There is no reliable single “average” cyber insurance premium for a UK small or medium-sized business. Quotations can differ because insurers assess business activity, turnover, data, technology dependence, security controls, claims history, limits, excesses and optional cover differently.
A price shown by one provider may describe a selected customer profile, a package policy or a minimum starting point. It should not be presented as the expected price for every SME.
This guide explains how cyber insurance costs are built and how to compare quotations. For the underlying cover categories, start with the Cyber Insurance UK guide and What Cyber Insurance Covers.
Quick answer
Cost tends to rise where a business has greater potential interruption, sensitive or high-volume data, weak controls, significant online revenue, complex suppliers, previous incidents, higher limits or broad extensions such as social engineering and dependent-system cover.
Good controls can improve risk quality, but no single control guarantees a discount or acceptance. Insurers consider the full submission and their current underwriting appetite.
Why an average can mislead
Two businesses with the same number of employees may have very different cyber exposure. A consultancy storing limited contact details and using standard cloud applications differs from an online retailer processing high transaction volumes, a health provider handling sensitive data or a software company hosting client systems.
Premium evidence can also differ because:
- one quotation includes cyber within a wider package;
- another is a standalone policy;
- limits and excesses are not the same;
- social-engineering cover may be included in one but excluded in another;
- the businesses use different security controls;
- commissions, taxes and fees may be presented differently;
- promotional starting prices reflect selected low-risk cases.
The appropriate comparison is between quotations prepared from the same, accurate risk information and measured against the same required cover.
Business activity and sector
The work a business performs affects the likelihood and potential severity of cyber loss. Insurers may distinguish between professional services, retail, health, finance, education, hospitality, technology, manufacturing and other sectors.
Relevant considerations can include:
- statutory or contractual confidentiality duties;
- payment-card or financial activity;
- safety-critical or operational technology;
- dependence on online trading;
- attractiveness of the data to criminals;
- concentration of client systems or information;
- potential for one failure to affect many customers.
A technology firm may also need to compare cyber with professional indemnity insurance because a client claim can allege both a security incident and a defective service.
Turnover and interruption exposure
Turnover is often used as a rating measure, but the insurer may also consider gross profit, online revenue and the cost of downtime.
A business that can operate manually for several days may have a different interruption exposure from one that cannot take orders, access case files, schedule work or communicate with customers when a cloud system is unavailable.
Estimate:
- revenue at risk per day;
- continuing payroll and overheads;
- emergency supplier costs;
- contractual service credits or client consequences;
- time needed to rebuild systems and validate data;
- seasonal peaks;
- the effect of a key supplier outage.
These estimates help assess both price and the required business-interruption limit.
Data type and volume
Insurers may ask what information the organisation holds and in what quantity. Personal data is not one uniform category. Health, financial, identity and children’s information can create different response and liability considerations from ordinary business contact details.
The business should understand:
- approximate record numbers;
- whether data belongs to customers, staff or clients;
- where it is stored;
- how long it is retained;
- whether it is encrypted;
- who can access it;
- whether payment-card data is handled directly;
- whether a supplier processes it on the business’s behalf.
Do not guess a very low number merely to simplify the application. The duty of fair presentation under the Insurance Act 2015 requires material circumstances to be disclosed or sufficient information provided to put a prudent insurer on notice to ask further questions.
Security controls
Security controls are a central underwriting factor. Common questions concern:
- multi-factor authentication;
- remote access;
- privileged and administrator accounts;
- email security;
- backups and restoration tests;
- patching and unsupported software;
- endpoint detection and malware protection;
- network segmentation;
- vulnerability scanning;
- staff awareness and phishing exercises;
- payment-verification processes;
- incident-response planning;
- supplier security.
The NCSC describes Cyber Essentials as the minimum cyber-security standard recommended by the Government. Its five technical controls provide a useful baseline, but an insurer can require additional controls or a particular scope.
A declaration such as “MFA is enabled” should be checked across all relevant email, remote access, cloud and privileged accounts. An inaccurate broad answer can create a serious dispute later.
Backups and recovery
Insurers may ask how often backups run, where they are stored, who can delete them and when restoration was last tested.
Backups that are continuously connected to the same network may be encrypted with production systems. A backup process that has never been restored may not support the assumed recovery time.
Document:
- which systems are backed up;
- recovery-point and recovery-time objectives;
- offline or isolated copies;
- access controls;
- retention periods;
- test results;
- dependencies needed for restoration.
Previous incidents and claims
Previous ransomware, phishing, data loss, fraudulent payment, system compromise, regulatory contact or insurance claim may affect price and terms. The insurer may ask what happened and which improvements followed.
A prior event does not automatically mean cover is unavailable, but concealing it is not a safe response. Provide a clear timeline, root-cause information where known and evidence of remedial action.
Limits and sub-limits
Higher limits usually cost more, but the relationship is not linear. A policy with a £1 million main limit and a small social-engineering sub-limit can provide less usable cover for one scenario than a differently structured policy with a lower main limit.
Compare:
- aggregate policy limit;
- first-party and third-party limits;
- breach-response sub-limit;
- ransomware or extortion sub-limit;
- social-engineering or funds-transfer sub-limit;
- dependent-system sub-limit;
- regulatory or legal-cost sub-limit;
- business-interruption indemnity period;
- defence costs inside or outside the limit.
The cyber claim examples can help test which limit would be used first.
Excesses and waiting periods
The insured may retain part of each loss through a monetary excess. Business interruption may also use a time waiting period.
A larger excess can reduce premium but increase the amount the business must fund during an incident. Consider available cash, not only expected claim frequency.
Check whether separate excesses apply to different sections and whether several excesses can arise from one event.
Optional and extended cover
Price may change when adding:
- social-engineering fraud;
- cybercrime or theft of funds;
- dependent-system interruption;
- system failure without malicious attack;
- reputational-harm loss;
- multimedia liability;
- broader territorial cover;
- increased restoration or response limits;
- longer indemnity periods.
Do not pay for a heading without reading its definition and sub-limit. Equally, do not remove an extension solely to reduce price before checking whether it addresses a central exposure.
Cloud and supplier dependence
A small business may outsource nearly all of its IT while remaining heavily exposed to an outage. Insurers may ask about cloud hosting, software-as-a-service, managed IT, payment processors and other key suppliers.
A dependent-system extension can be limited to named suppliers or defined technology services. The concentration created by one cloud platform may affect underwriting even where the business maintains no physical server.
Contractual requirements
A client, lender, platform or procurement framework may require a cyber limit or specified terms. These requirements can affect the amount and breadth purchased.
Check whether the contract asks for cyber insurance, professional indemnity, data-breach cover or all of them. The cyber versus professional indemnity guide explains why the labels are not interchangeable.
How to prepare a consistent quotation submission
Use a single fact pack containing:
- legal entity names;
- turnover and online revenue;
- staff numbers and locations;
- systems and critical suppliers;
- data types and approximate volumes;
- security-control evidence;
- backup and recovery arrangements;
- previous incidents and claims;
- required limits and contract terms;
- desired optional sections.
The Business Insurance Review Checklist provides a wider renewal structure. Keep copies of the submitted answers and any assumptions generated by an online quotation system.
How to compare quotations
A useful comparison table should include:
| Item | Quote A | Quote B | Quote C |
|---|---|---|---|
| Total premium, tax and fees | |||
| Main aggregate limit | |||
| Excess and time waiting period | |||
| Incident-response limit | |||
| Business-interruption period | |||
| Social-engineering cover | |||
| Dependent-system cover | |||
| Extortion cover | |||
| Key security conditions | |||
| Major exclusions | |||
| Incident-response provider |
A cheaper policy may still be suitable, but only after differences in trigger, limit, wording and service are understood.
Cost-control steps that do not weaken protection
A business may improve insurability and reduce uncertainty by:
- completing accurate security and asset records;
- applying multi-factor authentication consistently;
- removing unsupported systems;
- testing backups and recovery;
- limiting privileged access;
- training staff and verifying payment changes independently;
- preparing an incident-response plan;
- documenting supplier dependencies;
- selecting an excess the business can genuinely fund;
- avoiding duplicate extensions across policies while preserving necessary overlap.
These steps do not guarantee a particular premium. Their primary purpose is to reduce risk and improve the quality of underwriting information.
When to review cost and cover
Review the policy when the business:
- grows materially;
- launches an online service;
- changes cloud or IT provider;
- begins handling new sensitive data;
- enters a new territory;
- signs a major contract;
- acquires another business;
- suffers an incident;
- changes payment processes;
- adopts new operational technology.
Waiting until renewal can leave the insurer with outdated information or the business with an unsuitable limit.
Limits of cost evidence
Provider pages can help identify rating factors, but a quoted starting price, one customer example or one product’s minimum premium is not a representative UK market average. Market conditions and underwriting appetite also change.
Use this page to prepare questions, not to predict an exact premium. Obtain current quotations based on the same facts and read the final documents described in the Business Insurance Documents guide.
Business size is not the whole risk
Employee count is a convenient measure but can hide concentration. A five-person online platform may depend on one production environment and hold information for thousands of users, while a larger local business may have limited online dependency.
Underwriters may therefore look beyond headcount to transaction volume, number of records, privileged users, external connectivity and the financial effect of one outage.
Policy structure and packaging
Cyber cover can be bought as a standalone policy or as part of a broader commercial package. A package extension can be economical, but compare its limit, incident support, exclusions and dependent-system wording with a specialist product.
Premium allocation inside a package may not show the true stand-alone cost of cyber cover. This is another reason not to create an “average” from a mixed collection of package and standalone prices.
Broker and service differences
The premium can reflect more than risk transfer. Some products include security scanning, training, breach coaches or incident-response retainers. Others offer a narrower insurance contract with services charged when used.
Compare who supplies the service, whether it is available before a claim, whether usage affects the limit and whether the business is comfortable with the response panel.
Taxes, fees and instalments
When comparing price, identify Insurance Premium Tax, broker fees, policy fees and interest for instalments. A monthly figure may be a credit arrangement rather than one twelfth of the annual premium.
Use the total amount payable for the same period and record whether optional services or other policy sections are included.