For many UK SMEs, the first cyber insurance quote looks either oddly cheap or worryingly high. The problem is rarely the cover on the page; it is the excess, the limit, the turnover band and the type of business behind it. A shop with no online payments will not be priced like an accountant, agency or retailer handling card data every day.
Cyber insurance price benchmarks for UK SMEs vary widely, but the right comparison depends on turnover, employee count, sector, cover limits and excess. Small low-risk firms may pay a few hundred pounds a year, while data-heavy or online businesses often pay more. The key is comparing like-for-like cover, not headline premiums, so a quote can be judged quickly and with confidence.
Cyber insurance costs: the real UK SME price range
Most small UK firms sit in a wide band, not a single neat price. A simple quote for a low-risk business can start at about £250 to £750 a year, while online retailers, firms handling client data or businesses with payment exposure often see £1,000 to £5,000 plus.
The reason is simple. Insurers price the risk, not the label on the door. A ten-person design studio and a ten-person law firm can face very different premiums because one holds basic project files and the other handles sensitive client records.
The Association of British Insurers and the National Cyber Security Centre both point to rising attack volumes across UK firms, and insurers react to that pressure in their pricing. The exact premium still depends on the risk assessment, the controls in place and the size of the potential loss.
A quote that is 20% cheaper can still be worse value if it carries a £10,000 excess, a £25,000 sub-limit on ransomware, or no cover for business interruption.
What a small SME usually pays
Very small firms with low digital exposure often see the lowest end of the market. A micro-business with under £1m turnover, few employees and modest customer data handling may see premiums from about £250 to £600 a year.
Once a firm moves into regular card payments, online bookings or larger customer records, the range usually shifts. Many English SMEs in the £1m to £5m turnover band see quotes from about £600 to £2,000, with wider spreads when the business depends on systems every day.
A quote near the bottom of that band is not always a bargain. It may be like buying a cheap umbrella with a hole in the middle. It looks fine until the rain starts.
What pushes the price up fast
Sector matters because some businesses hold more valuable data or face more frequent attacks. Legal services, accountancy, healthcare, retail and online trading usually sit above lower-risk local service firms.
The biggest price jump often comes from payment handling, remote access, older systems and weak security basics. If the insurer sees no multi-factor authentication, poor patching or weak backups, the premium can rise fast, or the quote can vanish entirely.
<Data from UK claims patterns is useful here. The Information Commissioner's Office reported 3,398 personal data breach reports in Q1 2024, which helps explain why insurers scrutinise data handling so closely. ICO data breach trends
Which quote details matter most
The headline premium matters, but only after the policy terms. A £900 quote with a £1,000 excess and £250,000 cover can be better than a £700 quote with a £5,000 excess and £50,000 cover.
Look for these details in every quote:
- Cover limits: the most the insurer will pay for the policy year.
- Policy excess: what the business pays first on each claim.
- First-party cover: costs the business suffers itself, such as recovery and interruption.
- Third-party liability: claims from customers or other outside parties.
- Incident response: help after a breach or ransomware event.
Elige esto si: your business is small, low-risk and wants a rough annual budget before comparing quotes.
Benchmarks by turnover, staff and sector
The fairest way to compare cyber cover is by business size and exposure, not by headcount alone. Turnover gives a useful first filter, staff count shows how many people and devices may need protection, and sector tells you how attractive the business looks to attackers.
What turnover bands usually indicate
Turnover often acts as a rough proxy for data volume and operational dependence. A business with under £1m turnover may pay hundreds rather than thousands, while firms between £1m and £5m often move into the £600 to £2,000 range, depending on controls and claims history.
Once turnover passes £5m, underwriters often look harder at systems, suppliers and incident planning. At that point, premiums can move into the low thousands, especially if the business uses cloud systems, takes online payments or stores customer records at scale.
A useful benchmark is this: the more the business would struggle after a systems outage, the more the insurer tends to charge.
Why headcount changes underwriting
Employee count matters because it affects the number of logins, devices and human mistakes. A 5-person business has fewer doors to lock than a 50-person business, and every extra user gives attackers another try.
That does not mean staff count is the main price driver on its own. A five-person solicitors' practice can cost more to insure than a 20-person local trades firm if the first holds sensitive client files and the second holds little personal data.
The error most often seen here is treating headcount as the whole story. It is only one piece of the picture.
Which sectors pay more in england
Sectors with sensitive data, payment flows or downtime risk usually pay more. Legal, accountancy, healthcare, e-commerce, recruitment and professional services often sit above a simple local services or light manufacturing risk profile.
A small online retailer in London can face a different premium from a small plumbing firm in Kent, even if both have the same turnover. The retailer has payment data, website reliance and higher fraud exposure.
The British Insurance Brokers' Association regularly notes that the best cyber quote comes from a clear risk profile, not a generic business description. That is why sector wording in the proposal form can change the price.
Typical benchmark: a low-risk micro-business may see £250 to £750 a year, while a data-heavy SME can move past £2,000 if the limits are higher and controls are weaker.
| SME profile |
Typical annual premium |
Typical excess |
Typical cover limit |
Price signal |
| Micro-business, low risk |
£250 to £750 |
£250 to £1,000 |
£50,000 to £250,000 |
Often basic cover only |
| Small SME, moderate risk |
£600 to £2,000 |
£500 to £2,500 |
£250,000 to £500,000 |
Common for firms with customer data |
| Data-heavy or online business |
£1,500 to £5,000+ |
£1,000 to £5,000 |
£500,000 to £1m+ |
Higher cost reflects exposure |
Elige esto si: you want to place your own quote in a realistic band before asking a broker to review it.
What a low premium can hide
A cheap policy can look sensible until a claim arrives. Then the small print matters far more than the price tag.
The most common hidden problem is a narrow scope. Some policies cover only a breach response, but not the lost income from systems being down. Others cover the initial clean-up, yet cap ransom response, legal support or customer notification at very low amounts.
Why cheap cover can fail in a claim
A low premium often means the insurer has trimmed the policy somewhere. That may be a lower limit, a larger excess, a smaller service panel or stricter wording on what counts as a cyber event.
A claim can also fail if the business did not meet basic security conditions. Missing patches, weak passwords, no backups or poor access control can all create problems at claim stage.
This is why many SMEs only spot these gaps after a breach. By then, the quote has turned into a very expensive lesson.
Which exclusions to check first
Start with the exclusions that most often catch SMEs out. These are the ones that usually change the real value of the policy.
- Misconfiguration: cover may fail if a system was set up badly.
- Failure to maintain: old software or ignored updates can void support.
- Unapproved third parties: some providers must appear on the insurer's panel.
- Fraud carve-outs: social engineering or payment scams may be limited.
- Uninsured loss categories: some policies exclude reputational harm or certain fines.
The Financial Conduct Authority expects firms to treat customers fairly, and insurance products should be sold clearly. That does not stop the buyer from checking the wording line by line before signing.
How sub-limits reduce real value
A sub-limit is a mini cap inside the main policy limit. Think of it like a wallet inside a handbag. The bag may look big, but one pocket can still run out fast.
Ransomware response, forensic investigation, payment card support and public relations costs often sit under separate caps. A policy with a £250,000 overall limit can still be weak if ransomware support is capped at £25,000.
Look out for this phrase in the schedule: “sub-limit applies”. It often means the headline number tells only part of the story.
Elige esto si: you are reviewing a cheap quote and want to know whether it hides weak terms.
Cover levels that change the price
The main price jump usually comes from the scope of cover, not just the insurer's brand. A policy that includes business interruption, ransomware support and third-party liability costs more than a bare-bones option.
What first-party cover includes
First-party cover pays for the business's own losses. That can include system recovery, data restoration, extortion response, crisis help and the cost of telling affected customers.
For many SMEs, this is the part that matters most. If email stops, stock cannot move or online sales freeze, the firm can lose cash every day.
A policy that only covers technical clean-up may leave the cash loss untouched. That is a common and expensive gap.
What third-party liability adds
Third-party liability covers claims from others. A customer, supplier or partner may say the breach harmed them, and that can bring legal costs or compensation demands.
This cover matters more for firms handling personal data, payment data or client files. A small solicitor, agency or accountancy practice can face this risk even if its own direct losses are modest.
The Information Commissioner's Office does not hand out cyber insurance, of course, but its enforcement work shows why this area matters. UK GDPR and the Data Protection Act 2018 create real pressure after a breach.
The ICO can fine firms for data protection failings, but many cyber policies focus on breach response costs rather than the fine itself.
When business interruption matters most
Business interruption cover pays for lost income when systems fail after a cyber event. It matters most for firms that sell online, run bookings, or depend on live systems to trade.
A bakery with a broken website may lose some orders. An online retailer may lose every order for days. That is why the same cover has very different value across sectors.
Lloyd's of London and several specialist markets often tie interruption cover to clear proof of systems resilience. If the business cannot show backups and recovery steps, pricing can rise or cover can narrow.
| Cover level |
What it usually includes |
Price effect |
Best fit |
| Basic |
Breach response, limited recovery |
Lowest |
Very small, low-risk firms |
| Standard |
Recovery, interruption, liability |
Mid-range |
Most SMEs with customer data |
| Broader |
Higher limits, more services, wider trigger |
Higher |
Online, regulated or data-heavy firms |
Elige esto si: your business would lose money quickly if systems stopped or customer data leaked.
A useful way to benchmark cyber insurance premiums is to compare the same business profile with different levels of cover. For example, a micro-SME might be quoted around £350 to £500 for basic SME cyber cover with a £2,500 policy excess, £100,000 cover limits and limited incident response. If that same firm wants stronger business interruption cover, ransomware cover and third-party liability, the price can move closer to £700 to £1,200, especially where payment card data is held or remote access is widespread.
In practice, lower excesses and higher cover limits tend to push premiums up together, because the insurer is taking on more of the loss and more of the volatility.
Real-world scenarios make the price bands easier to judge. A five-person accountancy practice with good security controls, multi-factor authentication and limited client data might see a quote around £450 to £900 a year for first-party cover and modest third-party liability. A retailer processing payment card data, with business interruption cover and ransomware cover included, could land closer to £1,200 to £3,000 depending on turnover band, sector risk and the size of the policy excess.
An online agency with a higher limit, broader incident response support and weaker security controls may be priced above that, even if the headcount is small, because the data breach risk and downtime exposure are materially higher.
Excess and limits: the value test
The right policy is not the cheapest one. It is the one where the premium, excess and limit fit the firm's real exposure.
How excess changes your real cost
The excess is the amount the business pays before the insurer starts paying. A policy with a £5,000 excess may look cheaper at renewal, but it can hurt cash flow after a breach.
For a small firm, a high excess can make a claim feel almost pointless. If the likely loss is £8,000 and the excess is £5,000, the insurance only helps a little.
A good rule is simple: the excess should stay below the amount the business can pay without stress.
Why low limits distort value
A low limit can be fine for a tiny business with little digital exposure. It is weak for a firm that stores personal data, processes payments or depends on live systems.
A £50,000 policy may look affordable, yet one ransomware event can burn through that limit fast. For most SMEs, legal costs, IT recovery and interruption quickly stack up.
The UK Government's cyber security guidance and the National Cyber Security Centre both stress basic resilience because small incidents can create large losses. Insurance follows the same logic.
A simple quote comparison matrix
Use this when comparing two or three offers. Match the same cover first, then compare price.
| Quote A |
Quote B |
Better value if... |
| £850 premium, £1,000 excess, £250,000 limit |
£720 premium, £5,000 excess, £100,000 limit |
Quote A, if a claim could be costly |
| £1,300 premium, £2,500 excess, ransomware included |
£1,050 premium, £2,500 excess, ransomware capped at £25,000 |
Quote A, if ransomware would hurt trading |
Elige esto si: you want to judge price against real payout potential, not just the annual bill.
How insurers actually set the price
Insurers price cyber cover using a mix of underwriting questions, risk controls, sector exposure and claims history. That is why two similar firms can see different premiums.
Which controls reduce premium pricing
Simple controls can help. Multi-factor authentication, regular patching, offline backups and staff training often improve the quote.
These controls do not make the risk disappear. They just lower the chance that a basic attack turns into a large loss. That is enough for many underwriters to soften the price.
The National Cyber Security Centre's guidance on the Cyber Essentials approach lines up with this. Basic controls are not glamorous, but they lower real-world risk.
Why claims history matters
A previous breach can push the premium up at renewal. Insurers read it as a sign that the business may face the same problem again.
A clean claims record can help, but it will not rescue weak controls. Good security matters more than a quiet past.
A common case is a retailer with no prior claim that still pays more after a poor security review. The insurer sees weak backups and weak password control, then prices the quote as if a problem is waiting to happen.
Where UK benchmark data comes from
Useful benchmarks come from a mix of market quotes, broker data, insurer guidance and public breach reports. No single source tells the whole story.
The Information Commissioner's Office provides breach figures. The Association of British Insurers gives market context. The British Insurance Brokers' Association helps explain how policies are actually sold in practice.
That mix matters. A benchmark without method is just a number with confidence issues.
The best benchmark is a quote set from the same sector, similar turnover and similar cover limits, not a single average premium from a mixed market.
Elige esto si: you want to understand why one insurer quoted less and another quoted more.
These benchmark ranges are best understood as market-style estimates rather than fixed tariffs. They are typically drawn from broker quotations, insurer appetite, published underwriting guidance and public breach trends, then grouped by turnover band, employee count and sector risk to make like-for-like comparisons easier. That matters because cyber insurance premiums are rarely priced from turnover alone: a business with strong security controls, multi-factor authentication and limited payment card data exposure can sit below a less secure peer of the same size.
The ranges in this article therefore reflect relative market positioning, not a single national average, and should be read as practical price benchmarks for UK SMEs rather than guaranteed quotes.
How to compare quotes without missing the catch
A good comparison starts with the policy wording, not the price. If the cover, excess and exclusions do not match, the quotes are not equal.
Which questions to ask brokers
Ask whether the policy covers ransomware, business interruption, data breach response and third-party claims. Then ask what the insurer excludes, caps or requires before paying.
Also ask who handles the claim. Some insurers use a strong incident response team. Others leave the business to manage the first chaotic hours alone.
How to compare like with like
Put the quotes side by side and match five points: premium, excess, cover limit, sub-limits and exclusions. If one quote is missing a point, ask for the wording in writing.
This is where many buyers go wrong. They compare the annual fee, not the shape of the cover. It is like comparing car insurance without checking whether theft is included.
When to walk away from a quote
Walk away if the insurer will not explain exclusions clearly. Walk away if the excess is too high for the firm's cash flow. Walk away if the policy limit looks generous but the key parts are capped too tightly.
The UK Government and the ICO both expect firms to handle personal data properly. A policy that ignores that reality may be cheap, but it is not helpful.
Elige esto si: you have two or three quotes and need a clean way to spot the real difference.
What nobody tells you about cyber quotes
The best premium is not always the one you can negotiate down. Sometimes the best move is to accept a slightly higher price for a policy that will actually respond when needed.
This works well for firms that hold customer data or rely on online sales. It works less well when the insurer loads too many conditions onto the policy. In that case, the quote can look strong on paper and weak in real life.
One thing most guides miss is that pricing also reflects claims handling quality. A firm may happily pay a bit more if the insurer answers fast after a breach and does not argue over every line of the loss.
Another quiet point is this: some businesses should not chase the lowest premium at all. If the business would struggle to survive a week offline, policy quality matters more than saving £200 a year.
Elige esto si: you want a policy that behaves well in a real incident, not just on the comparison sheet.
This pricing guide is less useful if the business already has a highly tailored policy, wants only technical cyber security help, or has no meaningful digital exposure. In those cases, the right answer may be a policy review, an IT control review, or no stand-alone cyber cover at all.
Questions to ask before you buy
Does this cover my real exposure?
Yes, if the policy matches how the business actually works. A firm with online sales needs business interruption and payment-related cover. A professional practice with sensitive files needs strong breach response and liability support.
The right question is not “Is this cyber insurance?”. It is “Would this policy help if email stops, files lock up or customer data leaks?”. That test cuts through the marketing fast.
Is this compliant with UK rules?
The policy should sit comfortably alongside UK GDPR, the Data Protection Act 2018 and any sector rules that apply. It does not replace compliance, but it should support it.
For payment handling, firms should also check whether any card or payment obligations change the risk picture. A policy that ignores those duties may leave a gap when the business needs help most.
Do I need a higher limit?
A higher limit makes sense when one breach could create several types of loss at once. Recovery, legal help, notification, lost income and outside claims can stack up quickly.
If the business is small and low-risk, a modest limit may be fine. If the business handles lots of data or relies on online trading, a low limit can run out too quickly.
What should I compare first?
Compare excess, cover limit and exclusions before premium. Those three items tell most of the real story.
If those three do not line up, the cheapest quote is usually not the best one. That is the clearest shortcut available.
Can I negotiate the price?
Yes, sometimes. Better controls, lower limits, a higher excess or clearer security evidence can improve the quote.
The smarter move is often to negotiate the terms, not just the number. A slightly lower price with worse cover can still leave the business exposed.
What if no quote feels right?
Then the market is telling the business something useful. Either the exposure is high, the controls are weak, or the requested cover is too broad for the current risk profile.
In that case, step back and review the security basics first, then ask for new quotes. A cleaner risk profile usually opens better terms.
Elige esto si: you are ready to buy, but want the final checks before signing.
Which quote fits your situation
Choose the cheapest quote only when the business is tiny, low-risk and has very limited digital exposure. Even then, the policy must still cover the losses that would hurt most.
Choose the mid-range quote for most UK SMEs. That is usually the sweet spot when the business handles customer data, uses cloud systems and wants proper breach response, interruption cover and liability protection.
Choose the higher-priced quote when online sales, client confidentiality or payment risk could create a large loss. In that case, a stronger policy often saves money if a real incident happens.
The best decision is blunt: if one quote looks cheaper but fails on excess, limits or exclusions, reject it. A good cyber policy should make a breach manageable, not just look affordable on paper.
If the business has no meaningful digital exposure, stand-alone cover may be the wrong product. If it already has a tailored policy, ask for a review instead of starting from scratch.
Who helps if I am attacked?
A useful policy gives access to people who can act quickly. That may include forensic specialists, legal support, breach notification help and ransom negotiators.
If the insurer only promises money later, the cover may feel thin in the moment of crisis. Speed matters more than many buyers expect.