A monthly cyber plan can look reassuring. But cybersecurity tools, breach response, and regulated insurance are different protections.
If a client asks for proof of cover, check the policy wording. If ransomware stops your business trading, that wording sets out what you can claim.
It can, but the paperwork decides this. A platform arranging insurance in England may need Financial Conduct Authority authorisation.
It can also work through an authorised firm. The subscription label alone does not prove you have insurance.
Insurance, broker or cyber SaaS?
An insurer carries the financial risk. Its name should appear in the policy schedule.
A broker or marketplace arranges a policy. A SaaS platform gives tools, such as monitoring, password management, or staff training.
Separate the insurer, policy wording and certificate of insurance from every subscription service. Think of this as checking whether a home alarm includes home insurance.
FCA status and insurer evidence
Check the firm's name on the Financial Conduct Authority Register. The policy schedule should name the insurer and policyholder.
It should also show the insurance period and limit. These details help prove what cover exists.
A monthly direct debit proves you paid for a plan. A policy schedule and wording show if it includes regulated insurance. They also show who underwrites it and what it may pay.
A cyber insurance marketplace may combine software, insurance placement, and expert services. These parts are not always covered by one contract.
Platform terms may govern access to SaaS tools. The named insurer issues the insurance policy.
An incident-response provider may work under a separate service agreement. The most frequent mistake here is treating every monthly feature as insured cover.
A broker normally advises or arranges cover for the customer. An insurer accepts the insured risk.
A marketplace may do one role, several roles, or none. Ask which party handles advice, premium collection, claims notices, and complaints.
Keep each contract with the policy schedule.
Monthly payments versus policy terms
Monthly billing can help cash flow. It does not always mean cover lasts only one month.
Check whether payments fund a rolling service or an annual policy. A missed payment may affect services and insurance at different times.
Check the cover period first
Read the start date and end date. Check the renewal process, missed-payment terms, and claim-reporting deadlines.
Do not compare monthly prices alone. Check limits, excesses, annual commitments, and whether insurance is included.
| Check | Monthly platform plan | Annual policy route |
|---|
| Payment | Rolling fee or annual instalments | Lump sum or instalments |
| Limit | Check policy schedule, often £100,000 to £5m | Check policy schedule, often £100,000 to £5m |
| Excess | May be £250 to £5,000 | May be £250 to £5,000 |
| Business interruption | Check waiting period, often 8 to 24 hours | Check waiting period, often 8 to 24 hours |
| Cancellation | May stop services and cover on different dates | Usually governed by policy cancellation terms |
Sort the bundle into four boxes
Ask the provider to put each item into one of four boxes. The boxes are insured loss, prevention service, response service, and paid add-on.
This makes the price easier to judge. It also shows where you may face extra costs.
What your monthly plan may contain
Insured
Ransomware, breach costs
Prevent
MFA checks, training
Respond
Helpline, triage
Extra cost
Forensics, legal work
📦
Available on Amazon
A USB security key can help an SME meet an MFA requirement. Many cyber insurance forms show this requirement. It supports a control, but does not replace checking policy wording.
- It gives key business accounts a physical second sign-in factor.
- It can cut risk from stolen-password account takeovers.
- It gives staff a simple option when mobile sign-in is unsuitable.
Search on Amazon →
The business usually shapes monthly cyber insurance prices. Payment frequency matters less than the risk itself.
Insurers often assess turnover, sector, and records held. They also assess payment processes and reliance on cloud or online sales.
They may check prior incidents, security controls, excesses, and policy limits. These checks help the insurer price the risk.
A small consultancy may use MFA and managed cloud services. It may also hold limited customer data.
That risk differs from an online retailer processing card payments. The retailer may lose trade during a website outage.
Treat platform starting prices as illustrations only. Compare total annual cost, included services, cancellation terms, and available limits.
The payment method is only the first check. The next section links cover to the losses your firm could face.
Match cover to your SME’s real exposure
Buy cover for the loss your business could not absorb. Do not buy only by turnover.
A £1 million limit may sound large. It can shrink quickly after a long outage, legal advice, and customer notices.
Map systems, data and contracts
List customer data, payment systems, and cloud providers. Include outsourced IT and key email accounts.
Check client contracts carefully. Customers may require set liability limits or fast incident notice.
A common situation involves a firm using cloud software. Its contract requires notice within 24 hours, but its policy response route is unclear.
The firm then loses time during an incident. This is why contract duties should sit beside policy duties.
Select limits and control evidence
Compare the main limit with smaller sub-limits. A sub-limit is a smaller cap for one type of cost.
Sub-limits may apply to extortion or payment fraud. Check these caps before relying on the headline limit.
Test cover against a realistic outage. Include lost sales, IT recovery, customer messages, and data restoration.
Your likely outage cost should guide the limit. The next section explains why controls can still decide a claim.
A policy works best when controls, contacts, and evidence are ready. These must exist before an incident.
Having a tool is not always enough. You may need records proving that staff used it.
Keep controls and declarations current
Keep the schedule, wording, insurer contact, and platform support number offline. You may need them when your email is unavailable.
Tell the provider when turnover or data volumes change. Also report changes to payment systems, overseas work, or key suppliers.
- Turn on MFA for email, finance, administrator, and cloud accounts.
- Keep backups apart from the main network and test restoring them.
- Keep an asset list for laptops, servers, cloud systems, and IT suppliers.
- Run short staff training on phishing and payment-change checks.
- Test incident contacts and the response process at least once each year.
Know what may be excluded
Typical restrictions can include known incidents and unsupported software. They can also include missing controls and some social engineering losses.
Policies may exclude contract promises beyond the policy. War-related events may also have limits or exclusions.
A marketplace subscription may not suit an SME with complex overseas work. It may also not suit unusually sensitive data or a past cyber incident. A broker-led placement can suit firms needing bespoke insurer talks. It can present the risk to insurers one by one.
Before relying on ransomware or outage cover, identify what evidence the insurer may request. It may ask for MFA records and backup test results.
It may also ask for patching records and staff-training logs. Asset lists, supplier agreements, and incident timing can matter too.
Policy wording may require an approved breach coach. It may also require a named forensic firm or legal adviser.
This can apply before you spend money or contact affected people. The practical issue is simple: a control without evidence can be hard to prove.
Keep short records and review them after system changes. The remaining questions cover the checks owners ask most often.
What people ask
Is a monthly cyber cover subscription insurance?
A monthly subscription is insurance only if it includes a policy from an insurer. Check the schedule, wording, insurer, limit, and FCA status.
How much does cyber insurance cost in the UK?
Cost depends on turnover, sector, data, controls, and chosen limits. Compare excesses and check if monthly payments fund annual cover.
Does Cyber Essentials guarantee that a claim will be paid?
Cyber Essentials does not guarantee payment of a claim. Policy wording, declarations, and incident facts still decide cover.
What should I do after a cyber incident?
Call the insurer or appointed response number as soon as possible. Keep evidence, isolate devices where safe, and seek legal advice on UK GDPR reporting.
Choose proof of cover, not a promise
The essentials:- Monthly billing does not prove a platform sold you cyber insurance.
- The schedule, wording, insurer, and FCA status establish the regulated insurance arrangement.
- Compare limits, excesses, sub-limits, and outage waiting periods before monthly prices.
- Keep MFA, tested backups, and incident contacts ready, as controls and fast notice can affect a claim.
Ask for the full wording before purchase. Review it when systems, suppliers, or client needs change.
Learn more
Here are some additional resources on this subject: