Underinsurance is not just a property or liability problem
The report highlighted by London Business News on Britain’s SME underinsurance challenge points to a broader issue: many small and medium-sized businesses do not fully understand either the risks they face or the limits of the insurance policies they already hold. For UK SMEs, that knowledge gap is especially consequential in cyber insurance.
A business may have public liability, employers’ liability, professional indemnity and contents cover in place, then assume that a cyber incident will be handled somewhere within that portfolio. Often, it will not. Traditional policies can contain narrow cyber exclusions, limited extensions, or no meaningful protection for costs such as ransomware negotiation, forensic investigation, customer notification, data restoration or business interruption caused by a systems outage.
The practical risk is not merely being uninsured. It is being underinsured: having a policy that exists on paper but whose limit, scope, exclusions or incident-response arrangements do not match the business’s actual exposure.
For an SME, the difference matters. A compromised Microsoft 365 account, fraudulent payment instruction, encrypted server, stolen customer database or outage at a key cloud supplier can create several categories of loss at once. The financial impact may include lost sales, professional IT support, legal advice, regulatory reporting, recovery of records, crisis communications and claims from affected clients. A low policy limit or poorly understood exclusion can leave the company funding the gap itself.
Why the cyber knowledge gap persists among UK SMEs
Cyber risk is often mistaken for an IT issue
Many owners see cyber security as a technical matter for an outsourced IT provider, rather than a board-level business-continuity and financial-risk issue. That view can delay a proper insurance decision. The business may purchase antivirus software and cloud backups, but never calculate what a five-day outage would cost in payroll, missed bookings, delayed contracts and lost customer confidence.
Cyber insurance should not replace sensible controls. Insurers increasingly expect controls such as multi-factor authentication (MFA), patching, secure backups and staff phishing training. Yet good controls and insurance serve different purposes. Controls reduce the likelihood and severity of an attack; insurance can help fund specialist response and residual losses when prevention fails.
Standard business packages create false confidence
SMEs frequently buy insurance as a bundle at renewal, concentrating on legally required cover or visible physical assets. That is understandable: a van, workshop or office equipment has an obvious replacement value. Digital dependencies are harder to price.
However, a cyber event can stop a firm trading even when no physical property is damaged. A recruitment agency unable to access candidate records, a retailer locked out of its e-commerce platform, or an accountancy practice whose email has been hijacked may be unable to operate normally. Whether the resulting loss is covered depends on policy wording, triggers, waiting periods, sub-limits and the evidence the business can provide.
Policy language does not always match operational reality
Terms such as “cyber event”, “security failure”, “social engineering”, “computer fraud”, “dependent business interruption” and “privacy liability” can sound similar while providing very different protections. This creates a dangerous gap between what a director believes the policy covers and what it actually pays for.
For example, an employee receiving a convincing email that appears to come from a supplier may alter bank details and send a payment to a criminal account. A cyber policy may cover this only if social engineering or funds-transfer fraud is specifically included, and often only up to a separate sub-limit. Similarly, business interruption cover may require a defined security failure and may not respond in the same way to every third-party software outage.
What underinsurance can look like in a cyber claim
Cyber underinsurance is not limited to a business with no cyber policy. It can arise in several common ways:
- The limit is too low. A £50,000 policy may seem substantial until forensic specialists, legal advisers, notification costs, restoration work and lost income are considered together.
- Key fraud losses are excluded or capped. Invoice redirection, phishing-led payments and payroll diversion require close review of social-engineering and crime cover.
- Business interruption is misunderstood. The policy may contain a waiting period, an indemnity period that is too short, or a definition of “income” that does not reflect the firm’s revenue model.
- Third-party dependencies are overlooked. SMEs rely on payment processors, managed service providers, cloud platforms, e-commerce hosts and software-as-a-service tools. Their outage may be commercially damaging even if the SME’s own systems have not been breached.
- The company has outgrown its original proposal. More staff, higher turnover, international clients, online sales, new data types or a move to cloud-based operations can materially change exposure.
- Incident-response services are absent. A policy’s value is not solely its indemnity limit. Access to a 24/7 breach-response helpline, approved forensic partners and specialist legal support can materially reduce the duration and cost of an incident.
How UK SMEs can assess their cyber insurance needs
Start with a realistic loss scenario
Do not begin with the premium. Begin with an interruption scenario. Ask: what would happen if staff could not access email, accounting systems, customer data or online ordering for three, seven or 14 days?
Estimate the cash impact of lost gross profit or revenue, continuing wages, emergency IT support, contractual penalties and the costs of communicating with customers. Then consider a separate data-breach scenario: how many records are held, what personal or confidential data is involved, and which suppliers or clients must be informed?
The purpose is not to predict an exact claim amount. It is to avoid selecting a limit based on an arbitrary round number or the cheapest quote.
Map the data and suppliers that keep the business running
Create a concise inventory covering:
- Customer, employee and supplier data held by the business.
- Critical systems, including email, finance, CRM, e-commerce and booking platforms.
- External technology providers, managed IT firms and cloud services.
- Payment processes and people authorised to change bank details.
- Contracts that impose security, notification or insurance obligations.
This exercise reveals the exposures that insurance discussions often miss. A company that processes modest volumes of personal data may still face substantial interruption risk if one cloud application is indispensable to daily trading.
Compare wording, not only premium and headline limits
When reviewing cyber insurance, SMEs should ask a broker or insurer direct questions:
- Is ransomware response, including forensic investigation and restoration, covered?
- Does the policy cover privacy liability, legal defence and regulatory investigation costs where insurable?
- What cover applies to social engineering, invoice fraud and funds-transfer fraud?
- Is dependent business interruption included for named or unnamed technology suppliers?
- What are the policy excess, waiting period and relevant sub-limits?
- Does cover include reputational harm, customer notification and credit-monitoring services where appropriate?
- Is there a 24/7 incident-response number, and must the insurer approve suppliers before costs are incurred?
Written answers and the full policy documentation matter. Marketing summaries are useful starting points, not a substitute for the policy schedule, endorsements and exclusions.
Insurance and cyber hygiene must be reviewed together
An effective cyber insurance programme is easier to buy, more likely to respond smoothly and potentially more competitively priced when basic security controls are demonstrably in place. For most SMEs, the immediate priorities should include MFA for email, remote access and privileged accounts; tested offline or immutable backups; prompt patching; removal of unused accounts; least-privilege access; and a rehearsed process for verifying payment-detail changes by telephone using trusted contact details.
Staff training also needs to be practical. Employees should know how to report a suspicious email, a lost device or an accidental data disclosure without fear of blame. Finance teams need a documented two-person verification process for material payments and bank-detail amendments. These controls tackle risks that insurance may exclude, sub-limit or scrutinise closely during a claim.
A practical 30-day action plan for SME owners
- Locate every current policy and renewal date. Identify cyber extensions, crime policies and technology-related endorsements.
- Run one ransomware and one payment-fraud scenario. Estimate operational and financial consequences rather than relying on intuition.
- Ask your broker for a coverage comparison. Focus on exclusions, sub-limits, interruption triggers and third-party outages.
- Confirm your incident contacts. Keep the insurer’s breach helpline, broker details, IT provider and key legal contacts accessible offline.
- Close obvious control gaps. Enable MFA, test backups and introduce out-of-band verification for changes to supplier bank details.
- Review at change points, not only renewal. Reassess cover after major growth, a new online sales channel, acquisition, overseas expansion, a move to a new cloud platform or a significant client contract.
The central lesson from the underinsurance discussion is that insurance literacy is part of resilience. Cyber cover is not a generic add-on to be selected once and forgotten. It is a financial safeguard that must be aligned with the systems, data, suppliers and cash-flow pressures that make an individual SME vulnerable.
FAQ
Does a standard business insurance policy cover cyber attacks?
Not necessarily. Some commercial policies include limited cyber extensions, but these may not cover ransomware, data-breach response, cyber-related business interruption or social-engineering fraud in a meaningful way. Check the wording and limits rather than relying on the policy title.
How much cyber insurance does a UK SME need?
There is no universal figure. The appropriate limit should reflect likely response costs, the cost of a prolonged outage, data volumes, contractual obligations, potential fraud exposure and reliance on third-party technology. A broker can help model scenarios, but the business owner should validate the assumptions.
Will cyber insurance pay for a fraudulent bank transfer?
It may, but this is highly policy-specific. Cover for invoice manipulation, impersonation and authorised payment fraud is often subject to specific definitions, conditions and sub-limits. Review social-engineering and crime cover carefully before a loss occurs.
Can an insurer refuse a cyber claim because MFA was not enabled?
Some policies include security conditions or proposal-form statements relating to MFA, backups and other controls. A failure to meet a stated requirement may affect cover, depending on the wording and circumstances. SMEs should document implemented controls and promptly tell their broker about material changes.
Source: London Business News — Thu, 13 Aug 2026 07:14:38 GMT