Yes, cyber insurance can suit SMEs with legacy systems. Coverage often has gaps for unsupported or bespoke software, so check wording and declare assets. Ask your broker for time‑bound endorsements while you fix or isolate legacy systems.
Which UK SMEs with legacy systems are eligible?
Insurers may cover SMEs that show controls and a clear remediation plan. Evidence helps underwriters assess risk and offer conditional cover.
What underwriters want
Underwriters want an up‑to‑date asset inventory and patch history. Proof of backups and network segmentation also helps.
Practical eligibility criteria
SMEs that show asset lists, MFA on admin accounts, and tested backups get better terms. Acceptance still depends on how many legacy assets exist and how critical they are. Underwriters often add loadings, exclusions, or time‑bound endorsements for high‑risk EOL systems.
Start with a clear inventory and simple mitigation steps.
Evidence that speeds binding
A managed service agreement speeds acceptance. A recent penetration test report also helps reduce loadings.
A suitability check must go beyond a simple inventory. Translate technical traits into insurance outcomes.
An internet‑exposed server on an end‑of‑life Windows variant draws higher compromise risk. An isolated legacy POS often contains damage when segmentation works.
Underwriters look at attack surface, patchability, and business criticality. They also check compensating controls such as segmentation, EDR, and MFA.
Use a simple insurability score like low, medium, high. This score helps brokers set expectations and agree remediation milestones.
Make files short and timestamp every key action.
Common policy exclusions for legacy technology risks
Most policies exclude unsupported software, known unpatched vulnerabilities and systems outside the declared scope. Read policy wording closely to spot limits.
Unsupported or end-of-life software
Policies often exclude loss caused by software that is end of life or no longer supported by the vendor. Check vendor support dates against your inventory.
Known vulnerability and patch clauses
Policies may require reasonable patching and can exclude incidents from vulnerabilities known before policy inception. Keep timestamps and evidence of patch activity.
Scope and boundary exclusions
Some wordings exclude losses where the affected system sits outside the declared network or asset inventory. Declare all material systems when you bind cover.
A clause that seems ordinary can exclude EOL software. Read any line that mentions maintenance or support dates.
Insurers repeat a set of exclusion themes and clause phrasings. Common phrases include loss caused by use of end‑of‑life software and loss from known unpatched vulnerabilities.
Insurers may add sub‑limits for losses tied to legacy systems. Check whether the policy defines end of life by vendor support date, patch availability, or by the insurer’s own schedule.
Real claims: how legacy systems drive payouts
Legacy systems increase downtime and raise forensic and remediation bills, which drives larger claim sizes. Expect longer forensic timelines when systems are obsolete or bespoke.
Ransomware and unpatched servers
A legacy, externally facing server commonly leads to extended downtime and larger business interruption claims. Recovery times often exceed typical SLAs.
Data theft via old POS
Unpatched payment systems expose cardholder data and can trigger ICO notification costs and fines under the Data Protection Act 2018. PCI scope work also adds cost.
Forensics and contested claims
Claims handlers often request patch logs and restore evidence. Lack of clear records can prompt sub‑limits or declined cover.
The most frequent error is assuming a standard cyber policy covers such failures. If the wording does not mention unsupported software, the insurer can decline.
Representative, anonymised claim scenarios illustrate how legacy technology amplifies loss and shapes claim outcomes.
-
Scenario A (2022): a retail business ran a customer database on an unsupported server. Attackers deployed ransomware and demanded £120,000. Forensic and incident response fees cost about £40,000. Three weeks of lost sales added about £200,000. The insurer paid incident response but capped ransom payments. It also raised the excess and required staged remediation.
-
Scenario B (2021): an independent café used an end‑of‑life POS system. Card skimming forced ICO notifications and reissue costs. Forensic PCI‑DSS scope work cost about £70,000. The insurer paid some forensic costs but contested fines.
These examples show how costs split across ransom, forensic, BI, and regulatory items. Policy wording, declared asset status, and timely evidence decide the recoverable amount.
Hidden costs, excesses and underwriting trade-offs
Legacy exposure usually appears in price, excess and sub‑limits rather than a simple yes or no on cover. Plan for cost loadings even when cover exists.
How endorsements work
Insurers use time‑bound endorsements to allow cover while remediation occurs. These give the insured breathing room to fix issues.
Excesses and sub‑limits
Expect higher excesses for incidents caused by legacy assets. Underwriters also set lower sub‑limits for incident response or ransom demands.
Market options and capacity
Specialist cyber markets, including Lloyd's syndicates, may offer capacity with stricter conditions. They often attach tighter milestone requirements than mainstream insurers like Aviva or Hiscox.
Most guides say patch and insure. They often omit that insurers will accept staged remediation plans. This works well in theory, but in practice underwriters need clear milestones and documentary evidence to remove endorsements.
Checklist: assessing suitability and gaps for legacy SMEs
A broker should submit evidence, not promises, to underwriters. Pack files so an underwriter can verify them quickly.
Underwriting checklist for brokers
- Asset inventory with device type, OS and support status.
- Patch history or vulnerability scan timestamps.
- Network diagram showing segmentation for legacy assets.
- MFA evidence for remote and admin access.
- Backup logs and restore test results.
- Incident response plan and retention of a digital forensics contact.
- Evidence of any Cyber Essentials or ISO/IEC 27001 work.
How to present the evidence
Label documents clearly and include timestamps. Underwriters accept screenshots, logs and signed MSP statements.
Broker submission template
Submission: [Company name] Summary:
- Legacy assets declared
- Remediation plan attached. Assets: [CSV of devices with OS and EOL date]
- Controls: MFA enabled (yes/no)
- Backup: off-site tested [date]
- Segmentation diagram attached
Requests: Conditional endorsement for EOL asset X until [date]. Contacts: MSP name, incident response retained firm.
Affordable mitigations SMEs can use
Small steps give big benefits for underwriting and real security. Start with items that cost little and add clear evidence.
Enable MFA, check backups, isolate legacy devices, and run endpoint detection. These actions often cut immediate risk.
Mid-term steps that underwriters accept
Document patch schedules and a time‑bound remediation plan. These often turn a declinature into conditional cover.
When to outsource to an MSP or MSSP
Hire an MSP if no in‑house IT exists. A retained MSSP helps with monitoring and faster detection.
1
List and labelInventory every device and mark EOL status.
2
Contain and back upIsolate legacy systems and verify tested off‑site backups.
3
Agree conditional coverAsk broker for time‑bound endorsement while remediating.
Underwriting decisions hinge on precise words in your submission. Use exact language when you list systems.
Words to check in the policy
Look for "end of life", "unsupported", "known vulnerability", "patch required" and "scope of cover". Flag any phrase that limits cover for EOL items.
Sample claim notification wording
To: [Insurer claims email]
Policy: [Policy number]
Incident date: [DD/MM/YYYY]
Summary: Ransomware event affecting server [ID]. Server listed as EOL in our submission dated [date]. Compensating controls: backups tested [date], network segmented, MFA applied to admin accounts. Request: Emergency incident response assistance and confirmation of cover.
Attachments: Inventory.csv, backup_test.pdf, segmentation_diagram.pdf
Negotiating conditional endorsements
Ask for a time limit and clear milestones. Request monthly evidence submissions and removal upon verification.
| Endorsement type |
What it does |
Typical term |
| Time‑bound remediation |
Cover allowed while fixes are planned |
60–180 days |
| Sub‑limit for legacy cause |
Lower cap for costs tied to EOL systems |
Permanent until removed |
| Exclusion with carve‑back |
Excludes EOL but covers if controls present |
Negotiable |
The plan to follow
Start by making a short remediation plan and share it with your broker. A clear plan speeds binding and improves negotiating position.
First 30 days
Create an asset list, confirm backups, and enable MFA on cloud accounts. Label assets with EOL dates and vendor support info.
Next 90 days
Segment legacy systems and agree milestones with the insurer. Provide monthly evidence to show progress.
Long term
Replace or properly isolate legacy assets and keep documented patch and backup logs. This preserves future insurability.
The guidance above does not apply when all systems are current and patched, or when the primary risk is non‑cyber operational risk. Also it is not a substitute for legal or regulatory advice when regulatory liability or professional indemnity cover is required.
Use the broker checklist and sample claim wording above to start renewal conversations and to ask for a conditional endorsement while remediation proceeds.
Ask your broker to negotiate a conditional endorsement if remediation will take over 30 days.
Frequently asked questions
SMEs that document controls and a remediation timeline often secure conditional cover. Provide asset lists, backup tests and MFA evidence to the broker.
Does standard cyber cover pay for ICO fines?
Many cyber policies exclude or limit cover for regulatory fines and penalties; wording varies between insurers. Some policies offer specific regulatory-cost cover, while others explicitly exclude statutory fines or treat them as uninsurable under local law. Firms must check the exact policy wording and any jurisdictional limits.
What evidence will underwriters accept for legacy systems?
Underwriters accept screenshots of patch logs, automated vulnerability scans with timestamps and signed MSP statements confirming segmentation. These reduce the chance of endorsements.
Can insurers refuse to cover a breach caused by unsupported software?
Yes — if the policy contains an exclusion for unsupported software and the incident matches that wording. Disclose EOL assets at submission to avoid contested claims later.
How much can premiums rise because of legacy exposure?
Premium increases vary widely; some markets add 10–100% depending on exposure and controls. Presenting a remediation plan often limits the increase.
Is a time‑bound endorsement a common compromise?
Yes. Insurers frequently allow temporary cover for legacy assets while remediation happens, with milestones and proof required to remove the endorsement.
Final steps
Prepare the broker submission using the checklist and claim template above, and ask the broker to negotiate a conditional endorsement if full remediation will take over 30 days. Include the document pack below when you submit the case.
Document pack to send to broker
- Asset inventory CSV
- Patch history or vulnerability scans
- Backup test evidence
- Network diagram and segmentation proof
- Remediation timetable with milestones
Useful reference
Official guidance for small businesses on basic cyber security is available from the National Cyber Security Centre: NCSC small business guide.