Cyber insurance pays incident response, legal defence and short business interruption costs. It does not replace GDPR compliance or cover ICO fines in most policies.
Quick comparison
The table below compares three common policy tiers and key differences to check before buying. Each row shows likely sublimits, covered costs and common compliance gaps.
| Policy type |
Typical limit |
Common sublimits |
What it pays |
Compliance gaps |
| Entry level |
£50k–£250k |
Ransomware £10k–£50k; BI small |
Forensics, notification, basic BI |
Usually excludes fines; limited supplier cover |
| Mid‑tier |
£250k–£1m |
Ransomware £50k–£200k; BI higher |
Full incident response, PR, BI, legal defence |
Fines usually excluded; better third‑party cover |
| Comprehensive |
£1m–£5m+ |
Ransomware higher, BI tailored |
Extensive BI, supplier failure cover, legal defence |
Some policies still exclude regulatory fines |
What the table shows
Sublimits often sit inside a larger overall limit. Check the specific numbers on the schedule.
A common problem is a high overall limit with a tiny ransomware sublimit. That gap can leave a practice exposed.
Stand back and compare absolute sums, not just percentages.
This helps avoid surprises at claim time.
Quick actionable check
If a ransomware sublimit looks small, treat it as a red flag. Compare that sublimit to realistic ransom scenarios and BI estimates.
Insurers also ask for evidence to approve ransom payments. Keep backup test reports and MFA logs ready.
Visual: cover allocation for a mid‑tier policy
Ransomware control and extortion
Business interruption
Forensics, PR and notification
Third‑party liability and defence
Concrete pricing and limit examples help turn policy language into business choices.
- Entry level with £50k–£250k limits can cost roughly £500–£2,000 per year.
- Mid‑tier £250k–£1m often ranges £2,000–£8,000 per year.
- Comprehensive £1m–£5m+ commonly starts around £8,000 and can exceed £25,000.
A worked example: a £50,000 ransom plus five days' BI at £6,000 per day gives roughly £80,000 first‑party need.
If the ransomware sublimit is £25,000, the policy leaves a large gap.
Similarly, a mid‑tier claim with £60k response costs may still hit a £30k ransomware sublimit. That can change how funds are allocated.
Use such examples to check whether ransom sublimits, BI cover and the deductible match likely losses.
Entry‑level and mid‑tier cyber insurance: when to choose
Entry cover suits very small practices with low turnover and a small IT footprint. It keeps immediate response costs affordable for small incidents.
Entry cover pays for basic forensics, patient notification and short BI periods. It rarely covers long closures or large ICO investigations.
Mid‑tier suits practices with moderate patient volumes and some outsourced IT. It balances cost with limits that fit a typical clinic.
Mid‑tier improves access to incident response teams, legal support and PR. It raises BI and ransomware sublimits.
Advantages
- Entry: lower premium and faster placement for micro‑practices. It gives basic cover for forensics, notification and short BI.
- Mid‑tier: higher BI and ransomware limits and better access to responders and legal advisers.
Limitations to watch
- Both: insurers generally exclude regulatory fines unless an endorsement lists them.
- Both: supplier‑chain failures may need specific wording to be covered.
Who should pick each
- Entry‑level: choose if annual turnover is under £200k and the IT footprint is minimal.
- Mid‑tier: choose if turnover sits around £200k–£1m or the practice uses cloud EPRs or outsourced IT.
Underwriting and renewal evidence
Insurers often require tested, isolated backups and MFA at underwriting and renewal. Many insurers request proof of these controls to bind cover or approve ransom payments.
For mid‑tier, keep DSPT or similar compliance evidence ready at renewal.
Comprehensive cover: when to choose
Comprehensive cover fits multi‑partner practices and those with large patient records. It pays for extended BI, supplier failure and higher legal defence costs.
Premiums rise and underwriting checks get stricter.
Advantages of comprehensive
This cover gives higher sublimits and better third‑party liability protection. It often supports cross‑jurisdiction claims and wider supply‑chain incidents.
Limitations of comprehensive
Insurers still often exclude statutory fines under UK GDPR. Underwriting can require pen testing and ISO 27001 or Cyber Essentials proof.
Who should pick it
Choose comprehensive if turnover exceeds £1m or if many third‑party suppliers are used. Also choose it if patient data volume is high.
Expect higher premiums and more conditions.
Third‑party and supply‑chain exposure requires explicit wording and realistic examples. Contingent BI responds when a named supplier's failure causes loss to the practice.
Supplier failure cover can be a separate sublimit and may need the supplier to be named. Policies can require vendor cooperation, such as access to logs and joint forensics.
Check whether supplier outages are excluded if caused by the supplier's own failures or limitations in its cover. Also check whether policies ask for SOC reports or Cyber Essentials for key vendors.
These details determine whether cyber cover really protects against supply‑chain breaches.
How to choose according to your situation
Decide by mapping likely BI cost, ransom exposure and the ability to show controls. Match likely losses to policy limits and sublimits.
Use the matrix above and the templates below to provide evidence at quote time.
Quick method to size cover
Estimate five days of clinic closure costs. Estimate forensics and legal fees. Estimate notification and PR costs.
Add those figures to set a minimum first‑party limit.
If the sum exceeds the ransomware sublimit, raise the limit or improve backup evidence.
Controls that reduce premium
Insurers reward MFA, tested offline backups, regular patch logs and staff training records. The error most frequent at underwriting is missing documented control evidence.
Templates to use now
Breach notification template (edit and copy):
[Practice letterhead]
Date: [DD/MM/YYYY]
To: Information Commissioner's Office and affected patients
Subject: Personal data breach affecting [number] patients
Dear [name],
This notice confirms an incident on [date] that affected [brief description]. The practice discovered the incident on [date]. The likely data types affected are: [list].
Actions taken: forensic investigation started, affected systems isolated, patients notified, enhanced security measures applied. Contact point: [DPO or Practice Manager contact].
Steps patients can take: [advice], and credit monitoring is offered where appropriate.
Yours faithfully,
[Practice owner / Practice Manager]
Claim evidence pack checklist:
- Incident timeline with timestamps.
- Forensic report and hash values.
- Backup restoration logs showing recoverability.
- Invoices for forensics, PR, legal and lost revenue.
- Staff training records and MFA configuration proof.
What no one tells you about cover vs compliance
Insurance often pays response costs but rarely pays UK GDPR fines. The difference between defence costs and fines matters for healthcare practices.
Some brokers and policies blur that line and owners can face gaps at claim time.
Interaction with regulatory enforcement
Insurance may pay legal representation costs for an ICO investigation but not the fine itself. The ICO can impose monetary penalties under the Data Protection Act 2018.
Evidence and the claims process
This works in theory, but in practice insurers demand clear, contemporaneous control evidence. Missing backup logs or MFA records can reduce payment or cause denial.
A common case
A common case: a GP partner clicks a phishing link. EPR access gets compromised and patient contact details leak.
The insurer paid £32k for response but refused fine coverage because DSPT logs were incomplete. The practice still faced possible ICO action.
A practical cover‑vs‑compliance matrix helps buying choices become clearer. Most policies for healthcare SMEs pay first‑party costs and fund regulatory defence.
Policies typically do not pay statutory penalties, criminal sanctions or losses from wilful misconduct. The practice remains legally responsible for compliance, such as DPIAs and retention records.
When assessing a schedule, read line by line. Confirm whether regulatory defence covers legal costs only, whether ransom payments need insurer consent, and whether sublimits leave the practice exposed.
Actionable synthesis and next steps
Map likely incident costs to policy limits and keep evidence ready at renewal. A short gap analysis now prevents claim denials later.
If ransom or BI exposure exceeds sublimits, upgrade cover or strengthen controls.
Prioritised next steps
- Gather evidence: MFA screenshots, backup test reports, patch logs and DSPT or Cyber Essentials status.
- Run a five‑day BI estimate and compare it with the policy sublimits.
- Speak with a cyber insurance broker who knows healthcare risks.
What to prepare for a broker meeting
Bring DSPT score or Cyber Essentials certificate, a list of core suppliers and recent backup test logs. Also bring estimates of daily turnover loss for clinic closure.
The guidance does not apply to large hospitals, NHS Trusts, or entities outside England. Policies do not cover incidents known before purchase. For binding legal advice on compliance or ongoing incidents consult a solicitor experienced in data protection.
Contact a specialist cyber insurance broker with DSPT and backup reports for a tailored quote before renewal.
Frequently asked questions
How much cyber insurance do I need?
Estimate by adding five days of clinic closure, forensic costs and notification costs. Compare that total with policy limits and check ransomware sublimits.
To calculate, add lost patient revenue, staff wages, supplier penalties and one‑off forensics, PR and legal fees. Many small practices start with £250k–£1m depending on turnover.
How much cyber insurance do I need in the UK?
Start with a BI estimate linked to average weekly turnover and add likely response costs. For many English practices, a sensible bracket sits between £250k and £1m.
Brokers sometimes suggest higher limits where cloud EPRs or many third‑party vendors increase exposure.
Do small businesses need cyber insurance?
Yes. It covers immediate financial and reputational costs after an incident. It must sit alongside compliance measures like UK GDPR, DSPT and good cyber hygiene.
Insurance eases short‑term financial pain but does not remove the legal duty to protect patient data or report breaches to the ICO.
Does cyber insurance cover ransomware?
Often yes for ransom and extortion costs, but subject to sublimits and insurer approval. Policies may require tested offline backups and MFA before paying.
Check whether payments need insurer consent and whether a negotiator is included. Some policies cap ransom payments or exclude them.
What does cyber insurance for healthcare cover?
Typical cover includes incident response, forensic investigation, patient notification, PR, business interruption and third‑party defence. Coverage varies by insurer and policy.
Check sublimits for ransomware, social‑engineering fraud and supplier failure. Also confirm retroactive dates and territorial scope.
How does cyber insurance interact with GDPR?
Insurance commonly pays legal defence and incident response fees, but ICO fines remain the practice's responsibility. Prompt notification and documented controls improve insurer support chances.
Notify the insurer immediately after a suspected breach and keep the DPO, Practice Manager and Caldicott Guardian informed.
Final recommendation and practical checklist
For most English healthcare SMEs, combine mid‑tier cover with strong evidence of controls. Review schedules for sublimits, retroactive dates and supplier cover.
Keep breach and claim templates ready and update them each year.
Checklist before renewal:
- Confirm ransom and BI sublimits match estimated losses.
- Collect MFA screenshots, backup test reports and patch logs.
- Ensure DSPT, Cyber Essentials or ISO evidence is current.
- Ask the broker for explicit wording on fines, supplier failure and retroactivity.
Relevant reading and guidance: ICO guidance on data breaches and notification can clarify legal duties. ICO breach reporting. The NCSC publishes practical incident response guidance for small organisations. NCSC small business guide.
Will cyber insurance cover regulatory fines?
Generally no. Statutory fines under UK GDPR are usually excluded. Policies may pay legal defence costs for ICO investigations but not the fine itself.
If a policy seems to include fines, request specific clause wording and broker confirmation in writing.