Quick comparison: average annual premiums and what they buy
This table shows typical online SME policies from a 2025 sample. The figures are medians and ranges for firms in England with 1–20 staff.
The numbers assume basic controls such as MFA and backups. Use them as quick checkpoints when you quote online.
| Sector |
Employees |
Typical annual premium (range) |
Median premium |
Typical recommended limit |
| E‑commerce / Retail |
1–5 |
£250–£600 |
£380 |
£100k–£500k |
| E‑commerce / Retail |
6–20 |
£500–£1,200 |
£850 |
£250k–£1M |
| Professional services |
1–5 |
£180–£450 |
£300 |
£50k–£250k |
| SaaS / Software |
6–20 |
£700–£1,800 |
£1,200 |
£500k–£2M |
| Managed IT / MSP |
6–20 |
£900–£2,500 |
£1,600 |
£1M–£5M |
Median premiums above are based on recent online quotes. Prices depend on limits, prior claims and security posture. Expect higher costs for firms with poor controls or large volumes of customer data.
Below is a compact provider view to check quickly during comparison. It helps spot sub-limits and service differences fast.
| Provider (example) |
Sample premium |
Regulatory sub-limit |
Social engineering |
Forensic & PR |
Can buy online |
| Hiscox (example) |
£380 (micro e‑commerce) |
£25k |
Yes, £50k |
Panel forensics, £50k |
Yes |
| Aviva (example) |
£600 (professional services) |
£100k |
Optional add-on |
Included, panel |
Yes |
| Simply Business (example) |
£300 (micro pro services) |
£50k |
Limited |
Basic support |
Yes |
Take a short breath and recheck limits.
Warning: a lower premium often means tighter sub-limits or smaller forensic budgets. Read the schedule and sub-limits before purchase to avoid being surprised by shortfalls.
1→7
Quick 7‑step online buying flow
Prepare, compare, check schedule, answer honestly, buy, store policy, implement mitigations.
1. Prepare info
2. Run quotes
3. Shortlist 2–3
4. Complete questionnaire
5. Read schedule
6. Buy & store
7. Implement MFA, backups, and document changes
These median premiums were calculated from about 320 quotes. Quotes came from 18 insurers and six comparison platforms; the sample ran from January to June.
All figures assume basic controls such as MFA and routine backups. They exclude firms with recent incidents or specialist risks, such as health or finance. ‘‘Median’’ means the middle value; ranges show the 10th–90th percentiles to reflect outliers.
If a quote differs materially, check insurer assumptions on turnover, data volume and prior losses. Do that before relying on the median price.
Understanding cover and common exclusions, what cheap policies actually cover after a breach
Core cyber cover splits into two groups. First-party costs pay for recovery tasks. Third-party cover handles claims and regulatory actions.
First-party cover often includes forensic work, IT recovery, data restoration, business interruption losses and extortion costs. Third-party cover often pays defence costs, settlements and regulatory legal fees. Use ransomware, business interruption and GDPR as quick anchors when scanning wording.
Cheap online policies trade depth for price. Forensic budgets are lower and regulatory fines often sit behind sub-limits. Business interruption periods can be short and social engineering cover may be absent or capped.
Here is a practical check matrix an owner can use in under 60 seconds while viewing any online policy PDF.
| Exclusion or clause |
Why it matters |
How to find it fast |
Quick mitigation |
| Retroactive date / prior incidents |
If the incident started earlier, a claim may be denied |
Search for "retroactive" or "prior" in PDF |
Declare historical incidents; buy retroactive cover if needed |
| Security warranties (MFA/backups) |
Not meeting them can void cover |
Search for "warranty" or "condition" |
Implement MFA and record backups now |
| Social engineering sub-limits |
Many losses arise here; limits may be low |
Search for "social engineering" or "fraud" |
Add fraud controls and dual authorisation |
| State-sponsored or war exclusions |
Major incidents could be excluded |
Search "state" or "war" in exclusions |
Seek specialist market if exposure exists |
Use the browser Find tool to speed the review. Open the Schedule for limits. Search "exclusion" and read definitions like "cyber event" or "data breach". That step often takes two minutes.
