Cyber policies with the same headline limit can respond very differently to a ransomware attack, data breach or IT outage. Compare the full contract, not only the premium and limit. Match it to the risks, suppliers and systems your SME relies on.
What UK SMEs must check in policy wording
The contract has three parts: the policy schedule, endorsements and the full wording. Read all three together. The schedule shows what you bought. An endorsement is a written change that can narrow, replace or extend the standard wording.
Choose the quote that clearly covers your systems, data and suppliers. A low premium means little if a key supplier sits outside the definition.
The schedule and endorsements can override the main wording.
The definitions that change the result
A computer system definition says which hardware, software and cloud services count. A narrow definition may cover your network but exclude a managed IT provider. It may also exclude a payment processor or Microsoft 365 tenant.
Think of it like home contents cover. It protects your kitchen but not tools in a separate shed. The exact definition decides whether that shed counts.
The most common mistake is treating a supplier as covered because it is vital. The policy must include that supplier under its own words.
Claims-made cover and past events
Most SME cyber insurance is claims-made. The insurer usually looks at when you first report a claim or circumstance. It does not only look at when the attack began.
A retroactive date is the earliest date for an unknown past event. An event before that date may not be covered. This can matter when malware sat unnoticed for months.
A high overall limit does not promise a high payout. Incident response, ransomware, business interruption, cyber crime and regulatory costs can each have their own limit, excess, waiting period or exclusion.
Choose this wording if its definitions include your cloud services and key suppliers. Avoid it if the schedule leaves those names or services unclear.
Quick matrix: compare limits, clauses and claims
A like-for-like matrix turns long policy PDFs into a clear decision record. Put the exact schedule wording beside a realistic claim. Record what the insurer pays, what you pay, and what must happen first.
Choose the policy with the best result for your highest-impact scenario. Do not choose the policy with the neatest brochure.
A £1m headline limit can still leave a major loss uninsured.
| What to compare | Quote A: enter schedule wording | Quote B: enter schedule wording | Claim effect |
|---|
| Overall limit and policy excess | £[schedule figure] / £[excess] | £[schedule figure] / £[excess] | Shows the maximum insurer payment and your first share. |
| Ransomware and extortion sub-limit | £[sub-limit], ransom included: yes/no | £[sub-limit], ransom included: yes/no | A £1m policy may cap extortion far below £1m. |
| Business interruption | Waiting period [hours], period [months] | Waiting period [hours], period [months] | A 12-hour outage may fail a 24-hour waiting period. |
| Cloud or supplier outage definition | Named supplier / any supplier / excluded | Named supplier / any supplier / excluded | Decides whether outsourced IT failure is covered. |
| Consent and panel providers | Prior consent / panel required | Emergency exception / panel required | Can affect payment for your own lawyer or forensic firm. |
Separate first-party and third-party loss
First-party cyber cover pays your own costs. These can include forensic work, data restoration, notification costs and lost income. Third-party cyber liability cover deals with claims against you.
Those claims can include privacy liability or network security liability. Do not assume strong first-party cover includes a useful third-party limit.
Choose a higher third-party limit if customer data creates your greatest exposure. Avoid relying on bundled cover where that limit is not shown.
A copyable pre-purchase checklist
- Match each endorsement number in the schedule to its full endorsement text.
- Write the overall limit, each sub-limit, each excess and each waiting period into the matrix.
- Test ransomware, misdirected payment, cloud outage and customer-data breach against each definition.
- Check the retroactive date, claim notice deadline and continuous-cover condition.
- Record exclusions for cyber war, sanctions, dishonest acts, known circumstances and uninsurable loss.
- Confirm whether the insurer must approve lawyers, forensic firms, PR support and ransom negotiators before costs arise.
Aggregation and the duty to mitigate
Check the aggregation clause as carefully as the headline limit. It decides whether related events count as one claim or several claims. One phishing campaign may compromise three employee accounts.
The insurer may treat that as one loss. You would then have one policy limit and one cyber insurance excess. Separate claims may instead apply an excess to each customer, payment or incident.
Read the duty to mitigate too. It usually requires reasonable steps after you find an event. Examples include isolating devices, saving evidence and calling approved response support.
Delayed action can reduce what the insurer pays.
This does not mean an SME must solve the incident alone. Avoidable delay or extra loss can affect recovery.
Choose the policy with clear aggregation terms and workable emergency support. Avoid a policy if its excess could apply repeatedly to one attack.
How wording changes ransomware and outage claims
A small wording change can reverse a claim result. Cover depends on the trigger, exclusions and conditions. Test ransomware, supplier outage and data-breach response before buying.
Choose the policy that covers the event you cannot fund yourself. This is more useful than asking which insurer has the best wording overall.
A policy can look strong on paper but fail in practice. It may require a named supplier, prior consent, or 24 hours of lost trading.
Ransomware, fraud and panel conditions
Ransomware and cyber extortion may cover negotiator fees, forensic work and restoration. Some policies also cover a ransom payment. Cyber crime and social engineering fraud are different covers.
They concern money sent after a deceptive email, call or message. A policy can pay one loss and exclude the other.
A common case involves a fake supplier email. The firm sends payment to a criminal account. Extortion cover may not pay because no ransomware event occurred.
Choose this cover if it includes extortion and social engineering fraud. Avoid assuming one section pays both losses.
Supplier outages and excluded events
A dependent business interruption clause can pay lost income after a covered supplier failure. The wording may require a named supplier. It may only cover a security failure.
It may also exclude utility and infrastructure faults. Check your cloud host, managed service provider, payroll platform and card-payment provider. Name them where the policy requires it.
Read each claim in this order
1. Trigger
Did a defined security failure occur?
2. Limits
Which sub-limit and excess apply?
3. Exclusions
Is supplier failure, war or fraud removed?
4. Conditions
Were notice, consent and MFA requirements met?
Choose named supplier cover if your key providers appear in the schedule. Avoid broad assumptions about cloud outage cover.
Exclusions need a wording-by-wording comparison
Compare exclusions by their trigger, not only their heading. A cyber war exclusion may need proof of state attribution. Broader wording may exclude a large hostile cyber operation.
That can apply even when nobody knows who caused it. Infrastructure exclusions can remove loss from public internet, power, telecoms or cloud outages. Managed IT provider cover may only respond to a defined security failure.
Dishonest-acts exclusions may treat employee fraud differently from outside crime. Sanctions clauses can stop payment to a prohibited person or territory. Fines and other uninsurable losses may remain uninsured.
Read the exclusions before trusting the limit.
Map the data-breach response before comparing
A customer-data breach can create several losses at once. Test each stage against the wording. Incident response may pay for forensic work, legal advice, containment and data restoration.
It may also pay for communications support. Each payment remains subject to the limit, exclusions and panel-provider rules. Check notification costs, credit monitoring and privacy liability too.
Check whether defence costs sit inside or outside the overall limit. If a breach stops orders, bookings or online payments, check business interruption cover. Identify the business interruption waiting period.
Do not assume ransomware cover protects a data breach in the same way. Choose the wording that funds the stages your business would need first.
For most SMEs, choose the quote with named supplier cover, clear breach response and a workable waiting period. A cheaper quote can suit firms with few cloud systems and little personal data. If neither quote covers your key supplier or loss type, ask for an endorsement or seek another quote. Record the insurer's answer in writing before buying.
This comparison matters less if your business has no meaningful digital work, confidential data, online payments or IT suppliers. It is not legal, regulatory or insurance advice for a live incident, disputed claim, complex contract or regulated activity. In those cases, notify the insurer promptly and get qualified advice.
Before you bind cover, send your completed matrix to your broker or insurer. Ask them to confirm any unclear supplier, limit, exclusion or consent condition in writing.
Frequently asked questions
The answers apply to typical England-based SMEs. The schedule, endorsements and current wording always decide the claim. Use these questions with your broker or insurer before you bind cover.
Does cyber insurance cover ransomware?
Ransomware may be covered if the wording includes cyber extortion and you meet its conditions. Check the ransom sub-limit, forensic costs, restoration costs, MFA rule and panel negotiator requirement.
Does cyber insurance cover a cloud outage?
A cloud outage is covered only if business interruption and supplier definitions include it. A waiting period of 12 to 24 hours can stop payment for a shorter outage.
Are GDPR fines covered by cyber insurance?
GDPR defence costs are often separate from fines. The ICO can impose up to £17.5 million or 4% of worldwide turnover. A policy only pays fines that are legally insurable and expressly covered.
What is a retroactive date in cyber insurance?
A retroactive date is the earliest date for an unknown past cyber event. If the breach began before that date, cover may fail. This can happen even if discovery occurs during the policy period.
Can I appoint my own incident response firm?
You may appoint your own firm, but many policies need prior insurer consent. Many also require an approved panel firm. Costs before notice can be challenged unless the wording gives a clear emergency exception.
Which policy wording fits your SME?
Choose the wording that best fits your real loss scenario. Do this even if it is not the lowest premium. A cloud-reliant firm should favour supplier definitions, waiting periods and business interruption limits.
A firm holding customer records should favour breach response, privacy liability and legal support. A firm handling payments should check social engineering fraud cover. These risks need separate tests.
The best policy is the one that pays your likely major loss.
Choose the more complete wording when one quote clearly covers your named suppliers and key events. Accept its limits only if you can fund the uninsured part. Avoid the cheaper policy when its exclusions, sub-limits or waiting periods remove the loss that would hurt most.
Choose this wording if it matches your actual systems, data and suppliers. Avoid any wording that leaves your main claim scenario uncertain.