Updated in July 2026
Factors that determine the cover
The main factors are data access, contract wording and client limits.
Who needs which cover?
If a supplier accesses client networks or holds personal data, first‑party and third‑party cover apply.
If work is purely offline and contains no client data, a professional indemnity policy may suffice.
If a client asks to be named or requests a waiver of subrogation, the supplier needs endorsements.
Identify the exact contract wording before signing.
What clients usually ask
Large firms ask for minimum limits, incident response proof and contractual liability cover.
Procurement often sets limits between £500,000 and £2,000,000 depending on sector and risk.
Ask procurement for exact certificate wording early to avoid delays and failed bids.
How to decide quickly
Decide by checking access, data sensitivity, and the client contract wording.
If any answer is yes, buy both first‑party and third‑party cover before signing.
If unsure, ask the broker to confirm you can be named on the policy or provide the required certificate wording.
Typical contract clauses and templates
Large clients expect clear certificate wording, named insured status and subrogation language.
Provide ready texts that procurement can accept to speed approvals.
Certificate wording sample
Supply this clause for procurement review.
"This is to certify that, subject to the terms, conditions, exclusions and any applicable endorsements of the policy, the cover includes Network Security & Privacy Liability, Regulatory Defence and Penalties (where insurable), and First‑Party Incident Response Costs. The aggregate limit of indemnity is not less than £[LIMIT] for the period stated. The insured is [Your trading name]. Any waiver of subrogation in favour of [Client Name] and any contractual liability extension is subject to insurer endorsement or written confirmation from the insurer and may be subject to underwriting review or additional premium."
A certificate that lacks a waiver or contractual liability wording often fails client checks.
Supplier clause sample
Use this red‑lineable supplier clause in bids.
"The Supplier shall maintain cyber insurance with limits of not less than £[X] each claim and £[Y] aggregate covering privacy breach, network security liability, business interruption and incident response. The Supplier will provide a certificate, policy schedule and insurer contact before commencement. The Supplier will accept a waiver of subrogation in favour of the Client where insurer approval is provided."
Avoid unconditional, unlimited indemnities that shift unsupportable financial risk to the supplier.
Legal requirement: UK insurance and data-protection law can affect how insurers assess disclosure and fines; always present full facts when you notify a claim.
Evidence pack suppliers should prepare
Prepare a single zipped pack to attach to proposals, containing the exact certificate wording and policy schedule.
Include insurer contact, claims history for the last 5 years, Cyber Essentials or pen‑test summary, screenshots of MFA and backups, and an incident reporting contact.
Add a short incident report template and a one‑page controls checklist the client can read in a minute.
1. Policy
Limit, named insured, waiver, aggregate
2. Controls
MFA, backups, patching, Cyber Essentials
3. Evidence
Certificate, schedule, incident plan, contact
Model endorsement wording and practicalities
Insurers usually issue an endorsement or a broker letter to show cover to a client.
Common endorsement text names the subcontractor and may waive subrogation, subject to terms.
Obtaining that wording often triggers an underwriting check and may increase premium.
Get written authorisation from the insurer or broker and keep the signed endorsement with the evidence pack.
First‑party vs third‑party: practical differences
First‑party covers the supplier's recovery costs. Third‑party covers claims from clients or regulators.
What first‑party pays
First‑party pays forensic costs, restoration, ransom negotiation if allowed, business interruption and PR/legal fees.
If files for a client project are encrypted, first‑party cover funds recovery and lost income while systems are restored.
What third‑party pays
Third‑party pays defence costs, settlements and client claims for losses caused by a supplier incident.
If a client sues for lost revenue after a supplier breach, third‑party pays defence and indemnity costs within limits.
Quick comparison table
| Coverage element |
First‑party (supplier) |
Third‑party (clients/third parties) |
| What it pays |
Forensics, restore, BI, ransom negotiation |
Legal defence, damages, settlements |
| Who benefits |
Supplier to resume operations |
Client or third parties claiming loss |
| Common limits |
£50k–£1m for small suppliers |
£250k–£5m for client exposure |
Estimated premiums by profile
Premiums vary by turnover, sector, controls and requested limits.
Premium bands
Micro suppliers with low data exposure often pay £150–£700 per year for basic cover.
Small suppliers with some access or personal data typically pay £700–£2,500 per year for mid limits.
Higher exposure suppliers or those in regulated sectors commonly pay £2,500–£10,000+ per year for higher limits.
What raises premiums
Insurers increase pricing after past claims, access to sensitive data, and client‑required limits over £1m.
Other multipliers include no MFA, no tested backups and requests for waivers or unlimited indemnities.
The data shows most premium changes follow exposure and contractual demands, not marketing claims.
The legal background also matters: the Insurance Act 2015 changed disclosure rules.
Regulatory impact
Under GDPR, a personal data breach that risks individuals must normally be reported to the ICO without undue delay.
Where feasible, report within 72 hours of becoming aware, as the rule states.
The NIS Regulations 2018 cover incidents that affect network and information systems for essential services and digital service providers.
Policies often reference both regimes in contract and insurer guidance.
Not all statutory fines and penalties are insurable in the UK.
Many cyber policies cover regulatory defence costs and, where allowed by law, some regulatory penalties.
Policies often exclude uninsurable fines or limit cover subject to underwriter agreement.
For freelancers and subcontractors, read the policy schedule and the "Regulatory Defence and Penalties" section line by line.
Check whether the insurer covers ICO investigations, legal costs, sublimits for regulatory matters, and whether the policy requires immediate notification.
ICO guidance on data breach reporting
Incident response: step‑by‑step playbook
A short sequence guides a non‑technical supplier from containment to claim submission.
Isolate affected devices and disconnect from client systems to stop spread.
Call the insurer or broker and report that you suspect a cyber incident.
Follow the claims handler's directions.
Preserve evidence by taking screenshots, noting times, and listing affected files and systems.
Capture backup status.
Short term
Engage a forensic provider if the insurer requires it or if data exfiltration is suspected.
Notify the client per contract and prepare a short incident report for procurement and legal.
If personal data is involved, plan ICO notification and notifications to affected subjects if required by the risk assessment.
Claims and recovery
Submit the full claim pack with forensic report, invoices, downtime calculation and logs.
Cooperate with client claims processes and keep one point of contact for all communications.
After closure, review controls, update the evidence pack and test restores to prevent recurrence.
Incident report template
Incident report
Date: [YYYY‑MM‑DD]
Time detected: [HH:MM]
Detected by: [user/system]
Systems affected: [list]
Data types affected: [personal / financial / other]
Action taken: [isolation, backups, vendor engaged]
Backups status: [last successful backup date]
Initial estimate of downtime: [hours/days]
Notified parties: [insurer, client, ICO if applicable]
Next steps: [forensic, restore schedule]
Sample notification email to client
Subject: Incident notification – [Project/Contract ref]
Dear [Client contact],
On [date], the supplier detected a cyber incident affecting [systems].
The supplier isolated the systems and engaged [forensic firm].
The supplier has notified the insurer.
A detailed incident report will follow within 24 hours, and an estimated recovery time will be provided soon.
Kind regards,
[Supplier contact | Role | Phone]
Errors to avoid when contracting
The most frequent error is assuming the client's insurance covers the subcontractor without being named.
Common mistakes
Assuming indemnity flows from the client's policy leaves suppliers uninsured in many cases.
Only holding third‑party cover and not first‑party leaves suppliers unable to fund recovery or meet short payroll costs.
Presenting a generic certificate without the client's wording often delays contract award or causes rejection.
Negotiation tips
Ask procurement for exact certificate wording and accept the insurer's endorsement rather than changing it later.
Negotiate caps on liability and limit waivers of subrogation to situations with insurer consent.
One anonymous case: a web developer subcontracted to a financial firm lost client access after a ransomware attack.
The developer had third‑party cover only and no first‑party cover.
The client withheld payment and the developer paid recovery costs for three weeks, losing two contracts.
This would have worked if the supplier had been named on the client policy, but many corporate policies exclude subcontractors unless named.
If you work completely offline and never handle client data, these rules do not apply. Also, if the client explicitly names you as an insured on their policy, avoid duplicating cover unnecessarily.
Ask a broker to review the client's exact certificate wording and your policy schedule before signing the contract.
A single mismatched clause can cause months of disputes.
Frequently asked questions
Do freelancers need cyber insurance?
Not always by law, but clients commonly require it for contracts.
If handling client systems or personal data, clients expect proof of cover to avoid contract rejection.
How much does cyber insurance cost?
Typical ranges are £150 to £10,000 per year depending on exposure.
Most solo providers fall between £150 and £2,500 per year; regulated sectors pay more for high limits.
What does supplier cyber cover include?
It commonly includes incident response, data restoration, business interruption and liability to third parties.
Policies vary widely on ransomware payments, regulatory fines and contractual liability endorsements, so inspect the wording carefully.
What limits do large firms usually require?
Commonly £500,000 to £2,000,000; regulated sectors may ask for higher limits.
Higher limits raise premiums and may require stronger controls like ISO 27001 or Cyber Essentials Plus.
What evidence proves compliance to procurement?
A tailored evidence pack with certificate wording, policy schedule, insurer contact and controls screenshots usually suffices.
Include a tested incident plan and proof of backups and MFA; procurement often rejects packs missing basic controls documentation.
What to do next
Gather your current policy schedule, certificate and a short controls checklist before bidding for large contracts.
Contact a broker with the client's exact certificate wording and limits to confirm endorsements are possible.
Negotiate reasonable caps on indemnities, get waiver of subrogation agreed with insurer consent, and keep a one‑page evidence pack ready for procurement.
Contact a broker to check your wording before you sign.
Procurement‑friendly evidence pack
Use the evidence pack checklist in this article when preparing materials for procurement.
Will my client's cyber policy cover me?
Rarely by default; the client's insurer must name the subcontractor or confirm cover for suppliers.
Ask procurement for written confirmation and do not assume coverage without an explicit endorsement or naming on the schedule.