Cyber Insurance for UK Small Businesses: Do You Need It?
Cyber insurance pays the costs of recovering from a cyber attack: IT forensics, data recovery, business interruption, and liability claims. For small businesses, a single ransomware attack or data breach can cost £10,000–£50,000 to recover from. This guide explains what cyber insurance covers, what it does not, and how to decide whether you need it.
Insurance is not a substitute for security
Cyber insurance covers the financial aftermath of an incident; it does not prevent one. Insurers also require basic security measures to be in place for claims to be valid. Get your security fundamentals right first, then consider insurance as a backstop.
What Cyber Insurance Typically Covers
What Cyber Insurance Typically Does Not Cover
Should Your Business Get Cyber Insurance?
Answer these four questions. The more you answer “yes”, the stronger the case for a policy.
Do you hold significant customer or employee personal data?
If yes: a breach can trigger ICO fines, client claims, and breach notification costs, all of which insurance covers.
Could a ransomware attack shut down your business for a week or more?
Business interruption cover is often the most valuable part of a policy. If you cannot afford to be offline, insurance absorbs that risk.
Do your clients require you to hold cyber insurance?
Larger clients and public sector contracts increasingly require suppliers to carry cyber insurance. Check your contract terms.
Could you afford a major incident without insurance?
An incident response firm costs £200–£500 per hour. A two-day investigation can cost £5,000–£10,000 before you account for recovery costs.
How to Get Cyber Insurance
- 1Check your existing policies first: some business insurance includes limited cyber cover. Ask your insurer explicitly.
- 2Compare standalone cyber insurance policies via a commercial insurance broker or comparison site (Simply Business, Hiscox, AXA, and Aviva all offer SMB cyber products).
- 3Implement basic security before applying: most insurers ask about MFA, antivirus, and patch management. Meeting Cyber Essentials can unlock better terms.
- 4Read the exclusions carefully: focus on what voids a claim, the excess amount, and whether ransomware payments are covered.
- 5Review annually: your cyber risk profile changes as your business grows and as the threat landscape evolves.
Build the security insurers require. Free.
Cyber Nova AI gives you a personalised checklist covering the security controls most cyber insurers require: MFA, patching, malware protection, and more. Start your free check today.
Start for free →Related guides
Frequently asked questions
Does my UK business insurance already cover cyber attacks?
Standard business insurance policies (public liability, professional indemnity, employers liability) do not typically cover cyber incidents. Some policies include limited cyber cover, but it is often capped at a low amount or excludes many common scenarios. Always check your existing policy and ask your insurer directly.
How much does cyber insurance cost for a small UK business?
For a small UK business with revenue under £1 million, standalone cyber insurance typically costs £200–£800 per year depending on the sector, the amount of personal data you hold, and the security measures you have in place. Holding Cyber Essentials certification can reduce premiums.
Will cyber insurance pay out if I did not have basic security in place?
Most cyber insurance policies have security requirements as a condition of cover. If you suffer a breach and the insurer finds you had no multi-factor authentication on key accounts, no antivirus software, or ignored security patches, your claim may be declined or reduced. Basic security hygiene is both good practice and a policy requirement.
What is the difference between first-party and third-party cyber cover?
First-party cover pays for your own losses: IT forensics, data recovery, business interruption, and ransomware payments. Third-party cover pays for claims made against you by others; for example, if a client sues you because their data was exposed in your breach. Most small business cyber policies include both.