransomware victims it handled. Well-protected companies will keep enjoying a competitive market; those arriving at renewal without MFA or EDR will see their premium climb or their policy not renewed. The other levers to contain the increase are those of your traditional policies, and we have listed ten of them.
Frequently asked questions
What is the minimum price of cyber insurance for an SME?
For a company of 10 to 49 employees, rarely less than €1,000 a year in 2026 for a complete policy (first-party costs, business interruption, third-party liability, a limit of at least €500,000). Offers at a few dozen euros a month target very small structures and are often capped at €100,000.
Is cyber insurance mandatory in 2026?
No, no law requires it. However, NIS2, DORA and above all your large customers' contracts increasingly demand cyber cover with a minimum limit. We detail those requirements in our article on NIS2 and DORA for SMEs.
Can an SME without MFA be insured?
With difficulty. Most insurers refuse to quote or exclude losses linked to account compromise. Rolling out MFA on email, remote access and administrator accounts takes a few days and immediately unlocks several offers.
Is the ransom reimbursed by cyber insurance?
Some policies cover it, subject to filing a police complaint within 72 hours as required by France's 2023 LOPMI law. Insurers favour restoration from backups, and many limit or exclude this cover for companies without offline backups.
At Lesto, we treat your cyber file as an underwriting case to prepare, not a form to fill in: we audit your actual measures (MFA, EDR, backups, response plan), consult nine insurers on average and tell you which measure unlocks which saving, with an analysis delivered within 72 hours. Want to know what your premium should be worth? Discover our cyber insurance offer and request your analysis.
Recommended coverage
Our offers
The coverages we recommend most often to businesses.
Professional Liability
When a client blames you for a mistake or a delay, legal fees pile up fast. Professional Liability picks up the bill for you.
DiscoverProperty Damage (BOP)
A fire or water damage can shut your premises overnight. This insurance pays for the repairs and keeps you afloat until you reopen.
DiscoverCyber
One morning your files are locked and a hacker demands a ransom. Cyber insurance pays for the recovery and the crisis response.
DiscoverTags
- #cyber insurance
- #pricing
- #SME
- #cybersecurity
- #insurance premium

Loïc Carbonne
CTO
Loïc is passionate about tech, code and artificial intelligence. He is building the platform that allows Lesto's clients to be properly insured.
LinkedIn →