The renewal quote may look manageable. However, a quick “yes” to questions about MFA, tested backups, or payment checks can expose donor and beneficiary data if those controls are not actually in place.
Can your charity afford cyber cover safely?
A charity can afford cover safely when it can pay the premium, excess, and control costs. It must also avoid leaving a major loss uninsured.
What makes a cheap policy costly?
Compare the main cover limit with the smaller limits inside it. A £250,000 policy may have a lower sub-limit for social engineering or business interruption.
Social engineering means a fraudster tricks someone into making a payment. Those smaller figures can decide whether a claim helps during the incident most likely to affect your charity.
Cheap cover can leave expensive gaps.
Which losses can reserves absorb?
Trustees should estimate a plausible bad week. Include specialist help, file recovery, affected-person notices, donor queries, and extra staff time.
Insurance can cover first-party losses, which are the charity’s own costs. It can also cover third-party liability, which is money claimed by another person or organisation.
For a defensible trustee decision, record three figures beside each quote: the annual premium, the excess payable on a claim, and the lowest relevant sub-limit. Then record which incident the charity could still not afford to handle.
Which security controls will insurers expect?
Insurers usually separate essential quote controls from controls that improve terms. They may ask for stronger safeguards from charities with higher risks.
Controls needed for a credible quote
Most proposal forms ask about MFA, supported software, patching, endpoint protection, and backups. MFA means logging in with a password plus another proof.
That extra proof may be an authenticator app code. Backups help only when the charity can restore them.
Keep at least one backup separate from normal access. Test restores at recorded intervals.
⭐
Picked for you
A USB security key can add a physical second check to selected email and administrator accounts. It can help finance staff approve payments or manage cloud settings. It must work with the charity’s chosen systems.
- It gives a second sign-in factor separate from a reusable password.
- It can reduce phishing risk for supported Microsoft 365 or Google administrator accounts.
- It gives trustees a simple item for MFA evidence on critical users.
View on Amazon →
Controls that can improve terms
Insurers may offer better terms when charities have phishing training and protected backups. Payment checks and clear access management can also help.
If a supplier emails new bank details, staff should call a known number already on file. They should not call a number in the email.
This helps prevent business email compromise. That is fraud through a compromised or convincing business email account.
Three layers of insurer evidence
1. Basic quote
MFA, patching, endpoint protection and backups.
2. Better terms
Tested restores, staff training and payment checks.
3. Higher-risk scrutiny
Privileged access, sensitive data controls and response testing.
Keep dated evidence: MFA screenshots, restore-test notes, patch reports, training records, and payment procedures.
Enhanced questions are likely when a charity handles special-category data. Safeguarding, health, children’s data, high-value grants, or international payments can also trigger them.
Higher exposure does not make cover impossible. However, generic answers are less likely to be enough.
The evidence level shapes the quote. The next section shows how to set limits without letting budget decide alone.
Choose limits from your loss, not budget
A proportionate limit reflects what an incident could cost. It should cover investigation, containment, restoration, and defence.
It should not simply match the remaining insurance budget. Think of the limit as a fire bucket sized for the likely fire.
A sensible limit starts with a realistic bad-week estimate. The assessment should then test whether the charity could pay the excess without disrupting services.
| Charity profile |
Indicative limit discussion |
Excess range to test |
Priority controls |
| Local group, 1 to 10 staff, basic donor records |
£50,000 to £100,000 after checking response and recovery costs |
£250 to £1,000 if reserves allow |
MFA, patching, protected backups |
| Growing charity, 10 to 50 staff, cloud fundraising and payroll |
£100,000 to £500,000, including interruption cover |
£500 to £2,500 if a claim remains affordable |
Tested restores, training, payment verification |
| Sensitive data, safeguarding services or high-value payments |
£500,000 or more, based on specialist risk review |
Set only after modelling cash-flow impact |
Enhanced MFA, access control, rehearsed response plan |
Which sub-limits change the decision?
Social engineering cover needs separate attention. It may not follow automatically from data breach or ransomware cover.
Check fraudulent-transfer limits and call-back conditions. Also check dual-approval rules, cyber extortion, data restoration, and supplier-outage cover.
Cyber liability may help with legal defence, privacy claims, and regulatory investigation costs after a breach. It does not remove the duty to assess, contain, and report some breaches.
The ICO expects reports within 72 hours of awareness for certain personal data breaches. Sub-limits and conditions matter as much as the main limit.
Avoid declaration gaps and uninsured fraud
Treat the renewal form as a board-level factual check. Claims can be harder when declared controls and routine practice do not match.
Incident facts must also match the proposal. The most frequent error at this point is treating a planned control as an existing one.
Evidence to keep before renewal
Keep short, dated proof for every declared control. Ask IT suppliers for plain-English confirmation instead of guessing about technical settings.
Good evidence makes the proposal easier to defend. It also helps trustees see gaps before an incident.
- MFA evidence showing coverage for email, remote access, cloud administration, and finance accounts.
- A backup restore-test record showing the date, restored system, and result.
- A patching report for laptops, servers, and key applications, including unsupported systems.
- Staff training and phishing-reporting records, including volunteers with system access.
- An incident response contact sheet and a documented payment verification procedure.
Fraud, trustees and policy exclusions
Cyber insurance does not automatically protect trustee liability or every loss of charity funds. Ask whether social engineering, crime, fidelity, and fraudulent-transfer cover are separate sections.
Also ask whether ignoring an independent call-back rule could restrict a claim. A call-back means checking payment details through a trusted contact route.
This works well in theory, but practice decides claims. A charity may have a procedure, yet staff may not follow it during urgent payments.
This guide does not replace specialist review for charities handling health, safeguarding, or children’s data. The same applies to large sensitive records, critical infrastructure, material international payments, or a past incident. The approach also changes for entities without meaningful personal data, digital systems, or operational reliance on technology.
Clear declarations reduce avoidable disputes. The questions below address the checks trustees most often raise.
Common questions
How much does charity cyber insurance cost?
Costs vary with data sensitivity, turnover, controls, excess, and limit. Compare matched quotes and sub-limits.
Is cyber essentials required for cyber insurance?
Cyber Essentials is not automatically required for cyber insurance. Insurers, funders, or contracts may still request it.
Does cyber insurance cover a GDPR fine?
Cyber insurance may cover legally insurable ICO fines. Check the regulatory defence and privacy-liability wording.
What security proof will an insurer ask a charity for?
Insurers may request proof of MFA, tested backups, patching, training, incident plans, and payment checks. The exact proof depends on the charity’s risk profile.
Does cyber insurance cover phishing payment fraud?
Phishing payment fraud often needs separate social engineering or crime cover. Check both the limit and payment conditions.
What excess should a small charity choose?
Choose an excess that the charity can pay promptly without disrupting services. Then compare the premium saving against the retained risk.
The essentials:- Judge affordability through premium, excess, control costs, sub-limits, and the uninsured loss that remains.
- Keep evidence for MFA, tested backups, patching, and payment verification before signing a proposal.
- Choose the main limit from a realistic disruption and recovery scenario, not budget alone.
- Check social engineering fraud separately because it may have different conditions and a lower limit.
Learn more
Here are some additional resources on this subject: