Could a string of minor claims leave a small firm with no cyber cover? Many UK SME owners and directors (1–50 employees) assume minor incidents pose little risk. Some policies aggregate excesses or treat linked events as one claim. Repeated small losses can quickly erode protection.
Why excess aggregation can exhaust SME cover
Excess aggregation decides whether repeated incidents draw from one pot or many. Policy wording and definitions control the outcome.
What aggregation means
Aggregation clause sets the rule for grouping losses. It says when separate events count as one claim.
Aggregation can be time based, cause based or both. Time windows such as 24 or 72 hours often determine grouping.
The most frequent error at this point is to treat "per claim" as always meaning the excess resets for each incident.
Check your policy wording and note the precise aggregation wording.
Which costs draw the limit
Some policies put defence, forensics and notification costs inside the main limit. Those costs then reduce the amount left to pay settlements.
Other policies show those costs as paid outside the limit so the main limit stays for damages and business interruption. Check the exact phrase used.
A red flag is any clause that lacks a clear definition of "defence costs" or that bundles fines and legal costs with first‑party response costs.
Which SMEs are most vulnerable to cumulative claims
SMEs with frequent customer contact or high‑volume data run a higher risk of running down a single aggregate limit. Policy design and business model together decide exposure.
Business types at risk
Retail, accounting, legal and small healthcare providers handle repeated personal data and customer payments. Each small incident can add response and notification expense.
Microclaims such as repeated phishing breaches of low value can add up when each incident needs forensic work, breach coach time and notification letters.
Policy features that raise risk
Policies with narrow per incident definitions, combined defence and response costs, and low aggregate limits increase the chance of exhaustion. These features make the cover fragile.
It works well in theory, but in practice brokers sometimes rely on verbal assurances.
Real examples and numeric scenarios
Numeric scenarios show how several small incidents consume a limit faster than one large loss. Use the figures to model your own exposure.
Three concrete scenarios
Scenario A: Aggregate limit £250,000; defence and notification inside limit. Five incidents each cost £10,000 for response. Add £25,000 shared notification costs. These items draw down £75,000. The remaining limit then pays any business interruption or third‑party claims.
- Scenario B: Limit £150,000 and defence costs outside limit.
- If defence and forensic costs are paid outside the main limit and each microclaim sits at or below the per claim excess, ten £5,000 incidents would not erode the main aggregate capacity.
- If each £5,000 incident exceeds the per claim excess, the same sequence would reduce the aggregate limit. The scenario depends on the interaction between the per incident excess and whether defence costs sit inside or outside the limit.
- Scenario C: Aggressive aggregation wording treats ten £2,500 incidents as one event. Ten response items at £2,500 total £25,000. Add a forensic investigation at £15,000, notification and call centre costs at £10,000 and a modest business interruption estimate at £10,000. The combined exposure reaches £60,000. Stating the component assumptions shows how many small incidents can create a single larger claim when aggregated.
Anonymous case: small accounting firm
An anonymous accounting firm in Leeds reported seven separate phishing incidents over three months. The insurer treated them as a series and aggregated costs.
The firm exhausted a £100,000 limit within five incidents. The outcome meant no cover for a later larger extortion demand.
This is a typical pattern when policies say "series of related acts" without a clear time limit.
Use this table in your review: list incidents by date, root cause, direct cost, defence cost, notification cost, BI cost, aggregated flag, cumulative drawdown and remaining limit. Tracking these columns shows when the aggregate limit will break.
Below is a worked numerical run through that makes aggregate limit exhaustion concrete.
- Assume an SME cyber policy with an aggregate limit of £100,000, per incident excess of £5,000, and defence and forensic costs inside the main limit.
- A first microclaim with response and forensic costs of £8,000 draws down the limit by £3,000 after the insured pays the £5,000 excess. The remaining limit becomes £97,000.
- A second identical microclaim reduces the limit by another £3,000 to £94,000.
- After six such incidents the cumulative drawdown is £18,000 and the remaining limit is £82,000.
- If a shared notification exercise costs £20,000 and is allocated to the aggregated losses, that single shared cost reduces the remaining limit to £62,000.
This shows how microclaims and notification costs, combined with defence costs inside limit, produce cumulative claims risk. They can cause aggregate limit exhaustion far sooner than many SMEs expect.
Modelling per incident cost and aggregate excess in a spreadsheet shows the exact tipping point for an SME.
How aggregation appears in policy wording
The exact clause wording decides the legal result. Minor word differences change whether ten low value losses count as one or many.
Verbatim clause comparisons
| Clause type |
Common wording |
Practical effect |
| Per‑event (narrow) |
"All losses arising from the same event shall be treated as one loss." |
Groups incidents with a clear single trigger. This makes separation easier to argue. |
| Series / cause‑based |
"Series of related acts or omissions shall be one occurrence." |
Allows grouping over time. Many small acts can then form a single large claim. |
| Time window aggregation |
"Acts within 72 hours shall be deemed one occurrence." |
Short windows limit grouping. Long windows expand grouping. |
Dangerous wording flags
Look for words such as "series", "continuing" or "connected" without temporal limits. These are usual traps.
Prefer explicit phrasing: "each claim shall be treated separately" or a clear time window of 24 to 72 hours.
Simple flow: incident to exhaustion
1
Incident occursPhishing, malware, or lost laptop
2
Response costsForensic, breach coach, notification
3
Aggregation checkInsurer applies clause text to group losses
Cumulative drawdown shows remaining limit
Different insurers use subtly different aggregation clauses. Small wording changes can flip outcomes.
Example 1 (time based): "Acts occurring within 72 hours shall be deemed one occurrence." Incidents within the 72 hour window are aggregated automatically.
Example 2 (cause based / series): "Series of related acts or omissions arising out of the same defect in systems shall be considered one occurrence." Repeated phishing emails exploiting the same vulnerability over weeks may be aggregated.
Example 3 (narrow per event): "All losses directly caused by the same identifiable act shall be treated as one loss." This requires a clear single trigger to aggregate.
When interpreting a linked events clause, look for whether the clause is time based, cause based or requires a single identifiable trigger. Each option gives different outcomes for aggregate excess and limit exhaustion in SME cyber policies.
Check your policy wording and document the clause clearly.
How to stop running out of cover
Policy drafting and operational steps can reduce the chance of exhausting cover. Both the insurer and the insured must act before renewal.
Quick policy fixes
Ask for defence costs to be paid outside the main limit and for explicit per claim wording. These changes often cost little more at renewal.
Negotiate clear time windows for aggregation. Ask the underwriter for worked examples showing how multiple events would be treated.
Operational controls to reduce claims
Apply multi‑factor authentication, regular patching and staff phishing training to reduce incident rates. Appoint or outsource a DPO and a breach coach to speed response.
Keep incident logs with dates and root cause notes. Insurers and solicitors use those logs when deciding aggregation.
Broker templates and scripts
Use the checklist and email scripts below verbatim when contacting a broker or insurer.
Broker checklist
- Policy number: [ ]
- Retroactive date: [ ]
- Claims made or occurrence policy: [ ]
- Exact aggregation clause (copy text): [ ]
- Where defence costs sit (inside/outside limit): [ ]
- Notification sublimit: [ ]
- Excess per claim / aggregate excess: [ ]
- Examples requested: ask insurer to show how 3, 5 and 10 small incidents would be treated
Email to broker / insurer
Subject: Urgent: aggregation clause and incident treatment — Policy [insert number]
Dear [Broker name],
Please confirm in writing the exact aggregation clause that applies to Policy [number]. Specifically, provide the clause text and state whether defence, forensic and notification costs are inside the main limit. Also supply worked examples for 3, 5 and 10 small incidents over 30 and 90 days.
Please respond in writing within 7 days so the policyholder can assess exposure.
Regards,
[Director name]
Follow up call script
Ask the underwriter to confirm the clause text line by line. Request a written position to attach to the claim file.
Not relevant when the policy expressly provides separate per claim limits with no aggregation wording, when limits exceed realistic exposure, or when incidents are genuinely unrelated and clearly fall under distinct per claim coverage.
If there is any doubt, request a formal written position from the insurer and attach it to the claim. A written position helps avoid disagreements later and gives evidence if a dispute goes to litigation.
A short, actionable post‑incident plan helps brokers and SMEs preserve cover and model remaining capacity.
- Step 1 (within 24 hours): record incident date and time, root cause, systems affected, direct response costs and the name of any retained forensic firm or breach coach.
- Mark whether the cost is billed or estimated.
- Step 2 (days 1 to 7): calculate per incident net drawdown as: amount recoverable = max(incident_cost - per incident excess, 0).
- If defence and forensic costs sit inside the limit, add them to the aggregate drawdown.
- Step 3 (ongoing): maintain a running cumulative total and remaining limit.
- Log any shared notification or PR costs separately and allocate pro rata when the insurer groups incidents.
- Step 4 (escalation timetable): if cumulative drawdown exceeds 25% of the aggregate limit, notify the broker and request a written underwriter position on aggregation.
- If it exceeds 50%, convene broker, DPO and legal counsel to consider interim mitigation and pre‑emptive negotiation of limit relief.
This plan makes it straightforward to model aggregate excess outcomes, check sublimits and decide whether to suspend risky activity pending insurer clarification.
Frequently asked questions
What does "Excess aggregation" mean in plain terms
Excess aggregation is the rule that decides when multiple incidents count as one claim. The clause groups losses by event, cause or time window and says if the excess applies once or repeatedly. Read the exact wording in the policy to see which test the insurer will use.
Can several small claims really deplete my limit
Yes. If defence, forensic and notification costs sit inside a single aggregate limit, small repeated incidents can use a large share of the limit. Ten microclaims with shared notification costs can equal one medium‑sized claim in combined cost.
How does claims made versus occurrence affect
A claims made policy looks at when the claim is reported to the insurer. An occurrence policy looks at when the event happened. Aggregation rules interact with this distinction and with any retroactive date in the policy.
What practical wording stops aggregation problems?
Prefer clear language: "Each claim will be treated separately" and "Defence costs are paid in addition to the limit." Also seek defined time windows such as 24 or 72 hours if time grouping applies.
How long to wait for the insurer's written reply
Ask for a written reply within 7 days and a substantive position within 14 days. If no timely written position arrives, escalate to the underwriter or ask the broker's compliance team for help.
What to do now
Find the aggregation clause now and copy the exact wording into a single document. Do this within 3 working days so the record exists before further incidents.
Send the checklist and the exact email script to the broker and request a written position within 7 days. If the reply is unclear, escalate to the underwriter or the broker's complaints contact.
Keep an incident log with dates, short cause notes and costs. That log helps when the insurer applies aggregation tests and if the dispute reaches the Civil Procedure Rules or insurers' dispute processes.
References and further reading: the UK Data Protection Act 2018 and the Network and Information Systems Regulations 2018 set notification duties. The Insurance Act 2015 governs duty of disclosure and warranties. For ICO guidance on breach notification timing see ICO.
Who should be involved in the review at the SME?
Involve the director who holds insurance responsibility, the DPO or external privacy advisor, the broker and any retained breach coach. Legal counsel or a solicitor may be needed if aggregation disputes arise.