Cost drivers and premiums reflect the loss your business could cause or suffer. They do not reflect turnover alone. Insurers assess your data, system reliance, past incidents, and controls for email and remote access.
What sets your cyber premium and can you lower it?
Your premium starts with baseline risk. This means the cyber loss your business could face before insurers assess security gaps.
Baseline risk starts with your business model
Cloud and SaaS services also affect your risk. SaaS means software you access online, such as Microsoft 365 or booking software.
Ask whether staff can still invoice, serve customers, or check stock records if a hosted platform or IT supplier fails.
This reliance can raise business interruption risk. It means lost income and extra costs after a covered cyber event.
Your trading may depend on one system.
Loadings, discounts and entry requirements
The National Cyber Security Centre recommends MFA, patching, and backups. Its small business guidance explains these basic measures.
Think of these controls as locks, an alarm, and a spare key elsewhere. Each can cut break-in risk or reduce recovery costs.
Missing controls can raise your price or restrict cover. Stronger controls can improve terms, but they do not always create a discount.
Evidence matters as much as intent.
Four separate quote influences:
Baseline risk: sector, turnover, data and IT dependence.
Loadings: missing controls, prior incidents or weak evidence.
Discounts: stronger controls that exceed the insurer’s minimum.
Requirements: controls that must exist before the insurer will offer key cover.
A consultancy and retailer need different cover
A small consultancy often needs strong data and email protection. A retailer usually needs broader fraud, payment, and outage planning.
The same turnover does not mean the same cyber risk. An online retailer may hold far more customer data than a consultancy.
A manufacturer may face larger losses from stopped production. Its main concern may be systems that run machinery or manage suppliers.
Cover should follow your real exposure.
Comparable SME quote scenarios
These examples are illustrative comparisons, not market price promises. Insurers set their own appetite, wording, and rating approach.
This includes syndicates in the Lloyd’s of London market. Each insurer may view the same business differently.
| Illustrative SME | Risk facts | Cover comparison | Likely underwriting focus |
|---|
| £1m consultancy | Limited sensitive data, 15 staff, cloud email | £250k limit, £2,500 excess | MFA, client-data controls, email fraud |
| £1m online retailer | High customer-data volume, online sales | £500k limit, £5,000 excess | Payment fraud, privacy breach, website outage |
| £3m manufacturer | Production systems, supplier reliance | £1m limit, £10,000 excess | Ransomware, recovery time, operational downtime |
Fraud and new technology change the question
A lower premium makes sense only when the policy covers systems, fraud routes, and recovery time your SME relies on.
For many UK SMEs, cyber insurance cost sits in hundreds or low thousands of pounds each year. The same turnover can still produce very different prices.
A £1m consultancy with 15 staff may see quotes between roughly £400 and £1,200. This assumes limited sensitive data, £250,000 cover, £2,500 excess, and proven MFA and backups.
A £1m online retailer may face £800 to £2,500. This applies where it handles high customer-data volumes and buys £500,000 cover.
A £3m manufacturer seeking £1m cover for production disruption can move into several thousand pounds. Production downtime can make its potential loss much larger.
These figures are not price promises.
Sector, claims history, data volume, limit, retention, and control evidence set the final premium. Retention is the amount you must fund before cover starts.
Cheaper cover can leave a costly gap
The true policy cost includes the premium and your retained loss. Retained loss can come from excesses, sub-limits, coinsurance, exclusions, and a short indemnity period.
An excess is the amount your business pays first. An indemnity period is the time during which interruption cover can pay.
A cheap policy can leave major costs uninsured. Check the parts of a claim that sit outside the main limit.
The lowest price may not protect cash flow.
Terms that alter the uninsured amount
A sub-limit is a smaller cap within the overall policy limit. It restricts the amount available for one type of loss.
A £1m policy may set a £50,000 cap for cyber extortion. Similar caps may apply to social engineering or public-relations costs.
For that loss type, £50,000 is the available amount. The full £1m limit does not apply.
Match downtime cover to cash exposure
Compare the policy limit, excess, response costs, and ransomware and fraud sub-limits. Also compare the interruption trigger, indemnity period, retroactive date, and territorial scope.
A retroactive date sets how far back a security failure may have begun. It decides whether the policy can treat that failure as covered.
Choose the excess your business can fund immediately. Then test whether the remaining limit covers investigation, restoration, legal help, notification, and lost trading.
Policy structure can change your retained loss more than a small premium saving. Cyber insurance sub-limits can cap extortion, payment fraud, forensic work, or notification costs.
An exclusion can remove cover for an unpatched system or supplier outage. It can also remove cover for a stated fraud method.
Coinsurance means the business pays an agreed share of a loss. A waiting period delays interruption cover until downtime lasts a stated number of hours.
Read the policy wording closely.
Check if the excess applies once per event or per cover section. Also check whether recovery and incident-response costs reduce the main limit.
Improve insurability before renewal questions arrive
A 30/60/90-day plan gives insurers proof of better controls. It also gives directors a clear order for spending.
Start with controls that insurers often expect. Then test whether staff and suppliers can follow them.
Written policies alone rarely prove much. Insurers usually want evidence that controls work in daily practice.
Small fixes can change eligibility.
Days 1 to 30: close basic entry gaps
Apply MFA to email, remote access, cloud administration, and privileged accounts. MFA asks for more than a password before granting access.
List every administrator account and remove unused access. Ensure supported systems receive patches.
Patches fix known software flaws. Think of them as repairing a broken lock before someone finds it.
Days 31 to 60: show that controls work
Check your outsourced IT and cloud providers. Ask who handles a breach and how quickly they notify you.
Ask whether they can access your backups or administrator accounts. This access can affect how quickly you regain control.
Supplier governance means knowing which third party could create or worsen your loss. A supplier problem can still stop your business.
Know who holds the keys.
Days 61 to 90: test and compare properly
Run a short exercise for a ransomware email or fake supplier invoice. Test who calls the insurer and who approves emergency spending.
Test how you would tell customers about a material outage. A material outage is one that seriously affects normal trading.
Consider new exposures alongside the 30/60/90-day control plan. Email fraud controls and staff training should address AI-written supplier messages and cloned voices.
Use independent checks for changed bank details. A phone call to a known number can stop a false payment.
In addition, EDR on supported endpoints can give stronger evidence than a written policy. EDR is software that spots and contains suspicious activity on devices.
Keep tested immutable data backups and restrict administrator privileges. Immutable backups cannot be changed or deleted easily.
Map cloud and SaaS dependencies and identify critical suppliers. Know where people access or transfer personal data internationally.
Security patching, MFA, and tested recovery reduce the chance of long downtime. They can limit damage from supplier compromise, ransomware, or cloud administrator takeover.
Questions & answers
How much does cyber insurance cost in the UK?
UK cyber insurance prices vary because insurers rate exposure, controls, and policy terms. They do not apply one fixed SME price.
Compare quotes only after matching limits, excesses, and interruption periods. Excesses alone can differ by £2,500 to £10,000.
What factors affect cyber insurance premiums?
Turnover, sector, data held, IT reliance, claims history, suppliers, and security controls affect premiums. Missing MFA or untested backups may create a loading.
Stronger evidence can improve eligibility or policy terms. It may not always lower the price.
Does MFA always lower the premium?
MFA may not lower the price when insurers treat it as a minimum requirement. It can still prevent a decline or a ransomware restriction.
It can also avoid a higher excess. MFA should protect email, remote access, and administrator accounts.
Are GDPR fines covered by cyber insurance?
GDPR defence costs and some insurable regulatory liabilities may be covered. Not every fine is automatically insured.
Check the policy wording, regulator, and any sub-limit before relying on cover. A sub-limit may be far below the main policy limit.
Is a higher excess worth a lower premium?
A higher excess works only if the business can pay it immediately. It must not harm recovery.
Test £2,500, £5,000, and £10,000 cash exposures. Do not judge the choice by the premium saving alone.
Does cyber insurance cover a cloud outage?
Cloud outage cover depends on the wording. It may require a security failure at the named provider.
A general Microsoft 365 or SaaS disruption may be excluded. Check the interruption trigger and supplier definition.
This guidance matters less if your organisation has no meaningful digital systems, personal data, online payments, or IT reliance. That is uncommon for modern SMEs. It cannot set an individual premium or confirm cover. Pricing depends on the insurer, full proposal, and policy wording. Regulated firms, businesses with major international operations, and organisations facing an active incident should seek suitable specialist or legal support.
Build cover around the loss you cannot fund
Start with the event that would strain the business most. This may be a week without sales or a six-week system rebuild.
It may also be a large client-data breach or a fraudulent payment. Match your cover to the loss you could not fund yourself.
A policy should protect the cash crisis, not just meet a buying target.