Underinsurance is a survival issue, not merely an insurance issue
The recent report on where UK small businesses are most underinsured and most likely to fail should be read as a warning about business resilience. Underinsurance is often discussed as an administrative problem: a policy limit was not reviewed, turnover changed, stock increased or a business selected the cheapest renewal quote. In reality, it can determine whether an otherwise viable small business can continue trading after a major loss.
For UK SMEs, cyber risk deserves particular attention within that conversation. A fire, flood or theft is visible and familiar. A cyber incident can be less tangible at first: an employee clicks a convincing Microsoft 365 login link, a supplier's email account is compromised, customer information is accessed, or ransomware prevents access to bookings, payroll and accounts. Yet the financial effects can escalate quickly, especially where a firm has limited cash reserves and depends on a small number of people or systems.
The central lesson is not that every business needs the largest available policy. It is that insurance must reflect the business as it operates today, including its data, technology dependence, contractual obligations and realistic cost of interruption.
Why small firms can be underinsured for cyber losses
Many SMEs assume that cyber cover is included in a standard package policy, public liability policy or professional indemnity policy. Sometimes there is limited extension cover, but it may be narrowly defined, subject to a low sub-limit, or exclude key costs such as ransomware response, forensic investigation, regulatory support and business interruption.
This creates an important distinction: having some cyber-related cover is not necessarily the same as having insurance that would fund a meaningful recovery.
A cyber claim can involve several cost categories at the same time:
- specialist IT forensics to contain and investigate the incident;
- legal and data-protection advice, particularly where personal data may be affected;
- notification and communications costs;
- recovery or rebuilding of systems and data;
- loss of income while systems, orders or services are unavailable;
- cyber extortion payments and associated negotiation support, where lawful and covered;
- third-party claims from customers, suppliers or partners; and
- reputational and crisis-management costs.
A small accountancy practice, for example, may not own expensive physical machinery, but it holds financially sensitive client records and relies on cloud software to meet filing deadlines. A restaurant may rely on online reservations, payment terminals and delivery platforms. A manufacturer may be unable to dispatch goods if a ransomware event locks production planning or warehouse systems. In each case, the most serious cost may be the inability to trade rather than the cost of replacing hardware.
The hidden link between cyber disruption and business failure
Business failure following a major incident is rarely caused by one invoice alone. It is more commonly the result of cash-flow pressure accumulating while the owner is trying to make urgent decisions with incomplete information.
Cyber disruption can create exactly this pattern. Revenue stops or falls; employees cannot work normally; customers ask for updates; suppliers may still expect payment; and external specialists are needed immediately. Even a short outage can be damaging for firms with slim margins, seasonal income or committed delivery dates.
Business interruption needs realistic assumptions
One of the most consequential areas of underinsurance is business interruption. A policy may provide cover, but the indemnity period or sum insured may not match the time needed to restore systems, re-enter data, rebuild customer confidence and return to normal turnover.
SME owners should not estimate interruption loss solely by asking, “What would we lose in a week?” They should consider:
- How long would it take to identify and contain a compromise?
- Can the business continue manually if its principal systems are unavailable?
- Are data backups tested and capable of rapid restoration?
- Would a breach prevent trading because of contractual, regulatory or safety concerns?
- How long would it take to work through delayed orders, invoices or customer queries after systems return?
The answer may be materially longer than the period of technical downtime. A business may restore access in three days but need several weeks to clear an order backlog and recover lost sales.
Growth can quietly make cover inadequate
Underinsurance frequently develops when the business changes faster than its insurance review process. Hiring remote staff, adopting a cloud-based CRM, launching e-commerce, collecting more customer data, entering a new supply chain or signing a larger client contract all alter cyber exposure.
A policy arranged when a company had five staff and a basic website may no longer be appropriate when it has 25 hybrid workers, online payment processes, outsourced IT and contractual obligations to notify a corporate customer of incidents. The policy wording, limits and insurer security requirements should evolve with the operation.
What UK SME owners should do now
The practical response is a structured review, not panic buying. Cyber insurance should be part of a wider continuity plan, because insurers generally expect sensible controls and because good controls reduce both the likelihood and severity of a claim.
1. Map your critical digital dependencies
List the services without which you cannot trade for 24 hours: email, accounting software, point-of-sale systems, cloud storage, booking platforms, production software, payment providers and customer databases. Identify the owner of each system, whether you have administrator access and what happens if that provider is unavailable or an account is compromised.
This exercise often reveals that a business is more digitally dependent than its insurance declaration suggests.
2. Test the controls insurers commonly examine
At a minimum, SMEs should implement multi-factor authentication for email, remote access and privileged accounts; patch operating systems and applications promptly; maintain protected and tested backups; restrict administrator privileges; and provide regular phishing awareness training.
These are not simply box-ticking measures. Business email compromise and stolen credentials are common routes into SME systems. A tested backup can make the difference between a contained outage and a prolonged operational crisis.
3. Review cyber policy limits and exclusions with a broker
Ask a broker or insurer direct questions. Does the policy cover business interruption caused by a cyber event? Is there a waiting period? Are social-engineering or invoice-redirection losses covered, and to what limit? Does cover include incident response, legal advice, forensic services and data restoration? Are attacks on key suppliers, cloud providers or managed service providers addressed? What security conditions must be maintained for a claim to be valid?
Do not rely on a policy schedule alone. Request and read the relevant wording, definitions, endorsements and exclusions. The scope of cover matters as much as the headline limit.
Document who can authorise decisions, contact the insurer, call the IT provider, speak to the bank and communicate with customers. Keep the contact sheet accessible outside the company network. During a ransomware event or email compromise, speed and clarity can limit losses.
5. Align insurance with contractual commitments
Check customer and supplier contracts for cyber, data-security and notification requirements. A contract may require a minimum level of cyber insurance or impose liability that exceeds what the firm has purchased. Where possible, obtain professional advice before accepting broad indemnities or unrealistic security warranties.
Cyber insurance can provide access to specialist response services at a time when a small business may not know where to start. It can protect liquidity and help fund the recovery process. However, it cannot replace basic security discipline, accurate financial records, tested backups or a workable continuity plan.
The report's broader underinsurance message is therefore highly relevant to cyber risk. SMEs should treat renewal as a strategic review of their ability to survive disruption, not simply a procurement exercise. The right question is not, “Do we have cyber insurance?” It is, “If our core systems failed tomorrow, could this policy and our response plan keep the business trading?”
FAQ
Does a standard business insurance policy include cyber cover?
Not necessarily. Some commercial policies include small cyber extensions, but these may have low limits or restricted cover. Check the wording for data breaches, cyber extortion, business interruption, crime and incident-response costs rather than assuming they are included.
How much cyber insurance should a UK SME buy?
There is no universal figure. Base the limit on likely business interruption, forensic and recovery costs, the volume and sensitivity of data held, contractual requirements, potential third-party liability and available cash reserves. A specialist broker can help model realistic scenarios.
Will cyber insurance pay if an employee falls for a phishing email?
It depends on the policy and the nature of the loss. Some policies may respond to incident response and system damage, while social-engineering or funds-transfer fraud can have separate conditions and sub-limits. Confirm this before purchase.
What is the first action after a suspected cyber incident?
Contact your IT or incident-response provider and notify your cyber insurer or broker using the claims contact route in your policy. Preserve evidence, isolate affected devices where appropriate, and contact your bank immediately if a fraudulent payment may have been made. Avoid deleting logs or attempting an uncoordinated recovery that could complicate investigation.
Source: insurancebusinessmag.com — Fri, 11 Sep 2026 04:57:46 GMT