Cyber insurance cost calculators can help a UK SME with 1–50 employees set an initial budget before requesting quotes. They assess turnover, industry, customer data, payment systems and basic security. But they may miss the cost of several days without email, files or trading systems.
A calculator gives a planning range, not a firm price.
What changes a UK SME cyber insurance quote?
Quotes rise when an attack is likely to cost more or take longer to fix.
Data volume, payment systems and weak MFA can raise an estimate. MFA means using a second sign-in check, such as an app code or security key.
Planning ranges, not promised premiums
The figures below are planning bands for English SMEs with 1 to 50 employees. They are not insurer averages, offers or promised renewal prices.
A ransomware claim, weak controls or a high-risk sector can push prices beyond these ranges.
| SME profile | Usual cover limit | Likely excess | Planning range a year |
|---|
| Low-data professional service, under £250k turnover | £100k to £250k | £250 to £1,000 | £300 to £700 |
| Retail, trades or office firm, £250k to £1m turnover | £250k to £500k | £500 to £2,500 | £600 to £1,800 |
| Recruitment, accountancy, e-commerce or IT supplier | £500k to £1m+ | £1,000 to £5,000 | £1,200 to £4,000+ |
A cyber insurance cost calculator usually gives an estimate, not a binding offer. Its SME risk assessment may start with turnover, staff numbers, industry, records held and payment processing.
It may then adjust the result for chosen policy limits and insurance excess. The excess is the amount your business pays towards a claim.
MFA, backup restore tests and an incident response plan can affect eligibility. Online tools may not assess contracts, overseas customers or a complex supplier chain.
UK cyber insurance quotes come only after insurer or broker underwriting. Underwriting means checking the answers and deciding whether to offer cover.
Treat a calculator as a budget range. A new limit, excess or answer can change the final insurance premium.
Security controls that can change the price
Controls can affect both eligibility and price.
Evidence underwriters may request
Keep simple evidence before asking for quotes:
- A list showing MFA on email, admin and remote-access accounts.
- A recent backup restore test, with its date and the system restored.
- A patching record for laptops, servers and internet-facing software.
- A short incident response plan naming who calls IT, the insurer and affected customers.
- A list of key cloud, payroll, payment and managed IT suppliers.
The most common mistake is claiming a control exists without evidence that it works.
Cyber essentials helps, with limits
⭐
Picked for you
A USB security key adds a physical MFA option for administrator and email accounts. It helps where app codes alone offer too little protection against phishing.
- It adds a second sign-in factor for compatible Microsoft 365 and Google Workspace accounts.
- It reduces reliance on text-message codes, which SIM-swap fraud can target.
- It gives a simple item to record as evidence for privileged account controls.
View on Amazon →
Controls influence the quote, but policy wording decides what happens after an incident.
Cyber Essentials can offer useful baseline evidence for a cyber insurance application. It checks secure settings, access control, malware protection, updates and firewalls.
But certification is not a full security questionnaire. An insurer may still ask whether MFA protects email, remote access and administrator accounts.
It may also ask whether backups are separate and tested. It may ask how fast you apply critical patches.
Keep the current certificate with dated records for these controls. Do not assume the certificate alone changes the insurance premium.
It can support eligibility or reduce an underwriter's doubt. Its effect depends on the insurer, sector, cover and wider risk profile.
Compare downtime cover before the premium
The scope of downtime cover matters as much as the premium.
First-party and third-party losses
First-party cover pays for your own response and recovery costs. It can pay for forensic IT help, customer notices, legal advice and ransomware recovery costs.
It can also include business interruption cover while systems are unavailable. This is the part that can work like downtime insurance for a small business.
Check the waiting period before cover starts. Also check the longest outage period covered.
Check these policy gaps
Social engineering fraud happens when a criminal persuades someone to send money or change bank details. It is not included automatically in every cyber policy.
The same can apply to supplier outages, cloud failure and invoice redirection. These losses can stop trading even when your own systems still work.
For an English SME, choose a limit by pricing five to ten lost working days. Add outside IT help, legal advice and customer communication. Then test sub-limits for ransomware, fraud and supplier interruption. A £250,000 policy may suit a low-data firm that can trade manually. A payment-dependent business may need £500,000 or more. Lost income and recovery costs can run together.
A quote estimate becomes a buying decision in four checks
1. Price
Annual premium and excess
2. Loss
Limit and key sub-limits
3. Downtime
Waiting and indemnity periods
4. Proof
MFA, backups and supplier checks
Third-party cover deals with claims after a breach that affects customers, clients or other parties. It can include defence costs where the policy covers them.
Compare policy limits and sub-limits separately for extortion, social engineering fraud and funds transfer fraud. A high overall limit may not apply fully to each loss type.
The key buying question is simple: could this cover fund recovery while your business cannot trade? The next section shows where calculator results can mislead.
Avoid quote traps before you buy cover
A calculator result does not prove a future claim is covered.
A calculator suits some firms less well. This includes firms with overseas customers, a recent incident, public-sector contracts or regulated work.
Financial services firms may face FCA conduct rules and stricter contract demands. Health, legal and technology businesses may also need closer wording checks.
This approach is not enough for businesses with high turnover, complex regulated work, large public contracts or overseas exposure. It is also not enough after recent incidents or where contracts set special demands. Those cases may need a specialist broker and a policy wording review. It does not replace insurance, legal or cyber security advice.
Use the quote comparison properly
Ask for two or three like-for-like quotes. Use the same turnover, staff count and cover limit for each quote.
Then change one item at a time. For example, raise the excess from £500 to £1,000.
You can also extend interruption cover from three to six months. This makes the price difference meaningful.
A lower premium can hide a much shorter recovery period.
Questions & answers
How much does cyber insurance cost for a small UK business?
A small UK business may budget £300 to £4,000+ yearly. Cost depends on turnover, sector, security controls, chosen limit and policy excess.
Higher-risk firms can exceed that range after underwriting.
Does Cyber Essentials guarantee cheaper cyber insurance?
Cyber Essentials can support an application, but it does not guarantee a discount, acceptance or claim payment. Certification lasts 12 months.
Insurers may still check MFA, backups and supplier controls.
What excess should a small business choose?
Many small businesses compare excesses from £250 to £2,500. The right choice depends on cash reserves and premium savings.
Choose an amount the business could pay quickly during an incident.
Does cyber insurance cover ransomware and payment fraud?
Ransomware and payment fraud need clear policy wording and fulfilled conditions. Check cyber extortion, social engineering fraud and funds-transfer sub-limits separately.
Those sub-limits may be lower than the total policy limit.
Choose cover that can fund recovery
- Use a calculator to set a budget, not as a binding quote.
- Compare the total limit, sub-limits, excess and interruption period before comparing premiums.
- Keep evidence of MFA, tested separate backups, patching and supplier controls before applying.
- Cyber Essentials can show baseline controls, but it does not guarantee cover or a lower price.
Further reading
If you want to learn more about this topic, these sources may interest you: