Monday morning: your team cannot access Microsoft 365. Orders wait in your ecommerce platform. Your IT provider checks whether the cause is the cloud service, a compromised account, or a failed integration. Microsoft may restore its platform. It will not usually repay lost sales, forensic support, or customer notices.
For a cloud-first UK SME without in-house IT, choose cover with 24/7 incident response. It must also respond when Microsoft 365, Google Workspace, or a SaaS provider fails.
Cloud providers protect systems, not your loss
Cloud providers protect parts of their platforms. Their contracts do not automatically pay lost turnover, forensic bills, or UK GDPR notification costs.
A Microsoft 365 takeover may start with a stolen password. A SaaS outage may start in a supplier's own systems. Either event can stop trading. The provider may not owe you money for the loss.
Look for dependent business interruption cover. It can respond when a qualifying external technology provider has an outage or cyber event.
The UK GDPR can require notification to the Information Commissioner's Office within 72 hours. This applies where a personal-data breach may risk people's rights and freedoms.
A policy can include a breach coach and insurer-appointed legal support. They can help assess evidence, reporting duties, and customer notices quickly.
A cloud provider may fix its service. Your policy must cover your business loss.
Compare cloud-first cyber insurance
The table compares common routes available through UK brokers. Prices are broad indications for lower-risk England-based firms with 1 to 50 staff. They assume turnover below £2 million and MFA is in place.
| Route | Typical annual premium | 24/7 response | Cloud/SaaS outage check | Main limitation |
| Hiscox CyberClear via broker | Often £300 to £1,200 | Usually insurer-led, subject to policy | Ask for dependent interruption wording | Fraud and outage terms can differ by schedule |
| CFC [cyber policy](https://dealergen.uk/your-first-party-cyber-policy-may-miss-client-claims/) via specialist broker | Often £500 to £2,000 | 24/7 specialist response is central | Confirm named supplier and waiting-period terms | Can cost more for payment-heavy firms |
| Packaged SME cyber add-on | Often £150 to £600 | Varies widely | Often narrow or absent | Lower sub-limits and weaker fraud [cover](https://dealergen.uk/why-uk-saas-cyber-cover-can-exclude-customer-data/) are common |
A £1 million limit does not give £1 million for every claim part. Sub-limits may apply to payment diversion, restoration, or dependent interruption. The excess is the amount you pay first.
What happens in the first 72 hours
0-1 hour
Call the insurer and preserve evidence.
1-24 hours
Forensics contain the incident with your MSP.
24-72 hours
Legal team assesses ICO and customer notices.
Afterwards
Recover systems and calculate lost income.
A cloud-first comparison should separate each cover section. Do not rely on the headline limit alone.
For UK small businesses, check whether 24/7 incident response includes forensic investigation cover. Check for legal advice and data breach notification costs. Check whether ransomware cover has separate extortion or restoration sub-limits.
Compare social-engineering fraud separately from data liability. Payment diversion is often capped more tightly than a breach claim.
Test Microsoft 365 and Google Workspace cover against the policy's covered technology failure definition. Do not rely on general business interruption wording.
Hiscox CyberClear: broad SME starting point
Hiscox CyberClear can be a practical broker-led starting point for lower-risk SMEs. The schedule and endorsements decide the cover you actually buy.
Pros
It can suit directors wanting cyber cover with professional indemnity or office insurance. One broker can coordinate renewals and claims arrangements.
Cons
Do not treat the total limit as the main comparison. Ask the broker for written fraud, restoration, and SaaS-interruption sub-limits. Ask about waiting periods and maximum indemnity periods too.
This route suits consultancies, agencies, or retailers with consistent MFA. It also suits firms with modest payment-fraud exposure and an MSP that can give evidence promptly.
Choose this route if you want a broad starting point. Avoid it if cloud downtime could stop trading within hours.
CFC cyber: response-led specialist cover
CFC can suit a cloud-dependent SME where immediate specialist help matters as much as the insurance limit.
Pros
A specialist response panel can coordinate forensics, lawyers, ransom advice, and customer notices. This helps where no internal IT lead can manage a fast-moving breach and complements robust MFA for key cloud accounts.
📦
Available on Amazon
A USB security key adds a physical second check to key cloud accounts. It helps where Microsoft 365 or Google Workspace supports security-key sign-in.
- It reduces the chance that a stolen password alone unlocks an administrator account.
- It gives finance staff a stronger sign-in method for payment and banking workflows.
- It creates simple evidence of multi-factor authentication for an insurance application.
Search on Amazon
Cons
Specialist cover may cost more for payment-heavy or sensitive-data businesses. Wrong statements about MFA, backups, or administrator controls can weaken a claim.
Choose this route if cloud or SaaS failure could stop trading within a day. It suits directors who value guided incident response over the lowest premium.
Read exclusions and claims conditions alongside the insured events. Cloud service outage cover may exclude a provider's general operational failure. Cover needs dependent business interruption wording. The waiting period must also pass.
Policies can restrict claims linked to known unpatched vulnerabilities. They can also restrict claims after untested backups or failed backups. Other limits may apply to fraudulent payment instructions, war, state-backed events, and outsourced supplier failures.
In a live event, notify the insurer quickly and preserve evidence. Your MSP can contain systems and give logs. The insurer's lawyers and forensic team may control breach strategy and recovery-cost approval.
Guided response can matter more than a low premium during the first day.
Which policy to choose for your situation
Prioritise specialist response-led cover if a Microsoft 365 lockout could halt trading quickly. The same applies to a Shopify failure or compromised finance mailbox.
Match limits to the likely loss
Estimate two weeks of lost gross profit. Add urgent IT recovery, legal advice, and customer communication costs. Compare that total with each policy limit and sub-limit.
Prepare evidence before requesting quotes
Give the broker proof of MFA and separate administrator accounts. Include tested backups, patching duties, and your MSP's out-of-hours contact.
List Microsoft 365, Google Workspace, Amazon Web Services, payroll, ecommerce, and accounting suppliers. Ask whether each critical dependency is covered.
This approach does not suit businesses that barely store data or use digital systems. It also does not suit firms needing only professional indemnity insurance. This is not legal, insurance, or incident-response advice for a live breach. Review your active policy, contract duties, and incident facts before acting.
Before underwriting, a cloud-first SME can create a short evidence pack. It does not need an in-house IT manager.
The pack should show MFA rules for every user. It should show separate administrator accounts. Include security-key or phishing-resistant MFA for finance and privileged users. Add backup reports and a recent restore test.
For Microsoft 365 or Google Workspace, keep conditional-access settings and audit-log retention records. Keep your MSP's patching duties too. For AWS or Azure, keep account ownership, privileged-access, and backup records.
A simple staff-training record can help. Name an out-of-hours contact. Proof of Cyber Essentials or similar controls can reduce unanswered underwriting questions. It can also make renewal talks easier.
Choose CFC-style specialist cover when downtime creates a same-day trading risk. Choose Hiscox-style cover when risks are lower and your broker can confirm wording clearly.
FAQs
Do Microsoft 365 and Google pay for a cyber incident?
They do not normally pay lost income, legal fees, or fraud loss after a compromised account. Their service terms often limit what they owe.
Does cyber insurance cover a SaaS outage?
It covers a SaaS outage only if dependent business interruption wording applies. Check supplier rules, triggers, and waiting periods.
How much does cyber insurance cost for a UK SME?
Lower-risk SMEs may see annual quotes between £300 and £1,500. Cost depends on turnover, claims history, payment exposure, and MFA.
What does an excess mean on cyber insurance?
An excess is the first part of an insured loss that your business pays. The insurer pays after that amount.
Does cyber insurance cover ransomware?
Many policies cover ransomware response and extortion. Sanctions, consent, and separate restoration or interruption limits may apply.
Can our MSP handle the cyber insurance claim?
Your MSP can contain the incident and give evidence. Insurers often appoint their own legal and forensic suppliers.
Do we need cyber essentials for cyber insurance?
Cyber Essentials is not always required for cyber insurance. It can support an application with MFA, backup, and patching controls.
Is payment diversion covered by cyber insurance?
Payment diversion may be covered as social engineering fraud. It often has a lower sub-limit or needs a separate extension.
What matters most:- Choose insurer-led 24/7 response before the cheapest premium.
- Get written proof that business interruption includes key cloud and SaaS dependencies.
- Read sub-limits for ransomware, payment fraud, recovery, and notification costs.
- Keep simple proof that MFA, backups, and administrator controls work.
Related sources
These articles can help you explore the topic in more depth: