A £250,000 cyber policy can seem reassuring. One breach may trigger IT forensics, legal help, customer notices, lost income, and a ransom demand. Lower caps for key costs can leave a large uninsured bill.
Coverage limits & sublimits explained: a policy limit is the most an insurer will pay for covered loss. The schedule states if it applies per claim, annually, or both. Sublimits can set lower caps for named types of loss. Test the wording against a realistic breach before buying or renewing.
Why a £250,000 limit may not pay £250,000
A £250,000 limit is an overall ceiling for covered payments. It is not cash automatically available for every cost. Excesses, exclusions, and lower caps can apply.
Forensic work, legal advice, notification, restoration, and business interruption may all use one overall limit. Early response costs can consume much of the cover before the insurer calculates lost income.
The headline figure is only useful when it matches the loss.
| Common cover section | Possible sublimit | Cost that may use it | Wording point to check |
|---|
| Cyber extortion | £25,000 to £100,000 | Ransom payment and negotiator fees | Per incident or annual aggregate |
| Social engineering fraud | £10,000 to £100,000 | Fraudulent supplier payment | Verification rules and exclusions |
| PR and crisis support | £10,000 to £50,000 | Customer communications | Inside or outside the main limit |
| Regulatory defence | £25,000 to £100,000 | Legal representation in an ICO inquiry | Fines treated separately from defence costs |
How aggregate, per-claim and sublimits differ
An aggregate limit is the most payable during a policy year. A per-claim limit applies to one claim. A sublimit caps one named type of loss.
Is the cap inside the main limit?
Most SME policies count sublimit payments within the aggregate. If £50,000 is paid for extortion under a £250,000 annual limit, £200,000 may remain. The wording must clearly say if the amount is extra.
Is it per event or per policy year?
For each sublimit, check four points. Check if it sits within the main limit. Check if it applies per claim or annually. Check if an excess applies. Also check if response costs reduce the same cap. These answers show the real amount available.
A cyber insurance policy limit is the most payable for covered loss. The schedule must show how that limit works. A per-claim limit applies to each accepted claim. An aggregate limit is the most payable for all claims during the policy year.
The limit of liability may be per claim, aggregate, or both. An insurance sublimit is a smaller cap for one loss type within that structure. Think of it as a smaller bucket inside a larger bucket.
For example, a £250,000 per-claim limit may sit with a £500,000 annual aggregate. It could pay up to £250,000 for one incident. It could not pay more than £500,000 across the year. The policy excess is then deducted as the wording states.
Consider a ransomware incident with £70,000 of forensic costs. It also has £30,000 of legal costs and £45,000 of restoration costs. The ransom demand is £90,000.
If extortion cover has a £50,000 ransom sublimit, the insurer may pay only £50,000. That leaves £40,000 of the demand uninsured before any excess. If all other costs are covered, the total covered amount is £195,000 before the excess.
This assumes the £250,000 limit is an annual aggregate. The £195,000 includes £70,000, £30,000, £45,000, and £50,000. Only £55,000 then remains for later covered claims. This changes if the extortion sublimit is clearly additional.
When comparing cyber quotes, test one likely severe incident against every relevant cap. Add technical response, restoration, legal help, ransom, lost income, and customer notices. Then check whether each payment reduces the annual aggregate and whether an excess applies. A high headline limit can still leave a gap if one crucial sublimit is low for your business.
Test your cover against one realistic loss scenario
Adequate cover meets the cost of a plausible severe incident. It must allow for sublimits, excesses, and uninsured costs. Turnover alone cannot show the right amount.
Build costs into one incident
Model forensic work, legal help, notification, restoration, lost gross profit, and extra working costs. For example, £25,000 of technical response may combine with £15,000 of legal support. Add £40,000 of restoration and £100,000 of lost income. That creates a £180,000 incident before excesses or interruption sublimits.
A realistic scenario gives the schedule a practical stress test.
Check the indemnity and waiting periods
📦
Find it on Amazon
An encrypted business hard drive can keep a separate protected copy of key files. It does not replace tested backups. It also does not change insurance cover. It can support a faster recovery plan.
- It helps protect stored business files if the device is lost or stolen.
- It gives an offline backup option when ransomware affects live systems.
- It can cut the time needed to restore key documents and customer records.
Search Amazon →
Set the limit by estimating the largest plausible loss. Do not use a fixed share of turnover. Start with revenue at risk during the recovery time objective, or RTO.
The RTO is the target time to restore a service. Add likely forensic costs, restoration, customer notices, legal help, and regulatory defence. Check how many sensitive records could be affected.
Also check if cloud platforms or online payments are essential. Ask how long the business could work by hand. For business interruption, test the waiting period and indemnity period. The indemnity period is the time when the policy can pay for lost income.
Most guides mention the main limit. They often miss the time needed to rebuild systems and regain normal trading.
A firm using one core platform may be unable to trade for ten days. It may need a higher interruption limit. A similar firm may return to offline processes within hours. Its need may be lower.
GDPR, geography and liability limits are different
UK GDPR exposure, territorial limits, and liability limits answer different questions. They cover data duties, where cover applies, and what the insurer may pay.
Territorial and jurisdiction limits
A territorial limit states where an event, system, or insured activity must be located. A jurisdiction limit states where someone can bring a claim. Neither tells you the money limit. Neither confirms if regulatory fines are insured.
First-party and third-party costs
First-party costs are your own costs after an incident. They can include forensic work, restoring systems, and lost income. Third-party costs arise when another person claims against your business. They can include legal defence and damages.
An ICO inquiry can create defence costs even without a fine. Check whether the policy separates defence costs from fines. Check the geographic scope if customers, staff, or suppliers are outside the UK.
A common case involves a UK firm using a US cloud provider. The event may affect UK customers, but contract claims may arise elsewhere. The policy wording decides whether that claim fits its territory and jurisdiction terms.
This guidance is less relevant if your business lacks meaningful digital systems, customer data, or online payment exposure. It also does not answer questions about non-cyber liability policies. The schedule, endorsements, and full wording decide what a policy covers. You may need regulated insurance advice before buying or renewing.
Questions & answers
What is the difference between a limit and a sublimit?
A policy limit is the most payable under the policy. A sublimit is a lower cap for a defined loss type. A £250,000 main limit may contain a £25,000 social engineering fraud cap.
Do sublimits reduce the overall policy limit?
Usually, yes. Sublimit payments often reduce the remaining annual aggregate. Treat a sublimit as extra cover only when the wording clearly says so.
Does cyber insurance pay GDPR fines?
Not automatically. Defence costs for an ICO inquiry may be covered. Fines depend on the wording, legal insurability, and the regulator's decision.
How do I know whether my cyber limit is enough?
Model one severe but plausible incident. Compare each cost with the relevant sublimit, excess, and indemnity period. Include downtime, technical response, restoration, legal help, and notification costs.
Use the wording to find your real protection
Your real protection depends on the cover section and its sublimit. It also depends on the policy excess, exclusions, and payment structure. Check if payments reduce the per-claim or annual aggregate.
The largest schedule figure matters only when it applies to the loss being tested. Read every cover section beside its endorsements. Then test it against an incident that could genuinely stop trading.
A policy can look large on paper but fail at one expensive point. Check the smaller caps before you rely on the larger one.
Further reading
If you want to learn more about this topic, these sources may interest you: