Almost two in five UK small businesses reported a cyber attack last year. Many policies pay out only for narrow scenarios.
For owners who handle customer data or online payments, a cheap quote can leave them exposed to ransom demands. It can also leave them exposed to regulatory fines or liable for losses from disrupted trading.
Compare cyber insurance UK SMEs by checking cover for ransomware, data-breach response and business interruption. Also check regulatory costs, limits, sub-limits and exclusions.
Practical comparisons show what each policy pays for. They also show how premiums vary by sector and size. The piece includes a checklist to shortlist three insurers you can trust.
Quick comparison table
The table below helps shortlist suitable SME products by headline limit, common sub‑limits and practical triggers. Read the first row as a checklist for what to check before asking for quotes.
| Insurer |
Headline limit (typical) |
Ransom sub‑limit |
Forensic limit |
PR / notification |
BI indemnity period |
Typical excess |
Social engineering cover |
| Hiscox (SME product) |
£250k–£2m |
£25k–£150k |
£25k–£100k |
£10k–£75k |
30–180 days |
£500–£2,500 |
Often included |
| Aviva (SME & commercial) |
£500k–£5m |
£50k–£250k |
£50k–£200k |
£25k–£100k |
60–180 days |
£1,000–£5,000 |
Sometimes excluded |
| Beazley (London market SME) |
£500k–£10m |
£50k–£500k |
£50k–£300k |
£25k–£150k |
90–365 days |
£1,000–£10,000 |
Usually included |
| AXA XL / Chubb / AIG |
£500k–£10m+ |
£50k–£500k |
£50k–£300k |
£25k–£200k |
90–365 days |
£1,000–£10,000 |
Often included |
How to read this table
Read the ransom and forensic columns as the real limits that matter during an incident. Do not assume the headline limit covers every cost.
Check the BI indemnity period and social engineering wording before shortlisting.
Sector and size bands
Use staff bands (micro 1–9, small 10–50) and sector risk to filter insurers. Retail and e‑commerce need higher social engineering and fraud cover.
Professional services need longer BI periods and greater third‑party liability cover.
Different sectors and staff bands face different exposures and need different cover mixes; choose cover and limits that match those exposures.
For example, a micro online retailer (1–9 staff) typically faces immediate customer‑facing risks. These include card‑not‑present fraud, supply‑chain fulfilment disruption and reputational loss.
Practical cover targets for that profile prioritise social engineering and fraud wording, and aim for a ransom sub‑limit in the £10k–£75k band.
They also seek forensic and PR limits that match short restoration windows of 30–60 days BI.
By contrast, a 10–50 person professional services firm usually needs longer BI indemnity. It also needs higher forensic and legal defence limits, often £50k–£200k.
It needs broader third‑party liability wording because client SLAs and contractual liabilities drive much loss.
Managed service providers or SMEs that host client systems should treat themselves as higher-risk. They need higher ransom and forensic sub‑limits, explicit contractual liability cover and bespoke retroactive wording.
Framing cover choices by the intersection of sector risk and staff band helps pick realistic limits. This avoids relying on headline sums alone.
Headline limits give a quick comparison. Exclusions and precise wording determine whether a claim is paid and for how much.
Typical variations to watch for include social engineering cover, ransom sub‑limits, explicit exclusions and war or nation‑state clauses. Social engineering cover may be an optional extension or entirely excluded.
When included, social engineering cover often has a separate cap. Ransom sub‑limits often sit well below headline limits.
Some policies explicitly exclude contractual fines or punitive damages. War, terrorism or nation‑state exclusions can remove cover for state‑sponsored incidents.
Insurers also apply retroactive dates that exclude incidents before a set date. They add control‑based conditions tied to MFA, backups and patching.
Failure to maintain these controls can trigger higher excesses or refusal to pay a claim.
Two policies with the same £1m headline can diverge significantly. One may exclude social engineering and have a £25k ransom sub‑limit.
Another may include social engineering, offer a £150k sub‑limit and have no retroactive exclusion. Reading exclusions and sub‑limits in context determines real protection.
Provider A: SME‑focused products
SME‑focused insurers market simpler policies for smaller firms with lower headline limits. They usually bundle basic first‑party cover like forensics and notification.
These products often save premium but use tighter sub‑limits.
Pros for micro firms
Lower premiums and simpler underwriting make these products quick to buy. Many micro firms prefer simplicity for straightforward operations.
They work well when your maximum loss fits inside the product sub‑limits.
Cons and real limits
The most frequent error at this point is choosing based on headline limit alone. Sub‑limits for ransom or PR often cap real recovery at £10k–£50k.
This fails when an incident requires extended forensic work or long BI recovery.
Check key limits before requesting any formal quotation.
Provider B: broader commercial policies
Larger SME products give higher headline limits and longer BI periods. They often include wider social engineering and PCI exposures.
Premium rises accordingly and underwriting is more detailed.
Advantages for 10–50 staff
These products supply larger ransom and forensic sub‑limits suitable for client data risks. They also offer longer indemnity periods for business interruption.
They suit firms with higher revenue and client SLAs.
Practical limitations
This works well in theory. Insurers demand stronger controls in practice.
Missing MFA or untested backups often trigger higher excesses or exclusions. Insurers may ask for Cyber Essentials or ISO evidence.
Provider C: london market and bespoke limits
Lloyd’s syndicates and specialist carriers provide bespoke wording for high exposure SMEs. They accept higher limits and complex BI wording.
The process is slower and costs more.
Pros for high‑risk SMEs
They place higher ransom and forensic limits and tailor retroactive dates. They can include contractual liability cover for large clients.
This suits SMEs with cross‑border services or sensitive data.
Cons and who should avoid
The main downside is cost and negotiation time. For micro businesses, bespoke cover often costs more than the added protection is worth.
Avoid bespoke placements unless residual risk exceeds standard products.
Check key limits before requesting any formal quotation.
How to choose for your SME
Choose by matching the insurer limits to your likely incident costs. Estimate likely ransom, forensic and BI exposure before selecting limits.
Use the table rules: pick ransom and forensic limits that match your worst realistic incident.
Step checklist to pick a policy
Estimate probable ransom and forensic costs using your sector examples. Check whether PR, credit monitoring and legal defence have separate sub‑limits.
Confirm whether ICO response costs are covered but fines are excluded.
Decision rules by profile
If you take payments online, prioritise social engineering cover and fraud wording. If you host client systems, prioritise longer BI indemnity periods.
If you hold health or financial data, prefer higher forensic and legal defence limits.
The evidence points to faster containment when specialist incident response begins within 24–72 hours. Early insurer engagement accelerates forensic access and reduces total loss in many cases.
Most SME policies exclude ICO fines but typically pay for legal costs and breach response. Check the wording: response costs are commonly covered, while fines and criminal penalties are not.
For most UK SMEs a policy that matches likely operational loss makes sense. Spending first on core controls reduces incident likelihood and premiums.
A mid‑range policy with clear ransom and forensic sub‑limits works well. Increase limits and document security controls if contracts expose you to client claims above £250k.
What nobody tells you about SME cyber cover
Many brokers and comparison sites list headline limits prominently, not sub‑limits. The most damaging surprise in claims is finding the ransom or forensic cap is far lower than expected.
A simple sentence in a policy can change what counts as a business interruption trigger.
Hidden costs and timeframes
Claim settlement often needs BI reconciliation that can take 30–180 days. Forensic and legal bills may accrue before an insurer approves larger payments.
Expect provisional payments in complex claims, not immediate full settlement.
A common anonymous case
A typical case: a 12‑person consultancy suffered ransomware. They believed they had £1m cover, but then found the ransom cap was £25k.
The claim exposed the mismatch between headline limits and sub‑limits.
This guidance does not apply if your business exceeds SME complexity, operates critical infrastructure, or needs tailored international legal advice. In such cases consult a specialist broker or legal counsel.
Contact a BIBA‑registered broker or an experienced insurer representative to validate wordings before you sign.
Two anonymised, practical incident timelines illustrate how sub‑limits and wording change outcomes.
Case A:
- an 8‑person e‑commerce shop detected ransomware on Day 0.
- Day 1 they notified insurer.
- Insurer-approved forensics attended Day 2.
- Forensic costs totalled c. £18k.
- Containment and rebuild costs totalled c. £22k.
- The attacker demanded £40k.
- The policy had a ransom sub‑limit of £25k and a forensic limit of £20k.
- The firm received provisional forensic payments but funded the £15k shortfall themselves.
- They also funded additional rebuild costs while insurers reconciled BI losses.
The whole claim took about 90 days to settle.
Case B:
- a 25‑person consultancy suffered a business email compromise that led to a £75k fraudulent payment.
- Forensics cost £30k.
- Legal and regulatory response costs were £20k.
- Client remediation costs were £40k.
- The policy included social engineering cover with a £50k sub‑limit.
- The insured recovered £50k for the fraud element.
- The firm had to pursue the balance through crime recovery and client negotiation.
These examples show typical day-by-day steps: detect, notify, forensic engagement, containment, BI reconciliation. They show how shortfalls between headline and sub‑limits produce out‑of‑pocket exposure.
Frequently asked questions
What percentage of UK businesses have cyber insurance?
Around 30–40% of UK businesses report holding cyber insurance in industry surveys in recent years. Uptake rises with company size and sector risk, particularly in payments and health sectors.
Do small businesses need cyber insurance?
Yes, businesses that process customer data or payments should consider cyber cover. Typical SME incident costs for forensics, BI and PR often exceed small IT budgets.
How fast must I notify the ICO about a breach?
You must notify the ICO within 72 hours if the breach meets reportable thresholds under UK GDPR. Seek legal advice before submitting formal notices when complex facts exist.
Does previous incident history stop me getting cover?
Disclosing previous incidents is mandatory under underwriting rules. Insurers may impose higher premiums, exclusions or a retroactive exclusion date, not always outright refusal.
How long does a typical SME cyber claim take?
A straightforward claim can resolve in 30–90 days; complex BI and regulatory matters commonly take 90–180 days. Early engagement with responders shortens containment time.
What minimum controls do insurers expect?
Insurers commonly expect MFA, tested backups, patch management and endpoint defences. Certification like Cyber Essentials or ISO/IEC 27001 can widen insurer options.
Final recommendation and next steps
Start by estimating probable ransom, forensic and BI costs for one realistic incident. Shortlist two or three insurers from the table whose ransom and forensic sub‑limits match that estimate.
Validate the full policy wording and underwriting questions with a BIBA broker before committing.
Incident notification email template
Subject: Immediate claim notification, cyber incident
To: [insurer claims email]
We detected a cyber incident on [date]. Systems affected: [list]. We request immediate activation of our cyber policy and incident response services under policy [policy number].
We confirm this notification discloses all known facts to date.
Contact for incident management: [Name, role, phone, email].
Attached: timeline of detection and initial containment steps.
Regards,
[Company name]
Minimum controls checklist
- Multi‑factor authentication on remote and admin access.
- Daily or frequent tested backups with offline copies.
- Regular patching of servers and key applications.
- Endpoint detection and response or equivalent.
- Staff phishing awareness records and simulation logs.
- Isolate affected systems and preserve logs.
- Notify insurer and follow their instructions.
- Engage forensic responders approved by insurer if required.
- Prepare a short factual timeline for regulator and clients.
NCSC guidance explains practical incident handling and basic controls useful for underwriting.
Typical ransom and forensic sub‑limits for SME policies range from £10,000 to £500,000 depending on insurer and product. Always match these numbers to a realistic worst‑case for your business before choosing a limit.
Day 0–1: Detect and isolate systems. Preserve logs.
Day 1–3: Notify insurer. Engage forensics (insurer approval may be needed).
Day 3–30: Contain and restore. Begin customer and regulator notices.
Day 30–180+: BI reconciliation, legal processes and settlement.
Will my insurer pay ICO fines?
Most policies exclude ICO fines and criminal penalties. Policies commonly pay legal defence and regulatory response costs but not fines themselves.