Cyber insurance is designed to help an organisation respond to selected financial, operational, legal and liability consequences of a cyber incident. Depending on the policy, it may fund specialist incident response, forensic investigation, data restoration, business interruption, legal advice, notification work, public relations and certain claims made by customers or other third parties.
It does not make a business secure, guarantee that every incident is covered or replace normal cyber-security and data-protection duties. The National Cyber Security Centre says organisations should understand their existing defences, likely incident impacts, the cover being offered and the services available during an incident before buying a policy.
For a wider starting point, read Business Insurance Explained. This guide then brings together the core questions for a UK SME considering cyber insurance: what may be covered, what may be excluded, what affects cost, what an insurer may ask and how cyber cover overlaps with professional indemnity and other policies.
Quick answer
Cyber insurance may be relevant where a business depends on email, cloud systems, websites, online payments, customer or employee information, connected equipment, digital suppliers or remote access. That includes many businesses that do not describe themselves as technology companies.
A useful policy can provide both money and access to specialists when time matters. However, policy wording varies substantially. Cover for ransomware, fraudulent payments, dependent-system outages, regulatory investigations, contractual liability and restoration costs can be limited, sub-limited, conditional or absent.
Start by reading what cyber insurance covers, then compare the proposed wording with the business’s systems, data, dependencies and incident plan.
Why cyber risk is a business issue
Cyber incidents can interrupt trading, prevent staff from accessing systems, expose personal data, corrupt records, redirect payments, damage customer confidence and create contractual or regulatory work. The consequences can arise from malicious attacks, human error, stolen credentials, supplier failure or a poorly configured service.
The UK Government’s Cyber Security Breaches Survey 2025/2026 reported that 43% of businesses identified a cyber-security breach or attack in the previous 12 months. It also reported that 47% of businesses said they were insured against cyber risks in some way, most commonly through a wider policy rather than a standalone cyber policy. These are survey estimates, not a prediction that any particular business will suffer a loss or that its current insurance is adequate.
The same survey found that phishing remained the most commonly identified type of breach or attack. That matters because apparently routine email activity can lead to credential theft, account takeover, invoice fraud or access to cloud systems.
What cyber insurance is
Cyber insurance is a category of commercial insurance rather than one standard policy. It may combine:
- first-party cover for the insured business’s own costs or loss;
- third-party cover for certain liabilities to customers, employees, clients or other people;
- incident-response services arranged through an insurer’s panel or helpline;
- risk-management services supplied before an incident, sometimes as part of the policy.
The balance between these elements differs. One policy may emphasise data-breach response, another may provide broader network interruption and cybercrime options, while a package-policy extension may have a narrower limit and fewer services.
The detailed cover guide explains these components and the wording checks that sit behind them.
First-party losses
First-party cover concerns the insured organisation’s own loss or expenditure. Subject to wording, this can include:
- investigating what happened and containing the incident;
- restoring or recreating data and software;
- hiring incident-response, forensic, legal or communications specialists;
- notifying affected individuals where appropriate;
- operating call centres or credit-monitoring services where covered and justified;
- loss of income and increased cost of working during a covered interruption;
- cyber extortion response and, in some policies, a ransom payment where lawful and approved;
- loss of funds through specified forms of social engineering or computer fraud, if expressly included.
These headings should not be treated as automatic promises. Policies define the event, waiting period, indemnity period, evidence required, applicable limit and which suppliers may be used.
Third-party liability
Third-party cyber liability may address certain claims alleging that the insured failed to protect information or systems, transmitted harmful code or caused another person financial loss. It can include defence costs and covered damages, subject to exclusions and the policy’s consent and control provisions.
Privacy liability and network-security liability are often described separately. A claim may involve personal information, confidential commercial data, system access or an allegation that the insured’s security failure affected a client.
A policy may also provide legal help with a regulator’s enquiry. Payment of a fine or penalty is a different question: it depends on the wording, the law, public-policy considerations and whether the amount is legally insurable. Do not assume that every regulatory amount is covered.
Incident-response services
The practical value of cyber insurance can begin before liability or final loss is known. Some policies provide a 24-hour notification line and access to approved forensic, legal, public-relations, restoration and breach-response specialists.
The business should know:
- which number or portal to use;
- whether prior consent is required before appointing a supplier;
- which services are within the main limit or a separate sub-limit;
- whether an excess applies;
- whether the insurer chooses the provider;
- whether emergency costs incurred before consent can be considered;
- what records must be preserved.
Put the incident number, policy number and broker contact into the organisation’s response plan, but keep an offline copy. During a serious outage, the usual network, password manager or cloud drive may not be available.
Cyber insurance and data breaches
A cyber incident and a personal-data breach are not identical. A cyber attack may cause no personal-data breach, while a personal-data breach may result from an accidental email, lost device or unauthorised internal disclosure rather than an external attack.
Where a personal-data breach is likely to result in a risk to people’s rights and freedoms, the UK GDPR requires the controller to notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Higher-risk breaches may also require communication to affected people. The organisation remains responsible for assessing and meeting its legal duties even when an insurer or specialist adviser is helping.
The ICO recognises that complete information may not be available within 72 hours and permits phased reporting in the circumstances described by Article 33. The business should therefore escalate quickly rather than wait for a perfect forensic picture.
Cyber insurance does not replace security
The NCSC states that cyber insurance does not remove the need for good cyber security. Insurers may ask about controls because weak or inaccurate risk information can affect underwriting and claims.
Cyber Essentials is the minimum cyber-security standard recommended by the UK Government for organisations of all sizes. Its five technical control themes address firewalls, secure configuration, security updates, user access control and malware protection. Certification is not a guarantee that an incident cannot occur, and it is not automatically a substitute for the controls required by a particular insurer.
Other relevant measures may include:
- multi-factor authentication, especially for email, remote access and privileged accounts;
- tested offline or appropriately isolated backups;
- security updates and vulnerability management;
- endpoint protection and monitoring;
- restricted administrator privileges;
- staff training and phishing-resistant processes;
- supplier and cloud-service due diligence;
- an incident-response plan with tested decision routes;
- payment-verification procedures that do not rely solely on an email request;
- logging that is sufficient to investigate an event.
Security answers given during quotation should reflect the controls actually operating across the relevant organisation, not an intended future state.
What insurers may ask
A proposal form or online journey may request information about:
- turnover, sector, locations and number of staff;
- the type and volume of personal, payment, health or confidential data held;
- dependence on websites, cloud platforms, hosted applications and key suppliers;
- previous incidents, claims, ransom demands or regulatory contact;
- multi-factor authentication and remote-access arrangements;
- backup frequency, separation and restoration testing;
- patching and unsupported software;
- endpoint detection, antivirus and monitoring;
- access controls and privileged accounts;
- staff training and payment-verification controls;
- incident-response planning;
- outsourced IT and managed-service providers;
- territories, customers and contractual requirements.
Under the Insurance Act 2015, a business policyholder must make a fair presentation of the risk. Material circumstances must be disclosed, or sufficient clear information supplied to put a prudent insurer on notice that it needs to ask further questions. The Business Insurance Review Checklist can help organise the facts before quotation or renewal.
Common cover areas
A cyber policy may address the following areas, but every heading requires a wording check.
Forensic investigation and containment
Specialists may identify entry points, affected systems, persistence, data access and practical containment steps. Cover can depend on using an approved provider and obtaining consent.
Data and software restoration
The policy may pay reasonable costs to restore data or software from backups or recreate it where restoration is not possible. It may not pay to improve systems beyond their previous state unless the wording allows it.
Business interruption
Cyber business interruption may respond to lost income and increased cost of working caused by a covered system event. Check the waiting period, the method for calculating loss, the maximum indemnity period and whether an outage at a supplier or cloud provider is included.
Privacy and network liability
Cover may respond to claims alleging unauthorised disclosure, failure to secure data or systems, or transmission of malware. Contractual liabilities assumed beyond the ordinary legal position may be restricted.
Breach response and notification
Legal assessment, notification, communications and support services may be covered. The decision to notify the ICO or individuals must still be made under the applicable law and facts.
Cyber extortion
Some policies provide specialist negotiation and response support for ransomware or other extortion. A payment is not guaranteed, may be unlawful in some circumstances and may not recover data. The NCSC and UK law-enforcement bodies do not encourage, endorse or condone ransom payments.
Cybercrime and social engineering
Loss of money through a fraudulent transfer, invoice manipulation or social engineering is not necessarily included in a standard cyber section. It may require a specific cybercrime, funds-transfer-fraud or crime extension and can have a low sub-limit or strict verification conditions.
Common exclusions and limitations
Cyber policies can contain exclusions or limitations concerning:
- known circumstances or incidents predating the policy;
- inaccurate security declarations;
- failure to maintain specified controls;
- unencrypted portable devices or unsupported software;
- bodily injury and physical property damage;
- deliberate or dishonest acts by senior management;
- contractual liability that exceeds liability at law;
- intellectual-property infringement;
- infrastructure failure outside the defined dependent system;
- war, cyber operations or systemic events, depending on wording;
- betterment and system upgrades;
- voluntary shutdown without the required trigger or consent;
- fraudulent payments unless expressly covered;
- fines or penalties that are uninsurable or excluded.
The ABI notes that bodily injury and physical property damage are commonly outside cyber policies because those losses may sit under property or liability cover. Connected machinery and operational technology can create difficult boundaries, so a business with physical-process exposure should review all relevant policies together.
Limits, sub-limits and excesses
The headline policy limit does not tell the whole story. A policy may include:
- one aggregate limit for all claims in the period;
- separate limits for first-party and third-party loss;
- lower sub-limits for extortion, social engineering, data restoration, dependent-system interruption or regulatory work;
- an excess expressed as money, time or both;
- defence costs inside or outside the limit;
- a maximum restoration period or indemnity period.
Model plausible incidents before choosing a limit. Consider response costs, lost gross profit, additional payroll, supplier replacement, data restoration, legal work, communication and potential third-party claims. The purpose is not to predict one exact loss but to identify which limit could be exhausted first.
How much cyber insurance costs
There is no dependable universal average premium for UK SMEs. Pricing is quote-specific and can vary because of business activity, data, turnover, security controls, incident history, requested limits, excesses, territories and optional sections.
A provider’s advertised starting price or a price paid by one firm is not a market average. The Cyber Insurance Costs for SMEs guide explains how to compare evidence and quotations without presenting a narrow promotional example as the normal price.
Cyber insurance and professional indemnity
Cyber and professional indemnity can overlap, particularly for technology consultants, software providers, digital agencies and businesses handling client systems or data.
Cyber insurance commonly emphasises the organisation’s own incident-response and interruption costs, alongside privacy or network-security liability. Professional indemnity commonly addresses claims that professional work, advice, design or services were negligent or failed to meet an obligation.
A single incident can trigger both allegations. For example, a software implementation problem may interrupt a client, expose data and lead to a contractual claim. The cyber insurance versus professional indemnity comparison explains how to test the policies without assuming one automatically fills every gap in the other.
Cyber insurance and other policies
Cyber events can touch several policy sections:
- property insurance where equipment is physically damaged;
- business interruption attached to property cover;
- crime or fidelity insurance for theft of money;
- professional indemnity for service failures and client claims;
- public liability or product liability where physical injury or damage is alleged;
- directors’ and officers’ insurance for claims against management;
- legal expenses insurance for specified disputes.
Check “other insurance” clauses, notification duties and the allocation of defence or investigation costs. Notify each potentially relevant insurer or broker in accordance with its policy rather than deciding privately that only one policy can respond.
How to compare policies
Use the same factual submission for each quotation and compare more than price. Ask:
- What events trigger first-party cover?
- Which incident-response firms and legal advisers may be used?
- Does the policy cover privacy, network security and multimedia liability?
- Is social engineering or fraudulent transfer included?
- How are ransomware and extortion addressed?
- Does interruption cover the business’s cloud and technology suppliers?
- What are the waiting periods and indemnity periods?
- Which sub-limits sit below the main limit?
- Are defence and response costs inside the limit?
- Which controls must be maintained throughout the policy?
- How are prior incidents and known vulnerabilities treated?
- What territories and jurisdictions apply?
- What notification route and consent rules apply?
- Does the wording contain a cyber-war, infrastructure or systemic-event exclusion?
- How does the cyber policy coordinate with PI, crime and property cover?
The Business Insurance Documents guide explains why the schedule, wording, endorsements and statement of fact should be read together.
What to do during an incident
A written response plan should be followed, but common priorities include:
- protect people and critical operations;
- contain the incident without unnecessarily destroying evidence;
- use an alternative trusted communication route if email may be compromised;
- contact the cyber insurer or broker through the policy route;
- preserve logs, messages, payment details and system images;
- involve appropriate technical, legal and communications specialists;
- assess personal-data breach duties promptly;
- report crime or serious incidents to the appropriate authorities;
- document decisions, costs and approvals;
- restore from known-good systems and monitor for recurrence.
Do not delay notification while trying to complete the entire investigation. The wording may require notice as soon as reasonably practicable or within a stated period.
Cyber claim examples
A ransomware infection, fraudulent invoice, accidental disclosure, cloud outage or supplier compromise can produce different combinations of cost and liability. Cover depends on the event definition, facts, limits, exclusions, security representations and use of approved providers.
Read the Cyber Insurance Claim Scenarios and Examples for simplified, hypothetical examples that show the questions to ask without promising a claim outcome.
Buying checklist for an SME
Before accepting a quotation:
- map critical systems, data and suppliers;
- estimate the impact of one day, one week and a longer outage;
- verify the controls described in the application;
- disclose previous incidents and known circumstances accurately;
- identify contractual cyber or data obligations;
- compare the full wording, schedule and endorsements;
- test the main limit and sub-limits against plausible costs;
- check social-engineering and dependent-system cover explicitly;
- understand the incident hotline and consent process;
- store the policy and response contacts offline;
- align the policy with the incident-response plan;
- schedule a review when systems, suppliers, turnover or data use changes.
Limits of this guide
This is general educational information. It does not determine whether a particular incident is covered, whether a regulatory notification is required or which policy is suitable for one business. Read the actual wording and the Insurance Information Disclaimer, and obtain appropriate technical, legal or authorised insurance help where needed.
Building a cyber-risk picture before buying
A useful cyber-insurance review begins with the business operation, not the insurance product. List the services that must continue, the information the organisation is responsible for, the systems that support those services and the third parties on which recovery depends.
For each critical activity, record:
- the system or supplier involved;
- the longest tolerable outage;
- the oldest data that could be restored without material harm;
- any legal, regulatory or contractual deadline;
- the people authorised to make emergency decisions;
- the likely cost of operating manually or through an alternative supplier;
- the customers or counterparties that would need communication.
This exercise helps distinguish a minor IT inconvenience from a business-threatening interruption. It also produces better answers for the insurer and a more defensible choice of limit.
Internal responsibility and governance
Cyber insurance is sometimes delegated entirely to IT, but the policy can affect finance, legal, data protection, operations, communications and senior management. A small business may not have separate departments, yet the decisions still need named owners.
Before an incident, decide who can:
- notify the insurer and broker;
- authorise emergency expenditure;
- disconnect systems or invoke continuity arrangements;
- contact the ICO, police, bank or customers;
- preserve evidence and control communications;
- approve restoration to production;
- decide whether a ransom demand is escalated for legal assessment.
The board or business owner should understand material exclusions and security conditions. A policy arranged without operational involvement may contain application answers that staff cannot evidence or maintain.
Contract and procurement review
Customer and supplier contracts can shape the cyber exposure. Review provisions concerning data security, breach notification, service levels, indemnities, liability caps, audit rights, subcontracting and insurance.
An insurance requirement in a contract does not prove that the purchased policy meets every contractual obligation. A contract may require notice to a customer within a shorter period than a regulator, impose service credits, or accept liabilities that the policy restricts.
Similarly, a supplier’s promise to maintain insurance does not guarantee that the business is protected. The supplier may have a limit shared across many customers or an exclusion that affects the event. Build contractual remedies into continuity planning rather than treating them as immediate recovery funding.
Renewals and mid-term change
Cyber risk can change quickly. A policy review is appropriate when the business acquires an entity, launches a new platform, starts processing different data, changes its cloud architecture, outsources a critical service, expands overseas or experiences an incident.
At renewal, compare the current submission with the previous year. Confirm that security answers remain accurate, all legal entities are included and any new contractual requirement is reflected. Keep the final proposal, statement of fact and insurer correspondence with the policy documents.
The Business Insurance Resources hub brings together the checklist, documents guide and glossary that support this work.
Common buying mistakes
Avoid these recurring errors:
- buying solely on the headline limit;
- assuming “cybercrime” includes every fraudulent transfer;
- describing intended controls as already implemented;
- overlooking a cloud or payment supplier;
- choosing an interruption period without modelling recovery;
- storing the incident contact only on the insured network;
- failing to notify another potentially relevant policy;
- accepting a contractual liability without checking insurance;
- treating a certificate or product summary as the full wording;
- waiting for certainty before notifying a suspected incident.
A clear comparison record is useful at claim time because it shows which risks and differences were considered when the policy was selected.
Small businesses and outsourced IT
Using a managed IT company does not transfer all cyber risk. The SME still decides which data and services matter, who may access them and what contractual protections are required. It also remains responsible for its own legal duties.
Ask the provider how incidents are reported, how logs are retained, how privileged access is controlled, where backups sit and how quickly the provider can support an insurance investigation. Confirm whether the cyber policy permits that provider to undertake emergency work or requires an insurer-appointed specialist.
The supplier contract, service description and insurance policy should be reviewed together. A gap can arise where each party assumes the other will fund restoration, customer communication or business interruption.
Recordkeeping before a claim
Keep a current technology and supplier inventory, copies of material contracts, security policies, backup test results, staff-training records and evidence supporting proposal answers. These records can help the insurer understand the pre-incident position and can reduce delay when facts are disputed.
They should be stored securely, with essential response information available even when the main network is unavailable. Access should be limited because security records can themselves contain sensitive information.