Imagen2: images/are-you-choosing-aggregate-over-per-incident-cyber-cover-2.jpg
Schema_json: {"@context":"https://schema.org","@graph":[{"@type":"BlogPosting","@id":"https://dealergen.uk/are-you-choosing-aggregate-over-per-incident-cyber-cover/#article","headline":"Are you choosing aggregate over per-incident cyber cover?","description":"Are you relying on a £1m headline limit? Aggregate vs per-incident limits: what suits a growing SME depends on one severe loss and repeat claims..","datePublished":"2026-07-14T14:39:00+00:00","dateModified":"2026-07-14T14:39:00+00:00","author":{"@type":"Person","name":"Peter White","url":"https://dealergen.uk/author/peter-white/"},"publisher":{"@type":"Organization","name":"CyberCover UK"},"image":{"@type":"ImageObject","url":"https://dealergen.uk/images/are-you-choosing-aggregate-over-per-incident-cyber-cover.jpg"},"url":"https://dealergen.uk/are-you-choosing-aggregate-over-per-incident-cyber-cover/","mainEntityOfPage":"https://dealergen.uk/are-you-choosing-aggregate-over-per-incident-cyber-cover/","inLanguage":"en-GB","keywords":"Aggregate vs per-incident limits: what suits a growing SME?"},{"@type":"BreadcrumbList","@id":"https://dealergen.uk/are-you-choosing-aggregate-over-per-incident-cyber-cover/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Inicio","item":"https://dealergen.uk/"},{"@type":"ListItem","position":2,"name":"Myths, Mistakes & FAQs","item":"https://dealergen.uk/category/myths,-mistakes-&-faqs/"},{"@type":"ListItem","position":3,"name":"Are you choosing aggregate over per-incident cyber cover?","item":"https://dealergen.uk/are-you-choosing-aggregate-over-per-incident-cyber-cover/"}]}]}
A £1 million limit can look reassuring. A ransomware incident may use £700,000. A later business email compromise claim may need £400,000. With an annual aggregate, only £300,000 may remain for the second claim. With per-incident cover, the limit may reset for each covered event, subject to policy terms.
For a growing UK SME, a per-incident limit protects against one severe breach. An annual aggregate is the total the insurer will pay during the policy year.
Choose limits by worst loss and repeat claims
Choose a per-incident limit for your worst credible loss. Choose an annual aggregate that can withstand repeat claims.
A higher per-incident limit matters when one event could stop the business. It also matters when liability claims could be large. This can affect software firms, online retailers, accountancy practices, and healthcare suppliers. It can also affect firms holding many customer records.
A larger annual aggregate matters when several incidents seem likely within 12 months. Phishing, supplier outages, malware clean-up, and misdirected emails can each cost less than ransomware. But they can steadily use the insurer's annual claims budget.
Small claims can drain cover faster than most owners expect.
Start by estimating one severe loss. Then add between two and four plausible smaller claims. If that total exceeds the annual aggregate, the headline limit may not match your exposure.
A £1m limit may not cover every event
The schedule, definitions, endorsements, and exclusions decide how £1 million applies. It may apply per incident, for the year, or only to one cover section.
Insurance labels are not set out in the same way across all policies. Related attacks, claims, or affected customers may count as one occurrence. The policy definition decides this.
Four terms to separate on every quote
A per-incident limit is the most the insurer will pay for one defined event. An annual aggregate is the most it will pay across covered events during the policy period. A policy limit is a broad maximum. A sublimit is a smaller cap within it, such as extortion or social engineering.
Costs can erode the headline limit
Defence and incident-response costs may sit inside the limit. This reduces the amount left for compensation or recovery. Check separate caps for ransomware, lost income, regulator reviews, customer notices, data recovery, and fraud.
A £1 million headline can contain several smaller limits.
Track cover left after several cyber claims
An annual aggregate falls after each paid claim. It only resets if the policy provides reinstatement.
| Claim during policy year | Covered cost paid | Aggregate left | Business excess |
|---|
| Phishing and forensic review | £150,000 | £850,000 | £5,000 |
| Ransomware and lost income | £500,000 | £350,000 | £5,000 |
| Supplier breach affecting clients | £400,000 | £0 | £55,000 shortfall plus excess |
Related claims may count as one incident. This happens when wording links them to the same cause, attack, or security failure. This can help when one attack affects many customers. But it can limit how often a per-incident cap applies.
Ask whether the aggregate reinstates
Aggregate reinstatement means the insurer restores some or all of the annual limit after a claim. The wording may require an extra premium. Ask if it is automatic, available on request, or excluded for some cover sections.
Reinstatement can matter after a large early-year claim.
How £1m annual aggregate is used
Phishing
£150k
Ransomware
£500k
Left after two claims
£350k
A £400,000 third claim would leave a £50,000 uninsured gap before the policy excess.
Match limits to your SME's exposure pattern
The right mix depends on the cost of one severe event. It also depends on how often smaller losses could happen.
A matrix for four common exposures
| Business exposure | Limit to prioritise | Wording to test |
|---|
| One catastrophic ransomware loss | Higher per-incident limit | Extortion, recovery and downtime sublimits |
| Repeated phishing or fraud attempts | Higher annual aggregate | Social-engineering cap and each-claim excess |
| Critical supplier compromise | Both limits | Dependent business interruption and related-claims wording |
| International expansion | Both limits | Territory, jurisdiction and overseas data clauses |
Contract requirements need exact matching
Customer contracts may require an each-claim limit, an aggregate limit, or both. Read the insurance clause word for word before asking for quotes. A certificate saying “£1m cyber insurance” may not meet an each-claim requirement.
A growing SME should first size one severe cyber loss. Then it should add two to four smaller, likely claims. A per-incident limit helps if one ransomware event could halt trading. A larger annual aggregate helps if fraud, phishing, or supplier failures could recur. Contract terms can override this general approach. Match the limit basis in the contract before choosing cover.
Avoid headline limits and hidden trade-offs
A cheaper quote may have a higher excess. It may also have a longer lost-income wait. It may have lower sublimits. Defence costs may also reduce the main limit.
Compare six lines on every quotation
Use this checklist before choosing cover. You can also ask a broker to refine a quote.
- Per-incident limit: Confirm the cap for one ransomware event, data breach, or liability claim.
- Annual aggregate: Work out what remains after between two and four plausible claims.
- Excess: Check if it applies per claim, per affected person, or per cover section.
- Response and defence costs: Check if they sit inside or outside the main limit.
- Sublimits and waiting periods: Check extortion, fraud, lost income, and supplier-outage caps.
- Contract wording: Match each-claim and aggregate terms set by customers, suppliers, or landlords.
The most common mistake is comparing only the largest limit. A policy may show £1 million, but give £100,000 for fraud. It may also make you wait 24 hours before lost-income cover starts. Ask the insurer or broker to show each cap in plain English. This makes two similar quotes far easier to compare.
GDPR, fines and ransomware are not automatic
Cyber insurance does not automatically pay every UK GDPR-related cost or regulator fine. Ransomware claims may need insurer consent. They may also require approved response firms and sanctions checks.
Policy wording decides what the insurer will actually pay.
This framework does not replace reading the policy wording or getting regulated insurance advice. It matters less where an SME has no real digital work or data exposure. Even small firms using email, online banking, cloud software, or payment systems may face cyber risk.
Your questions answered
Is aggregate cover better than per incident?
Neither is always better. Per-incident cover protects against one large loss. An annual aggregate sets the total claims budget during the policy year.
What does £1 million aggregate mean?
A £1 million aggregate usually means the insurer pays no more than £1 million for covered claims that year. Paid claims reduce the balance. Costs inside the limit also reduce it, unless reinstatement applies.
Does £1m per occurrence mean £1m each time?
Not always. It usually means up to £1 million for one defined occurrence. The policy may group related claims under one occurrence.
Can legal and forensic costs reduce my limit?
Yes, they can. Many policies put defence, legal advice, and forensic work within the limit. That leaves less for other covered loss.
Will cyber insurance pay a GDPR fine?
Sometimes, but never assume it will. Cover depends on the policy wording and regulator action. It also depends on whether the payment can legally be insured.
What aggregate should a growing SME buy?
Start with your worst plausible claim. Then add between two and four likely smaller claims within 12 months. Excesses, sublimits, cash reserves, and contracts also matter.
Does Cyber Essentials guarantee better cyber cover?
No, it does not. Cyber Essentials can support security controls and insurance talks. It does not guarantee cover or override exclusions.
Set a limit structure before requesting quotes
Choose a per-incident limit for one severe event. Choose an annual aggregate that still works after repeat claims.
Ask each insurer or broker to explain the limit basis in plain English. Ask about sublimits, excess, response costs, and reinstatement. This is more useful than asking only for “£1 million cyber cover”.
A safer structure usually covers one severe cyber loss. It also leaves enough annual cover for realistic repeat events.
For a growing SME, the safer structure usually has a per-incident limit for one severe cyber loss. Its annual aggregate should also cover realistic repeat events.