Cyber insurance for estate agents & lettings must cover first‑party response and third‑party liability. It should name funds‑transfer cover and give clear sub‑limits for fraud and ransom.
Cyber insurance for estate agents & lettings
Buy a cyber policy that gives forensics, ransomware cover and business interruption for first‑party losses. Also include third‑party liability for privacy claims, legal defence and regulatory costs.
Insurance jargon can hide holes. Read the full wording. Limits, sub‑limits and exclusions decide whether a claim pays.
Many insurers list a headline limit (e.g. £1m) but split it across sub‑limits for ransom, BI or social engineering. That split matters more than the headline.
If your agency handles client money or updates bank details, insist on explicit cover wording for payment redirection. Also demand cover for social engineering. Otherwise you risk an uninsured loss.
Data highlight
Typical micro‑agency ransomware claims I handle cost £40k–£80k. This covers containment, legal fees, ICO work and BI. Funds‑transfer fraud often hits £10k–£50k per incident.
Decision tool: which cover to prioritise
Answer three quick questions and pick the priority cover.
- If you hold client bank details or move money, prioritise social‑engineering/funds‑transfer cover.
- If you store tenant documents like IDs and references, prioritise privacy liability and notification costs.
- If downtime interrupts referencing, lettings or rent processing, prioritise business interruption with a clear indemnity period.
Result: ask for policy wording that names these covers and shows sub‑limits clearly.
Key cover components
Check for forensic costs, incident response, legal and PR, ransomware/cyber extortion and business interruption with a clear indemnity period. Also check for privacy liability, regulatory fines and social‑engineering/funds‑transfer cover.
Who needs which limits
Micro agencies with turnover under £1m may be fine with £250k–£500k limits if funds‑transfer cover is adequate. Larger portfolios or firms that handle client money should aim for £1m or more.
Keep details short and clear.
Small lettings firms handling client funds
All letting firms that take rent payments or hold deposits face redirected payment risk and CMP rules. A cyber policy must reflect that exposure.
If an employee updates a landlord's bank details after a phishing email, the loss is usually a first‑party social‑engineering loss. Policies often exclude or limit that loss without explicit wording.
I often see owners assume the bank will return diverted funds. Banks sometimes refuse liability and litigation follows. Litigation is costly and slow.
Typical losses
Ransomware: forensics £5k–£15k. Ransom demands £5k–£30k. BI losses £10k–£50k. Legal and PR £3k–£10k.
Social‑engineering: diverted client monies £5k–£50k. Add investigation and solicitor costs.
Controls that reduce risk
Use dual‑authorisation for bank changes. Ask for written bank‑change confirmations and verify them by calling known numbers. Keep a documented client money procedure.
Maintain daily reconciliations and clear audit trails.
Many recommend adding cyber to Professional Indemnity. After analysing cases, the most frequent error is relying on PI alone without checking cyber exclusions.
GDPR compliance in a breach needs both procedure and law.
- Notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware if the breach is likely to risk people’s rights or freedoms.
- If you miss 72 hours, record objective reasons. Your ICO notification must include a description of the breach and the categories of personal data involved. Give the approximate number of affected data subjects.
- Say likely consequences and the measures you have taken or will take to reduce harm. Give a named contact point.
- For tenant or landlord notifications, explain in plain English what happened and what information was exposed. Examples: scanned ID documents, referencing history, payment redirection risk.
- Say the practical steps you took like password resets, monitoring services and bank‑change verification.
- Where financial information or identity documents are exposed, consider offering paid credit monitoring or targeted remediation.
- Document every notification and keep copies for insurer claims and regulator queries.
Short proof of process helps claims.
Agencies using third‑party portals and PropTech
If you rely on portals like Rightmove or Zoopla, your attack surface includes those providers. Insurers will ask about contracts and supplier security.
Some policies exclude losses caused by a third‑party provider unless you have contractual indemnities or the provider has equivalent cover. That gap can leave your agency bearing the loss.
In practice in England, portal breaches often begin via weak connector credentials. Insurers will look for MFA across integrations and documented account‑management controls.
Third‑party breaches
A portal compromise that exposes tenant references can lead to privacy claims and ICO interest. Expect notification duties and remediation costs even if the portal caused the breach.
Contractual checks
Review contracts with PropTech providers. Check who is the data controller and who is the processor. Ask what security assurances they give and whether they carry cyber insurance.
Keep written evidence for your insurer.
Common pitfalls when buying cover
Buyers often focus on premiums rather than wordings. The cheapest policy can have small sub‑limits and biting exclusions.
Many brokers quote headline limits without mapping sub‑limits. Ask for a side‑by‑side wording comparison, not just a summary sheet.
Insurers differ on whether they treat regulatory fines as insurable. Check policy wording against UK GDPR and the Data Protection Act 2018.
Sub‑limits and exclusions
Look for explicit numbers for ransom, social engineering and business interruption. If the social‑engineering limit is tiny, the policy is not fit for purpose when you hold client money.
Relying on PI alone
PI can help with negligent referencing advice. PI typically excludes cyber events. You often need both PI and a tailored cyber policy. Confirm overlap to avoid gaps.
Policy comparison matrix
| Insurer |
Headline limit |
Social‑engineering limit |
Ransom limit |
BI indemnity period |
Named IR provider |
| Hiscox |
£1,000,000 |
£50,000 |
Included |
30 days |
Yes (IR firm named) |
| Aviva |
£500,000 |
£25,000 |
Sub‑limit applies |
14 days |
Panel (check SLA) |
| AXA |
£1,000,000+ |
Negotiable |
Included |
30–90 days |
Named or panel |
Practical note
An insurer that names an IR firm but refuses to share the SLA can cost you days in mobilisation. Insist on SLA terms and an estimate of fees the policy will pick up.
Many buyers see a headline limit and assume it covers everything. Estate and letting agents need a clear line‑by‑line breakdown.
Typical, market‑realistic sub‑limits for small UK letting agencies are:
- Forensic and incident‑response fees £10k–£50k. Often no sub‑limit if included.
- Ransom/cyber‑extortion £25k–£250k.
- Social‑engineering/funds‑transfer fraud £10k–£100k.
- Notification and credit‑monitoring £5k–£50k.
- Legal and PR £5k–£50k.
Business interruption cover usually shows as an indemnity period of 14–90 days. Check whether BI is on gross profit or on additional increased costs.
Common exclusions agents must watch for include employee collusion, failure to apply vendor patches and uninsured third‑party provider losses. Also check for punitive or uninsurable fines in some wordings.
Explicitly check wording definitions like what the policy calls a "fraudulent instruction" or "social engineering". Also check the retroactive date. A visible £1m headline can be hollow if ransom and social‑engineering sub‑limits are tiny or excluded for tenant‑referencing or client‑money scenarios.
Exceptions and limits
Common policy exceptions agents must read include employee collusion or deliberate acts by staff. Also watch for pre‑existing incidents before the retroactive date.
Failure to follow minimum security conditions, for example no MFA where the policy requires it, can void cover. Uninsured losses caused by third‑party PropTech suppliers can be excluded unless those suppliers carry equivalent cover or contractual indemnities.
Confirm whether ransom payments, social‑engineering losses and business interruption are subject to separate sub‑limits. Check whether notification and PR costs are aggregated with third‑party liability or treated as first‑party costs.
Frequently asked questions
Is cyber insurance mandatory for agents?
No, it is not legally mandatory. Regulatory duties under UK GDPR remain and some lenders or portals may require cover.
Do policies cover ICO fines and legal costs?
Policies vary; many cover defence costs and regulatory investigations but exclude certain fines. Insist on explicit wording for UK GDPR and DPA 2018 compliance.
How long do claims take to settle?
Initial containment and forensic work usually takes 1–14 days. Full regulatory closure and remediation can take weeks to months. Expect active insurer involvement throughout.
What questions should I ask a broker now?
Ask about social‑engineering limits, ransomware cover and the BI indemnity period. Also ask the retroactive date, named IR provider and any exclusions for third‑party portals.
How much will cyber insurance cost my agency?
Micro agencies typically pay £150–£1,500 pa. Firms handling client money or many tenancies can pay £1,500–£5,000. Controls and claims history drive price.
Can I rely on insurer incident response partners?
They give expertise, but confirm SLA, scope and whether any costs sit outside the policy. Keep your own incident plan and do not outsource all responsibility.
A clear, timed sequence reduces loss.
When an incident occurs, follow a clear sequence to reduce loss and support a claim. First 0–24 hours: contain, preserve logs and evidence, and notify your broker or insurer as the policy requires. Many wordings expect notification "as soon as practicable" or within 24–72 hours.
24–72 hours: the insurer typically appoints or authorises an IR firm. Expect initial triage and forensic containment in 1–7 days. Week 1–4: forensic report, scope of breach and preliminary BI figures.
Regulator notification decisions and communications planning happen here. Weeks 2–12+: quantify BI losses, legal and regulatory costs and third‑party claims. Remediation and restoration continue while claims negotiation runs in parallel.
Typical mobilisation times: an IR firm should be on site or engaged remotely within 24–48 hours of insurer appointment. A substantive forensic report is usually available within 3–14 days.
Keep a claim chronology and preserve evidence. Agree who will pay IR fees upfront and do not authorise ransom payments or major system changes without insurer or IR consent. Doing so can breach policy terms and delay settlement.
What to do now
-
Ask your broker for full policy wordings from at least three insurers. Populate the policy comparison matrix above.
-
Implement three immediate controls: enforce MFA everywhere, require written confirmation by phone for bank‑detail changes, and schedule daily client‑money reconciliation.
-
Prepare a one‑page incident checklist and a claims chronology spreadsheet. Have your designated contact practise the notification call with your broker.
Experience and field notes
Many recommend X, but after managing real claims for English agents, the most frequent error is accepting summary documents instead of checking full policy wordings.
This works on paper. In practice in England, insurers may decline or limit social‑engineering claims unless you can prove the exact verification steps staff followed.
A scenario I handled: a phishing email led to a bank‑detail change. Diverted rent of £28,000 followed. The insurer refused due to lack of documented phone verification. The agency bore £28,000 and £6,000 legal costs. The agency then added dual approval and tightened procedures.
Will my professional indemnity cover
Sometimes, but many PI policies exclude cyber and breach response. Treat PI and cyber as complementary and check overlap carefully.