Actualizado en March 2026

Could a single data breach saddle an SME with six-figure bills and a damaged reputation? For an owner or director with no internal IT team, the immediate pressures are legal notification duties, urgent forensic work and uncertain insurer response. Report the incident to the insurer now. Preserve evidence and follow insurer instructions. Get written confirmation of any emergency appointments to protect the claim.
Most UK SME cyber policies will cover forensic investigation and legal notification costs up to stated limits. Sub-limits, excesses and exclusions vary a lot. As above, report the incident promptly and preserve evidence; follow your insurer's incident steps. Owners will find cost ranges, worked estimates and a claims checklist in the sections below.
Forensic & notification costs: what standard policies cover
Most standard first-party cyber policies include cover for forensic investigation and notification costs as separate budget lines. This means insurers often pay for a digital forensic analyst to determine scope. They usually pay for customer notifications too within stated limits. Many policies still set specific sub-limits and excesses. Always check policy wording for those numbers before assuming full payment.
Forensic cover usually pays for digital imaging, log analysis, root-cause checks and evidence preservation. It also pays for a formal forensic report. These deliverables form the backbone of any claim. Evidence must show chain of custody. Insurers expect a signed report with methodology and timestamps.
Notification cover typically includes drafting ICO reports and sending messages to affected people. It often covers operating a call centre and postal mailings. Some policies offer credit monitoring. A few bundle PR and legal advice for notifications.
Policies separate this cover from business interruption, legal defence and regulatory fines. Many policies list a specific amount for forensic work and a separate amount for notification work. This can limit a total claim by two separate caps instead of a single global limit.
The ICO expects a breach to be reported within 72 hours where feasible. UK data protection legislation provides the regulatory framework for reporting obligations.
Quick fact: Digital forensics reports are usually required by insurers to support a claim. If no report exists, expect delays or challenge to payment.
Sub-limits, excesses and panel supplier clauses
A policy can have an overall limit and specific sub-limits for forensic and notification costs. A common setup is a large overall limit with smaller sub-limits for each cost type. Example: £1m overall limit with a £50k notification sub-limit. If notification needs exceed that, the business may pay the balance.
Excesses may apply per claim or per incident. An excess of £5,000 means the first £5,000 is the insured's responsibility. Some policies require use of insurer-approved suppliers. Using non-approved vendors can cause reimbursement disputes when prior approval was required.
Approved suppliers and emergency appointments
Many policies list panel firms for forensics and notification services. Panel firms are pre-vetted. If the policy requires panel use, contact the insurer first. Some policies allow immediate emergency action for containment and evidence preservation. Always get written authorisation for emergency vendor appointments.
Not following the insurer's incident procedures is frequently a reason insurers cite when contesting claims; while it is not the only cause of denial, failure to obtain required prior approval, to preserve chain of custody or to document key decisions commonly leads to disputes. Always record dates, times and communications, secure written authorisation for emergency vendor appointments where the policy requires it, and ask your broker to note any insurer exceptions in writing.
Keep insurer procedures logged. Record dates, times and communications. Secure written authorisation for emergency vendor appointments where the policy requires it. Ask the broker to note any insurer exceptions in writing.
While the article explains what forensic and notification cover typically pays for, it omits how much businesses pay for the insurance itself. In the UK SME market premiums vary widely. Underwriters price risk by sector, turnover, data sensitivity and controls. As a broad guide, micro-businesses with minimal personal data might pay a few hundred pounds a year.
Small SMEs with simple exposures commonly pay in the low thousands. Larger or higher-risk firms can pay several thousand to tens of thousands annually.
Underwriting factors that increase premium include special category data, prior breaches or poor security controls. Examples are no MFA, poor patching, many third-party integrations and high record volumes. Buyers should expect quoted premiums to rise sharply when these risk drivers exist. Disclose all material facts when buying cover to avoid mid-claim disputes.
Exceptions and key limits where cover may not apply to forensic or notification work
Cover will not apply if the incident predates the policy. If a breach began before the policy start date, insurers can deny liability. Intentional or fraudulent acts by staff often fall outside cover. Policies also exclude losses from criminal acts by the insured.
Cover may not apply when the insured failed to maintain agreed security controls. For example, if the policy required Multi-Factor Authentication and the business had none, the insurer may refuse payment. This is a frequent dispute in SME claims.
Where another policy has priority, that insurer may take responsibility. Professional indemnity or crime policies can overlap. The precise policy wording decides who pays first.
Warning: If the incident involves no personal data, ICO reporting is not required. Notification costs may still be claimed for customers or third parties, but regulatory action may not apply.
A concrete case where the direct answer does not apply
If an SME discovers staff deliberately exfiltrated data and evidence proves intent, many cyber policies exclude intentional acts. In that case forensic and notification costs may be disallowed. The insured must then rely on other covers or self-fund the response. This shows the quick answer at the top is not universal.
How to claim forensic and notification costs and what to do in the first 72 hours
Report the incident to the insurer or broker now. Do this within any policy notice period. Preserve evidence immediately. Record a tight incident chronology. These steps keep the claims process alive.
0–24 hours: isolate affected systems. Preserve logs and take screenshots. Start an incident log with timestamps and names. Call the insurer to confirm allowed immediate actions and whether a panel vendor must be used.
24–72 hours: request insurer approval for forensic analysts if required. Arrange containment and start a draft ICO notification if personal data is likely involved. Prepare a list of affected records and channels. Track all costs in a single ledger for the claim.
3–14 days: receive a forensic report and agree next steps with the insurer. Decide on customer communication content. Launch call-centre or mailing campaigns if required and authorised.
14–90 days: deliver remediation and reply to any ICO queries. Submit final invoices to the insurer. Keep copies of every invoice, timesheet and email.
Document to gather now: incident chronology, screenshots, system images, command outputs, list of affected records, all communications with staff and suppliers, and a cost ledger with invoices.
Act now.
Claim documentation checklist
Insurers will ask for the policy number and a written notice of claim. They will seek a forensic report with methodology. They will want evidence of chain of custody, a list of affected data and invoices for forensic and notification work. Provide copies of customer communications. Keep a signed statement from any external forensic firm.
When a supplier performed multiple roles, apportion costs clearly. Show timesheets or invoice line items that separate forensic analysis from remediation and communications work.
Initial insurer notification (short):
Subject: Incident notice - [Policy number]
Dear [Insurer/Broker],
This notice reports a suspected cyber incident discovered on [date]. Affected systems appear to include [brief list]. Immediate actions taken: [isolation, log preservation]. Requesting emergency approval to appoint forensic provider [name] or confirmation to use panel provider. Contact: [name, role, phone, email].
Draft ICO notification (core points):
- Nature of the breach and date discovered.
- Categories and approximate number of affected individuals.
- Measures taken so far and planned next steps.
- Contact point for further information.
Affected individuals message (short):
Subject: Important notice about your data
A data security incident affecting [type of data] may have involved your information. The business is investigating and has notified the regulator. Actions to take: [change password, monitor accounts]. Contact: [email/phone]. Support: [credit monitoring if offered].
Press holding line: "A data incident was detected. The issue is contained and under investigation. No further comment until forensic results are available."
Businesses need quick cost bands to check if their policy limits are adequate. These figures are not exact quotes. They are practical ranges to guide decisions.
Forensic investigation cost ranges by incident type
| Incident type |
Typical forensic cost |
Main drivers / deliverables |
| Limited account compromise / phishing |
£1,000–£10,000 |
Log review, credential checks, remediation advice |
| Targeted data exfiltration / moderate breach |
£10,000–£50,000 |
Full imaging, timeline reconstruction, report |
| Ransomware / advanced attack |
£50,000–£250,000+ |
Multi-system analysis, negotiations, extended consultancy |
| Insider theft / contested evidence |
£10,000–£100,000+ |
Forensic & legal co‑work, witness statements |
Timescales vary with complexity and access to logs. Cloud environments with good audit trails usually reduce time and cost. On-prem systems with incomplete logging raise costs.
Notification cost per person and worked examples
Per-contact ranges:
- Email: £0.20–£1 per contact for templated messages.
- Post: £0.50–£3 per contact depending on print and postage.
- Call centre: £5–£25 per contact depending on verification needs.
- Credit monitoring: £5–£25 per person for 12 months.
Worked examples:
- 500 contacts: email £100–£500; post £250–£1,500; call centre £2,500–£12,500.
- 10,000 contacts: email £2,000–£10,000; post £5,000–£30,000; call centre £50,000–£250,000.
Fixed costs such as legal review, ICO reporting prep and a PR statement commonly total £1,000–£10,000.
Estimate check: multiply per-contact cost by volume, then add forensic band and fixed legal/PR expenses to produce a realistic claim total.
Simple insurer comparison
| Insurer |
Forensic sub‑limit (typical) |
Notification sub‑limit (typical) |
Panel supplier clause |
Typical excess band |
| Hiscox (typical SME wording) |
£25k–£100k |
£10k–£50k |
Often yes |
£1k–£10k |
| Aviva (SME products) |
£25k–£150k |
£10k–£100k |
Sometimes |
£2k–£10k |
| Beazley / Lloyd's syndicates |
£50k–£250k |
£25k–£250k |
Often yes |
£2k–£10k |
| AIG / Zurich (SME lines) |
£25k–£200k |
£10k–£150k |
Varies |
£1k–£15k |
These ranges are indicative. Wording differs between insurers and between policies written in different years. Read the policy and ask the broker for specific clauses.
0–24 hrs
Isolate systems. Preserve logs. Call insurer.
24–72 hrs
Authorise forensics. Draft ICO notice. Prepare customer list.
72 hrs+
Finalise reports. Notify customers. Submit invoices to insurer.
The short insurer comparison is helpful but lacks policy-wording distinctions that decide sufficiency. When comparing offers, check whether amounts are stated as sub-limits within the aggregate limit or as 'in addition to' that limit. The financial difference can be decisive. Also check whether notification cover explicitly includes postage, call-centre mobilisation and credit monitoring. Check whether PR and legal fees sit inside the same line or as separate cover. Check whether use of panel suppliers is mandatory or discretionary.
Insist on seeing the exact clause wording. Ask the broker to give policy extracts before purchase.
To make the headline per-contact and forensic bands actionable, here are three worked sector examples that combine typical elements and show how sub-limits bite.
-
Example 1 – small law firm (1,000 affected clients): medium targeted breach
-
forensic £20k, templated email at £0.50 each £500, fixed legal/PR £3k → total ≈ £23,500.
-
Example 2 – GP surgery (10,000 records, sensitive health data): ransomware
-
forensic £75k, email £5k, printed mail £10k, call-centre triage £40k, credit monitoring £20k, legal/PR £10k → total ≈ £160k.
-
Example 3 – regional payments firm (50,000 records, financial data): large exfiltration
-
forensic £150k, email £25k, call-centre £125k, credit monitoring £250k, legal/PR £25k → total ≈ £575k.
These examples show how notification and remediation costs can dwarf forensic bands in high-volume or high-sensitivity sectors. Plug in your own volumes to test whether a quoted notification sub-limit is likely to be enough.
Practical steps to reduce notification and forensic outlays for SMEs
Use simple controls to cut investigation time and cost. Ensure central logging and retain logs for at least 90 days. Implement basic endpoint protection and Multi-Factor Authentication. These measures reduce forensic scope and speed recovery.
Maintain an incident playbook that includes insurer contacts and policy details. Test the playbook once a year. Keep vendor contracts and contact details ready. A tested plan shortens forensic time and lowers invoices.
Where possible, opt for templated notifications and automated email sends. These reduce per-contact and postage costs. Use segmented lists to avoid over-notifying and incurring unnecessary expense.
Comparing self-funded response versus insured notification cover for SME decisions
Self-funding can be faster and give full control. It requires immediate cash. Self-funding suits small, contained incidents where total spend sits below the policy excess.
Using insurer cover gives access to panel experts and financial capacity. It may impose vendor rules and prior approvals. Consider the excess, sub-limits and likely time to authorise invoices. Make a quick cost test. If self-fund cost looks lower than the excess, pay personally.
FAQ
Will an SME cyber policy always pay for a forensic report? Yes, if the incident falls within the policy period and policy terms. The insurer usually requires a professional forensic report showing scope, methods and chain of custody. If the policy requires panel suppliers, the panel report is often mandatory. If the breach predates the policy, insurers may deny payment.
How quickly must the ICO be notified? Notify the ICO within 72 hours where feasible. This follows the 2018 Data Protection Act and UK guidance. If a full assessment is not ready, give an initial report and follow up with details.
What documents prove chain of custody? Use system images, signed transfer logs, timestamps and recorded handling notes. Keep a clear incident chronology and saved communications. Insurers expect an auditable trail.
Can a non-panel forensic firm be used and still get paid? Sometimes, but only with insurer prior approval. If the policy mandates panel use, using an outside firm without approval risks rejection or partial payment. Always seek written permission first.
How much does notification cost for 5,000 contacts? Expect email costs £1,000–£5,000 and printed mail £2,500–£15,000. Call-centre costs vary widely and may add £25k–£125k depending on depth. Add fixed legal/PR fees of £1k–£10k.
What if staff intentionally leaked data? Intentional, dishonest acts by staff are commonly excluded from cyber policies. If intent is proven, many insurers deny forensic and notification costs. The insured then needs other cover or to self-fund the response.
Where can I read official ICO guidance on breach reporting? See ICO reporting guidance. Also consult the UK Government Cyber Security Breaches Survey 2023 for sector context.
Next actions for an SME with a suspected breach
Report to insurer and broker now. Preserve all logs and images. Start a one-line incident chronology with times and names. Ask for written authorisation for any emergency appointments. Collect invoices and timesheets for the claim. Keep calm. Take one clear step at a time.