By Ryan Windt | Head of Growth Marketing | Updated September 2026
The latest cyber claims data makes one thing clear: cyber risk is not reserved for enterprise organizations.
NetDiligence’s newly released 2026 Cyber Claims Study analyzed more than 10,300 cyber claims arising from incidents between 2021 and 2025. The study includes organizations of every size, but one segment is particularly relevant to MSPs and the businesses they support: organizations with less than $50 million in annual revenue, which NetDiligence categorizes as “Nano-Rev.”
These organizations represented 40% of all claims analyzed, the largest individual revenue category in the study.
For MSPs serving SMB clients, that makes the report more than a high-level look at the cyber insurance market. It is a window into the actual financial impact cyber events are having on organizations that look a lot like the average MSP customer.
For Businesses Under $50M, the Average Cyber Incident Still Costs Six Figures
One of the clearest findings is that “smaller business” does not mean “small cyber loss.”
Among Nano-Rev organizations with claims of at least $1,000, NetDiligence analyzed 3,872 incidents. The average incident cost was approximately $141,000, and the most expensive incident reached $10.4 million. Collectively, these organizations generated more than $545 million in incident costs during the study period.
For a business generating less than $50 million in annual revenue, a six-figure cyber event can be a material financial and operational disruption. And the average only tells part of the story. A business does not need enterprise-scale revenue to experience a seven-figure or eight-figure loss.
Incident Response Costs Add Up Quickly
The cost of an event is not limited to stolen funds, ransom payments, or damaged systems. For Nano-Rev organizations, NetDiligence reported the following average crisis-service expenses:
| Crisis service | Average cost (Nano-Rev) |
|---|---|
| Forensics | ~$36,000 |
| Notification | ~$56,000 |
| Legal guidance | ~$18,000 |
| Other response-related costs | ~$82,000 |
| Average total crisis services | ~$88,000 |
These are per-category averages across the incidents that incurred each service, so they do not sum to the total. Not every incident triggers every service, which is why the average total sits below the individual line items. The point is the range of expenses a single event can set off: forensic investigation, breach counsel, customer notification, restoration, operational downtime, and other costs a business may never have budgeted for. This is why the incident response side of a cyber policy matters as much as reimbursement for a direct loss.
Ransomware and Business Email Compromise Remain the Threats to Watch
Across SMEs generally, ransomware and business email compromise continue to dominate the claims environment. Together, they accounted for 51% of SME claims of $1,000 or more between 2021 and 2025, and nearly 64% of SME claims in 2025 alone.
That is especially relevant for smaller organizations because both threats frequently exploit controls that MSPs directly influence.
Business email compromise remains a high-frequency loss. NetDiligence recorded 612 BEC claims in 2025, and the report points to phishing-resistant MFA, conditional access, and stronger payment-change verification as important defenses.
Wire transfer fraud presents a similar challenge. NetDiligence observed victims ranging from organizations with just $40,000 in annual revenue to $1.2 billion, reinforcing that social engineering and fraudulent payment requests are not limited to large enterprises. On the ransomware side, the way a policy responds to extortion, recovery, and downtime is often what separates a recoverable event from a business-ending one.
The Financial Impact Can Be Disproportionate for Smaller Businesses
A $141,000 average incident may sound modest next to multimillion-dollar enterprise claims, but context matters. A six-figure loss can represent a far greater share of annual revenue, available cash, or operating margin for a $5 million, $10 million, or $25 million business than a multimillion-dollar event represents to a Fortune 500 company.
That is why the cyber conversation for SMBs should not simply be:
“Are we big enough for attackers to care about?”
The more useful question is:
“If something happens, can we financially and operationally absorb the impact?”
The data suggests that thousands of businesses under $50 million in revenue are already finding out the answer.
Cyber Insurance and Security Controls Are Becoming More Connected
The findings also reinforce why cybersecurity and cyber insurance increasingly need to be discussed together. Controls such as MFA, conditional access, endpoint protection, email security, tested backups, privileged-access controls, employee awareness, and incident response planning can influence both the likelihood of an attack succeeding and the severity of the resulting loss. Many of these are the same controls underwriters now verify before they will bind coverage.
For an MSP, that creates an opportunity to translate technical findings into business outcomes. Instead of telling a client:
“You need to implement MFA.”
The conversation can become:
“Businesses like yours are experiencing six-figure cyber losses, and compromised identities remain one of the pathways behind some of the most common claims. Improving this control can reduce your risk while also strengthening your position with cyber insurers.”
That is a much stronger business conversation, and it is worth noting that the controls a client attests to on an application also shape how a claim is handled later. Gaps between what was attested and what was in place are a common reason payouts get reduced or denied.
AI Is Likely to Make Familiar Attacks Faster and More Convincing
The report also highlights artificial intelligence as an emerging force multiplier rather than an entirely separate cyber threat. Contributors note that AI is accelerating reconnaissance, lowering the technical barrier for attackers, and making fraudulent communications increasingly difficult to distinguish from legitimate ones.
For SMBs, that could further increase exposure to BEC, social engineering, credential compromise, and payment fraud. At the same time, the report indicates that cyber insurers are beginning to take a greater interest in how organizations govern AI, protect data used with AI systems, and manage associated access and controls. That means AI readiness may increasingly become both a cybersecurity issue and an insurability issue. For MSPs that build, manage, or deploy AI on behalf of clients, it also raises the question of where that liability lands and how coverage responds.
What MSPs Should Take Away From the 2026 Data
For MSPs, the most useful takeaway from the NetDiligence study may be just how relevant the claims data is to the clients they already serve. Organizations under $50 million in revenue accounted for the largest known revenue segment in the study. They generated thousands of claims, more than half a billion dollars in total incident costs, and an average loss of approximately $141,000 per incident.
This creates an opportunity to move client conversations beyond technical recommendations and toward measurable business risk. Security assessments can help MSPs identify gaps in identity, licensing, email security, endpoint protection, backup strategy, or governance. But the conversation becomes significantly more valuable when those findings are connected to risk reduction, operational resilience, insurability, coverage quality, and potential insurance savings.
The goal is not simply to help clients buy more security technology. It is to help them understand what their current posture means financially, and to give them a roadmap for reducing that exposure. If you want a practical script for that discussion, see our guide on how to talk to MSP clients about cyber insurance.
The Bottom Line
The 2026 claims data should challenge the assumption that meaningful cyber losses primarily happen to large organizations. For businesses under $50 million in revenue, cyber incidents averaged approximately $141,000, with individual losses reaching more than $10 million.
Ransomware, business email compromise, payment fraud, and compromised identities remain central threats. Meanwhile, AI is making many of those attacks easier to execute and more difficult for employees to recognize.
For SMBs, the answer is not necessarily adding more tools. It is understanding where meaningful gaps exist, prioritizing the controls that materially reduce risk, preparing for recovery, and ensuring that security investments translate into both stronger resilience and better insurability.
Frequently Asked Questions
What is the average cost of a cyber incident for a business under $50 million in revenue?
In the NetDiligence 2026 Cyber Claims Study, organizations under $50 million in revenue (the “Nano-Rev” segment) averaged approximately $141,000 per incident among claims of at least $1,000, with the most severe single incident reaching $10.4 million.
Why does this claims data matter specifically to MSPs?
Businesses under $50 million in revenue made up 40% of all claims in the study, the largest single revenue category. That segment closely mirrors the typical MSP client base, so the data reflects the real financial exposure MSP clients carry rather than an enterprise-only picture.
Which threats drive the most SMB claims?
Ransomware and business email compromise dominate. Together they accounted for 51% of SME claims of $1,000 or more between 2021 and 2025, and nearly 64% of SME claims in 2025 alone.
How do security controls affect cyber insurance?
Controls such as MFA, conditional access, endpoint protection, tested backups, and incident response planning influence both the likelihood and the severity of a loss. They are also among the controls underwriters verify before binding, and the controls a business attests to can affect how a future claim is handled.
Related Resources
- How to Talk to MSP Clients About Cyber Insurance
- Cyber Insurance Requirements: What Underwriters Actually Check
- Does Cyber Insurance Cover Business Email Compromise?
- Funds Transfer Fraud Coverage: What Cyber Policies Pay
- What Cyber Claims Data Reveals About Risk, Losses, and Underwriting
- Cyber Insurance Built for How MSPs Actually Operate
SeedPod Cyber is a specialized provider of cyber and Tech E&O coverage built for MSPs and the businesses they support. To see how coverage responds to the risks in this report, contact our team or explore what our coverages include.