
¿Te worried about rising premiums and whether a higher excess could save the business money without exposing it to crippling cost? Many UK micro and small businesses face the same question when choosing cyber cover. This guide explains, in plain UK English, how insurers price small cyber policies, what excess options mean in practice, and how to optimise premium versus excess for typical SME profiles.
Key takeaways: what to know in 1 minute
- Small cyber policies are priced on a mix of exposure and controls, insurers use business size, revenue, sector and observed controls to set base premium.
- Excess choices trade certainty for cost, a higher excess typically lowers premium but increases out‑of‑pocket risk after a loss.
- Optimisation requires scenario testing, calculate expected annual cost (premium + expected retained losses) rather than focusing on sticker price alone.
- Basic security controls often buy both lower premium and lower excess demands, multi-factor authentication, patching and backups are especially influential.
- Microbusinesses can tailor limits and endorsements to match real exposure, reducing wasted cover cost.
How insurers price small cyber policies for SMEs
Insurers price small cyber policies using a combination of quantitative factors and expert judgement. For micro and small policies (typical limits £25k–£250k), underwriters rely on simpler models than those for large corporates but still follow consistent levers:
- Business attributes: annual revenue, number of employees, sector, and volume of personal data processed. A one‑person consultant with no client personal data will attract a lower base rate than a three‑person accountancy practice holding client tax records.
- Exposure metrics: number of devices, cloud usage, third‑party access and online payments. E‑commerce or payment processors often trigger higher base rates.
- Loss history and claims frequency: recent cyber claims, fraud incidents or data breaches can materially increase premiums.
- Security controls and certifications: MFA, endpoint protection, EDR, regular patching, backups, and insurance questionnaires. Presence of key controls often produces a premium credit and may allow a lower excess.
- Policy design choices: limits, sublimits (e.g. cyber crime vs incident response), retroactive date, and territorial scope.
Underwriters for small policies typically use bands rather than continuous models: size band, sector risk band and control tier. That means a specific control (e.g. MFA on remote access) can move a small SME into a better pricing band.
Sources and guidance from UK bodies such as the NCSC and the ICO are frequently referenced by insurers when assessing the sufficiency of controls.
Understanding excess choices on small cyber policies
Excess (also called deductible) is the sum the insured pays on a claim before the insurer pays. For small cyber policies, excess choices influence both the premium and the behaviour after an incident.
- Typical excess levels for UK micro/small cyber policies: £250, £500, £1,000, £2,500, £5,000. Some insurers offer percentage excesses or an excess tied to social engineering fraud amounts.
- Types of excess: per claim excess, aggregate excess (rare on small policies), and sublimit excesses for specific cover sections (e.g. cyber crime sublimit with separate excess).
- Impact on premium: each step-up in excess typically reduces premium by a discrete percentage, for small policies this may be ~5–25% per band depending on insurer appetite and the loss distribution the insurer expects.
- Behavioural impact: a small excess (e.g. £250) encourages making minor claims that increase insurer loss experience; a high excess discourages claims for small losses but may leave the business to self-fund remediation and regulatory fines.
Key practical point: excess selection should reflect the SME’s cash liquidity and the likely cost profile of plausible incidents. A business that can comfortably self-fund an incident of up to £2,500 may accept that excess to lower premium, provided critical costs (regulatory fines, business interruption) are separately modelled.
Balancing premium versus excess: practical decision checklist
Choosing the right mix requires a simple, repeatable calculation rather than guesswork. Use the checklist below to assess options.
- Annual premium quotes for each excess option (collect at least 3 quotes per excess level).
- Estimate of expected annual retained loss (E(RL)) for each excess band. E(RL) = frequency × average loss severity up to excess.
- Business cash buffer available for incident retention.
Step 2: compute expected annual cost (EAC)
EAC = premium + E(RL).
Compare EAC across excess bands. The band with the lowest EAC is the economically optimal choice for that simplified model, subject to non‑financial constraints (reputational risk, contractual obligations).
Step 3: sensitivity check
- Run simple scenarios: single cyber event causing regulatory fine (£10k–£50k), ransomware with response costs (£5k–£50k), business interruption loss for 2–5 days.
- Assess whether the selected excess leaves the business insolvent or compliant with contractual requirements (e.g. supply contracts requiring low excess).
Step 4: qualitative filters
- If the policyholder must be seen to have low out‑of‑pocket exposure (client contracts, regulated sectors), prefer a lower excess even if EAC is slightly higher.
- If the SME prioritises cost control and has reliable backups and incident playbooks, a higher excess may be acceptable.
- Premium at £500 excess: £900/yr. Premium at £2,500 excess: £650/yr.
- Estimated chance of minor incident costing £1,000: 10% per year.
- E(RL) at £500 excess: 0.10 × £500 = £50. E(RL) at £2,500 excess: 0 (incident below excess).
- EAC at £500 excess = £900 + £50 = £950. EAC at £2,500 excess = £650 + £0 = £650.
Under this simplified calculation, higher excess is cheaper. However, if a plausible single event could cost £5,000 that the business cannot pay, the higher excess introduces risk. These calculations are indicative and rely on realistic frequency estimates.
How security controls reduce pricing and excess demands
Insurers value demonstrable controls because they reduce both frequency and severity of claims. For small cyber policies, some controls have outsized effects:
- Multi-factor authentication (MFA) on all remote accounts: often yields premium credit and may allow insurers to offer lower excess for social engineering sections.
- Regular patching and asset inventory: reduces ransomware likelihood and may lower premium bands.
- Verified backups with tested recovery: reduces BI (business interruption) severity and can lower sublimits or excesses for BI claims.
- Endpoint protection with EDR or managed detection: demonstrable monitoring can tilt underwriting favourably.
Insurers often ask for control evidence via short attestations or screenshots. For microbusinesses, simple demonstrable measures (MFA screenshots, backup schedule evidence) can move them between pricing bands more cheaply than buying a lower premium.
Practical approach to controls vs cost:
- List controls that are low cost but high impact (MFA, backups, patch policy). Implement these first.
- Revisit insurer questionnaires after implementing controls; request re‑pricing or reassessment.
- For brokers and MGAs, present concise evidence (one‑page control summary) to speed underwriting and trigger band credits.
Tailoring cover limits and endorsements for microbusinesses
Microbusinesses frequently overpay for cover they will never use. Tailoring policy design can reduce premium while keeping meaningful protection:
- Choose limits that match realistic maximum exposures. For many solo professionals, a £50k limit may be ample; other sectors (e‑commerce) may need higher limits.
- Use sublimits deliberately: separate limits for regulatory fines, cyber crime and incident response. If regulatory exposure is low, a modest regulatory fines sublimit reduces premium.
- Consider endorsements that reflect the environment: e.g. cover for rectification of client data vs broad first‑party BI cover. Narrow, well‑documented endorsements often cost less.
- Beware of aggregate limits that can exhaust cover across multiple claims; single‑event limits are often preferable.
When tailoring, document assumptions, and ensure compliance with contractual or regulatory requirements. If contracts demand specific limit minimums, those set the floor.
Real UK claim examples: GDPR fines, business interruption and excess
Practical examples help illustrate how excess choices and policy design play out.
Example 1: GDPR enforcement notice and fines (professional services firm)
Scenario: A two‑person consultancy inadvertently exposed client personal data via misconfigured cloud storage. ICO investigation led to a corrective action and a potential fine. Incident response costs (for forensic, notification, legal) totalled £18,000.
Policy structure: limit £100k, excess £1,000, regulatory sublimit £25k.
Outcome: insurer covered response costs net of excess; regulatory penalty within sublimit was reviewed with insurer and covered up to sublimit less excess. The policyholder paid £1,000 excess. If excess had been £5,000, the firm would have paid the first £5,000 and insurer the remainder, possibly causing cashflow stress.
Lesson: moderately low excess helps microbusinesses absorb immediate remediation costs and prevents unpaid vendor bills that could escalate reputational damage.
Example 2: Ransomware causing business interruption (retailer)
Scenario: A small online retailer suffered ransomware that encrypted order systems. Total incident cost: £42,000 (for response, data recovery and 6 days revenue loss). No ransom paid.
Policy structure: limit £250k, excess £2,500, BI sublimit £50k.
Outcome: insurer paid response and BI less excess; business paid £2,500. The retailer's tested backups reduced recovery costs. A higher excess (£10k) would have meant the business paying the first £10k, risking solvency.
Lesson: backup maturity reduced severity and premium, but excess selection still materially changed out‑of‑pocket cost.
Example 3: Social engineering fraud (service provider)
Scenario: Staff were tricked into transferring £8,000 to a fraudulent account. Policy had a specific cyber crime sublimit with an excess of £1,000.
Outcome: insurer covered full loss less excess; some policies exclude social engineering by default or impose higher excess. The insured’s low excess allowed full recovery and preserved liquidity.
Lesson: check sublimits and exclusions for social engineering; excesses can be separate per section and significantly affect recoverability.
Advantages, risks and common mistakes
✅ Benefits / when to apply
- Reduced annual cost by choosing a higher excess when the business can self‑fund small incidents.
- Improved negotiating leverage with insurers by presenting strong control evidence.
- Better alignment of cover limits with actual exposure avoids overpaying for unused limits.
⚠️ Errors to avoid / risks
- Selecting a high excess without contingency cash or credit lines risks insolvency after an incident.
- Failing to read sublimits and section‑specific excesses, especially for social engineering and regulatory fines.
- Relying solely on premium comparison without modelling expected retained loss.
Visual decision flow for excess optimisation
Excess optimisation: quick decision flow
📊 Step 1 → Calculate current EAC (premium + expected retained loss)
🔐 Step 2 → List controls that lower frequency/severity (MFA, backups)
💷 Step 3 → Check cash buffer vs plausible single loss
⚖️ Step 4 → Choose excess with lowest EAC that meets liquidity constraints
📝 Step 5 → Document decisions and ask insurer for re‑pricing if controls improved
Comparative table: typical effect of excess on small cyber policy pricing
| Excess level |
Typical premium movement (vs baseline £500) |
When this suits the SME |
| £250 |
+10% to +20% |
Need minimal out‑of‑pocket on any claim; contractually required low excess |
| £500 (baseline) |
Reference |
Default for many micro policies |
| £1,000 |
−5% to −15% |
SMEs with small cash buffer and low incident frequency |
| £2,500 |
−15% to −30% |
SMEs with tested backups and contingency funds |
| £5,000+ |
−25% to −40% |
Larger cash buffer or portfolio approach; risk of unmanageable single loss |
Note: percentages indicative; actual insurer pricing varies by sector and controls.
Frequently asked questions
What drives premium differences between insurers for small cyber policies?
Premium variation often stems from appetite for sectors, underwriting bands, control weightings and how aggressively an insurer discounts for specific mitigations. Broker negotiation and bundling also matter.
How much can basic security controls lower a quote?
Basic controls such as MFA and verified backups often reduce premium bands by a noticeable margin; insurers may offer single‑digit to mid‑teens percentage credits depending on baseline risk.
Is a higher excess always cheaper in the long run?
Not always. A higher excess reduces premium but increases retained loss risk. Optimal choice depends on realistic incident frequency and available cash buffer. Use expected annual cost calculations.
Should microbusinesses accept sublimits to lower premium?
Sublimits can be appropriate when exposure to a specific peril (e.g. regulatory fines) is small. However, ensure sublimits do not leave critical exposures uninsured.
Can insurers insist on a particular excess if controls are weak?
Yes. Insurers may insist on higher excesses or exclude sections if controls fail minimum standards. Demonstrable controls can reduce these demands.
How quickly should control evidence be provided for a revised quote?
Often underwriters accept screenshots or short written attestations and can re‑price within days. For renewal, preparing evidence in advance speeds the process.
Do brokers help with excess optimisation?
Brokers can model scenarios, access multiple insurer panels and advise on market tendencies, but decisions should be based on the SME’s financial capacity and risk tolerance.
Are GDPR fines always covered by cyber insurance in the UK?
Coverage depends on policy wordings. Some insurers cover regulatory fines subject to local law, while others provide mitigation costs only. Check specific policy wording and sublimits.
Your next step:
- Run a simple expected annual cost (EAC) comparison for the excess bands quoted and pick the band with the lowest EAC while confirming cash availability.
- Implement or evidence three low‑cost controls (MFA, backups, patch schedule) and request re‑pricing from insurers or brokers.
- Document tailored limits and sublimits matching the business profile and retain copies of control evidence for renewal.