Buy both if the budget allows; if not, fix MFA and backups this week.
Cyber insurance vs security services for UK SMEs
Security lowers the chance of an incident. Insurance pays the costs that remain.
Key variables to weigh are the data held, online revenue and contract demands.
Insurers expect baseline controls like MFA, tested backups and documented patching.
Insurance covers first‑party costs such as forensic work, notification and business interruption. Insurance also covers third‑party defence and damages, subject to policy limits.
Security services prevent, find and respond to attacks. Typical services include MDR, endpoint protection and pen tests.
Practical rule: secure the basics first. Then buy cover sized to your residual risk.
Recommended baseline for most SMEs: MFA enabled, nightly encrypted backups with monthly restore tests, patch cadence documented, and an incident contact or retainer.
Short pause for clarity.
Direct, actionable comparison: what insurance covers vs what security services deliver
Insurance moves money risk off the balance sheet. Security cuts the chance and the scale of loss.
Actionable checklist when choosing spend: limits, sub‑limits, required controls and MSSP SLAs.
Typical policy limit bands are £50k, £250k and £1m. Look for ransomware sub‑limits and fines caps.
MDR SLAs often measure time to detect and time to contain. Many MDR services detect in minutes and contain within hours for simple incidents.
SaaS downtime is judged differently by insurers than retail POS downtime. Map your revenue model to BI wording.
Score options by what cost items are paid, what exclusions exist, and how fast a provider contains.
Peter White's experience shows that missing evidence of controls often blocks claims. Keep screenshots and logs ready.
⚠️ Cuándo esto NO es la mejor opción
Not relevant if the business processes no customer or personal data, never transacts online and has negligible cyber exposure. Also skip buying separate cover if a parent company policy already provides comprehensive cyber limits and incident response arrangements.
Which UK SMEs benefit most: online retailers, professional services and SaaS firms
Retail and e‑commerce face large customer databases and payment flows. That makes BI costly for these firms.
SaaS and subscription firms lose customers and face SLA penalties when they go offline. Downtime hits revenue fast.
Professional services hold sensitive client records and face regulatory risk under UK GDPR. That increases third‑party exposure.
Secondary candidates include trades with online invoicing and hospitality that stores booking data. Any SME with supply‑chain links should consider cover.
Decision triggers to buy within weeks include a nearby sector breach, a contract clause, or storing sensitive data for over six months.
| SME type |
Typical exposures |
Immediate action |
Insurance priority |
| Online retailer |
Customer PII, payments, supply disruption |
MFA, backups, payment security |
High |
| SaaS / platform |
Downtime, SLA claims, data loss |
MDR, BDR, SLA mapping |
High |
| Professional services |
Client data, regulatory fines, reputational harm |
Encryption, MFA, contract clauses review |
High |
Pause to breathe and decide.
Real scenarios: ransomware and data breach, and who pays what
Ransomware often follows phishing, then encryption and containment. Forensics then determines whether to restore from backups or to pay a ransom.
Security services detect and contain attacks fast. Backups let firms restore without paying ransoms.
Insurance pays residual costs like forensics, negotiation fees and BI losses within limits. Ransom payments depend on policy wording.
Data breaches mean exfiltration, regulator notification and customer contact. That can trigger third‑party claims.
Security stops exfiltration and preserves evidence for investigators. That helps both response and claims.
Insurance covers notification, credit monitoring and legal defence if the wording allows it.
An anonymised case: a 12‑staff retailer faced POS encryption. MSSP containment cut downtime to 48 hours.
Insurance paid about £18,000 for forensics and notifications, and the MSSP response saved roughly £25,000 in lost sales.
After reviewing public incident reviews and insurer summaries, combining security and cover reduces recovery time and cost. See NCSC guidance for practical controls.
If only one is affordable now: invest in MDR and backup hygiene first. This lowers claim frequency and often reduces premiums when applying for cover.
Prevent
Detect
Respond
Recover
Transfer
MSSP activities cover Prevent→Detect→Respond→Recover. Insurance provides Transfer (financial). Both build resilience.

Step‑by‑step claims process and how to maximise the chance a claim succeeds
Invoke your IR retainer or MSSP immediately to contain and preserve evidence. Time matters for both response and claims.
Preserve logs, backup records and chain of custody. Screenshots and timestamps help establish a clear timeline.
Notify the insurer within the policy timeframe and follow insurer directions. Late notice can jeopardise cover.
Commission a forensic firm, insurer‑approved or pre‑agreed. Secure a forensic report showing cause and remediation.
Collect proof of controls in place at incident time. MFA screenshots, patch records and restore logs are common asks.
Follow ICO reporting steps for UK GDPR while coordinating PR and customer contact. Clear communication cuts reputational harm.
Reviews of small claims show that missing contemporaneous evidence often causes denial. Keep everything well dated and stored.
Short pause to gather documents.
Cost breakdown and hidden policy exclusions to watch
Premiums are only part of the total cost. Total cost also includes excess, sub‑limits and control costs.
Typical SME premium bands in 2026 run from £300–£2,500 pa for basic cover. Price varies by turnover and sector.
MDR retainers for SMEs in 2026 typically range £500–£2,000 per month. Scope drives price.
Insurers base pricing on turnover, incident history and controls. Sector risk also affects cost.
Common exclusions include state‑sponsored attacks, failure to patch and unencrypted data. Watch limits on regulatory fines.
Sample red flag clause: no cover for loss from known unremedied vulnerabilities. That clause shifts risk back to the insured.
Policies may set ransomware sub‑limits or demand an insurer‑approved negotiator. Read the ransom and negotiation wording carefully.
Underwriting questionnaires matter. Inaccurate answers on controls or prior incidents can void cover.
Warning: a low premium that looks attractive may come with low limits, high excess and many exclusions. Always request full sample wording before purchase.
Matrix of policy types and example clauses UK SMEs should expect to see
Basic SME cover (£50k–£250k limits) usually gives first‑party forensic, notification and limited BI. It often has ransomware sub‑limits.
Mid‑market policies (£250k–£1m) add broader third‑party liability and higher BI. They often allow retainer‑friendly IR costs.
Comprehensive policies (>£1m) may offer regulatory fine cover, subject to wording and bespoke controls.
Red flags to watch include failure to patch clauses, ransom consent demands and explicit sub‑limits for ransomware response.
Always request the full policy wording and map clauses to your exposure. Insist on written confirmation of underwriting controls.
Short pause and breathe.
Use a simple tree to decide budget split between security and insurance. Inputs shape the result.
Sectoral rule of thumb for initial budget split: Retail 65% security / 35% insurance. SaaS 55/45. Professional services 60/40.
Step inputs should include employee count, online revenue and volume of personal data. Add recent incidents and current controls.
Action windows: enable MFA within 1 week. Verify backups and seek two insurer quotes within 2–4 weeks.
Onboard MDR or a retainer within 6–12 weeks. That gives time to collect underwriting evidence.
Procurement checklist for cyber insurance:
- Company contact, turnover, employee count, and online revenue split.
- Inventory of personal data and retention periods.
- Evidence of controls: MFA screenshots, backup restore logs, patching cadence.
- List of prior incidents with dates and remediation notes.
- Contracts that demand cyber cover and SLA clauses.
Key questions to ask a broker or insurer:
- Does the policy cover regulatory fines under UK GDPR and with what sub‑limit?
- Are state‑sponsored attacks excluded and how is that defined?
- What ransom payments are covered and what approvals are needed?
- What evidence does the insurer require to support a claim?
- What is the claims notification timeframe and the consequences of late notice?
- Can the insurer provide a sample policy wording and redline endorsements?
Questions to ask MSSPs/MDR providers:
- What is the SLA for detection and containment and how are incidents escalated?
- Is 24/7 monitoring included and what are onboarding costs?
- Can they integrate with existing backups and produce restore reports?
- Do they have SME references and a pre‑agreed IR retainer option?
Mini ROI examples:
-
Example 1, 10‑staff retailer: expected annual loss without controls estimated at £40,000. MDR and encrypted backups cost £9,000 pa and cut incident probability by about 50%.
-
Example 2, 30‑staff accountancy firm: security spend £15,000 pa plus insurance £3,000 pa gives faster ROI by lowering likely fines and defence costs.
Practical shortlist: request two insurer quotes and two MSSP proposals. Compare annual cost and sample policy wording.
CTA: Arrange two broker quotes and one MSSP emergency retainer this week. Provide clear evidence of MFA and backups to speed underwriting.
FAQ
Do small businesses need cyber insurance?
Often yes if customer data, online payments or contractual demands exist. Many UK small firms benefit from cover to handle forensic, notification and liability costs.
Insurance is much less useful without basic security controls. Insurers expect evidence of hygiene and may refuse cover if controls are missing.
What is the 80 20 rule in cyber security?
Focus on the 20% of controls that stop 80% of common attacks. Those controls include MFA, timely patching and encrypted backups with restore tests.
Prioritise these basics before advanced measures. They also help with insurability and lower premiums.
Is cyber insurance mandatory in the UK?
Not universally mandatory but sometimes contractually required. Large clients or certain sectors may demand cover.
Regulated firms face added scrutiny from the FCA and the NIS Regulations may impose duties on essential service operators.
Do small businesses need cybersecurity?
Yes, basic cybersecurity helps resilience and insurability. Insurers commonly require minimum controls.
A lack of basic measures risks claim denial and much higher recovery costs.
How quickly can cover be placed and still be valid for a claim?
Cover can often be placed within days but honesty on underwriting matters. Provide current evidence of controls to avoid problems.
Insurers may add retroactive dates or decline cover for incidents from pre‑existing vulnerabilities. Read the retroactive wording closely.
What documents will a broker ask for during underwriting?
Brokers ask for evidence of controls, incident history and business details. Common asks include MFA screenshots, backup restore logs and patching records.
Also prepare employee count, turnover and details of key third‑party suppliers. Accurate answers speed placement.
Act in the next 72 hours to lower risk and preserve insurability. Fast action keeps options open when buying cover.
Priority checklist for the next 72 hours:
-
Enable MFA across all admin and cloud accounts and save screenshots as evidence.
-
Verify backups and run a restore test; keep logs and timestamps.
-
Inventory personal data and note any contractual cyber insurance requirements.
-
Contact two brokers for sample policy wordings and request premium estimates.
-
Secure an MSSP emergency contact or IR retainer for fast response.
-
Run a basic vulnerability scan and schedule a pen test within 4–8 weeks.
Experience shows cheap policies without clear wording deliver poor outcomes. The common error is assuming insurance replaces security.
If budget is tight, buy the 20% controls first, then a policy that matches residual risk. That approach gives the best chance of lower downtime and smaller bills.
Author: Peter White. Over 12 years helping UK SMEs with cyber insurance choices. Date: 2026-04-07.
Who enforces cyber regulation and fines in the UK?
The Information Commissioner's Office enforces data protection rules. The ICO handles UK GDPR and the Data Protection Act 2018.
The NCSC issues technical guidance and the FCA supervises regulated financial firms on conduct and reporting.
Short closing thought to act now.
I know it is hard to split what insurers will pay versus what security services do. Spend ten minutes on a one‑page checklist listing critical systems, last backup, basic defences and estimated loss.
With that evidence, get two insurance quotes and a technical assessment. Ask insurers about exclusions and incident response and request a remediation price.
This will let an owner decide whether insurance, services or both are the right next step.