For firms with 1–5 staff, cyber insurance value often depends on the excess. A £500 excess may not help with a £1,000 bill, but it can help when scams, ransomware or outages cost £5,000 or more.
For a UK microbusiness, cover can be worthwhile when an incident costs more than the annual premium and excess.
A 10-minute test for cyber cover value
Cyber cover has value when you cannot easily fund specialist help after an incident. It can also help with lost trading and client contact.
A quick decision rule
Seek quotations if losing key systems for three days would cause a loss you cannot absorb. Key systems include email, cloud drives, websites and payment systems.
This matters most when you hold customer details or confidential files. It also matters if you hold card-payment data or health information.
Use this short test before comparing the best cyber insurance UK options:
- Data: You store personal or confidential information that may need a data breach response.
- Downtime: You lose sales, billable work or invoicing if systems fail for three to seven days.
- Money movement: You send invoices or change bank details by email, which creates business email compromise risk.
- Cash reserve: You cannot easily fund £2,000 to £10,000 of urgent technical and legal work.
Self-funding can be reasonable when you hold almost no data, take no online payments and can resume work elsewhere within one day.
Even then, you still need cash for IT help, advice, client notices and lost income.
A practical threshold: A £300 to £800 annual premium, plus a £250 to £1,000 excess, may cost less than recovery. This is sensible if a likely recovery bill is £5,000. Prices vary by turnover, trade, data, claims history and policy limit.
A five-day outage can hit tiny firms hard
A five-day outage can hurt a microbusiness because one account often supports the whole firm. Business-interruption wording decides when lost-income cover starts.
A single locked account can stop sales, billing and client contact. Small teams have fewer people who can work around it.
Add the costs people miss
Lost sales are only part of the bill. Include urgent IT time, data recovery, client calls and password resets.
Also include delayed invoices and work that needs doing again. A consultant billing £500 daily loses £1,500 after three lost days.
That loss comes before recovery support costs. A five-person agency may face £3,000 to £12,000 from idle staff and delayed work.
One mailbox can expose several systems
A compromised email account can expose invoices, reset links, customer details and supplier chats. Business email compromise needs separate attention.
Do not assume standard breach cover pays every diverted payment loss. Social engineering fraud and invoice fraud may have lower sub-limits.
The common mistake is treating email theft as only an IT problem. It can also become a payment and client-data problem.
💡
Puede interesarte
A FIDO2 USB security key can reduce password theft risks for email and cloud accounts. It supports multi-factor authentication. Many insurers expect this for administrator and remote-access accounts.
- Helps protect Microsoft 365, Google Workspace and password-manager logins from password-only attacks.
- Gives a physical second check for owners approving payments or holding administrator access.
- Can support stronger multi-factor authentication than text-message codes alone.
Ver opciones en Amazon →
Work out your break-even point in pounds
Your break-even point is reached when an uninsured incident costs more than your premium. Add the excess, required controls and uninsured exclusions.
Use a simple loss calculation
Estimate daily gross profit or billable income. Multiply it by likely downtime.
Then add urgent support, recovery, customer notices and refunds or write-offs. This shows the loss your cash reserve may need to meet.
- Estimate downtime: Allow three to seven working days unless tested recovery proves a shorter period.
- Add fixed response costs: Allow £1,500 to £8,000 for urgent IT, forensics and advice. Complexity affects the final cost.
- Allow for uninsured costs: Include the excess, waiting periods, fraud sub-limits and excluded future income.
Check the waiting period first
A waiting period is the delay before interruption cover starts paying. A 24-, 48- or 72-hour wait can leave short outages uninsured.
For most microbusinesses, buy security controls first, then insure the loss that remains. Cover is good value when one plausible incident exceeds available cash after the excess. It is less useful where a one-day recovery is proven and little data exists. Compare waiting periods and fraud sub-limits before choosing the lowest premium.
A microbusiness loss path
1. Account attack
Phishing or ransomware
2. Immediate cost
IT help and downtime
3. Policy checks
Excess, sub-limit, wait
4. Net result
Paid loss versus self-funded loss
For one-to-five-person firms, prevention and cover address different parts of one risk. A basic security baseline includes multi-factor authentication and managed endpoint protection.
It should also include tested cloud backups and short phishing training. These small business cyber security costs can be £20 to £100 per user monthly.
Owner time is also needed for recovery tests and payment-change checks. Controls reduce both the chance and scale of an incident.
They do not usually pay for forensics, solicitors, notices or lost income. Insurance can pay some of those costs after an attack succeeds.
Treat security spend as the first £500 to £2,000 of risk reduction. Then compare a cyber insurance for small businesses quote with remaining possible losses.
Match cover to your business and data
The right policy limit depends on data, online income and client duties. Staff numbers matter less than those risks.
A sole consultant may need more cover than a five-person shop. Sensitive files and contract terms can raise the required limit.
| Business profile | Likely exposure | Priority cover | Indicative annual premium |
|---|
| Consultant | Email takeover, client files | Response, liability, interruption | £250 to £700 |
| Ecommerce seller | Website, payment and account outage | Outage, extortion, fraud checks | £400 to £1,200 |
| Creative agency | Client access and shared cloud files | Forensics, liability, restoration | £500 to £1,500 |
| Local retailer | Till, booking and supplier email | Interruption, fraud, response | £300 to £900 |
| Legal or health firm | Sensitive personal data | Breach response, liability, advice | £800 to £2,500 |
Consultants need email resilience
Consultants should check for forensics, data recovery and third-party liability. They should also check interruption cover.
This matters when client contracts state a required limit. Check whether the policy gives access to a response service.
Ecommerce needs fraud wording checked
Ecommerce firms should ask about payment-provider outages and marketplace account takeovers. They should also ask about supplier compromise.
Ransomware and fraud wording can have separate limits. A high headline limit may not protect a payment-diversion loss.
Do not let exclusions erase the benefit
The lowest premium can be poor value when the excess is high. Short indemnity periods can also reduce its value.
Exclusions matter most when they affect your main risk. Read the wording for fraud, downtime and security conditions.
Questions that expose weak cover
Ask each insurer or broker these questions in writing:
- What excess applies to ransomware, data recovery and social engineering fraud?
- Does interruption start after 24, 48 or 72 hours, and how long can it pay?
- What sub-limit applies to invoice fraud, payment diversion and supplier impersonation?
- Must we use your incident-response panel before appointing our IT provider?
- Which controls are conditions of cover, including multi-factor authentication and backups?
Controls can affect a claim
A security condition can affect a claim when the policy requires it. Multi-factor authentication and supported software patching are common examples.
Answer proposal questions honestly and keep proof of your controls. Keep backup test records and payment-check procedures where possible.
This may work well in theory, but policy wording decides the claim. A control mentioned in marketing may not be a strict policy condition.
This comparison matters less when your business has few digital systems. It also matters less when you hold no personal or confidential data, take no online payments and can keep trading after losing email or devices. It cannot replace tailored advice when contracts, regulators or professional bodies require stated limits or wording.
Consider three realistic loss paths before choosing a limit. For example, a consultant may lose control of a Microsoft 365 account.
They may face £1,200 for urgent IT support, lose £900 income and spend £600 on client contact.
A £500 excess may still cut the bill if breach response is included. An ecommerce seller may be locked out by ransomware for four days.
That seller could lose £3,000 gross profit and face £2,500 recovery costs. Interruption cover may pay little during the first 24 to 72 hours.
A business email compromise can divert a £7,500 supplier payment. The policy may not pay it fully without express fraud cover.
Social engineering, invoice fraud or funds transfer wording must include it. The relevant sub-limit matters as much as the headline policy limit.
What people ask
Is cyber insurance worth it for a sole trader?
It can be worthwhile when email, cloud files or customer data drive income. Fixed technical and legal costs can reach £1,500 to £8,000 before lost work.
How much does cyber insurance cost in the UK?
A low-risk microbusiness may pay £250 to £700 yearly. Firms with sensitive data or online payments may pay £800 to £2,500.
Compare excesses and fraud sub-limits before choosing the cheaper quote.
Does cyber insurance pay for ransomware?
It may pay for response, recovery and extortion support. Wording and legal checks apply.
Ransom payments can face sanctions, approval rules or exclusions.
Does cyber insurance cover GDPR fines?
Not automatically. A policy may cover defence costs and breach response.
Whether it covers regulatory fines depends on law, facts and policy wording.
What security does an insurer expect?
Many insurers expect multi-factor authentication, patched software and secure backups. They also expect payment-change checks.
Cyber Essentials can give a useful baseline. It does not guarantee every claim.
Does business interruption cover a one-day outage?
Often it does not when the waiting period is 24, 48 or 72 hours. Check the waiting period and indemnity period.
Is invoice fraud included in cyber cover?
Sometimes, but it may have a lower fraud sub-limit. Ask about supplier impersonation and payment diversion.
Should I buy cover or spend more on security?
Do both based on your risk. Spend first on multi-factor authentication, backups, patching and payment checks.
Then insure the remaining loss and specialist response costs.
Buy cover after checking your likely net loss
Cyber insurance can make sense when a likely net loss threatens cash flow. It can also protect client trust and trading ability.
Secure accounts, test backups and check payment changes before comparing policies. Compare policies on like-for-like terms.
Reject quotes where excesses, waits or fraud sub-limits remove your main protection. Seek tailored advice when contracts, regulation or sensitive data need stated limits.
A policy should support your recovery plan, not replace it.