Are ransomware payments, incident response and lost earnings covered by a cyber policy? For many UK small businesses the answer depends, but practical clarity is possible.
This guide explains, in clear British English and with UK context, what ransomware cover for UK SMEs typically includes, what it usually excludes, realistic cost ranges (indicative for 2026), and an actionable checklist for SME directors to choose appropriate cover.
Key takeaways: what to know in one minute
- Ransomware cover often includes incident response and business interruption, and may include ransom negotiation and payment under tightly controlled conditions.
- Typical premiums vary widely: microbusinesses may pay from £300–£1,200 per year; small SMEs with higher revenue may pay £800–£5,000 (indicative at time of writing).
- Policy limits and sub-limits matter: sub-limits for ransom payments, negotiation and cyber extortion commonly apply and can be far lower than the overall policy limit.
- Exclusions can be hidden: pre-existing vulnerabilities, inadequate backups, unpatched systems, or failure to meet security warranties can void cover.
- Immediate steps matter: do not negotiate or pay without following insurer incident response steps; preserve evidence and contact the insurer’s incident response team and the ICO or NCSC guidance where required.
What ransomware cover actually protects UK SMEs
Ransomware cover in UK SME-focused cyber policies typically bundles a number of first- and third-party elements. Understanding what each part aims to pay helps set realistic expectations.
First-party costs often included
- Incident response and forensics: costs to hire forensic specialists, containment, malware removal and system restoration. Many insurers provide a panel of approved responders as part of the service.
- Business interruption (BI): loss of gross profit or additional increased costs of working while systems are down. BI cover usually has an indemnity period and requires proof of revenue loss or extra expenditure.
- Ransom negotiation and payment: some policies will pay for negotiation services and ransom payments (including cryptocurrency fees) but commonly under a sub-limit and only after insurer approval and legal review.
- Crisis communications and PR: costs to manage reputational damage, customer notifications and media handling.
- Data restoration: costs to restore or recreate lost data, including use of backups or manual reconstruction.
Third-party costs often included
- Liability and legal defence: legal costs to defend claims from customers or suppliers alleging data loss or system failure.
- Regulatory response: legal and consultant costs to respond to regulators and to prepare notifications (for example to the ICO). Note: cover for regulatory fines is subject to legal and policy limits (see below).
What ransomware cover commonly excludes or limits
- Policy conditions and warranties: failure to follow mandatory security measures (e.g. MFA, timely patching, verified backups) may result in claims denial.
- Deliberate or criminal acts by directors: intentional wrongdoing by insured parties is typically excluded.
- Uninsurable fines and penalties: in some cases, regulatory fines (statutory penalties) may be excluded or limited depending on insurer wording and legal insurability.
- War, nuclear, or state-sponsored acts: many policies limit cover for state-sponsored ransomware or acts considered war-like, though market wording varies.
Typical costs and premiums for ransomware cover (indicative 2026)
Pricing for ransomware cover depends on revenue, industry, previous claims, security posture and selected limits. Figures below are indicative at time of writing and should be used only as a budgetary guide.
Premium bands (annual, indicative)
- Microbusiness (0–2 employees, turnover under £100k): £300–£1,200.
- Small SME (3–25 employees, turnover £100k–£1.5m): £800–£3,500.
- Larger SME (26–50 employees, turnover £1.5m–£10m): £2,000–£6,000+.
Factors that can push premiums higher: prior ransomware claims, handling payment exposure, storing high volumes of personal data, operating in high-risk sectors (legal, finance, healthcare), and weak cyber hygiene.
Typical deductible/excess structure (examples)
- Fixed excess for cyber claims: £1,000–£10,000.
- Percentage excess for business interruption: 5–20% of the loss or a specified number of days (time excess).
Sub-limits and their cost impact
Policies often impose sub-limits for specific elements. A higher ransom sub-limit and an increased forensics allowance raise premiums but reduce uninsured exposure.
- Ransom payment sub-limit: commonly £25,000–£250,000 for SMEs.
- Forensics and incident response sub-limit: commonly £10,000–£100,000.
- Crisis communications: often capped at £10,000–£50,000.
Example scenario (indicative)
A 12-person online retailer (turnover £750k) might buy a £1m cyber policy with a £250k ransom sub-limit and a £100k BI retention. Premium could be around £1,600–£3,200 depending on security controls and claims history.

Policy limits, excesses and hidden exclusions explained
Understanding the fine print is essential: headline limits (e.g. £1m) can be undermined by sub-limits, time excesses, and clauses which deny cover in specific circumstances.
What a limit actually covers
- The aggregate policy limit is the maximum the insurer will pay across covered heads during the policy period. However, sub-limits apply per cover type (ransom, BI, forensics). A £1m policy might only permit £100k for ransom—check the schedule.
Excesses to watch
- Monetary excess: an insured contribution to every claim (e.g. £2,500).
- Time excess: BI payments may only start after a set number of hours/days.
- Percentage excess: some policies impose a percentage of the loss for BI or data restoration.
Common hidden exclusions and traps
- Pre-existing vulnerability exclusions: known but unpatched vulnerabilities exploited by attackers may lead to repudiation.
- Failure to follow insurer security warranties: formal conditions such as MFA on admin accounts, backup frequency and patching windows are often mandatory.
- Cryptocurrency payment clauses: some insurers require payments via specific channels or prohibit payment entirely if illegal or sanction-related.
- State-sponsored or nation-state attribution: when attribution to a nation-state is asserted, many policies restrict or exclude cover.
How to read the policy schedule
- Look for: ransom sub-limit, forensics sub-limit, BI indemnity period, time excess, monetary excess, confirmation of response panel, and security warranties.
- When in doubt, request a policy wording and a schedule showing sub-limits and warranties in plain language from the broker or provider.
Incident response, forensic support and ransom payments
The insured path after a ransomware event usually follows an insurer-led incident response. Understanding the sequence reduces mistakes that can void cover.
Typical incident response flow (high level)
- Immediate containment and preservation of evidence.
- Forensic triage to identify scope and entry vector.
- Decision point: restore systems from backups, negotiate or consider payment.
- Remediation, system rebuild and notification tasks.
Payment of ransom: legal and ethical complexities
- Many policies permit payment of ransom only after insurer approval and legal review. Insurers typically require involvement of legal counsel, forensic experts and an approved negotiator.
- Paying a ransom may have legal implications: sanctions screening and potential facilitation of criminal acts must be considered. For UK-context guidance see the National Crime Agency and HM Government advisories.
- Insurers that offer ransom payments will often attempt negotiated reduction and monitor payments closely.
Forensics and evidence preservation
- Preserve logs, disk images and communications. Do not overwrite devices unless instructed.
- Timely forensic investigation can support an insurer claim, help identify exposures and demonstrate compliance with notification duties.
Ransomware response: 6-step flow [for SMEs](https://dealergen.uk/data-breach-response-cover-uk-smes/)
🔒 Step 1, Contain
Disconnect affected devices; avoid powering down evidence.
🕵️ Step 2, Triage
Engage forensic experts via insurer panel.
💬 Step 3, Notify
Notify insurer, consider ICO/NCSC obligations.
🤝 Step 4, Decide
Assess restore vs negotiation; legal check for payments.
🔁 Step 5, Recover
Rebuild systems, restore data, test integrity.
📣 Step 6, Communicate
Issue customer and regulator communications if required.
How cyber insurance helps with GDPR fines and legal costs
Regulatory exposure is a major concern for SMEs that process personal data. Cyber policies can assist, but cover for fines is nuanced.
- Legal defence costs: cover for lawyers and consultants engaged to respond to regulator investigations.
- Notification costs: expenses to notify affected data subjects and set up call centres or credit monitoring.
- Regulatory penalties: some policies include cover for regulatory fines where legally insurable, but many exclude or restrict fines—checking wording is critical.
UK-specific context
- The ICO can issue monetary penalties under UK GDPR. Whether an insurer will pay these depends on policy wording and legal advice. Insurers often cover defence costs but not the fine itself; some offer limited cover for certain fines where not prohibited by law.
- Directors should record compliance actions (data protection impact assessments, training, breach response plans) as evidence insurers may request during claim validation.
Practical example
If a ransomware event results in personal data exposure and an ICO investigation, a policy commonly pays the legal defence and notification costs but may deny or cap payment of any fine. Directors should therefore budget for both insurance and remediation investments.
Choosing the right cover: checklist for UK SME directors
A practical checklist helps directors compare policies quickly. This is a starting point for board-level conversations and for presenting requirements to brokers.
Core checklist (use when requesting quotes)
- Confirm ransom payment sub-limit and whether payments are permitted after legal/sanctions checks.
- Check forensic/response sub-limit and whether an insurer panel must be used.
- Verify business interruption indemnity period, time excess and method of BI calculation.
- Confirm which security warranties apply (MFA, backup frequency, patching) and the consequences of breach.
- Check regulatory cover: legal costs, notification costs and whether fines are insured.
- Review criminal reward or extortion wording (what is and is not covered).
- Ask about retroactive date for coverage and prior acts exclusions.
- Request sample policy wording and a clear schedule of sub-limits and excesses.
Questions to ask a broker or insurer
- "What is the ransom sub-limit and do payments require insurer approval?"
- "Which incident response providers are on the panel and can the SME choose an external provider?"
- "How will BI losses be calculated for a small online business with seasonal sales?"
- "Are there exclusions for state-sponsored attacks or sanctioned entities?"
Advantages, risks and common errors
✅ Benefits / when to buy
- Reduces immediate cash exposure for ransom, forensic and BI costs.
- Access to specialist services (forensics, legal, PR) that SMEs cannot source quickly.
- Helps maintain business continuity by funding remediation and recovery.
⚠️ Risks / errors to avoid
- Assuming ransom is always covered, always check the ransom sub-limit and payment process.
- Ignoring security warranties, failing to meet mandatory controls can void claims.
- Choosing lowest premium only, low-cost policies may have small sub-limits, long time excesses or exclude key services.
Comparative table: common ransom/response elements and typical sub-limits
| Cover element |
Typical SME sub-limit |
Notes |
| Ransom payment |
£25,000–£250,000 |
Often requires insurer approval and legal checks |
| Forensics / incident response |
£10,000–£100,000 |
Panel-approved responders common |
| Business interruption |
Part of aggregate limit (e.g. £500k–£1m) |
Subject to time excess and indemnity period |
| Notification / PR |
£10,000–£50,000 |
Often includes call centre costs |
FAQ: common questions about ransomware cover for UK SMEs
Can insurers legally pay ransom under UK law?
Many insurers can pay ransom subject to sanction checks and legal advice, but payments are controlled and may be refused if illegal or linked to sanctioned parties.
Will cyber insurance cover ICO fines?
Policies vary. Many cover legal defence and notification costs but exclude or limit payment of fines; check the policy wording and request clarity from the insurer.
Is ransomware cover included in standard business insurance?
Ransomware cover is normally part of a dedicated cyber insurance policy, not standard property or liability insurance.
What security controls do insurers commonly require?
Common requirements include MFA on remote access, regular patching, tested backups, and anti-malware defences. Warranties differ by insurer.
How quickly must a ransomware incident be reported to the insurer?
Policies usually require immediate notification (often within 24–48 hours) to preserve cover and engage incident response resources.
Can paying a ransom be insured if the payment funds criminal activity?
Insurers conduct legal and sanctions checks; if the payment is unlawful, insurers will generally refuse to fund it and advise alternative actions.
Will insurers help with negotiations with attackers?
Many policies include access to specialised negotiators and forensic teams via insurer panels, and will coordinate negotiations where permitted.
What documentation is needed for a claim?
Evidence typically includes system logs, backup records, invoices for remediation, and proof of loss or lost revenue; retain copies and avoid altering evidence.
Your next step:
- Review current security posture against typical insurer warranties: MFA, backups, patch schedule.
- Request full policy wordings and a schedule showing ransom and forensics sub-limits before accepting cover.
- Agree an incident response plan that names the insurer contact, legal counsel and IT responder and rehearse the plan annually.