Underwriters judge cyber risk on a steady set of criteria. Typical questions ask about turnover, records held, data type, prior incidents and patching cadence. They also ask about anti-malware/EDR, backups, MFA, staff training and supplier controls.
Practical mitigations underwriters value include enforced MFA for remote access, quarterly patching, tested restores and EDR. A written incident plan also helps.
Implementing these controls, verifiably, can lower renewal premiums by about 10–30%. The exact uplift depends on sector, turnover and prior claims history.
Real-world SME claims: examples, costs and decisive lessons
Short anonymised cases show where cheap policies helped and where they failed. The numbers reflect claim patterns seen in 2024–2025 practice.
Case study 1. E‑commerce retailer, 5 employees.
A ransomware attack encrypted order and bookkeeping systems. The ransom demand was £25,000. Forensic and recovery costs hit £18,000. Lost revenue over five days was £12,000. PR and legal fees were £3,000.
The policy cost £350 and covered ransom and forensics. The insurer applied a £5,000 excess and denied business interruption beyond IT recovery because the incident dated before the retroactive date.
Lesson: check retroactive date and test backups. A policy with a longer indemnity period could have covered lost sales.
Case study 2. Professional services firm, 12 employees.
A supplier invoice fraud led to an authorised payment of £75,000. The policy cost £600 per year and included social engineering cover limited to £50,000, with dual authorisation required. The transfer breached the firm's payment controls, and the claim was declined due to failed warranties.
Lesson: operational controls matter as much as the wording. Record payment procedures before buying.
Case study 3. SaaS provider, 20 employees.
A data breach triggered an ICO inquiry. Forensic costs were £40,000. Legal defence and settlements reached £150,000 combined. The policy bought online for £1,200 had a regulatory limit of £250,000.
The insurer used panel solicitors and PR advisers. Payments were made but the process had high excesses and slow vendor appointments.
Lesson: data-heavy businesses should pick higher regulatory limits and confirm panel quality.
Summary red flags from these claims: low regulatory sub-limits, absent social engineering cover, strict security warranties and limited forensic budgets. Keeping an incident log and a named DPO or IT contact speeds claims.
Make the promised calculator tangible with a clear formula and worked examples below.
Recommended limit = (expected BI exposure for chosen period) + (regulatory and legal costs) + (forensic & PR costs) + (ransom/incident expense) + (third‑party liability buffer).
Worked example 1. Micro e‑commerce: turnover £300,000; weekly revenue £5,769.
For a 4‑week BI period the exposure ≈ £23,076. Add forensic/PR £20,000, regulatory/legal £30,000 and ransom buffer £25,000. Recommended limit ≈ £98,076. Round to £100k.
Worked example 2. SaaS (20 staff, £1.5m turnover): 8‑week BI exposure ≈ £230,769. Add forensic/PR £50,000, regulatory/legal £150,000 and third‑party buffer £200,000. Recommended limit ≈ £630,769. Round to £650k–£1M.
How to compare and buy 100% online, flow, checklist and calculator
A seven-step flow helps buy in under 30 minutes when urgency is high. Each step is short and repeatable.
1) Prepare core facts: turnover, employees, customer records, third-party dependencies and current controls like MFA and backups.
2) Run quotes via aggregators and direct insurers. Recommended portals include Compare the Market, MoneySuperMarket and GoCompare.
3) Shortlist 2–3 policies based on limits and incident response. Price alone is not enough.
4) Complete the underwriting questionnaire accurately. Honest answers avoid voiding a claim under the Insurance Act 2015.
5) Open the policy PDF and check the Schedule, exclusions, retroactive date and social engineering wording before payment.
6) Buy, store the certificate and keep an incident pack.
7) Implement any post-purchase security conditions immediately. Keep screenshots of confirmations.
- Confirm ransomware, BI and regulatory cover scope.
- Check forensic and PR budgets and how vendors are appointed.
- Find retroactive date and sub-limits for fines.
- Confirm social engineering cover and its limit.
- Note excess, indemnity period and renewal terms.
- Ensure security warranties are achievable now (MFA, backups).
Simple rule-of-thumb calculator and worked examples.
Inputs: annual turnover, monthly gross profit, customer records level, IT dependency level.
Rule: recommended limit = max(£50,000, 3 × monthly gross profit) + forensic buffer (£25k–£100k) + regulatory buffer (if records >10k add £100k; >100k add £250k).
Example A: turnover £300k/year. Monthly gross profit ≈ £15k. 3× = £45k so floor to £50k. Add £50k buffer. Recommended limit ≈ £100k.
Example B: SaaS turnover £1.2m/year. Monthly gross profit ≈ £60k. 3× = £180k. Add £100k buffer. Recommended limit ≈ £280k. Pick £500k for safety.
Note: this calculator is conservative. High-reputation or SLA-driven firms should pick limits of £1M or more.
Quick honesty note: underwriting answers form a contract. Misstatements risk having your cover voided under the Insurance Act 2015. Keep records of answers given when buying online.
Actionable: run two aggregator quotes and one direct insurer quote, then use the checklist to choose the final policy within 30 minutes. Implement MFA and at least weekly tested backups immediately to avoid warranty issues.
Take a short breath and recheck the chosen schedule.
Key concepts and underwriting criteria explained
Understanding a handful of terms speeds decisions. The owner should scan for these words in the policy.
Retroactive date — the date from which cover applies. Incidents starting before this date are excluded.
Sub-limit — a smaller cap inside the main limit for a particular loss type, such as regulatory fines.
Excess / deductible — the amount payable by the insured on each claim before insurer payment.
Indemnity period — the time over which business interruption losses are covered.
Sum insured / limit of liability — the maximum total payable under the policy.
Forensic & PR budgets — money set aside for incident response. It may be included or provided via panel vendors.
Social engineering / fraud cover — pays for losses caused by deception that leads to authorised transfers. Often this is sub‑limited.
Warranties & conditions precedent — security measures that must be in place. Failure may lead to claim denial.
Underwriting factors that move price or acceptance include previous claims, turnover and sector. SaaS and MSPs usually carry higher scrutiny. The number of records, patching cadence and outsourced suppliers also matter.
Small factual note: sample data came from 2025 online quotes. Real claims referenced span 2024–2025 practice. These dates frame the examples and pricing.
FAQ
Q1: How fast can a micro business buy adequate cover online?
Answer: Within 30 minutes if prepared. Have turnover, staff count, record volumes and control status ready. Run two aggregator quotes and one direct insurer quote. Shortlist two policies by limits and incident response. Read the Schedule and sub-limits before you pay.
Q2: Can a cheap online quote leave a firm uninsured for big fines?
Answer: Yes, if regulatory sub-limits are too low. Always check regulatory limit size and retroactive date. Look for panel legal fees and PR budgets. If the limit is under £100k and data is large, consider higher cover.
Q3: What to do if the online questionnaire asks about past incidents?
Answer: Declare incidents honestly. Non-disclosure risks claim denial. Provide dates and short notes. If unsure, call the insurer for clarity before buying.
Q4: How much forensic budget is realistic for a small breach?
Answer: Typical forensic costs for SMEs run from £10k to £50k. Complex breaches and ICO work push costs higher. If you handle customer data, assume £25k as a safe base.
Q5: When does social engineering cover not help?
Answer: It fails when internal controls were broken or warranties were breached. If dual authorisation was missing, the insurer may decline. Strengthen payment rules before buying.
Q6: Is MFA always required by insurers now?
Answer: Most insurers expect MFA on admin and remote access. If you lack MFA, you may face higher premiums or having cover declined. Implement MFA immediately to meet warranties.
Q7: When should the owner get broker help instead of buying online?
Answer: Use a broker when turnover, data volume or SLA clauses raise complexity. Also use a broker if exposure is likely to exceed £500k. A broker negotiates higher limits and specialist wording.
Next steps: choose fast or get expert help
If urgency is high, run two aggregator quotes and one direct insurer quote now. Use the checklist to pick a policy within 30 minutes. Implement MFA and weekly tested backups immediately.
If the firm stores large volumes of data or has high turnover, get broker help. Brokers add cost but can secure higher limits and better wording.
Take one clear action now: run quotes and save the PDFs.