A supply chain cyber incident can stop trading overnight: suppliers' ransomware, compromised SaaS platforms or third‑party data breaches often cascade down to small firms that rely on those services. For many UK small and medium‑sized enterprises this risk presents three urgent questions: what will it cost, what will an insurer actually pay, and how to choose cover that adds value rather than false reassurance. Immediate clarity is possible by understanding cover types, typical premiums and common exclusions, and by focusing on practical steps, basic written contracts, simple cyber hygiene and clear incident response plans, that materially reduce both the chance of a claim and the premium that underwriters may charge.
Key takeaways
- Supply chain cyber insurance transfers some financial and response costs when a supplier or technology provider causes a cyber loss to an SME.
- Typical annual premiums for SMEs vary widely, indicative ranges help budgeting but depend on turnover, sector, and security controls.
- Policy limits, sub-limits and exclusions (e.g. war, known vulnerabilities, contractual liability) materially affect value; the cheapest quote can leave gaps.
- Underwriters assess third‑party risk using supplier criticality, contractual risk transfer, patching and resilience evidence; improving controls often reduces cost.
- A short insurer questionnaire and three clarifying questions to ask prospective insurers help compare real value beyond premium alone.
How supply chain cyber insurance protects UK SMEs
Supply chain cyber insurance commonly covers financial losses that arise when a supplier, cloud provider or third‑party service is compromised and that compromise causes business interruption, data breach costs, or liabilities to clients. Typical covers include business interruption (loss of gross profit), dependent business interruption (loss caused by suppliers' incidents), incident response costs (forensic, legal, PR), third‑party liability (claims from clients) and cyber extortion. For UK SMEs, dependent business interruption is the most directly relevant element: it pays when a critical supplier outage stops or reduces trading. However, cover wording matters: some policies require a physical damage trigger or explicit dependent BI wording; others apply sub‑limits and waiting periods that reduce practical value.
What elements of a supply chain incident are commonly covered
Most policies for SMEs include: (1) costs to investigate and contain an incident at the SME itself, (2) business interruption losses where the SME cannot trade because a supplier is down, (3) third‑party liability for data loss or service failings, and (4) cyber extortion payments and negotiation costs. The extent to which a supplier’s own cyber insurance responds is a separate question, SMEs typically rely on their own policy as primary cover unless contractually otherwise. Where the supplier is responsible under contract, insurers may seek contribution or recovery from suppliers' policies.
Practical limits for SMEs
Insurers frequently impose waiting periods (e.g. 24–72 hours), monetary sub‑limits specifically for dependent BI, and limits per supplier. For example, a policy limit of £500,000 with a £50,000 dependent BI sub‑limit provides far less protection for lengthy supplier outages than the headline limit suggests. SMEs should identify their most critical suppliers, quantify likely losses per day and check how sub‑limits and waiting periods affect the pay‑out timeline.
Typical costs and premiums for supply chain cover
Indicative premium ranges are helpful for budgeting but are not quotes. For small UK SMEs with modest turnover and basic cyber controls, annual premiums for cyber packages including dependent BI often start from around £350–£750. Microbusinesses or sole traders with low risk profiles may see lower starting costs. For SMEs with higher turnover, regulated data handling (accountants, legal firms), or weak controls, typical premiums rise: £1,200–£5,000+ annually. Critical factors driving these ranges include turnover, industry sector, number of suppliers, presence of cloud/SaaS reliance and historic incidents.
Cost drivers underwriters use
Underwriters price supply chain risk by considering: (1) business exposure if a supplier fails (extent of downtime impact), (2) concentration of suppliers (single point of failure increases premium), (3) contractual risk transfer and supplier insurance, (4) basic cyber hygiene, MFA, patching, backups, and (5) sector risk (professional services and e‑commerce often attract higher rates). Demonstrable controls, supplier SLAs, incident response plans and proof of backups, typically lower premium or improve terms. Note that premiums shown as examples are indicative at time of writing and will vary by insurer and market conditions.
HTML comparative table: Typical policy features and indicative costs
| Policy feature |
What it covers |
Indicative SME annual cost |
Common caveats |
| Base cyber package |
Breach response, data liabilities, basic BI |
£350–£1,200 |
May not include dependent BI unless specified |
| Dependent business interruption |
Loss from supplier outages |
Often +£200–£2,000 (depends on limits) |
Sub‑limits/waiting periods often apply |
| Cyber extortion cover |
Ransom payments and negotiating costs |
Included or +£100–£800 |
May require approval for payments |
| Higher limits / longer tails |
Greater financial protection |
+£500–£5,000+ |
Costs scale with turnover and sector risk |
What policy limits and exclusions UK SMEs face
Policy wording influences practical protection more than premium alone. Commonly seen limitations include sub‑limits for dependent BI, time‑based waiting periods, aggregate limits across multiple suppliers and explicit exclusions for known or unpatched vulnerabilities, acts of war/state, or contractually assumed cyber liabilities. For SMEs this means a headline limit (e.g. £1m) can be eroded quickly by legal and forensic costs if sub‑limits apply. Policies may also exclude losses caused by the SME’s failure to maintain reasonable security standards or losses arising from vendors outside an insurer’s accepted list.
Common exclusions to watch
- Known/unresolved vulnerabilities at the time of policy inception./
- Losses arising from acts of state or nation‑state attacks (some policies carve these out)./
- Contractual liabilities where the SME has agreed indemnities without insurer consent./
- Failure to apply security standards detailed in the policy (e.g. no MFA requirement)./
Each exclusion can be material. For example, many supply chain incidents stem from an unpatched third‑party vulnerability; if the policy excludes known vulnerabilities without clarifying responsibility, recovery may be denied.
How underwriters assess supply chain cyber risk
Underwriters evaluate dependent risk through a mix of documentary evidence and questionnaires. Key inputs include supplier mapping (who are the critical suppliers), contractual protections (are suppliers insured and contractually liable), technical controls (MFA, backups, patching cadence) and business resilience (alternate suppliers, manual workarounds). Underwriters may ask for evidence such as a supplier inventory, recent penetration tests, or copies of critical supplier SLAs. For SMEs, being able to produce a short supplier list with criticality ratings and basic contractual clauses materially improves underwriting outcomes and shortens quotation time.
What insurers typically request
Common requests on supply chain risk: (1) a list of top 10 suppliers and the services they provide, (2) evidence of encrypted backups and restore testing, (3) password and access management policies, (4) incident response plan and named contacts, (5) any historical incidents and remediation steps. Providing concise, factual evidence reduces perceived uncertainty and can produce meaningful premium reductions or removal of restrictive endorsements.
Real claims: ransomware and supply chain breaches covered
Several high‑profile supply chain incidents demonstrate how third‑party failures affect SMEs: widespread ransomware against a cloud provider can prevent thousands of small firms from accessing critical data, while a compromised payroll processor can expose employee data for many clients. In practice, insurers have paid for forensic investigations, notification costs to affected clients, legal defence and some business interruption for SMEs dependent on affected platforms. Outcomes depend on policy wording; successful claims typically involved clear links between the supplier outage and measurable lost revenue, alongside prompt disclosure to the insurer and reasonable security measures in place prior to loss.
Example scenarios (anonymised)
1) A small e‑commerce retailer lost access to an order management SaaS for 48 hours after the SaaS supplier was hit by ransomware. The retailer had dependent BI cover with a 24‑hour waiting period; the insurer paid the documented lost profit for the 24 hours beyond the waiting period, plus forensic and CRM notification costs./
2) An accounting practice suffered client data exposure because a payroll provider was breached. The practice's policy covered notification, defence costs and third‑party liabilities; the insurer worked with the practice to fund PR and client remediation./
These anonymised examples illustrate two points: prompt notification to the insurer and clear evidence of loss are essential; and contractual protections with suppliers and basic security measures materially influence claim acceptability.
Choosing the right insurer: questions SMEs should ask
Selecting cover requires comparing more than premium. Questions that reveal practical value include: what constitutes a dependent supplier under the policy, are there sub‑limits for dependent BI, what is the waiting period and how is loss quantified, does the policy exclude state‑sponsored attacks, and does the insurer offer loss‑prevention resources or incident support lines? Asking for sample policy wording for dependent BI and a claims scenario response helps clarify how the insurer behaved in practice. Where possible, request the insurer's position on recovery from suppliers' policies and whether they will assist with recovery actions.
Checklist of clarifying questions to put to prospective insurers
- How is a "dependent supplier" defined in this policy?/
- Are there sub‑limits or aggregate limits that apply to supplier outages?/
- What waiting period applies to dependent BI and how is lost revenue calculated?/
- Does the policy include or exclude state‑sponsored attacks and known vulnerabilities?/
- What incident response services are included and are they mandatory to use?/
Quick risk vs value at a glance
Supply chain cyber cover, quick view
🧩 Identify critical suppliers → 🔒 Check contracts & insurance → 📊 Estimate daily loss → 🧾 Compare dependent BI sub‑limits
- Emoji signals show priority actions
- Arrows indicate flow from identification to procurement
✔️
Quick checks (10 min each)
Strategic considerations: pros and cons of supply chain cover for SMEs
- Pros: transfers some financial burden, access to insurer‑led incident services, potential client reassurance and support for regulatory notification costs./
- Cons: sub‑limits and exclusions can leave material gaps; premiums rise with exposure; insurers may seek contribution recovery from suppliers' insurers which can complicate and lengthen settlement./
For SMEs where the supplier dependency is critical and the daily loss would be material, dependent BI cover often provides net value. For businesses with diverse suppliers and short manual workarounds, the incremental benefit may be lower. Strategic choice should weigh the cost of cover against quantified likely losses and the expense of improving supplier contracts and resilience.
Frequently asked questions
What is dependent business interruption (dependent BI)?
Dependent BI covers financial loss when a supplier’s cyber incident prevents the SME from trading. It differs from standard BI by linking loss to third‑party disruption rather than the SME's own systems.
Will insurers pay if a cloud provider is hit by ransomware?
Insurers may pay if the policy includes dependent BI and the loss meets waiting periods and quantification rules; cover depends on wording, sub‑limits and exclusions for state‑level attacks or known vulnerabilities.
How much does supply chain cyber insurance add to a small SME policy?
Indicatively, dependent BI endorsements commonly add £200–£2,000+ annually depending on limits and sector risk; exact pricing depends on turnover, supplier concentration and controls.
Can a supplier's insurance replace the SME's cover?
Not reliably. Suppliers' policies may provide some recovery, but SMEs usually rely on their own policy as primary unless contracts explicitly state otherwise and insurers accept such arrangements.
Does cyber insurance cover GDPR fines?
Civil monetary penalties under GDPR are subject to legal restrictions; many UK policies exclude fines where prohibited, but may cover defence costs and regulatory response expenses. Refer to ICO guidance.
How should SMEs document suppliers for underwriting?
A concise supplier register showing supplier name, service provided, criticality (days to impact), contract clauses and whether the supplier has its own insurance helps underwriting and speeds quote turnaround.
Conclusion
Action plan: three quick steps (<10 minutes each)
1) Create a one‑page supplier map listing the top 5 critical suppliers and the service they provide./
2) Check policy wording for dependent BI, sub‑limits and waiting periods and request sample clauses from insurers./
3) Implement or confirm MFA and daily/weekly backup status for key systems and note these in underwriting questionnaires.
These actions provide immediate clarity on exposure, reveal obvious coverage gaps and produce evidence that can reduce premium or improve terms when speaking to insurers. For decisions involving costs, legal terms or compliance obligations, consult a regulated insurance or legal professional.
References: guidance from the NCSC, regulatory material at the FCA and breach notification guidance from the ICO.