Buying shares in an SME does not always mean cyber insurance continues unchanged. Change-of-control terms, late notice, past incidents, or weak MFA can affect cover. The real risk is a gap found after completion.
Will the target’s cyber policy survive completion?
A share sale may preserve the target’s policy. This only applies if policy terms, endorsements, and disclosure duties allow it.
Does a share sale preserve cover?
In a share purchase, the target normally remains the same legal entity. It may also remain the named insured.
That does not automatically protect the buyer’s group, new directors, or linked systems. Check the definition of insured carefully.
Check clauses on change in control, material risk changes, assignment, mergers, and acquisitions. Some require notice within 14 to 30 days. Others need written insurer consent or a new proposal form.
An asset purchase usually transfers selected assets, contracts, customer records, or staff. It does not transfer the seller’s insured company.
The seller’s cyber policy will not normally follow those assets. The buyer should arrange cover in its own name from completion.
This matters where personal data, software, customer contracts, or operating systems transfer. Data-protection duties depend on facts and contract terms. Database ownership alone does not decide responsibility.
What should the buyer ask the broker?
Ask the broker and insurer before signing whether the policy stays active after completion. Ask whether consent or new underwriting details are needed.
Get the answer in writing. A schedule proves the limit, period, and insured name. It rarely explains notice windows, known-circumstance exclusions, or special endorsements.
A buyer should separate three protection periods. These are cover before completion, cover from completion, and earlier events found later.
Share purchase cover may leave the target’s policy active. Yet a control-change clause can restrict a later claim. A known-circumstances exclusion can also limit cover.
In an asset deal, place cover in the buyer’s name from day one. Do not assume the seller’s policy follows the records or systems.
Ask if a run-off or tail endorsement is available. Ask how long it lasts and whether it shares the live policy limit.
This matters after phishing, supplier compromise, or a data breach. A past event may not yet have produced a claim.
Build a cyber-insurance data room before signing
The data room should show the policy terms and the risk presented to insurers. Think of it as the deal’s evidence folder.
Which documents belong in the data room?
Request current and past schedules, full wordings, endorsements, and renewal invitations. Also request proposal forms and broker correspondence.
Include claim notices, declined-claim letters, and reservation-of-rights letters. Add incident logs, ransomware reports, ICO notices, and backup test records.
Include penetration tests and managed service provider contracts. Check that underwriting answers match the evidence.
Pay close attention to MFA statements. Confirm that remote access and privileged accounts really use MFA.
Can no claims still hide cyber risk?
No reported claims do not prove an SME has no cyber risk. Check suspicious logins, malware, misdirected emails, and supplier compromise.
Also check lost system access and incidents handled inside the firm. These may be a circumstance.
A circumstance is a known fact that could lead to a later claim. A past incident does not automatically stop a deal.
It may justify a fix, a specific indemnity, or a higher premium. The most common error is treating “no claims” as proof of safety.
Which controls will underwriting test?
Insurers commonly assess MFA, patching, endpoint protection, tested backups, staff training, and incident plans. MFA needs a second identity check after a password.
That second check might be an app code. It is like needing both a house key and a door code.
The National Cyber Security Centre’s Cyber Essentials guidance can help test the target’s answers. It helps show whether stated controls actually work: National Cyber Security Centre.
Written answers are not enough without supporting evidence.
Which policy gaps can change the purchase price?
The headline limit matters less than cash for losses likely to stop this SME trading. A £1 million limit may hide much smaller sub-limits.
Which sub-limits matter most?
Compare ransomware, cyber extortion, funds-transfer fraud, and social engineering cover. Check incident response, legal advice, notification costs, and credit monitoring.
Check third-party liability separately from first-party loss. First-party loss is the firm’s own cost. Third-party liability covers claims made against the firm.
For business interruption, check the excess and waiting period. Also check supplier dependency cover for providers, payment platforms, and cloud hosts.
A two-day outage may create no insured loss. This happens if the waiting period is longer.
| Cover point | What to inspect | Deal impact |
| Ransomware | Sub-limit, MFA condition, prior-event exclusion | May require indemnity or remediation |
| Business interruption | Waiting period and supplier dependency | Can affect valuation of downtime risk |
| Social engineering | Separate fraud sub-limit and verification rules | May leave invoice fraud uninsured |
| Data breach liability | Defence costs, fines wording, privacy exclusions | Affects post-deal regulatory exposure |
How do exclusions defeat headline limits?
Check exclusions for known incidents, poor controls, and unpatched systems. Also check contract liability, senior fraud, cloud outages, war, and provider failures.
Match each major exclusion against the target’s systems, data flows, and supplier contracts. This comparison may work in theory, but the wording may not fit actual operations.
If the policy excludes loss from the only managed service provider, cover may not suit the target. The next issue is how replacement cover changes deal costs.
⭐
Picked for you
A plain-English cyber security book can help directors ask better questions before a broker meeting. It cannot replace legal advice or policy wording review during an acquisition.
- Helps directors understand MFA, backups, and phishing evidence requested during due diligence
- Supports clearer talks with IT providers about supplier and outage risks
- Gives a reference point for cyber-security questionnaires
View on Amazon →
Where replacement cover is needed, do not compare premiums alone. SME insurance costs depend on revenue, sector, data volumes, and claims history.
Costs also depend on ransomware exposure, supplier reliance, and cyber controls. A cheaper policy may have a higher retention.
It may also have a tight ransomware sub-limit. It may offer no useful cover for social-engineering loss or cloud interruption.
Get comparable quotes using the same turnover, security, and claims details. Then compare total limits, sub-limits, waiting periods, and response services.
Evidence of MFA, tested backups, patching, and staff training can improve terms. It does not remove the need to check exclusions.
Use the SPA to allocate cyber risk, not kill the deal
Known cyber gaps can often be dealt with in the SPA. They do not always need to end the transaction.
When is a price cut better than indemnity?
A price cut suits a cost that can be estimated. Examples include replacing unsupported software or buying better cover.
An escrow may suit a claim with uncertain value or timing. A specific indemnity can make the seller responsible for a defined past breach.
A warranty says a fact is true at signing or completion. It is not insurance. It does not automatically pay the buyer’s response costs.
Can a cyber issue become a condition?
A condition precedent must be met before completion. It can require insurer consent, replacement cover, or tested backups.
It can also require closure of a critical MFA gap. State the evidence needed, deadline, and result of failure.
Avoid vague wording such as “satisfactory cyber security”. Require clear actions, such as MFA for all privileged and remote-access accounts.
For a buyer, the practical aim is simple. Put each known risk with the party best able to fix it.
This guidance is less relevant without an acquisition or disposal. It also matters less where the business has no meaningful systems or personal data. It may not apply to isolated physical assets without operations, records, contracts, or technology. Regulated, cross-border, and complex deals need tailored legal and insurance advice.
Your questions answered
The answers below cover main continuity and underwriting issues in SME deals. They are general education, not legal or insurance advice.
Does a small business need cyber insurance?
Cyber insurance is not compulsory for most SMEs. It can cover losses that standard business policies often exclude.
It matters most where a firm holds personal data. It also matters where it takes online payments or relies on cloud systems.
What are the requirements for cyber insurance?
Insurers commonly assess MFA, patching, backups, endpoint protection, and incident-response planning. Requirements vary by turnover, sector, claims history, data sensitivity, and underwriting rules.
Does cyber cover transfer in a share purchase?
It may continue because the target remains the insured entity. Check control-change wording, notice duties, and whether insurer consent is needed.
Does cyber cover transfer in an asset purchase?
It does not usually transfer with assets, records, or contracts. The buyer should arrange new cover from completion and allocate earlier-event liability.
Can an undisclosed breach affect the sale price?
Yes, an undisclosed breach can affect price, warranties, and policy recovery. The parties may use a price cut, escrow, specific indemnity, or condition precedent.
Will cyber insurance pay an ICO fine?
Policies may cover defence and investigation costs, but fines depend on wording and legal limits. Do not assume an ICO monetary penalty is insured.
How soon should the insurer be told about the deal?
Tell the insurer or broker before signing if the policy has a control-change clause. Allow 14 to 30 days for consent, new underwriting, or replacement cover.
What to do before signing and closing
Treat cyber insurance as a deal document, not an annual renewal task. Give it the same care as key contracts.
Before signing, collect the full policy file, claims evidence, and security records. Before closing, get written confirmation on control change, consent, and replacement cover.
After closing, review the policy within 30 days against the combined business. Check new data flows, supplier access, turnover, systems, and interruption dependencies.
A dated deal plan is safer than a final-week check.
The essentials:- A policy schedule alone cannot confirm that cyber cover will continue after an SME deal.
- Share purchases and asset purchases create different continuity risks.
- Sub-limits, excesses, waiting periods, and exclusions can matter more than the headline limit.
- Known cyber issues can often be allocated through the SPA.
- Post-completion changes must be reflected in insurer notices and policy details.
The deal timetable should turn cyber insurance checks into dated actions. Do not leave them for the final week.
Before signing, compare the schedule, full wording, endorsements, and renewal date. Compare them with the target’s current systems and underwriting answers.
Between signing and completion, send required insurer notices. Get written consent where needed.
Disclose material changes, such as a new parent company or higher turnover. Also disclose access to the buyer’s network.
Immediately after completion, update users, locations, cloud services, and provider risk. At the first renewal, reassess limits and interruption reliance for the combined group.
Clear M&A insurance disclosure reduces later disputes about incomplete underwriting information.
Learn more
Here are some additional resources on this subject: