A ransomware alert can arrive on a Friday afternoon. Your website may be down, and an IT firm may ask for payment upfront. The cheaper quote can then look very different. A £1,000 excess means you fund the first £1,000 of covered costs. Cash pressure can rise if lost trading has a separate waiting period.
Is a higher excess worth it for microbusiness cyber cover? Only if the premium saving exceeds the extra risk you can fund immediately. Compare matching quotes, not price alone. A £1,000 excess may apply to each claim or each cost type. It may also sit beside a business interruption waiting period. Terms, limits and claim rules vary by policy.
When a higher excess can make sense
A higher policy excess is the part of a claim you pay yourself. It can suit a microbusiness with spare cash and a worthwhile premium saving. It is often a poor deal when savings are only £100 to £200 yearly. That is especially true if the excess rises by £750 or £1,000.
A higher excess should never create a cash crisis.
Use the break-even test
Divide the extra excess by the yearly premium saving. The result shows how many claim-free years you need. That is how long lower premiums need to repay one extra excess.
For example, moving from a £250 excess to £1,250 adds £1,000 of risk. A £175 yearly saving takes almost six claim-free years to repay it.
Check cash available on day one
An excess is not a later cost. You may need that cash while email is locked. You may also be restoring files and paying staff.
According to specialist policy guidance, the most common mistake is treating an excess as a paper figure. It is really an emergency bill that may arrive on day one.
Match the excess to your claim pattern
Smaller cyber claims still matter. Forensic work, data recovery, legal advice and customer notices can cost between £1,500 and £10,000. Such costs do not need a headline breach.
A £1,250 excess can leave little insurer payment on a £1,500 claim. The next section shows that cost in simple figures.
Premium savings versus out-of-pocket cost
A lower premium does not always mean a lower total cost. Add premiums across several years. Then add what you would pay in a realistic claim.
The table uses illustrative quotes with equal £100,000 aggregate limits. An aggregate limit is the most an insurer pays across covered claims that year. Real prices and terms vary by trade, turnover, controls and claims history.
| Quote structure | Annual premium | Excess | Your cost on £1,500 claim | Your cost on £10,000 claim |
| Lower excess quote | £620 | £250 | £250 | £250 |
| Higher excess quote | £440 | £1,250 | £1,250 | £1,250 |
| Difference | £180 saved yearly | £1,000 more risk | £1,000 more | £1,000 more |
Consider three realistic loss sizes
A £1,500 phishing incident can be hard to manage under a £1,250 excess. The policy pays very little after the excess. A £10,000 data breach still leaves £1,250 to fund.
A £50,000 ransomware claim may have a separate ransom limit or exclusion. Check this before choosing the lower premium.
The excess decision in three checks
1. Annual saving
Write down the premium difference.
2. Same-day cash
Set aside the higher excess today.
3. Policy wording
Check how often the excess can apply.
Compare matched quotes only
Ask insurers or brokers to match aggregate limits and ransomware limits. Also match incident response, business interruption periods and security rules. Comparing Aviva or Hiscox quotes is fair only when these details match.
Lower excess protects cash before savings build up.
Check what the small business cover actually pays for. A useful policy may include ransomware cover and forensic investigation costs. It may also pay for legal advice, data breach costs and customer notices.
It may cover data restoration and public relations help. It may also cover third-party liability. Third-party liability means someone else claims your firm caused them loss.
Business interruption may cover income lost after a systems outage. It is subject to a waiting period and a stated loss period. Two policies with matching limits can give very different value.
One may fund an incident-response team from the start. Another may limit recovery costs or extortion payments. A low premium is not a saving if it excludes your likely trading loss.
A higher excess suits firms with immediate spare cash and matched cover. The next section explains why one incident may still trigger several excesses.
Why one incident may trigger more than one excess
Do not assume one cyber incident means one excess. The schedule lists your chosen limits and excesses. The schedule and policy wording decide how the insurer counts costs.
The insurer may treat costs as one event. It may instead treat them as separate claims or cover sections.
Ask whether it is per claim or event
An excess per event usually applies once to a connected incident. An excess per claim may apply more than once. This can happen when several customers make separate allegations.
The wording decides the outcome. Ask for an answer in writing before buying.
Check separate cover sections
Some policies set separate excesses for cyber extortion and social engineering fraud. They may also set them for business interruption or third-party liability. This changes the real cost of a claim.
A business interruption waiting period is the time before lost-income cover starts. It often lasts between 12 and 24 hours. It is not a cash excess, but it can cut a payment sharply.
If trading stops for 18 hours, a 24-hour wait may mean no income payment. Other covered costs may still have an excess. This is why a short outage can still hurt.
One connected incident can create several gaps in funding. Next, test whether your cash can cover those gaps in the first hours.
Test cashflow before accepting a high excess
A higher excess works only if you can pay it without disrupting recovery. Annual turnover matters less than cash you can reach quickly. Focus on the first 24 to 72 hours.
The National Cyber Security Centre advises small firms to prepare for incidents. Its advice includes backups and response plans. Read the guidance at the National Cyber Security Centre.
Fast access to cash matters more than annual sales.
Run a same-day liquidity check
List cash in your business account. Add agreed overdraft room and confirmed director funds. Then subtract money already needed for PAYE, VAT, rent and wages.
Also subtract supplier bills and vital software subscriptions. If £800 remains, a £1,000 excess is not affordable today. Next month’s sales may not solve that problem.
Insurance cannot fix a short cash gap. The excess may be due before the insurer pays the claim.
Different firms need different excesses
A self-employed designer may work from one laptop. They may have encrypted backups and few customer records. That firm may accept a higher excess.
An e-commerce retailer in Manchester faces a different risk. Its checkout, fulfilment and support may rely on one website. A short outage can stop daily income.
A common case is an agency holding client passwords and campaign data. Urgent recovery, legal help and notices can raise costs before normal work resumes.
Reduce risk instead of raising excess
Better security can reduce quotes without moving as much cost to you. Multi-factor authentication adds a second proof of identity when you log in. It is like needing both a key and a door code.
Separate backups, quick software updates and tested payment checks also matter. These controls reduce common paths into small firms.
✅
Our recommendation
An encrypted external drive can support offline backups. It helps when an incident blocks cloud file access. It should support, not replace, tested backups and secure cloud storage.
- It keeps a separate copy of key files if ransomware encrypts the main device.
- Encryption helps protect customer data if the drive is lost or stolen.
- You can disconnect backup copies from the business network after each backup.
Check availability →
When comparing policy terms, Peter White’s research-led approach puts security rules before premium cuts. Cyber Essentials or Cyber Essentials Plus may support better controls. Neither replaces reading the insurance wording.
Do not raise the excess yet if you cannot access that cash immediately. Keep it lower if daily online sales fund your business. The same applies if you handle sensitive personal data or had a recent incident. Some policies also impose a fixed excess. First choose suitable limits, ransomware cover, incident response and interruption periods. A high excess cannot fix weak cover.
Request a one-page comparison before accepting a quote. It should show the premium, every excess and the aggregate limit. It should also show limits within the policy, waits, exclusions and security rules.
Ask the broker or insurer to confirm one claim example in writing. Use a phishing incident with several cost types. This reveals how the excess would work.
Security controls affect more than attack risk. They can affect whether an insurer offers a quote. They can also affect the premium and claim conditions.
Insurers often ask about multi-factor authentication for email and remote access. They may ask about endpoint detection, which watches devices for threats. They also ask whether backups are separate and tested.
Staff phishing training and payment checks can also matter. This is vital where fraud changes supplier bank details.
Cyber Essentials can show that basic controls are in place. It does not promise a discount or insurance cover. Read proposal answers and policy conditions carefully.
A required control must stay in place throughout the policy year. If it is not maintained, a claim may face problems.
The right excess also depends on how the firm earns money. A sole trader with limited data may accept more risk. That is more likely with a workable offline backup.
An agency may need fast recovery because it holds client logins. A professional practice may need legal help after confidential data leaks. An online retailer can lose money every hour its systems are down.
Any firm handling personal data should test this carefully. Can it fund the excess and urgent forensic, legal and communication costs? Turnover and aggregate limits alone do not answer that question.
A higher excess is worth considering only after this cash test. The questions below cover the final checks before you choose.
Frequently asked questions
Is a £1,000 cyber insurance excess too high for a small business?
A £1,000 excess is too high if you cannot pay it with three to seven days of essential costs. It can suit a low-risk firm with spare cash. The premium saving should repay the extra £750 to £1,000 within a sensible period.
Does cyber insurance excess apply to every cost?
Cyber insurance excess may apply per event, per claim or per cover section. The policy wording decides this. Check forensic costs, business interruption, extortion and third-party liability in the schedule.
What is a business interruption waiting period?
A waiting period is the first lost-trading period that business interruption cover does not pay. It often lasts between 12 and 24 hours. It can apply alongside a cash excess, reducing payment twice.
How can I compare UK cyber insurance quotes?
Compare quotes only after matching limits, sublimits, excesses, response help, waiting periods and exclusions. Ask each insurer about one phishing incident. Include several types of cost in that example.
The essentials:- A higher excess works only when the premium saving beats the cash risk you can fund today.
- Calculate break-even years instead of judging the yearly premium alone.
- Check whether the excess applies per event, claim or cover section.
- Match limits, ransom limits, waiting periods and exclusions before choosing quotes.
Learn more
Here are some additional resources on this subject: