UK SME underinsurance is not only a buying problem
The Fintech Times reports that Zing365 has linked UK SME underinsurance to a gap in broker knowledge. For small and medium-sized businesses, this should be read as more than a criticism of insurance distribution. It is a practical warning: a policy can look reassuring on a schedule while still failing to match the organisation’s real cyber exposure.
Cyber insurance is particularly vulnerable to this problem because the risk changes faster than many traditional insurance categories. A business may have bought cover when it had five staff, one office and basic cloud storage. Two years later, it may rely on Microsoft 365, outsourced payroll, online payments, a managed service provider, customer databases and several software-as-a-service suppliers. If the policy has not been reviewed with those changes in mind, the limit, extensions and conditions may no longer be appropriate.
Underinsurance does not necessarily mean a firm has no cyber policy. It can mean that the policy limit is too low, ransomware cover is constrained, business interruption is narrowly defined, incident-response costs are capped, or important technology dependencies have not been discussed. For a UK SME, the financial consequence can be the difference between recovering from an incident and facing prolonged disruption, lost customers and a severe cash-flow crisis.
Why cyber insurance is difficult to place well
The cover is technical and the language matters
Cyber policies are not interchangeable. Two policies with the same overall indemnity limit can respond very differently. One may include forensic investigation, breach coaching, legal advice, notification support, public relations and data restoration within the main limit. Another may apply lower sub-limits to one or more of these services.
A broker who treats cyber insurance as a simple add-on to a package policy may miss questions that materially alter the recommendation. Does the business hold special category data? Does it process card payments? Is a critical system hosted by a third party? Can staff work if Microsoft 365, a cloud accounting platform or a warehouse-management system becomes unavailable? Does the firm transfer client money or have contractual obligations to notify customers quickly?
The answers affect both the likely loss scenario and the cover required. This is why specialist knowledge is important: it helps translate operational reality into insurance requirements, rather than merely comparing premiums and headline limits.
SMEs often underestimate the cost of interruption
Many owners imagine a cyber claim as a data-breach notification exercise. Yet operational disruption can be the largest loss. A ransomware attack, compromised administrator account or supplier outage may prevent a company from invoicing, taking orders, dispatching goods, accessing records or paying staff.
The immediate costs are only part of the picture. A realistic claim may include an IT forensic team, emergency system recovery, legal advice on UK GDPR obligations, communications support, extra staff hours, lost gross profit and the expense of operating manually. If a business needs a week or more to restore systems, a £25,000 or £50,000 limit can be exhausted quickly.
A knowledgeable broker should therefore discuss the organisation’s maximum tolerable downtime and its gross-profit exposure, not simply ask whether it would like a cyber policy.
Insurance applications can produce false confidence
Cyber insurance underwriting commonly asks about multi-factor authentication (MFA), backups, patching, endpoint protection, staff training and privileged-access controls. These questions are useful, but they can become a box-ticking exercise if nobody checks what the answers mean in practice.
For example, MFA may be enabled for email but not for remote access, cloud administration or finance systems. Backups may exist but never have been tested for restoration. A business may have an incident response plan, but staff may not know who has authority to disconnect systems, contact the insurer or approve emergency spending.
Inaccurate or overly optimistic answers create two risks: the firm remains easier to compromise, and a claim may become more difficult if the insurer believes material information was misrepresented. SMEs should ensure that IT providers, internal finance teams and senior management all validate application responses before submission or renewal.
What the broker knowledge gap means for SME buyers
The key lesson from Zing365’s reported concern is not that every broker lacks competence. It is that SME owners should be active participants in the placement process. Cyber risk cannot be delegated entirely to a broker, insurer or outsourced IT provider because each sees only part of the business.
A broker understands policy structure and insurer appetite. An IT provider understands systems and controls. Management understands revenue, contractual commitments, reputational priorities and acceptable downtime. Effective cyber insurance emerges when those perspectives are brought together.
This also means price should not be the only comparison point. A cheaper policy may have a high excess, restrictive business-interruption wording, a short indemnity period, limited cover for social engineering or poor access to incident-response specialists. Conversely, a more expensive policy may not be better if it contains exclusions that conflict with the firm’s main exposure. The aim is an intelligible, evidenced decision about residual risk.
A practical cyber insurance review for UK SMEs
1. Map the scenarios that could stop trading
Start with three realistic incidents rather than an abstract list of threats. For example: a compromised Microsoft 365 account leading to fraudulent invoices; ransomware encrypting servers and shared drives; or a critical software provider becoming unavailable after a cyber event.
For each scenario, ask what stops, how long manual workarounds can operate, what revenue is delayed and which customers or regulators need to be contacted. This exercise supplies the information needed to assess a suitable limit and business-interruption period.
2. Ask for a coverage comparison in plain English
Request a written comparison of the proposed policies that identifies:
- the total limit and any sub-limits;
- the excess for each main section;
- first-party incident costs and data restoration;
- cyber business interruption and any waiting period;
- ransomware and extortion response;
- social engineering or funds-transfer fraud cover;
- liability arising from privacy, security or media claims;
- cover for supplier or cloud-service disruption; and
- significant exclusions, warranties and security conditions.
Do not accept a generic product brochure as the full answer. Ask how each policy would respond to the specific scenarios identified in the first step.
3. Test whether the declared controls are real
Before renewal, confirm that MFA is enforced for all high-risk access, backups are segregated and restoration-tested, critical software is patched, and administrator privileges are controlled. Keep evidence where possible. Insurance is not a substitute for cyber resilience; stronger controls can reduce the likelihood and severity of an incident while supporting more accurate underwriting.
4. Create a claims-ready response plan
Keep the insurer’s emergency claims number, broker contact and policy details somewhere accessible if email systems are unavailable. Name internal decision-makers and agree when the business will involve its insurer-approved incident response partners. Acting promptly can preserve evidence, contain an attack and avoid uninsured spending on suppliers who have not been approved under the policy.
The wider implication: cyber cover should be reviewed as the business changes
For UK SMEs, cyber insurance should be reviewed after material operational changes, not only on the annual renewal date. Triggers include adopting a new cloud platform, launching e-commerce, acquiring another business, opening remote access, processing more personal data, signing a major client contract or changing IT providers.
The broker knowledge issue reported by Zing365 highlights a broader market challenge: cyber insurance advice must keep pace with the technology choices of smaller firms. SME owners can protect themselves by asking detailed questions, documenting their exposure and selecting advisers who can explain the policy’s practical response without relying on jargon.
FAQ
What is cyber insurance underinsurance?
Cyber underinsurance occurs when a policy exists but its limit, scope, sub-limits or conditions do not adequately cover the cost of a plausible cyber incident. It may leave a business paying a substantial portion of recovery, interruption or liability costs itself.
How much cyber insurance does a UK SME need?
There is no universal figure. The appropriate limit depends on likely incident-response costs, annual gross profit, reliance on technology, data held, contractual obligations and the length of disruption the business could face. Scenario-based modelling is more useful than selecting a round number based solely on turnover.
Does cyber insurance cover invoice fraud or social engineering?
Sometimes, but not always and often subject to a separate sub-limit and conditions. Invoice manipulation, phishing-led payment fraud and social engineering should be discussed explicitly with the broker rather than assumed to be included in a standard cyber policy.
Can an IT provider arrange adequate cyber insurance for my business?
An IT provider can provide essential evidence about systems and controls, but it may not be authorised or suitably positioned to advise on policy wording and insurance suitability. The strongest approach is collaboration between management, the IT provider and a cyber-capable insurance broker.
Source: The Fintech Times — Fri, 02 Oct 2026 06:00:54 GMT