If your SME suspects a cyber incident, call your insurer’s approved claims hotline or broker straight away. Do not wait to decide how serious it is. Early notice can preserve evidence and bring in specialist help. It also avoids delay when the ICO’s 72-hour window may be running.
Call the insurer before judging the breach
Call early. Report a suspected incident to the claims hotline or broker before deciding if ICO reporting is needed.
For an England-based SME, the practical rule is simple: notify the insurer or broker through the claims route when an event is suspected. Then let legal and forensic advisers assess ICO reporting. The 72-hour period is not a reason to wait for certainty. It is a reason to create a dated record and get informed help promptly.
Disconnect an affected device safely. Do not wipe it, rebuild it or delete suspicious emails. Keep screenshots, phishing messages and a record of the time, person and system involved.
Preserved evidence often decides how quickly specialists can assess the incident.
- When the issue was first noticed, including the time zone and the name of the person who noticed it.
- What changed, such as locked files, strange email rules, failed payments or unknown administrator accounts.
- What action was taken, including devices isolated, passwords reset and suppliers contacted.
- What remains unavailable, including email, stock systems, online orders, payment terminals or shared files.
ICO deadlines are not the only deadlines
The ICO expects a report within 72 hours in some cases. This applies where a personal-data breach may risk people’s rights and freedoms.
Insurers, banks, payment providers and client contracts may have separate notice rules. Preserve facts first. Make legal conclusions second.
Incident response is more than IT repair
Incident response contains an attack, investigates it and restores operations. It also addresses legal, insurance and communication duties.
It is not just about making computers work again.
Who leads each part of the response?
The insurer may appoint panel suppliers. The SME gives business context and makes operational decisions.
| Role | Main job | Useful claim output |
|---|
| SME director or lead | Approves key business decisions and gives context | Timeline, access and loss records |
| Insurer and broker | Confirm claims route and appoint specialists | Cover direction and consent record |
| Forensic provider | Contains and investigates the incident | Technical findings and recovery scope |
| Solicitor and PR adviser | Assesses notification and manages communications | Advice, notices and approved wording |
When can your IT firm help?
Your IT firm can be vital because it knows the network and backups. But insurer approval should usually come first for chargeable forensic or recovery work.
Policy terms and approved suppliers differ. Unapproved work can create disputes over costs.
When comparing incident-response providers, do not choose on technical credentials alone. Ask if the provider has a genuine 24/7 cyber claims hotline. Ask its target time for initial triage.
Check whether the team can contain an attack remotely. This matters before a site visit becomes possible.
Check whether the forensic recovery scope includes endpoint analysis, cloud accounts and email tracing. It should also cover log preservation and support for tested data backups.
For example, a retailer with failed card payments needs fast coordination. The provider must work with its payment supplier and insurer, rather than simply rebuilding a laptop on Monday.
Check whether the provider is on the insurer’s approved supplier list. Using an unapproved firm without consent can create avoidable cost disputes.
A structured SME incident plan has clear stages. One external provider may complete several stages.
Triage establishes what is known. It identifies affected systems, data and any need for immediate isolation.
Containment limits further access. It should not destroy evidence without need.
Digital forensic work examines logs, devices, accounts and attacker activity. It identifies the likely entry point, affected records and recovery scope.
Recovery restores services in a controlled order. It also checks that credentials, backups and security settings are safe.
Legal advisers can assess the ICO’s 72-hour notification threshold after a personal data breach. The business should document decisions, customer messages and remedial actions.
This sequence creates a clearer record for regulators and insurers. Next, the focus shifts to records prepared before any attack.
Prepare a claim before an attack
Claims preparedness means keeping a 24/7 contact sheet, asset list and tested backups. Keep a short decision playbook before pressure makes records hard to keep.
Which records support lost-income claims?
A business interruption claim usually needs a dated outage timeline. It also needs sales and accounting records, order data and payroll information.
Keep saved costs and extra costs. Do not rely on a rough estimate of missed sales.
- Daily sales, invoices, order cancellations and customer refund records.
- Bank statements, payroll, management accounts and supplier invoices.
- Emergency costs, including temporary equipment, manual processing and specialist support.
- Copies of the insurer’s consent for suppliers or unusual spending.
What goes in a one-page playbook?
List the claims hotline, broker and key director. Include the IT provider, bank, payment provider and data processor.
Also list critical services and backup locations. Store a printed copy away from the main network.
🎯
Useful for this topic
An encrypted external drive can store offline copies of key claim records and contact lists. It does not replace tested, managed backups or insurer-led forensic evidence.
- Keeps incident notes and key records away from a compromised laptop
- Helps protect customer and financial files if the drive is lost or stolen
- Supports an offline backup routine for a small business without an IT team
Find on Amazon →
Run a 30-minute tabletop exercise twice each year. Use a realistic event, such as phishing takeover or ransomware.
Ask who calls whom. Ask where logs are stored and how orders continue without normal systems.
Small business cyber resilience should cover the incidents most likely to stop ordinary trading. These include phishing takeovers of Microsoft 365 or email accounts.
They also include ransomware that encrypts shared files. Malware on a staff device can also cause disruption.
Attacks on cloud, payroll or payment suppliers also matter. The loss rarely stops at IT repair.
A compromised mailbox can cause false payment instructions and missed orders. It can also delay payroll and cause customer refunds.
It may require data breach legal advice. Client contact can also cause reputational damage.
One compromised director account can stop trading for several days.
For a microbusiness without internal IT, the effect can be severe. Quotes, invoices and customer support may all stop.
Record the incident timeline from the first alert. Keep emails, logs and other evidence for the cyber claim.
Keep business interruption records showing actual sales effects. Include cancelled work and extra costs.
Avoid the mistakes that weaken a claim
Cyber insurance is not a blank cheque. Cover depends on wording, limits, excesses, exclusions and notice conditions.
Cover may also depend on insurer consent for suppliers or unusual costs.
Containment is necessary. But deleting logs, reinstalling devices or resetting passwords without records can hinder forensic work.
Keep original material where possible.
Match claimed turnover loss to sales records, orders and refunds. Match it to the actual outage period too.
Allow for normal seasonal or trading changes.
Frequently asked questions
What does cyber insurance cover for a small business?
Cyber insurance may cover response costs, data recovery, legal advice and notification. It may also cover cyber extortion and business interruption, subject to policy terms.
Limits, excesses and exclusions vary widely.
Do small businesses need incident response?
Small businesses need a clear incident response route when they rely on email, cloud systems or online payments. It also matters where they hold customer data.
Check if the policy includes a 24/7 response service.
How do I make a cyber insurance claim in England?
Notify the insurer through its stated claims route as soon as an incident is suspected. Preserve logs and records, and use approved suppliers where required.
Document losses as they arise.
Does cyber insurance cover ransomware in the UK?
Ransomware may be covered under cyber extortion sections. Payment is never automatic.
It may need insurer consent, forensic evidence, legal input and sanctions checks.
A prepared SME needs a fast claims call, preserved evidence and records of disruption costs.
The essentials:- Call the insurer’s claims hotline early, rather than waiting to assess ICO reporting.
- Keep logs, screenshots and a dated action timeline before restoring affected systems.
- Support interruption losses with sales, accounting, payroll and extra-cost records.
- Use a short playbook and a 30-minute exercise to prepare your team.
Review your policy’s incident-response panel. Compare cyber insurance for UK SMEs with controls needed for Cyber Essentials readiness.
Related sources
These articles can help you explore the topic in more depth: