The cheapest policy can cost more after a breach. A small business may need forensic IT support, legal advice and customer communications within hours. The full scale may still be unknown. Where personal data is involved, a reportable breach may need to be reported to the ICO within 72 hours.
To compare small business cyber insurance, look beyond the premium. Check first-party costs, liability, sub-limits, excesses, exclusions and response services. Use the same business facts for every quote. Then assess what each policy will pay after an incident.
Compare quotes by cover gaps, not premium alone
A useful comparison asks what the insurer will pay in the first 24 hours. It does not simply ask what it charges each year.
Compare the cost that would stop your business trading, then check whether that cost has its own sub-limit. For a web shop, this may mean lost online sales and data recovery. For a London consultancy, it may mean a compromised Microsoft 365 mailbox. It may also mean legal advice and client claims.
Which limits sit below the headline sum?
A sub-limit is a smaller cap within the main policy limit. Think of separate envelopes within one household budget. Once a smaller envelope is empty, the main limit may not help.
Check separate limits for:
- Social engineering fraud: money sent after a fake email or convincing phone request.
- Data recovery: restoring files, systems and backups after malware or ransomware.
- Business interruption: lost income and extra costs during a covered outage.
- Cyber extortion: specialist help and, where lawful and covered, ransom-related costs.
- Regulatory costs: lawyers and investigation costs after ICO contact.
The error most firms make is trusting the headline limit alone.
How does the excess alter the claim?
The policy excess is the amount you pay before insurance contributes. A £1,000 excess may suit a £40,000 recovery bill. It can hurt when initial response work costs £2,500 and cash is tight.
Also compare the business interruption waiting period. Some policies only pay after 8 to 24 hours of downtime. A payroll firm locked out for nine hours may face serious disruption. It may receive no payment under a 24-hour waiting period.
Use one fact sheet for every insurer: employee count, turnover, customer-data types, cloud suppliers, MFA use, backups, remote working and previous incidents. Different answers create different risks. The quotes then stop being comparable.
Match the policy to how the business earns money and what it holds. An e-commerce business should test downtime cover, payment fraud limits and hosting dependence. A consultancy should prioritise mailbox compromise, client files and contract liability. A clinic handling special-category data should check privacy liability, notice support and legal costs.
Businesses with remote staff should also confirm cover for home devices and cloud accounts.
The right SME cyber insurance cover differs for every firm. Compare sub-limits and the excess against losses most likely to interrupt your work. Choose this approach if your systems or customer data matter to daily trade. Avoid headline-limit comparisons if one type of loss could stop your business first.
Knowing the gaps is only the first test. The next section shows how quote types differ in practice.
Compare three quote types side by side
A low-price quote suits you only when its response service and sub-limits meet your likely loss.
| Quote pattern | Typical annual price | Common excess | Response support | Best fit |
| Budget extension | £300 to £600 | £500 to £1,000 | May be limited or outsourced | Low-data firm with simple systems |
| Standalone SME policy | £600 to £1,500 | £250 to £1,000 | Usually 24/7 breach line | Most firms handling client data |
| Higher-limit specialist policy | £1,500 to £5,000+ | £1,000 to £5,000 | Breach coach, forensics, legal and PR | Sensitive data or high downtime costs |
Quote score: give each policy 0, 1 or 2 points
24/7 response
0-2
Fraud sub-limit
0-2
Downtime cover
0-2
Excess level
0-2
Cloud outage cover
0-2
A score below 7 out of 10 needs closer review, even if the premium is cheapest.
What should score highest?
The highest score should go to cover for losses that could halt your work. Give priority to a 24/7 response line, recovery costs and downtime cover. Then score fraud limits, cloud outage cover and an excess you can pay.
A policy that looks broad can fail when its fraud sub-limit is low. This matters if staff can approve supplier payments by email. Choose the higher score if its terms fit your actual risks. Avoid a cheap quote that scores poorly on your main loss.
When is the cheapest quote fair value?
For a consistent cyber insurance comparison, define each score before reviewing quotes. Award 2 points for a meaningful limit and no harsh condition. The policy should also include a tested 24/7 breach response. Award 1 point for low limits, long waits or approved-supplier rules. Award 0 when cover is excluded or unclear.
Apply the scoring to incident response, downtime, cloud dependence, social engineering fraud, recovery costs and the excess.
Keep each schedule and wording beside the score. A high total can hide an exclusion affecting your main income source. Choose a budget extension only if you hold little data and use simple systems. Choose a standalone policy if you handle client data or rely on cloud tools. Avoid specialist cover only when high limits and sensitive data are not relevant.
The score reveals which quote is usable. Next, test whether it pays your own recovery bill.
Match first-party cover to your own losses
First-party cover pays your direct costs after an incident. It can fund forensic work, data recovery, ransomware response and breach lawyers. It can also cover lost income while systems are repaired.
Pros of strong first-party cover
Strong first-party cover can pay for urgent work before a client makes a claim. This can include forensic investigation, file recovery and help after ransomware. It is like calling an emergency plumber before flood damage spreads.
A practical claim can involve both parts of the policy. Ransomware may encrypt an online retailer’s order system. First-party costs may include forensic work, data recovery, lost income and extortion support.
Fast response can limit a small outage.
Limits of first-party cover
First-party cover does not always pay every cost under one limit. ICO advice, legal support and customer communications can sit in separate clauses. Each clause may have its own limit.
This works well in theory, but schedules often split costs more than owners expect. Check the schedule rather than trusting one headline limit. Choose strong first-party cover if recovery costs would strain cash flow. Avoid relying on it alone when clients could also claim against you.
Who needs this most?
This cover suits firms that depend on systems to earn income. Online retailers, payroll firms and cloud-based consultancies are common examples. It also suits firms without in-house IT support.
A usual case is an online shop losing access to orders after ransomware. Sales stop while specialists investigate and restore systems. Downtime cover may matter more than a large liability limit.
Choose this cover if one day offline would cause immediate loss.
Who should not rely on it alone?
First-party cover does not replace liability cover. Exposed customer details can lead to legal defence, client claims and privacy allegations. These costs may fall under third-party cyber liability.
Customer data creates a second type of risk. The next section explains how liability and GDPR costs change the decision.
Check liability and GDPR costs before buying
Third-party liability cover responds when someone says your cyber failure harmed them. It can include privacy liability, network security liability and legal defence costs. These costs differ from your own repair bill.
The Information Commissioner's Office says some personal-data breaches need reporting without undue delay. Where feasible, reports must reach it within 72 hours. This duty comes from UK GDPR and the Data Protection Act 2018. It does not come from the insurance policy. See the Information Commissioner's Office for current guidance.
Pros of liability-led cover
Liability-led cover can pay for legal defence when clients or data subjects allege harm. It may also pay privacy claims and some network security claims. This matters where your business stores customer records.
Regulatory fines and penalties are not always insurable under applicable law. A policy may pay legal and investigation costs. It cannot promise payment of every ICO fine.
Do not treat “regulatory cover” as a promise to pay every penalty.
Which data increases the need?
Special-category data can increase the need for careful liability cover. This includes health data and other sensitive personal data. A clinic or professional practice should check notice support and legal cost limits.
For most England-based SMEs, choose liability cover alongside first-party cover. The best choice is a standalone policy with both sections and a 24/7 line. A low-price policy may suit a low-data firm. It is a poor fit for businesses holding sensitive data or client records.
📦
Available on Amazon
An encrypted external drive can support a sensible backup routine. It does not replace cyber insurance or tested recovery plans. Keep backups separate from the main network. Check that your policy covers restoration work.
- It keeps a separate copy of key business files away from a compromised device.
- Encryption can reduce exposure if the backup drive is lost or stolen.
- It supports faster recovery when backups are current and tested.
Search on Amazon →
Liability cover protects against claims from others. The next test is whether exclusions block support when you need it.
Test exclusions and 24/7 response terms
Exclusions and response conditions decide whether a policy works in a real incident.
Comparing policy wordings and UK cyber-response guidance leads to the same advice. Notify the insurer as soon as you suspect an incident. Do not wait for proof. Delay can overwrite evidence, slow legal advice and breach prompt-notice rules.
Which exclusions need direct answers?
Ask each insurer or broker about critical cloud supplier outages. Ask about known vulnerabilities, earlier attacks, unpatched software and phishing payment fraud. Also ask whether multi-factor authentication is a cover condition. It may only be a pricing question.
The National Cyber Security Centre promotes MFA, patching and backups. Cyber Essentials can support those controls. Certification does not automatically guarantee claim payment. Read the policy’s security conditions.
The small print can decide the claim.
What happens in the first 72 hours?
A good process is simple:
- Disconnect affected devices only if this is safe and practical.
- Call the insurer’s incident line at once, including outside office hours.
- Ask if you must use approved forensic, legal and PR suppliers.
- Keep emails, logs and payment records without changing them.
- Get legal advice on ICO notice before contacting affected people.
This works well on paper, but staff often try to fix the issue first. That is often the biggest delay. Set a clear internal rule: report suspected phishing or ransomware at once.
What should the application disclose?
Declare earlier incidents, key suppliers and remote access accurately. Declare MFA use, backups, special-category data and payment approval processes too. Under the Insurance Act 2015, how you present risk matters.
A cheaper quote based on incomplete answers is not a real saving. Choose a policy only after the insurer sees complete facts. Avoid guessing about security controls or past incidents.
This comparison does not replace advice from an FCA-regulated broker or another regulated professional. Seek advice if your business has complex risks or works in a heavily regulated sector. Do so if you process special-category data at scale, trade abroad significantly or need high limits. Insurance also does not replace MFA, patching, secure backups and staff phishing training.
Before requesting a final quote, send the same completed fact sheet to each provider or broker. Ask for the policy schedule and wording. This makes quote comparisons far more reliable. Choose this process if you have two or more quotes. Avoid buying before you read the exclusions and response terms.
Frequently asked questions
How much does cyber insurance cost for a small UK business?
Small UK business cyber insurance often costs £300 to £1,500 a year. Data type, turnover, security controls and claims history can change the price. Compare the excess, fraud sub-limit and response service before choosing a lower premium.
Does cyber insurance cover phishing and invoice fraud?
Cyber insurance covers phishing fraud only if the policy includes social engineering or cyber crime cover. Check the separate sub-limit and payment-verification conditions. Check whether a staff member approved the transfer.
Should I call the insurer before I know what happened?
Call the incident-response line as soon as you suspect a cyber incident. Early reporting helps preserve evidence. It can give access to forensic, legal and communication support before the 72-hour ICO window becomes urgent.
Choose response quality over false savings
The best choice for most England-based SMEs is a standalone policy. It should include meaningful first-party cover, liability cover and tested 24/7 incident response.
Choose a lower-cost policy only if it covers your systems, data and payment risks. Its excess must not strain the business. Avoid any quote that is vague about phishing fraud, cloud interruption, approved providers or security conditions.
For firms with sensitive data or constant online trade, an FCA-regulated broker can add value. A broker can test wording against real exposure. The Financial Conduct Authority regulates insurance distribution. The Association of British Insurers and NCSC offer useful market and control context.
The essentials:- The headline limit matters less than sub-limits for fraud, recovery, downtime and notification.
- First-party cover pays your recovery costs; liability cover addresses others’ claims and privacy exposure.
- A 24/7 incident line, approved specialists and early notice can decide when support arrives.
- Use identical application facts and score every quote before choosing on price.
Will cyber insurance pay an ICO fine?
Cyber insurance may pay defence and investigation costs. It cannot guarantee payment of every ICO fine. Insurability depends on the law, policy wording and facts of the regulatory action.
Further reading
If you want to learn more about this topic, these sources may interest you: