A low-priced quote can look reassuring when budgets are tight. Yet it may have a higher excess, lower limits, or less incident support. This matters when systems fail or families need to be notified.
Commercial cover and the Department for Education’s Risk Protection Arrangement are not always like-for-like. Check eligibility, scope, claims handling, and the risk your school still carries.
UK insurers price cyber risk by assessing exposure and recovery strength. They review pupil and staff data, income, systems, claims history, and security controls. Similar enrolment figures can still lead to very different quotes.
The real issue is the protection you would receive after an attack.
Why similar English schools get different cyber quotes
Insurers price the likely cost of disruption, not pupil numbers alone. They ask what could fail, who could be affected, and how long recovery may take.
Does pupil count set the price?
A maintained school, academy, or multi-academy trust may share central IT and one Microsoft 365 tenant. An independent school may also depend on fee income and boarding systems.
An independent nursery may have fewer users. It can still hold payment details, medical information, and safeguarding records. Those records can make a breach serious.
A group with three to five sites is often treated as one connected risk. This applies where accounts or backups are shared.
Shared systems can turn one weak account into a group-wide problem.
Which systems raise downtime exposure?
A 72-hour outage can create costs after systems return. Insurers may consider IT help, data restoration, parent messages, temporary processes, and work needed to rebuild trust in records.
Insurers look closely at systems needed for daily school life. These may include email, registers, payment systems, learning platforms, payroll, and safeguarding records.
A system outage can stop work even when no data has been stolen. Think of it like losing keys to every classroom at once.
The most frequent error is to describe a cloud system as someone else’s risk. Your school may still face disruption when that provider fails.
Do sensitive records and claims matter?
How an underwriter turns school risk into terms
1. Exposure
People, data, income and sites
2. Controls
MFA, backups, EDR and patches
3. Loss scenario
Breach, fraud or system outage
4. Terms
Premium, limit, excess and conditions
Schools and nurseries often buy cyber cover after phishing, email compromise, ransomware, accidental record disclosure, or supplier outages. Policy wording decides what help is available.
A broad policy may fund incident response, IT investigation, legal help, communications advice, notification, and data restoration. It may also cover school data breaches and system outages.
Some policies cover liability claims and interruption-style costs. Check whether these sit within one limit, have sub-limits, or exclude a named supplier.
The details in the wording matter more than the product label.
A practical pricing review starts with pupils, employees, privileged users, sites, and connected suppliers. Insurers then assess data sensitivity, income, cloud reliance, and claims history.
A multi-academy trust can cost more than a similar-sized single school. One shared tenant, helpdesk, or backup system could affect every academy.
Strong controls can improve terms. These include MFA, tested immutable backups, EDR, prompt patching, and network segmentation. They do not create a fixed discount.
This first assessment explains the price difference. The next question is what evidence can support better terms.
Controls that improve terms, not guarantees
Security controls can improve underwriting confidence. No single certificate guarantees a lower premium or automatic cover.
Is Cyber Essentials enough for cover?
Cyber Essentials can support an application. It does not guarantee cover or a set premium discount.
Insurers may still ask about MFA, tested backups, patching, and legacy systems. Certification shows a baseline, not every risk in your environment.
🛒
Recommended product
A FIDO2 USB security key gives senior staff a second sign-in factor. It is separate from a text message. It supports stronger MFA where school systems are compatible.
- It can protect privileged accounts with access to cloud email and user records.
- It reduces reliance on SMS codes, which can face number-transfer fraud.
- It offers authorised staff a physical recovery option when mobile access fails.
View on Amazon →
MFA means multi-factor authentication. It asks for a second proof of identity, much like a bank card and PIN.
What proof will underwriters ask for?
Underwriters commonly ask for proof, not intentions. Prepare reports before you start the proposal form.
Useful evidence includes MFA coverage reports and EDR deployment records. EDR means software that watches devices for signs of attack.
Also keep patching timescales, backup settings, restoration-test results, incident plans, phishing-training records, and managed service provider details. Clear evidence can reduce follow-up questions.
A claim-ready file is more useful than a promise to improve later.
Can one weak site affect a group?
One weak site can affect a group where access, backups, or identities are shared. Insurers may treat the group as one connected exposure.
A common case involves one academy without MFA on administrator accounts. That gap can affect every academy using the same tenant.
This approach can work well in theory, but practice can differ. A central policy may exist while a local site still has old devices or unpatched systems.
Controls help explain your risk. Policy limits and excesses decide how much risk stays with you.
Compare recovery value, not just premium
The cheapest annual premium can leave the largest bill after an attack. Compare the cost of recovery, not only the price shown first.
Which excess applies after ransomware?
An excess is the amount your school pays before the insurer pays. It is like the first part of a repair bill that remains yours.
Check whether one excess applies to every claim. Some policies apply different excesses for ransomware, fraud, or interruption.
A £1,000 excess may suit one school. A £10,000 excess needs cash that can be found quickly during an incident.
The lowest premium can shift more of the first loss back to you.
How long can disruption be paid for?
A waiting period is the time before interruption cover starts. Costs during that period may remain with your school.
An indemnity period is the maximum time that interruption support can continue. Policies may offer three, six, or 12 months.
Choose a period that reflects recovery, not only system repair. Rebuilding records and restoring normal work can take longer.
| Check on each quote | Lower-cost wording may mean | Question to ask |
|---|
| Excess | More retained cost per claim | Does it differ for ransomware or fraud? |
| Incident-response sub-limit | Less forensic or legal support | Are supplier costs inside the overall limit? |
| Waiting period | Early outage costs stay with you | When does interruption cover begin? |
| Indemnity period | Support ends sooner | Is 3, 6 or 12 months realistic? |
| Ransomware and fraud cover | Smaller specialist sub-limits | What conditions apply before payment? |
Is RPA comparable with commercial cover?
The Department for Education’s Risk Protection Arrangement and commercial cover are not automatically like-for-like. Check current terms before you compare prices.
Review eligibility, scope, claims handling, exclusions, service providers, limits, and the risk your school or trust retains. Those details can change the value of cover.
Do not assume the same word means the same cover. A policy’s wording decides what happens when an incident occurs.
This guidance is less relevant where a local authority, landlord, franchisor, parent group, or central trust has arranged binding cyber protection. It is also not a substitute for current policy wording, RPA terms, eligibility rules, or advice from an authorised insurance professional.
A fair comparison needs matched limits and matched scenarios. The next section shows what to prepare before renewal.
Use one evidence pack before renewal
A clear evidence pack gives underwriters a fairer view of risk. It also gives school leaders a stronger basis for comparing terms.
Keep a short file with a current network diagram and MFA report. Include backup restoration records, patching reports, incident logs, supplier lists, and a named incident lead.
Record which data is held in England and which providers process it. State what happens if each critical system fails.
One accurate pack can prevent conflicting answers across forms.
Before signing, check each answer with your IT provider. Do not rely on assumptions.
State whether MFA protects all email, remote-access, and administrator accounts. Confirm whether backups are immutable, separate from live systems, and restoration-tested.
List outsourced IT, payroll, payment, safeguarding, and cloud providers. Also list ransomware, phishing, fraud, data-loss, and near-miss events, even without insurance claims.
Confirm revenue, pupil, and employee figures using the same basis as the accounts. Cyber Essentials helps, but it cannot replace clear answers about old devices or control gaps.
Before requesting terms, review a cyber insurance proposal form checklist and a school cyber incident response plan. These checks can help you compare quotes on the same basis.
Frequently asked questions
What is the average cost of cyber insurance in England?
There is no reliable single average for English schools and nurseries. Controls, systems, limits, excesses, and claims history vary widely.
Compare quotes only where overall limits, ransomware sub-limits, and indemnity periods match. A lower premium may reflect less cover.
Does Cyber Essentials guarantee cyber insurance?
Cyber Essentials does not guarantee cyber insurance or a fixed premium discount. It can support an application, but insurers may still require MFA and tested backups.
They may also ask about patching and legacy systems. The insurer decides its own underwriting terms.
Does nursery liability insurance include cyber cover?
Nursery liability insurance does not automatically include meaningful cyber incident support or data-recovery cover. Check for clear cover for data breach, ransomware, forensic IT work, and parent-payment fraud.
Ask whether those costs have sub-limits. Check whether supplier incidents are included.
How much excess should a school accept?
A school should accept only an excess it can fund promptly without harming recovery. Compare excesses between £1,000 and £10,000 with care.
Each policy can apply excesses differently. Check ransomware, fraud, and interruption claims separately.
The essentials:- Cyber pricing reflects disruption, data, and security evidence, not pupil numbers alone.
- MFA, tested immutable backups, and EDR can support better terms, but never guarantee them.
- Compare excesses, sub-limits, waiting periods, and indemnity periods alongside premium.
- For academies in England, compare commercial cover with current RPA terms, not headline cost.
Further reading
If you want to learn more about this topic, these sources may interest you: