A cyber policy can look solid on paper and still leave your SME out of pocket. A high excess can take a painful bite out of a ransomware or fraud claim, while a low sublimit can quietly cap the money you get for business interruption, recovery costs or payments to third parties. That can mean the difference between a manageable wobble and a cash-flow problem.
Excesses & sublimits: Will they break the bank? Yes, they can materially reduce what a UK SME gets paid after a cyber claim, sometimes by thousands of pounds. A high excess means you pay more upfront; a low sublimit can cap key costs such as ransomware, business interruption or fraud. The safe approach is to check the limits, compare them against likely losses, and negotiate weak points before renewal.
Will a high excess or sublimit hit your SME hard?
A high excess is the amount you pay before the insurer starts paying, and a sublimit is a smaller cap inside the main policy limit. In plain English, the policy may look large on the front page but still pay far less for the parts that matter most.
The real trap is that small and mid-sized claims often hurt most. If your business suffers a one-day lockout, a £7,500 fraud loss, or a short outage, a high excess can wipe out the benefit of claiming at all.
How much could you pay on a £25k claim?
You could pay between £2,500 and £15,000 on a £25,000 cyber claim, depending on the excess and any sublimit on the affected cover. That is the difference between an annoying claim and a painful one.
A £2,500 excess on a £25,000 incident is usually manageable for an SME with cash in reserve. A £10,000 excess on the same claim can swallow 40% of the loss before the insurer starts writing cheques.
A low excess sounds attractive, but it can push the premium up for cover you may never use. In practice, the best excess is the one your business can absorb without stress, not the lowest number on the page.
The error most often seen here is choosing a low premium with a high excess, then finding the first real incident is too small to claim. That leaves the SME paying the whole bill anyway, but with less flexibility and more delay.
Why cyber policies pay less than they promise
Cyber policies often split cover into separate buckets, and that is where surprise bills come from. The main policy limit is the ceiling for the whole policy, but many items inside it have their own sublimit, waiting period, or rule for payment.
Business interruption is the clearest example. The policy may promise broad support, but the payment may only start after a waiting period of 8, 12, or 24 hours, and then stop at a lower cap than the headline limit.
Which claims use separate caps?
Ransomware, social engineering, fraud by email, and business interruption are the usual weak spots. These areas often carry lower caps because insurers see them as more frequent or harder to price.
That matters because a policy can show £250,000 or £500,000 overall and still give only £10,000 to £25,000 for one of those claim types. The front page looks strong, but the fine print decides the cheque.
A waiting period is like the first stretch of a queue before a service starts. If your business is down for six hours but the policy only starts paying after eight, you get nothing for that loss.
Most UK SME cyber policies use a waiting period because not every short outage is serious enough to insure. That is fair in principle, but it can be harsh when the outage hits during trading hours or a busy sales day.
Incident response costs are not the same as cash losses. They may include forensics, legal advice, IT restoration, and call centre help, and each can sit inside a different pot.
This works well in theory, but in practice it means the “help” part of the policy may run out before the outage or fraud loss does. If your insurer pays the specialist only to a small sublimit, you may still face a bigger bill later.
A useful way to compare policies is to test the main policy limit against the most common cyber scenarios. In a ransomware event, the headline limit may look generous, but forensics, IT restoration and business interruption can each be restricted by separate sublimits, leaving the business to fund the gap itself. In a fraud loss caused by social engineering, the main policy limit may be £250,000, yet the social engineering cap might be only £10,000 to £25,000.
That means the policy can still be strong for large losses while being far less effective for the smaller, more frequent claims that hit an SME hardest.
What to check before renewal
You should compare the excess, each sublimit, the waiting period, and the main limit together before you renew. If you review them one by one, you can miss the real cost to your business.
Which five numbers matter most?
The five numbers that matter most are the excess, the ransomware sublimit, the fraud sublimit, the business interruption cap, and the waiting period. Those are the numbers that decide whether the policy feels useful after a loss.
If the excess is £7,500 and your likely first claim is around £8,000, the policy may help very little. If the ransomware sublimit is £15,000 but your typical restoration cost could reach £30,000, you already know there is a gap.
The easiest way to compare policies is to model three loss sizes: £5,000, £15,000, and £40,000. Those three points show whether the policy fails on small, medium, or serious incidents.
For each loss, write down what the insurer would likely pay after the excess and sublimit are applied. If two policies look similar on premium, the one that pays more at those three points is usually the better buy.
Ask your broker to quote lower excess options, higher sublimits on fraud and ransomware, and a longer period of indemnity if your business depends on online sales. Those are the levers that usually change the final result.
A broker can often ask for better terms if you show basic controls, such as multi-factor authentication, payment call-back checks, and staff training. Underwriting is not magic, but stronger controls can move the price and the wording.
Before renewal, it helps to run a simple policy audit rather than relying on the headline premium. Check the policy limit, then compare the excess, the sublimit, the waiting period and any period of indemnity against the losses your SME could actually face. A practical example is a retailer that loses £12,000 in card payment processing and IT restoration after a phishing attack: if the fraud sublimit is £5,000 and the excess is £2,500, the claim payout is far less useful than it first appears.
The same logic applies to business interruption, where a short outage can create lost sales, overtime costs and supplier delays that exceed the cap before the incident is even fully resolved.
High excesses suit some firms, not all
High excesses can suit larger SMEs with cash in reserve and a lower claim frequency. They can also make sense if the business mainly wants protection against rare, severe events rather than smaller incidents.
They do not suit firms with tight cash flow, thin margins, or regular payment activity. A small law firm, a recruitment agency, or an online shop may find that a high excess turns the policy into a paper shield.
A high excess can work if your business can self-insure the first slice and only wants cover for large shocks. In that setup, the policy is more like a safety net than day-to-day protection.
This is common in firms with strong cash reserves, low online payment risk, and a clear incident response plan. The premium may be lower, but the business must still be comfortable carrying the first loss.
A high excess becomes a false saving when it trims the premium by a few hundred pounds but leaves you funding a claim of several thousand. That is a poor trade for most SMEs.
The hidden cost is not just the excess itself. It is the delay, the admin, and the feeling that you paid for cover that does not really help when you need it.
Low sublimits can still leave you exposed
Low sublimits are the quiet problem in many cyber policies because they hide under a bigger headline limit. The cover may still be good value, but only if the sublimits match the losses your business is most likely to face.
Yes, they can, because breach response costs often sit under separate caps from the main liability cover. If customer notification, legal advice, or forensic work are limited, the policy may not fund the whole response.
It is worth separating fines from response costs. Under UK GDPR and the Data Protection Act 2018, some regulatory penalties may not be insurable, but the work to investigate and notify a breach often is, subject to wording and approval.
What happens in ransomware and fraud claims?
Ransomware claims often trigger several costs at once, including forensics, system recovery, and business interruption. If each part has a low cap, the claim can run out of room quickly.
Fraud claims are similar, especially with email payment diversion. Many policies treat social engineering as a separate risk, so the payment limit may be far below the main cyber limit.
What people ask
What is the difference between excess and
An excess is the amount you pay before the insurer pays anything. A sublimit is a lower cap inside the main policy limit for a specific type of loss, such as ransomware or fraud.
How much excess is normal for cyber insurance in
Many UK SME cyber policies use excesses between £500 and £5,000, but larger or higher-risk firms may see more. If the excess is close to your likely claim size, it can make the policy poor value.
Can a sublimit leave me with most of the bill?
Yes, if the loss type is capped too low. A £20,000 ransomware sublimit on a £60,000 incident still leaves a £40,000 gap before any excess is even counted.
Is a low premium worth a high excess?
Only if your business can safely absorb the first loss. A lower premium is not a saving if one incident turns into a five-figure bill you were not ready to pay.
Should i ask for higher sublimits at renewal?
Yes, if ransomware, fraud, or business interruption are real risks for your business. Brokers can often ask for better terms when you show controls such as MFA, call-back checks, and staff training.
Do cyber policies cover all business interruption
No, they usually cover only losses within the wording and within the time or money cap set by the policy. Waiting periods and periods of indemnity often mean the full outage cost is not paid.
Your renewal checklist for cyber cover
Check the excess first, then the sublimits for ransomware, fraud, and business interruption, because those three lines decide most SME claim outcomes. If any one of them is too low, the policy can still look good while paying too little.
Use a simple test: ask what happens on a £5,000, £15,000, and £40,000 incident. If the answer leaves you funding most of the loss, ask for a better quote or a better wording before you sign.
- Match the excess to cash you can pay within 7 days.
- Check each sublimit, not just the main policy limit.
- Ask whether forensics, recovery, and legal advice have separate caps.
- Confirm the waiting period for business interruption.
- Ask for written examples of how the policy pays on a ransomware, fraud, and outage claim.
- Use your broker to negotiate where controls and turnover justify it.
Action plan for your next renewal
The best cyber policy is not the one with the biggest headline limit; it is the one that pays enough after the excess and sublimits are applied. For most UK SMEs, that means testing the wording against real losses, not brochure claims.
If the excess is high, the premium savings may be real but modest. If the sublimits are low, the savings can be a false economy because the policy may stop paying right when the damage starts.
Take your broker a short list: your three most likely incidents, your cash limit for self-funding, and the figures you need improved. That is the simplest way to turn renewal into a better deal, not a surprise.
When negotiating with your broker, be specific about what you want changed and why. Ask for the excess to match the amount your business can absorb without harming cash flow, then push for higher sublimits on ransomware, fraud loss and business interruption if those are your main exposures. Brokers are more likely to secure better SME cover when you can show controls such as MFA, staff awareness training, incident response plans and call-back checks for payment changes.
It also helps to benchmark options at renewal: one insurer may offer a lower premium but a tight social engineering sublimit, while another may price a slightly higher premium in return for broader response costs and a more workable claim payout.