A cyber quote can look reassuring while leaving key losses uninsured. The costliest loss is often the days when your systems cannot trade.
SMEs often pay for familiar extras without checking the small print. Low sub-limits, long waiting periods, and exclusions can cut the value of cover.
Choose extras by payment authority, personal data, cloud reliance, supplier reliance, and downtime tolerance. Test one believable bad day and find the first cost.
For most UK SMEs, buy incident response first. Add business interruption if an outage would stop trade beyond the waiting period. Add social engineering or funds-transfer fraud when staff approve payments. Each cover can exclude scams covered by the other.
The right extra depends on your firm’s real weak point.
Start with payment authority
Social engineering fraud covers deception. Funds-transfer fraud may cover a hacked bank transfer. Crime or fidelity cover can address dishonest employees.
These covers are not interchangeable. Many policies exclude an authorised push payment sent by an employee who was tricked.
The most frequent error here is assuming every fraudulent payment has the same cover. A fake supplier email and a hacked bank login may trigger different policy sections.
Choose fraud cover if staff can release supplier, payroll, or client payments. Avoid paying for it if nobody can approve meaningful transfers.
Then measure downtime tolerance
Business interruption pays for lost income and added working costs after a covered cyber event. It normally starts only after a stated delay.
The policy must also define the event as covered. A cloud failure or supplier outage may fall outside basic wording.
Think of the waiting period like an excess measured in hours. If it is 12 hours, losses during the first 12 hours may not be paid.
Choose interruption cover if one IT outage would halt sales or delivery. The next section shows which wording tests matter most.
Compare cyber add-ons before paying more
The table shows common UK policy structures, not standard prices. Insurers assess turnover, controls, claims history, and sector in different ways.
A £250 annual extra can be poor value if its limit is too small. It can be good value where one mistake could cost £20,000.
| Add-on | Worth paying for when | Wording to test | Usually low value when |
| Incident response and forensics | You lack 24/7 IT, legal, and communications help | Panel access, prior consent, and 24/7 service | A wider policy already includes it without a small sub-limit |
| Business interruption | An outage of 8 to 24 hours would halt sales or delivery | Waiting period, gross profit, and 3 to 12-month indemnity period | You can trade normally during a short IT failure |
| Social engineering fraud | Staff approve supplier, payroll, or client payments | Invoice, authorised-payment, and callback exclusions | No staff payment authority or very low transfer values |
| Contingent interruption | A named cloud or IT supplier can stop your service | Supplier definition and cloud outage cover | You can switch provider quickly or work offline |
| GDPR legal and breach support | You hold client, employee, or special-category data | Legal costs, notification, and regulatory sub-limits | You hold no meaningful personal data |
Buy response before a larger limit
If funds force a choice, prioritise 24/7 incident response. This matters where you have no retained forensic, legal, or communications help.
A larger limit still matters when the likely loss exceeds the response limit. Compare the response sub-limit with the total policy limit before deciding.
A good response team can limit a loss quickly.
Choose response cover first if your business lacks specialist help at night or weekends. Check ransomware costs next, because one limit may pay for several losses.
Treat ransomware as separate costs
Ransomware cover is a group of costs, not just a possible extortion payment. Check limits for forensics, containment, restoration, legal advice, communications, and interruption.
These costs may have separate sub-limits. They may also reduce the same overall policy limit.
A common case is a locked email system that stops invoices and payroll. The extortion demand is small, but recovery work costs far more.
Judge the premium against the loss an extra can realistically prevent. Do not judge it only against the total price of cyber insurance for SMEs.
Ask the broker for the extra annual premium, each sub-limit, and the excess. For example, £250 yearly cover may include only a £10,000 fraud limit.
That limit leaves most exposure where staff can release a £20,000 payment. A cheap add-on fails when it cannot meet the first credible loss.
For interruption, work out one day of lost gross profit. Include overtime, alternative systems, and delayed fulfilment.
Compare that figure with the premium, waiting period, and indemnity period. An indemnity period often lasts between 3 and 12 months.
Choose ransomware cover if it funds recovery as well as extortion. The exclusions below can still remove its value.
Do not let exclusions erase the add-on
An add-on matters only when its trigger fits the policy definition. Your business must also meet every policy condition.
Compare the schedule with the full wording before renewal. The schedule is the short document that lists limits and selected covers.
A broad label can hide narrow terms.
Check the cloud supplier wording
Contingent business interruption covers loss caused by a supplier’s cyber event. Some wordings cover only named suppliers.
Other wordings exclude widespread cloud-service failures. Prioritise this cover when one hosted platform is essential.
This works well in theory, but it fails where the supplier definition is too narrow. Ask whether your main cloud provider is included by name or description.
Choose this extra if you cannot replace the platform quickly. Avoid it if you can switch providers or work offline.
GDPR support is not a fine guarantee
UK GDPR support can pay for lawyers, investigation, notification, and customer communications. It can help you manage a data breach properly.
Whether an Information Commissioner’s Office fine is insurable depends on law and policy wording. Never treat a possible fine payment as promised cover.
The Information Commissioner’s Office regulates UK data protection rules. It may investigate serious breaches involving personal data.
This comparison matters less if your business has little digital activity. It also matters less if you hold no client or payment data. It cannot replace a broker’s or insurer’s assessment for regulated work, high-value transfers, or sensitive special-category data.
Security controls affect both cover availability and its real value. Many insurers ask about multi-factor authentication, backups, patching, endpoint protection, training, and payment checks.
Cyber Essentials offers a useful baseline for recording these controls. A firm without proof may face a higher excess or narrower terms.
A ransomware claim may be disputed after a control failure. For example, a policy may require multi-factor authentication for remote email access.
Before buying ransomware or response cover, check which controls are conditions of cover. Confirm how the insurer defines each control.
Choose GDPR support if you hold meaningful personal data. The final package should reflect your business model, not every available extra.
Frequently asked questions
Ransomware cover is worthwhile when locked systems would stop trading. The policy should include restoration, forensics, and interruption costs. It should not cover extortion costs alone.
Do small firms need incident response cover?
Small firms usually need it without 24/7 specialist support. Check whether the base policy already gives adequate IT, legal, and forensic help.
Is social engineering fraud the same as invoice fraud?
Social engineering cover can include invoice fraud only when the wording says so. Check the exact deception and payment method involved.
Should I choose business interruption or data recovery cover?
Choose recovery cover when backups and restoration are weak. Choose interruption cover when each offline hour causes lost sales.
Choose the essential package first
For most microbusinesses, start with incident response, data recovery, and restoration. Add fraud cover when someone can approve payments.
Add interruption cover for e-commerce businesses. Add contingent interruption for technology firms that rely on one cloud provider.
Data-heavy practices should prioritise GDPR breach support and forensic help. They also need suitable limits for regulatory costs.
A technology or SaaS business may need cloud outage cover as core protection. Employee crime cover may matter less where no employee can move money.
No single package fits a business with high-value transfers and regulated work. In that case, ask a broker or insurer to assess the contract terms.
- Lo esencial: incident response often gives a small firm its first practical help.
- Lo esencial: business interruption must match waiting time, income loss, and cloud reliance.
- Lo esencial: social engineering, funds-transfer fraud, and employee crime are separate covers.
- Lo esencial: a sub-limit or failed security condition can remove a quote’s value.
Choose the essential package first, then add cover for clear exposures. Avoid extras that cannot pay for your first believable loss.
Learn more
Here are some additional resources on this subject: