Are there hidden holes in cyber insurance that can leave a small business exposed? Many UK SME owners discover exclusions only when they submit a claim. This guide focuses exclusively on common policy exclusions for SMEs, explaining typical wording, why insurers rely on them, examples of claim denials, and practical steps to close gaps or negotiate endorsements.
Key takeaways: what to know in 1 minute
- Many cyber policies exclude specific causes such as social engineering and some phishing losses, check defined triggers in the policy wording.
- Ransomware and malware cover is often restricted or conditional; insurers commonly require incident response protocols and up-to-date backups.
- Human error and negligence are frequent grounds for refusal unless the policy expressly includes them; record-keeping and staff training matter.
- Business interruption claims can be excluded for system failure or for partial outages caused by non-covered events; understand how indemnity periods and the definition of "interruption" apply.
- Many policies exclude regulatory fines and some GDPR-related liabilities; separate regulatory cover or legal expense extensions may be needed.
Common policy exclusions for SMEs: ransomware and malware
Ransomware and malware are headline risks, but the presence of cover does not guarantee a payout. Typical exclusions and conditional limitations include:
- pre-existing malware infections or unresolved vulnerabilities discovered before the policy inception date;
- failure to maintain required technical controls (for example, lack of endpoint detection and response (EDR) or missing multi-factor authentication (MFA) when listed as a condition precedent);
- costs of paying a ransom where local law or insurer wording prohibits payments, or when payment is not approved by the insurer;
- malware that originates from criminal acts excluded elsewhere, such as fraud or employee dishonesty claims.
Example clause wording (typical): "The insurer will not cover loss caused by malware where the insured failed to implement and maintain the controls listed in Schedule A at the time of the incident."
Why insurers exclude or limit cover
- Ransom payments can be high and hard to trace; insurers use conditions to reduce moral hazard.
- Controls-based underwriting allows premium differentiation and risk management: missing controls make incidents more likely and more costly.
Practical considerations for SMEs
- When a policy refers to technical controls, ask for exact definitions and where to evidence compliance (logs, dated screenshots, supplier attestations).
- Backups are often an underwriting requirement; verify the wording about backup frequency, isolation and test results.
- Consider separate extortion or ransomware response limits if standard cover is capped.
Policy exclusions often excluding social engineering and phishing
Social engineering and phishing are common attack vectors and commonly lead to expensive losses (funds transfer, data exfiltration). Insurers treat these differently:
- Some cyber policies explicitly exclude social engineering (often labelled "fraudulent instruction" exclusion).
- Others include social engineering cover but narrowly define it (for example, cover only for email account compromise and not telephone or impersonation scams).
- Crime or fidelity policies (separate products) may respond to some social engineering losses where cyber policies do not, but overlap and gaps are frequent.
Common wording examples
- Exclusion: "Loss arising from any fraudulent or dishonest act by any third party purporting to be an authorised person or organisation is excluded."
- Conditional cover: "The insurer will indemnify the insured for social engineering loss where the insured can demonstrate they acted in accordance with verified payment procedures and dual-authorisation controls."
Practical examples
- A supplier invoice is changed by a fraudster via email and funds are paid to a rogue account: the claim may be declined if the policy excludes business email compromise or lacks social engineering cover.
- A member of staff authorises a transfer after a convincing phone call from an attacker: verbal authorisations are often outside cyber policy definitions of a covered communication.
How to reduce the exclusion risk
- Tighten internal payment controls (dual authorisation, call-backs to verified numbers, segregation of duties); document procedures and keep auditable records.
- Keep vendor master changes under strict review and create an approval trail to support a future claim.
Typical policy exclusions for SMEs: human error and negligence
Human error and negligence cause many incidents. Insurers commonly exclude or limit cover where losses result from careless or negligent acts by employees or the insured's failure to follow stated procedures.
Forms of exclusion
- blanket exclusions for losses due to employee negligence;
- exclusions where the insured failed to follow the security practices stated in the policy;
- exclusions for losses resulting from unauthorised acts by employees that are criminal in nature.
Example clause: "Any loss directly or indirectly resulting from mistakes, errors, or omissions by employees which would reasonably have been prevented by the application of the controls set out in this policy is excluded."
Why this matters for SMEs
- SMEs often lack formalised IT policies and training; insurers therefore rely on exclusions to limit payouts when poor procedures contribute to loss.
- Evidence matters: training logs, disciplinary records and access control lists can demonstrate reasonable care.
Mitigation steps
- Maintain dated training records and run phishing simulations; keep results and remedial actions.
- Document IT change control, remote access policies and privileged account management.
- When negotiating, seek endorsements that carve back certain employee errors if reasonable training and documented procedures exist.
Policy exclusions around business interruption and system failure
Business interruption (BI) often represents the largest single monetary exposure after a cyber incident. However, BI cover commonly includes strict triggers and several exclusions:
- exclusions for "uninsured perils" such as normal wear and tear, hardware failure, or software bugs not caused by a covered cyber event;
- restrictions where BI only responds to a covered "security breach" or "malicious act", non-malicious system failure may be outside cover;
- exclusions for losses resulting from third-party cloud or managed service provider outages depending on wording.
Key wording to check
- Definition of interruption: "business interruption means reduction in gross revenue as a direct result of a security breach, not due to system failure or scheduled maintenance."
- Third-party dependency clauses: who is an insured third party and which supplier outages are included.
Typical scenario causing a denied BI claim
- A critical on-premise server fails due to hardware fault; business cannot trade for 48 hours. If the policy requires a malicious cyber event to trigger BI, the claim may be denied.
How SMEs can address BI exclusions
- Consider contingent business interruption cover or specific suppliers extension.
- Keep service-level agreements (SLAs) with cloud providers, and document redundancy and failover tests.
- Retain evidence of restoration efforts and recovery timelines to support any claim that may bridge policy wording.
| Exclusion / policy type |
Typical cyber policy |
Crime / fidelity policy |
PI / professional liability |
| Social engineering / BEC |
Often excluded or narrowly defined |
May respond depending on wording |
Usually not covered |
| Ransom payments |
Commonly covered but conditional |
Not typically covered |
Not covered |
| Regulatory fines / GDPR |
Often excluded; legal expenses sometimes included |
Not covered |
May cover some defence costs |
| System failure / hardware fault |
Frequently excluded unless linked to a covered cyber event |
Not covered |
Depends on alleged professional error |
Common policy exclusions for SMEs: regulatory fines and GDPR
Regulatory fines, especially under data protection law, are a major concern for UK SMEs handling personal data. However, many policies explicitly exclude fines and penalties imposed by regulators.
Common approaches seen in policy wordings
- Full exclusion: "No cover for regulatory fines, penalties, punitive or exemplary damages."
- Partial cover: certain legal defence costs or costs of notifying data subjects are covered while fines themselves remain excluded.
- Insurer-funded civil fines: some specialist cyber products may offer defence and settlement cover but still exclude statutory fines.
Relevant UK context
- The Information Commissioner's Office (ICO) has powers to levy monetary penalties under UK GDPR and the Data Protection Act. Official guidance is available at ICO.
- Regulators often assess whether the organisation demonstrated appropriate technical and organisational measures, whether those steps existed can affect both fines and insurers' stance on claims.
Practical implications
- If the policy excludes fines, the business remains liable for any regulatory penalties. Legal defence costs and incident response may still be insured, which reduces financial strain but does not replace fines.
- SMEs should check whether the policy includes cover for costs of compliance actions, such as credit monitoring, customer notifications and crisis PR.
Options to consider
- Negotiate an endorsement that provides limited cover for regulatory defence costs or fines where permitted.
- Consider a separate legal expenses or regulatory liability product.
Policy exclusions for third-party liability and contractual claims
Third-party liability and contractual claims arise when a client or partner sues after a data breach or service outage. Typical exclusions include:
- contractual liability exclusions where the insured has assumed liability beyond statutory obligations;
- exclusion for liabilities arising from failure to meet SLAs unless negligence or a covered cyber event is proven;
- exclusions where the loss arises from software or hardware defects supplied by a third party (supplier indemnities may be necessary).
Why contractual claims are treated differently
- Insurers price liability for third parties based on foreseeable legal exposure. Where a contract shifts disproportionate risk to the SME (for example full indemnity for any data loss), insurers may exclude or reduce cover.
- Claims arising from professional advice or negligent design are often managed under professional indemnity policies, not necessarily under a cyber policy.
Practical steps
- Review standard customer contracts and supplier agreements: avoid onerous indemnities that push uninsurable risk onto the SME.
- Seek a policy that clarifies how third-party claims are treated and whether defence costs, settlements and judgments are included.
Example claim denials and what went wrong (practical cases)
Case 1: ransomware payment declined
A small retailer paid a ransom after files were encrypted. The insurer declined because backups were not isolated and the policy required "air-gapped" or tested backups. The business lacked proof of tested restores.
Lesson: keep documented backup tests and clarify backup definitions in the policy.
Case 2: invoice fraud via phishing
An SME transferred funds following a spoofed supplier email. The cyber policy excluded social engineering losses; the crime policy also excluded electronic payment fraud. The claim failed due to conflicting product boundaries.
Lesson: check overlap between crime and cyber products and seek explicit social engineering cover or a combined wording.
Case 3: business interruption after cloud provider outage
A SaaS-dependent firm lost revenue when a supplier experienced an outage. The insurer denied BI because the event was a supplier outage not caused by a "security breach" at the insured.
Lesson: seek contingent BI endorsements for critical third-party suppliers.
Quick process to check exclusions and evidence compliance
Check exclusions: 5-step readiness flow
1️⃣
Review policy wording
Locate definitions: "security breach", "social engineering" and control conditions
2️⃣
Map controls
Match policy control list with actual tools: MFA, EDR, backups
3️⃣
Collect evidence
Logs, training records, backup test reports
4️⃣
Negotiate endorsements
Ask for carve-backs for social engineering or regulatory defence
5️⃣
Test response
Run tabletop exercises to confirm roles & evidence collection
Advantages, risks and common mistakes
Benefits / when to prioritise coverage
- ✅ When handling client data: policies that cover breach response can reduce incident costs.
- ✅ Where revenue depends on IT availability: BI cover can stabilise cash flow after downtime.
- ✅ If contractual obligations require cover: some clients demand cyber insurance, ensure exclusions do not nullify the benefit.
Errors to avoid / risks
- ⚠️ Assuming all losses are covered: many SMEs assume cyber policies cover ransomware, social engineering and regulatory fines equally; wording often says otherwise.
- ⚠️ Not evidencing technical controls: insurers deny claims if required controls were not active or evidenced.
- ⚠️ Overlooking supplier dependencies: failing to understand which third-party outages are excluded from BI can leave a business uncovered.
Frequently asked questions
What are the most common exclusions in cyber policies?
Policies commonly exclude regulatory fines, pre-existing incidents, some forms of social engineering, general employee negligence and system failures not caused by a covered cyber event.
Is ransomware always covered by SME cyber insurance?
Not always. Many policies cover ransomware subject to conditions (backups, MFA, EDR) and sometimes limit ransom payments or require insurer approval before payment.
Will an insurer pay GDPR fines after a data breach?
Many cyber policies exclude statutory fines and penalties. Some provide cover for legal defence costs or investigations but not the fines themselves. See the ICO for regulation details at ICO.
Does human error void a cyber insurance claim?
Human error does not automatically void a claim, but insurers may decline claims if the error resulted from failure to follow stated controls or from gross negligence.
Can social engineering losses be insured?
Yes, but cover is often specific and limited. Check whether the policy names social engineering, business email compromise or fraudulent instruction and what conditions apply.
How do exclusions affect business interruption claims?
BI cover often requires a defined triggering event (such as a security breach). System failures, supplier outages or gradual degradation can be excluded unless specifically included.
Should SMEs buy cyber and crime policies together?
Combining policies can reduce gaps, but overlap and conflicting exclusions exist. Review wordings together and seek clarity from brokers or insurers about shared cover boundaries.
How can an SME negotiate exclusions away?
Provide evidence of controls, documented procedures and vendor certifications. Seek endorsements or higher premiums to remove specific exclusions, and request clear sample wording for any change.
Your next step:
- Review the current policy wording and highlight all explicit exclusions and control conditions.
- Compile supporting evidence (backup test logs, MFA rollouts, training records) and store it centrally for claims.
- Consult a regulated insurance broker or solicitor to request endorsements, clarify boundaries with crime/PI policies, and obtain written confirmation of any negotiated changes.