¿Te worried about choosing the right cyber insurance limits and excesses? Many UK SME owners find policy wording confusing and worry about being underinsured or paying unnecessarily high premiums. This guide explains, in plain British English, how policy limits and deductibles work, how they apply to ransomware and business interruption, whether GDPR fines sit under limits, and how to decide voluntary and compulsory excesses.
Mastering Policy Limits and Deductibles Guide will help decision-makers: estimate appropriate sums insured, compare per-claim and aggregate limits, and use a simple checklist to set limits that reflect turnover, data exposure and operational risk. All figures are indicative and current at time of writing.
Key takeaways: what to know in 1 minute
- Policy limit = maximum insurer payout. Choose limits that cover likely worst-case costs (ransom, recovery, PI, BI).
- Excess (or deductible) reduces small claims. A higher voluntary excess can lower premium but increases the owner’s out-of-pocket exposure.
- Ransomware and business interruption often exhaust limits quickly. Consider separate BI sublimits and extended indemnity periods.
- GDPR fines may be excluded or subject to sublimits. Many insurers offer defence costs for ICO investigations but fines are often excluded, check wording.
- Per-claim vs aggregate matters for repeated incidents. Aggregate limits cap total payouts over the policy period and can leave the business exposed to subsequent events.
Understanding policy limits and deductibles in the UK: core definitions and how they interact with premiums
Policy limits
A policy limit is the maximum amount an insurer will pay for a covered loss under a policy section or for the policy as a whole. Limits may be stated per claim (per occurrence), per policy period (aggregate), or as sublimits for specific costs (for example, legal defence, regulatory response costs, or ransomware payments).
Excesses and deductibles
An excess (also called a deductible) is the portion of an insured loss that the policyholder must pay before the insurer pays. There are two main types:
- compulsory excess: set by the insurer and non-negotiable; applies to most claims.
- voluntary excess: chosen by the insured to reduce premium; increases the insured’s contribution in a claim.
How limits and excess affect premiums
- Higher limits generally increase premium roughly in proportion to the insurer’s exposure and the risk profile. For cyber, the marginal premium per additional £1m cover varies by sector and threat, but many insurers price increases steeply beyond certain brackets (for example, £1m→£5m).
- Increasing voluntary excess reduces premium but increases retained loss. For SMEs, a voluntary excess above reasonable operating cash may be counterproductive.
Practical note: insurers price on exposure, controls and claims history. Demonstrable cybersecurity measures (NCSC guidance, MFA, backups) often reduce premium and allow for more favourable limits.
Useful links for controls and guidance:
How policy limits affect ransomware and business interruption: scenarios and numeric examples
Why ransomware and BI consume limits rapidly
Ransomware incidents typically trigger multiple cover sections at once: first‑party response costs (forensic, containment, data recovery), ransom payments (where insured), business interruption loss (lost revenue or additional costs), and possible third‑party liabilities (if customer data is exposed). Those combined costs can exceed a single section limit very quickly.
Example scenario: a small e‑commerce SME (turnover £1.2m)
- Ransom demand: £50,000 (insured under ransom sublimit)
- Forensic and recovery: £35,000
- Extra IT and PR: £15,000
- Business interruption: 10 days closure; average daily gross profit £1,500 → £15,000
- Third‑party liabilities (customer claims): £25,000
Total cost ≈ £140,000. If the policy limit for the cyber section is £100,000, the business faces an uncovered shortfall of £40,000 plus any excess.
Business interruption calculations (simple formula)
- Estimate gross profit per day (turnover × gross margin ÷ 365)
- Multiply by expected or reasonable downtime days
- Add reasonable extra costs (temporary IT, hire, expedited services)
Indicative payout example table (illustrative only)
| Turnover band (annual) |
Typical suggested cyber limit (indicative) |
Typical BI cover period suggested |
| Up to £250k |
£100k–£250k |
30–60 days |
| £250k–£1m |
£250k–£1m |
60–120 days |
| £1m–£5m |
£1m–£3m |
120–365 days |
| £5m+ |
£3m+ (custom) |
180–365+ days |
Notes: these bands are indicative and depend heavily on sector, supply‑chain exposure and online revenue share.
Sublimits to check
- Ransom payment sublimit: some insurers cap payments (e.g. £100k). Verify whether ransom payments require insurer approval and whether facilitation services are included.
- Business interruption sublimit: BI may have a separate limit or a specified indemnity period.
- Forensic/notification/legal sublimits: these can be small relative to total loss; ensure they are realistic for likely breach response.

Choosing the right excess: voluntary and compulsory excesses explained for SMEs
Assess cashflow capacity
Choose an excess that the business can pay immediately without triggering insolvency. For micro and small businesses, a high voluntary excess (for example, >£5,000) can be risky if operational recovery requires immediate funds.
Match excess to likely loss size
If most claims historically fall below a threshold (e.g. phishing scams causing £1k–£3k loss), a small compulsory excess can be retained, and a voluntary excess set higher only if confident the business can absorb the retained loss.
Impact on claims behaviour and premium
- A higher voluntary excess will usually reduce the premium, sometimes materially. For cyber, savings increase with the excess level but are non-linear.
- Avoid setting an excess so high that the firm will not claim for incidents that would otherwise be covered; the real saving is not paying premiums but retaining manageable losses.
Example calculation: premium trade‑off (indicative)
- Base premium for a £250k limit: £1,200/year
- Increase voluntary excess from £500 to £2,500: premium reduces to £950/year (approximate 21% saving)
- If a claim of £4,000 occurs, excess £2,500 leaves insured to pay £2,500 vs £500, additional £2,000 retained. Over time, frequency matters.
Negotiating excesses with brokers or insurers
- Ask for clear split of compulsory vs voluntary excess on each section.
- Confirm whether excesses are aggregate (per policy year) or per claim and whether they stack across sections in a single event.
Are GDPR fines covered under policy limits? what typical policies include and exclude
GDPR fines: legal position and insurance practice
The ICO issues monetary penalties (fines) under UK GDPR. Historically, many cyber policies either exclude regulatory fines or provide cover only for defence costs, settlements and civil penalties where permitted by law.
Common approaches in market practice (indicative)
- Defence costs and response: commonly covered (e.g. legal fees, forensic reports, notification and PR) and often linked to a sublimit.
- Fines and penalties: many UK insurers exclude regulatory fines/penalties, but some offer limited cover subject to strict wording and insurer consent. For financial services firms, regulatory action clarity is often narrower.
Practical checks when reviewing policy wording
- Search for "regulatory fines" or "penalties" in the policy and read the exception/extension.
- Confirm whether defence costs are in addition to limits or fall within the overall limit.
- If fines are not covered, consider purchasing optional extensions or seeking a specialist policy.
Sources and guidance:
Limits per claim versus aggregate limits explained simply: why the difference matters
Per-claim (per-occurrence) limits
A per-claim limit applies independently to each insured event. If multiple separate incidents occur, each may be subject to the limit, assuming they qualify as distinct occurrences under the policy wording.
Aggregate limits
An aggregate limit caps the insurer’s payout for all claims in the policy period. Once exhausted, no further cover is available until policy renewal. For SMEs, aggregate limits can create exposure if there are multiple smaller incidents or a single heavy-cost incident early in the period.
Which is preferable?
- Per-claim limits are preferable when the business worries about a single large event and possible follow‑on third‑party claims.
- Aggregate limits can be acceptable for low-frequency risk profiles, but they require careful consideration for businesses with recurring exposure (multiple suppliers, seasonal attacks).
Example: repeated phishing incidents
If an SME suffers three separate phishing incidents in a year, each causing £20k loss:
- With a £50k per‑claim limit and no aggregate limit, insurer may pay each claim (subject to excess).
- With a single £50k aggregate limit, total payout will be capped at £50k, leaving the business to fund the remaining £10k per incident once aggregate exhausted.
Practical checklist: setting appropriate limits and deductibles (step‑by‑step)
-
Identify your exposures
-
Calculate online revenue share, third‑party data processed, and dependencies on cloud providers. Estimate maximum plausible BI days.
-
Quantify financial impact
-
Compute daily gross profit and multiply by plausible downtime scenarios (30 / 60 / 120 days). Add realistic extra costs (forensic, expedited engineering, PR).
-
Map cover sections to exposures
-
Ensure there are adequate sublimits for ransomware, BI, legal defence, regulatory response and third‑party liability.
-
Select limit bands (indicative)
-
Use turnover bands in the table above as a starting point; increase limits if the business holds high volumes of sensitive personal data or relies on digital platforms.
-
Decide excess levels
-
Set compulsory excess as per insurer. Choose voluntary excess no higher than the amount the business can pay immediately in a crisis.
-
Check policy wording for exclusions and stacking
-
Confirm whether excesses stack across sections and whether aggregate limits apply.
-
Validate with scenario testing
-
Run two scenarios: a single catastrophic ransomware event and multiple small incidents. Confirm funds available under each.
-
Review annually or after material change
-
Increase limits if turnover grows, the business acquires more data, or new digital services are launched.
Practical numeric example (SME with £600k turnover)
- Gross margin 40% → gross profit £240k/year → daily gross profit ≈ £657
- 60 days of BI at daily gross profit = £39,420
- Forensic/IT/PR estimate = £30,000
- Third‑party claim cushion = £25,000
Suggested total insured limit = BI £40k + first‑party response £50k + liability £50k = £140k (rounded up to £250k limit for headroom). Excess: voluntary £1,000, compulsory £500.
Reminder: these figures are indicative. Consult a broker or experienced adviser for bespoke calculations.
Advantages, risks and common mistakes
Benefits / when to apply ✅
- Better financial resilience: appropriate limits protect cashflow and credit lines.
- Faster recovery: adequate forensic and IT sublimits fund quick remediation.
- Contractual compliance: some clients or regulators require minimum limits.
Errors to avoid / risks ⚠️
- Underinsuring business interruption: choosing short indemnity periods or low BI limits.
- Ignoring sublimits: low forensic or notification sublimits create operational shortfalls.
- Excess mismatch: selecting a voluntary excess that the business cannot afford to pay at the time of claim.
- Assuming GDPR fines are covered: check exclusions and defence‑cost wording.
Limits & deductibles at a glance (visual flow)
Limits & deductibles at a glance
Step 1 → Assess turnover & daily gross profit
Step 2 → Model BI days (30 / 60 / 120)
Step 3 → Add response & liability costs
Step 4 → Choose limits and sensible excess
Step 5 → Test two scenarios and adjust
Frequently asked questions
What is the difference between excess and limit?
A limit is the maximum the insurer will pay; an excess is the amount the insured pays first. Limits cap insurer liability; excesses allocate small losses to the insured.
How much limit does a typical small UK SME need?
Indicative guidance: small micro businesses may be fine with £100k–£250k, while SMEs with online revenue often need £250k–£1m. Sector, turnover and data held change the outcome.
Will business interruption always be paid under a cyber policy?
Not always. BI cover depends on the policy wording, defined triggers (e.g. system outage, denial of service) and the indemnity period. Check if BI is a separate sublimit.
Are ransom payments covered under policy limits?
Often yes, but many policies apply a specific ransom sublimit, require insurer consent and may exclude unauthorised payments. Confirm the ransom clause.
If the policy has an aggregate limit, how should that affect choice?
An aggregate limit reduces cover for multiple events. Businesses with repeated exposure should favour higher per‑claim limits or higher aggregate limits to avoid exhaustion early in the year.
Can voluntary excess reduce premiums significantly?
Yes, voluntary excess can reduce premiums; however, savings must be weighed against increased retained loss in a claim.
How should GDPR fines be handled when limits are insufficient?
If fines are excluded, the business may face direct liability. Consider specialist regulatory insurance, legal reserves or negotiating contractual protections with clients.
How often should limits and excesses be reviewed?
At least annually and after material changes (increased turnover, new data processing, major IT platform changes, or a prior claim).
- Run a quick scenario: calculate daily gross profit and model 30/60/120 days BI to get a lower‑bound limit.
- Check current policy wording for ransom sublimits, BI indemnity period and whether regulatory fines are excluded.
- If unsure, prepare the scenario figures and consult a broker or regulated adviser to review limits and excesses (this guide is educational, not personalised advice).