Cyber Essentials is a government-backed scheme that certifies basic cyber hygiene. It checks controls such as patching, access control and firewall settings. No — Cyber Essentials does not replace cyber insurance.
Does Cyber Essentials Replace Cyber Insurance?
In the context of deciding whether to buy insurance, the answer is simple and direct. Cyber Essentials lowers common technical risk. It does not provide liability cover, business interruption or broad breach costs.
The factors that decide
In the context of choosing cover, the decision rests on what the business does and what it stores. The single most important criterion is the value and sensitivity of data processed. The second is contractual obligations to clients or public bodies.
If the business processes card payments, holds health or ID data, or serves large organisations, insurance is usually needed.
Key thresholds
- Data types: payment, health, ID or payroll.
- Turnover bands: under £250k, £250k–£2m, over £2m.
- Contracts: public-sector or large clients often demand limits.
Result
Buy tailored cyber insurance unless exposure is low.
Data type and sensitivity
In the context of risk, who you hold data on matters most. Personal data such as health records or ID raises regulatory risk. Cardholder data increases PCI expectations and potential fines. If sensitive data is present, a policy that covers regulatory defence and notification costs is needed.
This page gives clear and practical next steps.
Turnover and cost tolerance
In the context of financial resilience, turnover and cash buffer matter. If the business could not absorb a £20,000 to £100,000 unexpected hit, insurance is sensible. Many SMEs cannot handle extended downtime of 3 to 4 weeks without revenue replacement.
Such a shortfall can bankrupt a small business rapidly.
Contract terms and procurement
In the context of contracts, public-sector and many larger clients insist on insured limits. Often they specify at least £1 million in cyber liability cover. Certification alone rarely meets these clauses. Buyers should check procurement wording carefully.
Online payments and PCI requirements
In the context of payments, PCI DSS obligations differ from Cyber Essentials. Certification does not equal PCI compliance. Payment processors and acquirers commonly require evidence of insurance and traceable incident response plans.
Supply chain exposure
In the context of third parties, a breach at a supplier can cause your losses. Cyber Essentials does not transfer vendor risk. Insurance can cover incident response and claims from upstream failures.
Consider matching your cover to real exposure.
| Criterion |
Cyber Essentials |
Cyber Insurance |
When to choose |
| Primary purpose |
Baseline technical controls check |
Financial transfer for loss, liability and BI |
Both together for best protection |
| Financial limits |
No broad indemnity; IASME add-on caps at £25,000 |
Typical limits £100k to £10m depending on need |
Insurance when potential losses exceed £25k |
| Covers ransomware |
No, only limited IASME conditional cover |
Yes, if included and not excluded |
Insure where ransom or BI risk exists |
| Regulatory fines and defence |
Not covered except narrow IASME items |
Often covers defence costs and fines where insurable |
Choose insurance when handling regulated data |
The table shows Cyber Essentials reduces technical risk. Insurance transfers financial and legal risk. Together they close most SME gaps.
Is Cyber Essentials enough to cover data breach costs?
In the context of breach costs, Cyber Essentials alone is not enough for most SMEs. The IASME £25,000 option exists. It is limited, conditional and subject to strict eligibility rules.
This page lists the evidence insurers and assessors typically expect:
- Date and time when the incident was first noticed.
- System logs or EDR telemetry covering the first 72 hours after detection.
- Evidence of the state of patched systems at breach time, including update logs.
- Copies of ransom notes or extortion communications if applicable.
- A list of impacted records and type of data involved.
- Communications sent to customers and regulators, and drafts of notification letters.
Preserve these items within 24 to 72 hours of discovery. Insurers and assessors value preserved evidence over later reconstructions.
Hidden exclusions if you rely solely on Cyber Essentials
In the context of exclusions, the scheme does not cover many real costs. It excludes ransom payments in practice unless tightly defined. It does not cover third-party liability or long-term reputational damage.
Practical claims-handling detail: insurers often require preserved logs covering the first 72 hours; failure to keep these logs can void insurer assistance.
Do not assume the IASME £25,000 add-on covers ransom, prolonged downtime or regulatory fines. Check the policy wording and evidence list.
Will insurers reduce premiums with Cyber Essentials certification?
In the context of premiums, certification can help but outcomes vary. Some insurers offer small discounts or prefer certified clients at renewal. Many underwriters value other controls like EDR, backups and incident response plans more than simple certification.
Insurers will still price for sector risk, turnover and past loss history. Expect a premium change in the range 0% to 15% depending on the insurer and risk.
When should SMEs combine Cyber Essentials and insurance?
In the context of practical defence, combining both is the pragmatic choice for most SMEs. Cyber Essentials reduces the chance of common, opportunistic attacks. Insurance covers residual and severe risks that certification cannot remove.
Buy Cyber Essentials to win contracts and reduce opportunistic risk. Buy insurance when losses could exceed your cash reserves or when contracts require specific limits.
Match cover to what truly would break you.
IASME claim checklist
In the context of making a claim under the IASME add-on, prepare the following. Failure to provide these items delays or rejects claims.
- Date and time when the incident was first noticed.
- System logs or EDR telemetry covering the first 72 hours after detection.
- Evidence of the state of patched systems at breach time, including update logs.
- Copies of ransom notes or extortion communications if applicable.
- A list of impacted records and type of data involved.
- Communications sent to customers and regulators, and drafts of notification letters.
Follow these steps within 24 to 72 hours of discovery. Insurers and assessors value preserved evidence over later reconstructions.
Real SME claim case studies
In the context of real outcomes, these anonymised examples show when Cyber Essentials alone failed.
Retailer: 12 staff, online orders. Ransom demand £65,000. IASME denied because EDR logs were missing. The retailer spent four weeks restoring systems. Total loss exceeded £80,000.
Accountancy firm: payroll data for 300 clients. Data exfiltration led to regulatory notification. IASME offered limited assistance. Insurance covered defence and regulatory costs, totalling £45,000.
Small manufacturer with limited IT: malware caused three weeks' downtime. The manufacturer had Cyber Essentials but no business interruption cover. Insurers paid the business interruption claim after policy placement, limiting losses.
Errors when choosing based on certification alone
In the context of common mistakes, businesses often assume the IASME add-on is comprehensive. That is incorrect. Another frequent mistake is not preserving logs and evidence immediately after detection. A third mistake is failing to check client procurement wording for specific insured limits.
Errors When Buying Cyber Cover That Cost SMEs
When reviewing Errors When Buying Cyber Cover That Cost SMEs, the most costly mistake is assuming a basic policy will automatically match the realities of a UK SME. In practice, many businesses discover too late that their cover is thin on the areas that matter most after an attack.
Assuming Cyber Essentials certification is enough
Cyber Essentials is a useful security baseline, but it is not insurance. A business can be certified and still suffer ransomware, phishing losses or data restoration costs. One of the biggest Errors When Buying Cyber Cover That Cost SMEs is treating certification as a substitute for proper cover, rather than as one part of a wider risk strategy.
Underinsuring business interruption and incident response
Many SMEs focus on headline limits and overlook the costs that build up fastest after an incident. Business interruption, forensic investigation, legal advice, customer notification and crisis management can all be significant. If these sections are underinsured, the policy may look adequate on paper but fall short when operations are halted.
Choosing on price alone
A low premium can hide restrictive exclusions, high excesses and limited claims support. For SMEs, the difference often comes down to whether the insurer understands cyber events and can respond quickly. When comparing options, check what is excluded, how incident response is handled, and whether the insurer provides practical help as well as financial indemnity.
Frequently asked questions
Is Cyber Essentials the same as cyber insurance?
No. Cyber Essentials is a certification scheme for basic controls. Cyber insurance is a financial product. Insurance indemnifies losses, pays incident response and covers liability.
Do you need Cyber Essentials Plus?
Cyber Essentials Plus involves an assessor testing controls. It gives stronger assurance to clients. It may help some insurers but does not replace insurance.
Is Cyber Essentials any good?
Yes for reducing common, opportunistic attacks. The scheme targets the most exploited misconfigurations. It does not guarantee immunity from targeted or complex attacks.
What is better than Cyber Essentials?
Stronger controls and monitoring offer more protection. Endpoint detection and response, regular backups and a tested incident plan improve outcomes. Those controls also help with insurer requirements.
How much cyber insurance do I need in the UK?
Aim to cover plausible worst-case losses. For many SMEs that range from £100,000 to £1,000,000. Check contract clauses and the likely cost of 2 to 4 weeks outage.
Does Cyber Essentials Replace Cyber Insurance?
No. Certification reduces technical risk but does not provide financial indemnity. Insurance remains the route to transfer financial exposure.
Conclusion and next steps
In the context of action, the decision framework is clear. If the business handles sensitive data, takes payments, or faces contract limits, buy cyber insurance. If exposure is minimal and the business keeps no sensitive records, Cyber Essentials may be sufficient alone.
Practical next steps:
- Get Cyber Essentials as baseline security and to win contracts.
- Map your data and estimate likely breach costs.
- Talk to brokers for quotations with limits that match contract needs and plausible losses.
Cyber Security Breaches Survey 2023
IASME Consortium