A visible exclusion may not cost your agency the most. A missing multi-factor authentication requirement can cost more.
If one SaaS account, freelancer login, or director’s device lacks MFA, an insurer may challenge a claim. This can happen after stolen credentials and a client-data breach.
Cyber insurance exclusions are not automatically a dealbreaker for a remote-first UK agency. The key question is whether the excluded event affects a core dependency.
The risk may be reduced, negotiated, or covered elsewhere.
Test exclusions against your real agency risk
Start with the loss, not the policy summary.
An exclusion says the insurer will not pay for a named situation. A policy condition is different.
Think of an exclusion as a locked door. Think of a condition as the key you must keep.
The four-part dealbreaker test
A remote-first agency should treat an exclusion as a dealbreaker only when all four points apply:
- The event is plausible: Your people regularly use the affected system or process.
- The impact is material: The likely loss could threaten cash flow, a key client, or delivery work.
- Controls cannot reduce it: MFA, access reviews, or backups cannot make the loss less likely.
- No other cover exists: An endorsement, meaning an added clause, cannot fill the gap.
Conditions can matter more than exclusions
A large policy limit does not repair an unmet security condition.
A £1 million limit may sound reassuring. It offers little comfort if stated controls were missing.
The most common mistake here is comparing limits before checking conditions. A claim dispute can start with missing evidence of MFA or access control.
For an England-based agency, test each exclusion against your largest plausible incident. Consider lost client data, compromised ad accounts, payment fraud, lost income, and restoration costs. UK GDPR penalties can reach the higher of £17.5 million or 4% of worldwide annual turnover. Whether a fine is insurable depends on the law and policy wording.
The controls worth proving
Evidence is stronger when it shows setup and actual use. An MFA setting alone is weaker than an enforcement report.
Keep an access list and records showing leavers’ accounts were removed. These records help show that controls worked when the incident occurred.
This is the first test. The next section maps remote work to real claim paths.
Map remote work to likely claim events
Remote work changes the path of a loss.
An agency may have no office server. It can still hold client data in email, cloud drives, project tools, and ad platforms.
This spreads risk across people and suppliers. It does not keep risk in one locked room.
BYOD and unmanaged endpoints
BYOD means “bring your own device”. Staff use a personal laptop or phone for work.
A home laptop is not always unsafe. The issue is that the agency may not control encryption, updates, or local client files.
It may also lose control when someone leaves.
A typical claim path is simple. A freelancer enters credentials into a fake Microsoft 365 page.
An attacker reads email and resets an advertising account password. The attacker then spends client budget.
The cyber policy may fund incident response. Unauthorised ad spend, repayment, and professional error may sit under different wording.
Freelancers, leavers and home networks
The problem is often access, not geography.
A contractor in England or overseas needs only one active account. One weak recovery method can create an opening.
A remote-first agency should link each exposure to a control and policy question. This creates a practical cyber risk matrix.
For BYOD, check whether personal devices access client data only through managed apps. Check whether encryption, screen locks, and remote wipe are enforced.
For unmanaged devices, decide whether access is blocked. Another option is browser-only tools with conditional access.
SaaS account security should include phishing-resistant MFA and safe administrator recovery methods. It should also include audit logs and separate accounts.
Freelancer access should use named accounts and least-privilege permissions. It should also include an end date and prompt offboarding.
These steps do not create breach cover by themselves. They reduce the chance that a maintenance clause drives a claim dispute.
A common scenario is simple: a former freelancer keeps mailbox access. A later phishing attack then reaches client contact lists.
Remote controls matter most when policies test them after an incident. The next issue is often MFA wording.
Missing MFA can change a claim outcome
MFA is often the hinge point.
Exclusions, warranties and conditions
Do not assume all restrictive wording works the same way. An exclusion removes a category of loss.
A condition may require a control. A warranty can be a strict promise in some contracts.
A “failure to maintain” clause may test whether stated protections continued. The result depends on the exact wording.
Ask the broker about the remedy for a missed control. Must the insurer show that failure caused the loss?
Or can the breach affect cover more widely? The answer depends on wording and insurance law.
This is where generic reassurance can mislead. Ask for the answer in writing.
⭐
Picked for you
A USB security key can strengthen sign-in protection for email and administrator accounts. It helps where an insurer expects stronger MFA. It is most useful for accounts that reset passwords or release client funds.
- It reduces the risk that a fake sign-in page captures a reusable second factor.
- It gives finance and administrator accounts a physical sign-in check.
- It creates a clear control for an underwriting questionnaire.
View on Amazon →
Keep a claim evidence pack
Keep these records in one accessible place. Give each record an owner and review date.
- MFA enforcement reports for email, cloud storage, finance, and administrator accounts.
- An asset list showing company devices and permitted personal devices.
- MDM and EDR reports for managed endpoints.
- Backup test records, including restoration tests, not only proof that backups exist.
- Joiner and leaver records for employees, agencies, and freelancers.
- Logs showing key account activity, privileged access, and incident actions.
A cyber insurance claim dispute can start before technical investigation ends. This may happen if an agency delays notification.
It may also happen if the agency appoints its own forensic supplier. Deleting useful evidence can also harm a claim.
Most policies require prompt notice of a suspected incident. They may direct you to an insurer-approved response panel.
That panel may provide forensic work, legal advice, public relations, and breach notification. Preserve emails, login records, payment instructions, screenshots, and device details.
Avoid changing systems without advice. Unneeded changes can destroy useful evidence.
The incident lead should record when the agency learned of the event. They should record possible client data exposure and containment steps.
This protects incident response cover. It also creates a clearer record for later questions.
Good MFA evidence can protect a claim. Supplier outages need separate checks, which come next.
SaaS outages rarely mean automatic payment
A supplier outage is not always your insured event.
Business interruption can pay for lost income or extra cost after a covered event. It is not a promise to pay for every outage.
The trigger and waiting period matter.
Check contingent interruption wording
Contingent business interruption can cover a named or qualifying supplier failure. Think of it as a blocked delivery route.
It is not the same as a fire in your own warehouse. The supplier’s event must meet the policy trigger.
For a remote agency, suppliers may include cloud storage and email hosts. They may also include a CRM, managed IT provider, or marketing platform.
Ask whether the supplier needs a cyber incident. Ask whether the schedule must name that supplier.
Check whether broad internet or regional outages are excluded as systemic cyber risk. This wording can decide the claim.
Read sub-limits and time excesses
A sub-limit is a smaller ceiling within the total policy limit. It caps payment for one type of loss.
A £1 million overall limit may include only £25,000 to £100,000 for dependent interruption. The amount depends on the product and selected terms.
| Loss situation | Cover to test | Wording to check |
|---|
| Email provider cyber outage | Contingent business interruption | Supplier trigger, waiting period, sub-limit |
| Client data deleted in SaaS | Data restoration | Backup source, restoration cost ceiling |
| Platform-wide ad outage | Cyber or contract claim | Systemic outage exclusion, client contract |
Supplier cover can be useful, but it has narrow triggers. The next section puts each loss with the right policy.
Put each loss with the right policy
Cyber cover is not a catch-all.
Cyber versus professional indemnity
Cyber insurance can cover incident response, forensic work, legal support, and data restoration. It can also cover breach costs after a covered event.
It may include ransomware, cyber extortion, and business interruption. Limits and exclusions differ between policies.
Professional indemnity insurance responds when your service or advice causes client financial loss. It can also respond when campaign delivery causes that loss.
For example, an agency publishes the wrong price in a client campaign. The client then loses sales.
That may be a professional indemnity claim. No hacker, breach, or system compromise is needed.
Crime and payment deception
Invoice fraud occurs when a criminal changes bank details or persuades someone to approve payment. It resembles a convincing fake instruction on headed paper.
Your team may authorise the payment. The criminal induced that authorisation through deception.
Do not assume cyber insurance pays for it. Ask for crime cover or a social engineering fraud extension.
Then check its sub-limit, call-back rule, and excess. The excess is the insured loss your agency pays itself.
A practical buying checklist
Before accepting terms, send this checklist to the person who owns IT access:
- List every client-data system, ad platform, payment process, and remote administrator account.
- Match each exclusion to a plausible loss. Decide whether to accept, reduce, negotiate, or insure it elsewhere.
- Test MFA, backup restoration, and offboarding on real accounts, including freelancer accounts.
- Check limits against the maximum plausible loss, not only revenue. Many small agencies consider £250,000 to £2 million. Contracts, data volume, and supplier reliance can justify more.
- Request written confirmation on supplier interruption, social engineering fraud, data restoration, and contractual liability.
This framework is less relevant for businesses without third-party data. It is also less relevant for firms that do not rely on digital systems. It does not replace review of policy wording, client contracts, or regulatory advice.
Price should be compared as total risk cost, not annual premium alone. A cheaper policy can leave you paying much of a modest incident.
This can happen with a high excess or low social-engineering sub-limit. A long interruption waiting period can have the same effect.
Insurers often price around turnover and revenue concentration. They also consider client data, prior incidents, contracts, and remote worker controls.
Compare the premium with the excess and each relevant sub-limit. Also compare the cost of meeting MFA requirements.
Better MFA, managed devices, and tested backups may help underwriting. This works only when the insurer confirms those controls match policy terms.
A policy should match how your agency actually works. Use the checklist before you accept or renew cover.
Your questions answered
What does cyber insurance cover for an agency?
Cyber insurance can cover response work, legal support, restoration, and breach costs after a covered cyber event. It may include ransomware, extortion, and interruption, but terms differ.
Check each limit and exclusion before relying on cover.
Can missing MFA invalidate cyber insurance?
Missing MFA can affect a claim when the policy or proposal requires it for relevant accounts. Check whether MFA is required everywhere or only for remote, privileged, and finance users.
Ask the broker for the remedy in writing.
Does cyber insurance cover a SaaS outage?
A SaaS outage is covered only when the policy’s supplier-interruption trigger is met. Check the supplier definition, 8-to-24-hour waiting period, exclusion, and sub-limit.
A general outage does not always qualify.
Is invoice fraud covered by cyber insurance?
Invoice fraud may need crime or social engineering fraud cover, rather than standard cyber cover. Confirm the payment-verification rule and sub-limit before relying on the extension.
A call-back rule may be a condition of payment.
How much cyber insurance does a UK agency need?
A UK agency needs a limit that meets its maximum plausible breach, downtime, and recovery cost. Test limits between £250,000 and £2 million against data, income, restoration, and contracts.
A client contract may require more cover.
Is cyber essentials enough for insurance cover?
Cyber Essentials supports a stronger security baseline, but it does not guarantee claim payment. The insurer’s MFA, backup, patching, and access-control wording still applies.
Check the proposal and policy schedule.
Can professional indemnity replace cyber insurance?
Professional indemnity cannot usually replace cyber insurance after ransomware or a data breach. It covers negligent professional work, while cyber cover addresses technology-driven incident costs.
Some incidents may involve both policies.
- The essentials: An exclusion is a dealbreaker only when it removes cover for a realistic, material, and unmanageable agency loss.
- The essentials: Policy conditions, especially MFA and access controls, can decide a claim before the headline limit matters.
- The essentials: SaaS downtime needs contingent interruption wording, not assumptions based on “business interruption”.
- The essentials: Test cyber, professional indemnity, and crime cover together against data, campaign delivery, and payment workflows.
Related sources
These articles can help you explore the topic in more depth: