Updated in July 2026
A cyber policy can look harmless until a claim exposes a gap no one expected. Many UK SMEs let the same policy roll over, only to find higher premiums, stricter conditions, lower limits, or new exclusions that were never reviewed. When systems, suppliers or ways of working have changed over the year, a simple renewal can leave the business paying more for less.
Not every cyber policy should be renewed automatically. If the business risk, systems or insurer requirements have changed, switching at renewal can be the better option, but only after comparing exclusions, total cost, notice periods and cover continuity. The key is to decide before policy expiry and keep protection in place throughout the handover, so the business avoids costly gaps and keeps the renewal decision firmly on its terms.
Should you renew or switch?
Renewing is fine when the current policy still matches the business, the insurer has not tightened the terms, and the total cost still feels fair. Switching makes more sense when the new quote gives better cover, lower long-term cost, or fewer painful exclusions.
The first check is simple: do the risks still match the information used for the existing policy? A firm that uses more cloud apps, handles more customer data, or has had a claim is no longer the same buyer. Insurers know this, and they price accordingly.
A renewal quote can look neat on the page and still hide a weaker deal. The premium may hold steady while the excess rises, the support service shrinks, or a key exclusion appears. That is like buying the same-looking boiler only to find the hot water tank is half the size.
The best renewal decision is the one that protects the business on the exact day cover changes hands.
Renew when the terms still fit
Staying put works when the insurer still covers the risks that matter and the claims process has been reliable. If the price rise is modest and the wording is stable, renewal often wins on time and simplicity.
That said, the error most often missed is treating a renewal quote like a repeat purchase. It is not. Underwriters can change the rules each year, especially after a claim or a rise in cyber loss trends.
A policy can stay with the same insurer and still become less useful. That is the trap. The business thinks nothing has changed, then finds the response team has been cut back or the business interruption wording has narrowed.
Switch when price or terms worsen
Switching works best when the new policy improves the real outcome, not just the headline price. A lower premium with a much higher excess can cost more in a real incident.
The better test is plain: if a ransomware event, data breach, or outage happened next month, which policy would leave the firm better off? That is the question that matters.
A good switch also makes sense when the current insurer becomes awkward on controls. Many underwriters now ask harder questions about MFA, EDR, backups, and incident response before they renew. If the business cannot answer cleanly, the quote can come back pricier or thinner.
Use a no-gap timing check
The renewal date is the hard line. A new policy should begin the moment the old one ends, or the two policies should overlap briefly if the wording allows it.
A single day without cover can be enough to cause trouble. If an incident starts in that gap, the business may have nowhere to turn. That is why timing beats guesswork.
Key takeaways for UK SMEs
Most SMEs should compare renewal and switch options side by side, then decide before the expiry date. The cheapest premium rarely gives the cheapest outcome once excess, exclusions, and support services are added.
The core rule is simple: the right policy is the one that keeps cover continuous and still pays when something goes wrong. That sounds obvious, yet many renewal problems start with a rushed signature and end with a nasty surprise.
According to the National Cyber Security Centre small business guidance, basic controls like MFA and regular backups still reduce many common attacks. Insurers now use that kind of control as part of their pricing and renewal review.
Compare total cost, not just premium
The premium is only the sticker price. The true cost includes the excess, any sub-limits, legal fees, incident response support, and cancellation charges.
A policy with a slightly higher premium can still be cheaper overall if it gives wider cover. That is why the cheapest quote is often the most expensive mistake.
The most useful question is this: what would the business actually pay after a claim? That answer is what should drive the choice.
Check exclusions and sub-limits
Exclusions are the bits the insurer refuses to cover. Sub-limits are small caps inside the main policy limit, and they often catch people out.
For example, a policy may offer £250,000 overall, but only £25,000 for social engineering losses. That can be a problem if a finance team is tricked into sending money to the wrong account.
The sub-limit matters because it works like a small pocket inside a larger coat. The coat looks big, but the useful pocket may be tiny.
Match dates to avoid gaps
Date matching matters more than most renewal emails admit. The new policy must start exactly when the old one ends, unless there is a deliberate overlap.
A one-day gap can leave a claim outside both policies. That is harsh, but it is how wording works.
The UK General Data Protection Regulation and the Data Protection Act 2018 may still create legal exposure if customer data is involved, so the insurance handover should be handled with care.
Before renewal
Check expiry date, excess, exclusions, sub-limits, and controls required by the underwriter.
At decision time
Compare total cost, not premium alone, then confirm the exact start time in writing.
After handover
Keep quotes, emails, and wording copies in case a future claim needs proof.
What insurers re-check at renewal
A renewal is a fresh underwriting review, not a rubber stamp. Insurers want to know whether the business has improved its controls or drifted into more risk.
That matters because cyber loss patterns change fast. A firm that looked tidy last year may now look exposed if passwords, backups, or access controls have slipped.
The Financial Conduct Authority’s Consumer Duty also pushes firms to give clearer outcomes and fair value. For SMEs buying insurance, that means the wording and service should still make sense, not just the price tag.
MFA, EDR and backup controls
Multi-factor authentication, endpoint protection, and backups sit near the top of most renewal questionnaires. These are simple controls with a big effect.
MFA is like a second lock on the front door. EDR is like a smoke alarm for laptops and servers. Backups are the spare keys and duplicate papers kept somewhere safe.
If those controls are weak, the insurer may raise the premium, narrow cover, or decline the risk. That is especially common after ransomware claims.
Incident response and recovery plans
Insurers want to know what happens when an attack lands. Who is called first, how systems are isolated, and how the business gets back online.
A short incident response plan helps here, even if no IT team exists. It can be a simple page with names, phone numbers, and the first five steps.
The NCSC and the Association of British Insurers both keep pushing the same message: preparation reduces damage and speeds recovery. That message is boring only until the first incident.
Claims history and cyber risk
A recent claim changes how the market sees the business. The underwriter may assume the same weakness could happen again unless controls have improved.
That does not always mean a bad outcome. It often means more questions, a higher excess, or tighter wording. The first mistake is assuming the same insurer will be more forgiving than a new one.
A case that comes up often is a small retailer that had one phishing loss, then accepted a renewal without checking the new social engineering wording. The next year the cover existed, but the useful part had shrunk.
“Cyber insurance can help organisations manage the financial impact of cyber incidents.”
Evidence that changes the quote
Insurers often want proof, not promises. Screenshots of MFA, backup logs, or proof of staff training can help the quote land better.
The image of a clean backup dashboard or MFA rollout often tells the story faster than a long email. In more than one renewal file, that single proof point can shift the underwriting mood.

Timing matters more than many SMEs realise, because renewal markets tighten when the request is left too late. Ideally, start reviewing the cyber insurance renewal at least 30 to 60 days before expiry so there is time to compare the renewal quote, chase questions and negotiate terms. If the insurer asks for evidence of MFA, EDR, backups or incident response plans, send it promptly and keep a copy of what was supplied.
A late change in turnover, headcount, cloud usage or supplier dependencies can also affect underwriting, so the business should update those details before the quote is finalised. Good documentation often makes the difference between a smooth renewal and a rushed decision made under pressure.
Renewal traps that catch SMEs out
The biggest trap is accepting a policy that looks familiar but behaves differently in a claim. Renewal letters are often tidy and polite. The wording hidden behind them can be less friendly.
There is also a timing trap. Many SMEs leave the review too late, then rush into the default renewal because they fear a gap. That is how bad terms slip through.
The UK Government’s cyber security guidance for businesses keeps the message simple: strong basics matter, and staff training still helps. If the insurer asks for those controls and the business cannot show them, renewal can turn expensive very quickly.
Auto-renewal on weaker terms
Auto-renewal feels easy. It can also lock in a weaker deal.
The policy may renew with a higher excess, a lower limit, or a tighter exclusion list. The owner notices only after a problem starts.
This is why a renewal notice should never be filed away unread. It deserves the same attention as a supplier contract or loan change.
Hidden cancellation and change fees
Switching can trigger costs that are easy to miss. Some policies charge for cancellation, while others reduce a refund in ways that are not obvious at first glance.
A lower annual premium can disappear once fees are added. That is why total cost needs to be checked over the full policy term, not just the headline figure.
Lower limits and broader exclusions
A renewal quote can look like the same cover while quietly removing useful protection. That is a classic renewal trap.
Watch for narrower business interruption wording, stricter outsourcing exclusions, or lower cover for social engineering and funds transfer fraud. These changes can matter more than the premium itself.
The wrong renewal decision often shows up only after a claim, when the small wording changes suddenly matter a lot.
Compare renew versus switch costs
The cost of staying and the cost of moving are not the same thing. A renewal quote may be simple, but a switch can bring a better long-term result if the handover is managed well.
The right comparison includes premium, excess, sub-limits, exclusions, cancellation charges, and any loss of incident response support. If one quote is cheaper only because it hides weaker help after an attack, it is not cheaper at all.
The Lloyd’s market often uses tighter wording after cyber claims, and that is one reason comparing on price alone can mislead buyers. Cost and cover have to be read together.
Premium versus total cost
The premium is the yearly price. Total cost is what the business would really feel if an incident happened.
A policy with a low premium and a £10,000 excess may be worse than a slightly dearer one with a £1,000 excess. The difference can swallow the saving in one claim.
Response services and claims handling
Many cyber policies now include incident response help, legal support, and access to breach advisers. Those services can save time and reduce damage.
The quality of claims handling matters too. A fast, clear response after a breach is worth paying for, especially for SMEs without in-house specialists.
A policy that looks cheaper but leaves the owner chasing five different contacts after a ransomware event is not a bargain. It is stress with a discount label.
Comparison table: renew or switch
| Factor |
Renew with current insurer |
Switch at renewal |
| Premium |
Often simpler to predict |
Can be lower or higher depending on controls |
| Excess |
May rise without much notice |
Can improve if the new market is stronger |
| Exclusions |
Can narrow after a claim |
Can be wider, but needs checking |
| Claim continuity |
Usually simple if wording stays steady |
Needs exact start and end dates |
| Admin effort |
Lower effort |
More work, but sometimes worth it |
Costs that sit outside the premium
Some costs never appear in the headline number. Cancellation charges, extra legal support, and a higher excess can change the maths quickly.
That is why the renewal decision should use a simple side-by-side sheet. The owner does not need a finance degree. Just a full picture.
The biggest mistake is comparing only the premium and ignoring what happens after a claim. A renewal with a modest premium increase may still be the better deal if the claims process is quicker, the excess is lower and the policy exclusions are narrower. By contrast, a cheaper switching offer can be poor value if it adds a higher excess, removes social engineering or business interruption cover, or slows down incident response support when the business needs it most.
SMEs should compare the likely out-of-pocket cost after a realistic cyber event, not just the upfront price, because that is where the true difference between renewing and switching becomes obvious.
How to switch insurers without a gap
Switching safely is mostly about timing and paper trail. The new insurer should confirm the start date in writing, and that date should match the old expiry date.
The handover should be boring. Boring is good here. It means the business is not improvising with cover.
If the new insurer wants extra information before binding cover, send it early. Delays at the last minute are how gaps appear.
Confirm the expiry date first
Start with the current policy’s exact end date and time. Do not guess it from the email.
Check whether the policy ends at midnight or another set time. Small details like that decide whether the new cover begins safely.
Ask for written start confirmation
The new insurer should confirm the start date and time in writing. That confirmation is the anchor point.
If the broker or insurer cannot do that, pause the switch. A promise on the phone is not the same as a written contract.
Keep evidence of continuity
Keep the old schedule, the renewal quote, the acceptance email, and the new schedule together. If a claim later sits near the switch date, those files can settle the argument fast.
A simple folder is enough. Save the policy wording too, since the wording is what the claim will be judged against.
Short switch checklist
- Check the exact expiry time on the current policy.
- Confirm the new policy start time in writing.
- Make sure the dates touch, or overlap if needed.
- Keep copies of all quotes, emails, and policy wordings.
- Do not cancel the old policy until the new one is live.
Documents and checks insurers want
Insurers ask for evidence because they are pricing the risk, not guessing it. The cleaner the file, the easier the renewal or switch.
This section often gets rushed, yet it can move the price more than people expect. A tidy renewal pack can save time and avoid awkward back-and-forth.
The Information Commissioner's Office keeps reminding businesses that good data handling still matters. That matters here too, because insurers like to see signs of control, not hope.
Security questionnaire and controls
Expect questions on MFA, patching, backups, admin access, and staff training. Those are now standard for many cyber quotes.
If a question asks whether backups are tested, the answer should be clear. “Yes” is weak. “Yes, tested monthly and stored offline” is better.
Incident logs and previous claims
If a business has had a breach, the insurer will want to know what happened, what was fixed, and what changed afterwards.
That is fair. It helps the underwriter see whether the risk is now lower or still shaky.
Updated turnover and data profile
Changes in turnover, staff numbers, or customer data volumes can change the price. More data usually means more exposure.
A retailer taking card payments, for example, has a different risk picture from a small consultancy that stores mainly contact details.
Board approval and policy wording
The final decision should be written down, even for a small firm. A short note in the renewal file helps later.
Keep the accepted wording too. The wording is the actual contract, not the sales summary.
This does not work well if the business leaves renewal until the last few days. Then the market has less time, and the options get thinner.
Best-practice renewal checklist for SMEs
A good renewal decision starts early and ends with a written confirmation. The process does not need to be complex, just disciplined.
The practical rule is this: review early, compare properly, and only then bind cover. That sequence protects both cost and continuity.
For many SMEs in England, a sensible renewal review starts about 30 days before expiry. That gives enough time to gather documents, compare quotes, and avoid a rushed decision.
Thirty-day pre-renewal check
At 30 days out, check the current wording, the renewal quote, the excess, and any new exclusions. Ask whether the business has changed in the past year.
If the answer is yes, the insurer should see those changes too. More staff, more laptops, new software, or more data can all matter.
Seven-day final confirmation
At seven days out, the business should know whether it is renewing or switching. That choice should already be locked in.
Then confirm the start and end times in writing. This is the last sensible point to catch a date mistake.
Red flags before you accept
Treat these as warning signs: a sudden premium jump, a larger excess, a smaller response service, or a new exclusion on business interruption.
Also watch for control requirements the business cannot meet. If the underwriter now wants tools or backups that do not exist, the renewal is already under strain.
A simple decision rule
If the current policy still fits, the insurer is steady, and the price rise is modest, renewal often makes sense. If the wording has weakened, the total cost has climbed, or the insurer has tightened requirements, switching at renewal can be the better call.
The right answer is rarely emotional. It is usually arithmetic with a time limit.
Frequently asked questions
Should a small UK business always switch cyber
No, not always. A switch only makes sense when the new policy gives better value, stronger cover, or a cleaner claims path. Many SMEs are better off renewing if the wording still fits and the total cost stays fair. The key is to compare the premium, excess, exclusions, and support together.
What is the biggest risk when switching insurers
The biggest risk is a coverage gap. If the new policy starts even one day late, an incident in that gap may not be covered. That is why the dates must line up exactly, or overlap briefly if needed. Keep written proof of both policies and their start and end times.
Does the cheapest renewal quote usually offer the best value?
No, it often does not. A low quote can hide a higher excess, tighter exclusions, or weaker incident response support. A policy that costs a bit more can be better value if it pays more when a breach or ransomware event happens. The full cost picture matters more than the headline premium.
Can an insurer refuse to renew if MFA or backups
Yes, it can happen. Many underwriters now re-check MFA, backups, endpoint protection, and recovery plans before renewal. If those controls are weak, the insurer may raise the premium, reduce cover, or decline the risk. That is why pre-renewal checks should happen before the deadline, not after.
Does switching insurers improve GDPR fines cover?
Sometimes, but not automatically. Under UK GDPR and the Data Protection Act 2018, many policies do not cover regulatory fines in full, and some cover only defence costs. A new insurer may offer better wording, but the business must read the fine print. Check whether the cover includes investigation costs, defence, and any legal limits.
What documents do insurers usually want at renewal?
Most want a completed questionnaire, details of security controls, turnover, data volumes, and any claims history. Some also ask for proof of MFA, backup testing, and incident response steps. Clear answers help the quote and reduce back-and-forth. Keep the latest policy wording beside the renewal pack too.
When should a business start reviewing a cyber policy?
About 30 days before expiry is a sensible point for most SMEs. That gives enough time to compare quotes, check exclusions, and fix any missing documents. Waiting until the final week often leads to rushed choices. If the business has grown or had a claim, start even earlier.
The plan that avoids renewal regret
The safest renewal decision is the one made early, with the full wording in front of it. Renew if the current policy still fits and the total cost is reasonable. Switch if the new insurer gives better value and the dates can be matched without a gap.
The best result comes from one habit: never judge a cyber renewal by price alone. Read the exclusions, check the excess, confirm the support, and lock the handover in writing. That is how SMEs keep cover steady and avoid a nasty surprise later.
If you decide to switch insurers at renewal, the safest approach is to work backwards from the expiry date and treat the handover like a controlled transfer. Start by asking your broker or the new insurer for a binding confirmation that includes the exact start time, then check the current policy end time so the dates meet cleanly. Send any outstanding underwriting information early, because missing answers can delay binding. Only cancel the old policy once the new schedule is issued and checked, and keep both policy wordings, quote documents and acceptance emails together.
That way, if a claim lands near the switch date, you have proof of cover continuity and a clear paper trail showing there was no gap.