Are charities and non-profits unsure how much cyber insurance should cost or whether it is worth the spend? Many small charities lack clear figures, affordable options and a simple checklist to buy cover that actually matches limited budgets. This guide focuses tightly on Cyber insurance for charities and non-profits: cost-effective options, practical ranges, typical limits and exclusions, ways to lower premiums, and a short buying checklist tailored for UK charitable organisations.
Key takeaways: what to know in one minute
- Not every charity needs the same cover. Small volunteer-run groups often need basic data-breach and cyber-extortion limits; those handling payments or health data typically need higher limits.
- Typical costs are modest but variable. Indicative 2026 ranges: small charities often pay £150–£800 pa, mid-size charities £800–£3,500 pa; premiums depend on turnover, staff, data held and security controls.
- Watch the fine print. Many policies have GDPR-related exclusions, limits for contractual liabilities and narrow definitions of business interruption.
- Savings come from controls, not shortcuts. Implementing basic security controls can materially reduce premiums and excesses.
- A short checklist speeds buying. Confirm funds for first-loss, required excess, incident response partnerships and retroactive cover periods before applying.
Who needs cyber insurance in charities and non-profits
Charities and non-profits have widely differing cyber risk profiles. The following categories commonly need some form of cyber insurance or at least a documented risk-financing plan:
- Small charities and community groups that process personal data (donors, volunteers, beneficiaries). Even volunteer-run groups that store spreadsheets with names and contact details face notification costs and reputational effects.
- Organisations taking payments online or in person (donations, ticketing, trading subsidiaries). Payment processing increases exposure to financial fraud and PCI-related liabilities.
- Charities handling sensitive personal data (medical records, safeguarding files, counselling notes). Regulatory penalties and higher remediation costs push these organisations towards higher limits.
- Membership bodies, professional associations and charities offering online platforms (forums, portals) where breaches could expose many individuals.
- Organisations with contractual obligations requiring cover (funders, local authorities, schools). Some grants or contracts explicitly request cyber cover or minimum limits.
Not all charities must buy the largest policies available. Many small groups can manage residual risk by combining modest insurance with practical controls and incident-response planning. For regulatory context, see the Information Commissioner's guidance on data breach reporting: ICO: Report a breach, and basic charity cyber advice at the NCSC: NCSC: cyber security for charities.
Typical cover, limits and GDPR exclusions to expect
Charity cyber policies commonly bundle several core elements, but wording varies widely. Typical sections include:
- First-party data breach costs: forensic investigation, notification, credit monitoring, PR and legal expenses.
- Cyber extortion / ransomware payments: response costs, negotiation fees and sometimes the ransom itself (subject to insurer conditions).
- Business interruption: income loss and extra expense while systems are restored; often linked to specific systems or revenue streams.
- Third-party liability: claims from individuals or organisations for data loss, privacy breaches or failure to safeguard data.
- Regulatory defence and fines: legal defence costs for regulatory investigations. Note: statutory fines for GDPR are commonly excluded or limited—many policies cover regulatory defence costs but not the fine itself.
Common limits and typical ranges (indicative at time of writing):
- Small charity starter policy: £50,000–£250,000 aggregate limit.
- Mid-range charity policy: £250,000–£1,000,000 aggregate limit.
- Higher-risk organisations (clinical records, payment processing): £1m+ available but at higher premium.
Typical excesses and retention:
- Structured excess: £250–£1,000 for first-party claims, rising to £2,500–£10,000 for larger claims or ransomware.
- Percentage excesses: some policies apply a percentage of claim for business interruption (e.g. 5% of loss) rather than flat excess.
GDPR and regulatory exclusions to expect:
- Fines and penalties: Many UK policies explicitly exclude statutory fines or restrict cover to defence costs only. This is a frequent gap that charities should check closely.
- Deliberate acts by trustees or management: intentional breaches or dishonest acts are usually excluded.
- Bodily injury and property damage: Cyber policies often exclude or limit physical damage claims (rarely relevant to charities, but important for trading activities).
To understand how this affects a charity’s exposure, consult the ICO guidance and review policy wording for definitions of a "personal data breach" and covered defence costs: ICO resources.

Real-cost breakdown: premiums, excesses and hidden fees
Providing clear, indicative numbers helps charities set realistic budgets. These figures are examples only and indicative at time of writing (2026).
- Micro charity (turnover < £50k, volunteer-run, simple data): premium £150–£500 pa, excess £250–£1,000.
- Small charity (turnover £50k–£250k, some staff, payment acceptance): premium £400–£1,200 pa, excess £500–£2,500.
- Medium charity (turnover £250k–£2m, sensitive data or online services): premium £1,000–£4,000 pa, excess £1,000–£5,000.
- Higher-risk (clinical services, large payment volumes): premium £4,000+ pa and higher excesses; bespoke underwriting likely.
Hidden or variable costs to budget for:
- Policy administration fees: some brokers or insurers add a mid-term adjustment fee or new-business admin charge (£25–£150 typical).
- Claims handling excesses: some insurers charge separate expenses or apply claim-handling fees above the headline excess.
- Retroactive cover and prior acts: policies with a limited retroactive date can leave gaps; backdating or covering prior acts may increase premium.
- Premium tax and broker fees: Insurance Premium Tax (IPT) applies; broker fees may be added on top of the insurer premium.
Example cost breakdown (illustrative):
| Item |
Micro charity |
Small charity |
Medium charity |
| Annual premium (indicative) |
£200 |
£900 |
£2,500 |
| Typical excess |
£500 |
£1,000 |
£2,500 |
| Incident response limit |
£25,000 |
£75,000 |
£250,000 |
| Hidden fees (example) |
£25 admin |
£60 broker fee |
£150 broker fee |
Notes on the numbers above: these are indicative ranges to aid budget planning. Underwriting factors (number of records, technical controls, incident history) commonly push a quote to the higher end. Many insurers also apply rating factors for payment handling, fundraising events and high-profile beneficiaries.
Comparing insurers: policy wording, incident response and claims
Price comparisons alone are insufficient. Focus on three practical comparison axes when evaluating quotes for charities and non-profits:
- Policy wording and definitions
- Review the definition of a "data breach" and "event". Some wordings limit cover to unauthorised access, excluding accidental internal disclosure.
- Check what counts as a covered cost: are legal defence and regulatory fines included, or is only investigation covered?
-
Confirm retroactive date, run-off cover and whether prior incidents are excluded.
-
Incident response and panel providers
- Many insurers require use of their incident response panel for full cover; others allow choice of provider subject to approval.
-
Evaluate speed of access to forensic teams, legal advisers and PR support. Quick forensic containment can materially reduce loss.
-
Claims experience and service
- Ask for insurer or broker references from other charities. Claims settlement speed and willingness to fund negotiated ransoms (if covered) matter.
- Check whether the policy offers an advance on costs or immediate emergency support.
Useful comparison checklist items:
- Does the insurer cover legal defence costs for ICO investigations? If yes, are fines covered?
- Are ransom payments covered and under what conditions (e.g. authorisation protocols)?
- Is business interruption calculated by actual donations lost, traded income or gross profit?
- Does the policy include breach notification and credit monitoring costs for affected individuals?
For impartial guidance on cyber security expectations and incident planning, charities can use the NCSC small charity resources: NCSC charity guidance.
When cover won’t help: ransomware, reputational and exclusions
Insurance transfers some financial risk but does not eliminate operational disruption or reputational harm. Situations where insurance may be limited in benefit include:
- Widespread ransomware where systems are not backed up. If backups are inadequate, the technical recovery time and beneficiary impact may far exceed policy business interruption limits.
- Reputational damage without quantifiable loss. Many reputational harms (loss of trust, long-term donor reduction) are hard to quantify and may sit outside standard indemnity periods.
- Claims caused by deliberate trustee action or wilful non-compliance. Policies often exclude dishonest or wilful acts by senior management.
- Regulatory fines for systemic data protection failures. As noted, fines are frequently excluded; legal defence costs may be covered but fines themselves rarely are.
Practical implications:
- Insurance works best as part of a layered approach: prevention, response planning and insurance. Relying solely on cover for ransomware response without tested backups and response plans is likely to leave gaps.
- Review exclusions carefully. A policy that appears inexpensive but excludes key elements (GDPR fines, ransomware payment cover, or business interruption for fundraising) may provide limited value when most needed.
Quick checklist to choose cost-effective cyber cover
Quick checklist: essential questions to ask before buying
- What is the policy limit and is it appropriate for the data and income at risk? Match limits to potential notification, legal and restoration costs, not just to premium affordability.
- Does the policy cover GDPR-related defence costs, and are fines excluded? If fines are excluded, estimate the separate financial exposure and mitigation options.
- What is the excess for first-party and third-party claims? Ensure the charity can meet the excess and short-term cashflow needs during a claim.
- Are incident response services included (forensic, legal, PR)? If the insurer mandates panel providers, confirm response times and contact procedures.
- Are there requirements for security controls to qualify for best rates? Identify any mandatory measures (2FA, patching, cyber training) and implement them before renewal to reduce premium.
- Is business interruption calculated on a realistic basis for this charity? Check whether donations and fundraising income are included, and for how long.
- Is retroactive cover adequate and does run-off apply on trustee changes or winding up? Prior acts exclusions can create gaps.
- What are the broker fees and Insurance Premium Tax applied? Budget total landed cost, not insurer headline premium.
Cost-saving steps and buying flow
Cost-saving steps to a practical cyber policy
1️⃣
Confirm assets
List data types, payment flows and critical systems
2️⃣
Implement basics
Backups, MFA, patching and staff training reduce premiums
3️⃣
Get comparative quotes
Compare wording, incident response and excess, not just price
4️⃣
Negotiate cover
Ask for charity discounts, consider higher excess to lower premium
✅
Buy with plan
Ensure incident plan, contacts and funds to meet excess
Advantages, risks and common mistakes
Benefits / when to apply
- ✅ Budget predictability: Insurance converts potential large remediation costs into a controllable annual expense.
- ✅ Access to experts: Many policies include forensic, legal and PR support that small charities could not otherwise afford immediately.
- ✅ Contract and funder compliance: Demonstrable cover can be a condition of funding or partnership.
Errors to avoid / common risks
- ⚠️ Buying on price alone. Low premiums with narrow wording can leave major gaps at claim time.
- ⚠️ Ignoring policy conditions. Failing to meet required controls (e.g. no MFA) can void cover.
- ⚠️ Underinsuring business interruption. Short indemnity periods or narrow income definitions may not cover recovery time.
Frequently asked questions
What does cyber insurance for charities usually cover?
Most policies cover forensic investigation, notification costs, legal expenses, PR and third-party liability. Limits and exclusions vary; check the wording for GDPR fines and ransomware conditions.
How much should a small charity expect to pay for cyber insurance?
Indicative 2026 ranges for small charities are around £150–£1,200 pa, depending on turnover, data sensitivity and security controls. Exact premiums depend on underwriting.
Will insurance pay for GDPR fines?
Many UK policies cover legal defence costs for regulators but often exclude statutory fines. Review policy wording and rely on legal advice for regulatory exposures.
Can a charity negotiate lower premiums?
Yes. Implementing required controls (MFA, backups, staff training), choosing a higher excess and demonstrating an incident plan can reduce premiums. Brokers may secure charity-specific rates.
Is ransomware always covered by cyber insurance?
Coverage varies. Some policies include cyber extortion cover but may impose strict preconditions (use of insurer-approved negotiators, immediate notification). Coverage for ransom payments is not guaranteed.
How quickly do insurers respond to incidents?
Response times differ. Policies that include panel providers often offer immediate contact lines. Confirm emergency contacts and whether the insurer advances funds for urgent response.
Do trustees have personal liability if the charity is breached?
Trustees may face liability if there is negligent governance. Trustees' indemnity and directors' insurance coverage differ from cyber policies. Seek legal guidance for trustee exposures.
Are there grants to help charities pay for cyber insurance?
Some grant programmes and local authority schemes fund resilience measures, but dedicated grants for insurance premiums are uncommon. Funders may expect resilience planning; check funder guidance.
Next steps
- Review the charity’s data map and identify the highest-value systems and datasets. Use this to select appropriate policy limits.
- Implement basic security controls (MFA, regular backups, patching, staff training) to reduce underwriting risk and access better quotes.
- Get 3 comparative quotes focusing on wording, incident response and total landed cost (premium + fees + IPT). Keep documentation of controls for underwriting.
Legal notice: This guide is informational and not personalised financial, legal or insurance advice. Consult a regulated insurance broker or legal adviser before making purchasing decisions. See official guidance from the ICO and NCSC for regulatory and security context: ICO, NCSC.