A supplier’s ‘updated bank details’ email lands in a director’s personal inbox on Sunday evening. They check it on the same phone used for company email. They approve the change on Monday. The payment goes to a fraudster. The business may be family-run, but the loss is not automatically private or covered.
For family-owned SMEs, personal and business cyber risks often overlap. A relative’s email, phone, or social-media account can expose company banking, customer data, and supplier accounts. Cyber insurance may respond when covered company systems, data, or activity are affected. It will not automatically cover private losses.
Will your policy cover a family-started cyber loss?
A personal device can form part of a covered cyber incident. Device ownership alone does not decide cover.
Does a personal device make it private?
A personal laptop used for company email can cause a cyber incident. It may expose client records, payroll files, or business passwords. This is often called bring your own device. It means using a personally owned device for work.
Personal ownership does not remove the business risk.
- List every personal phone, tablet, and computer that can access company email, cloud storage, or accounts software.
- Turn on multi-factor authentication. It needs a second identity check, such as an app code.
- Remove company passwords and saved banking details from devices no longer used for work.
When does family email become business risk?
A family inbox becomes a company risk when it receives supplier invoices, customer details, password-reset links, or payment instructions. A criminal needs one convincing email. That email can move from a private chat into the firm’s accounts.
The error most firms make is treating a personal inbox as harmless. It stops being harmless when it handles business instructions.
Shared family access creates the easiest attack route
Family firms face a distinct risk because informal trust can become informal access.
Why do shared log-ins cause bigger losses?
A shared Microsoft 365, Xero, or cloud-storage account hides who read, changed, or deleted information. It also slows forensic work. Forensic work is the technical process of finding how an incident happened.
Shared log-ins can also make claims harder to prove.
One account, one owner: Shared passwords make attacks harder to trace. They can also make claims harder to evidence. Named access, multi-factor authentication, and written payment checks create a clear trail. They need not make daily work difficult.
Can a fake family request cause invoice fraud?
Yes. A criminal may copy a director’s writing style. They may use a stolen WhatsApp profile photo. Then they ask a relative to “pay this before lunch”.
This is invoice fraud when a message sends a genuine business payment to the criminal’s bank account.
- Use a call-back rule for every new bank detail or urgent transfer above a chosen amount.
- Call a known number from your records. Do not call the number shown in the suspicious email.
Which old access matters most?
Former family workers, ex-partners, retired directors, accountants, and old IT contractors may retain quiet access. Check online banking mandates and domain registrar accounts. Also check social-media pages, cloud administrators, and password-manager recovery contacts. Review Companies House filing access too.
Family firms should plan for more than invoice fraud or ransomware. Phishing can capture Microsoft 365 credentials. It can then lead to business email compromise. Malware can steal browser cookies or banking details from a home computer used for work.
A denial-of-service attack can stop customers reaching an online shop or booking system. This can happen even when no data was stolen. Supplier and cloud links matter too. A compromised accounting platform, IT provider, or payment processor can block vital records and trading systems.
Keep a list of key suppliers, their data access, and their account access. Keep another contact route for each supplier.
Knowing who can enter is only the first task. The next section explains what the policy may actually pay.
What cyber insurance may pay and refuse to pay
Cyber insurance can pay after a covered digital incident. The headline limit is only part of the answer.
Is a tricked bank transfer covered?
A director may approve a payment after being deceived. Ordinary cyber cover may not pay for that loss. It may need a social engineering fraud, crime, or funds-transfer fraud extension.
Each extension can have its own sub-limit and verification rules.
| Family-business loss | May be covered by cyber policy | What to check before buying |
| Ransomware encrypts company files | Forensics, recovery, extortion response | Back-up condition, excess, and recovery sub-limit |
| Supplier invoice changes through email fraud | Only if the fraud extension applies | Social engineering or funds-transfer fraud limit |
| Customer data leaves a personal inbox | Response and liability may apply | Definition of insured data and notification costs |
| Director loses private savings after a scam | Usually no | Personal cyber or identity protection options |
Does ransomware include lost trading income?
Business interruption cover may pay lost income and extra costs after a covered event. It often starts after a waiting period between 8 and 24 hours. It may not respond when only a supplier or cloud provider causes the outage.
Dependent business interruption cover may be needed for that supplier failure.
✅
Our recommendation
An encrypted external drive keeps essential company records away from a compromised home computer. It supports recovery. It does not replace tested cloud backups or insurance cover.
- Keeps key accounting and customer records outside the main business network.
- Encryption helps protect the copy if it is lost between home and office.
- Lets a family firm test file recovery before a ransomware event.
Check availability →
Before arranging or renewing cyber insurance, make a short underwriting checklist. Include turnover, sensitive data, and online banking arrangements. Include remote devices, cloud account access, key suppliers, and the highest payment one person can approve.
Compare those risks with response, business interruption, data liability, and funds-transfer fraud limits. Check lower sub-limits for social engineering too. Ask about outsourced IT failures, work devices, regulatory defence costs, and cloud-data restoration.
The checklist should identify cyber insurance policy exclusions. These can include known incidents, unsupported software, and unencrypted devices. They can also include failures to follow required payment checks.
Do not assume a headline limit pays every loss.
Lock down family access before renewal or a crisis
The best action is to map every person, device, and recovery route reaching key business systems. Then remove shared and outdated permissions.
Which accounts need named owners?
Give each critical account a named business owner and a back-up owner. Keep recovery email addresses under company control. Do not rely on one family member’s private mailbox.
Named ownership makes handovers less risky.
What changes after a family exit or death?
A separation, retirement, incapacity, or death should trigger an access review within 24 hours. Review banking, email, and domain rights. Remove multi-factor authentication methods and saved recovery numbers. Change shared passwords and record who now approves payments.
A family exit can leave hidden access behind.
What happens in the first 24 hours?
If you find a suspicious payment, takeover, or data breach, preserve evidence and contact the bank quickly. Call the insurer’s incident line. Seek legal or forensic help where needed.
Do not delete messages or reset every account before recording what happened. Evidence may be needed to stop further loss.
- Stop further payments and ask the bank to recall or freeze transfers.
- Disconnect affected devices from the network. Keep them available for investigation.
- Notify the insurer or broker through the policy’s claims contact details.
- Check whether UK GDPR reporting to the Information Commissioner’s Office is needed within 72 hours.
These measures matter less when family members have no company access. There must be real separation of identities, equipment, administration, and authority. They do not replace legal, forensic, or insurance advice after a specific incident.
Effective family business cyber security relies on routine controls. It does not rely only on actions after an incident. Give family members and staff short, repeated training on phishing, password-reset scams, and fake payment requests.
This matters when private and work messages overlap. That overlap creates a personal email business risk. Apply security updates quickly to phones, routers, laptops, and accounting software. Use a password manager with company-controlled recovery contacts.
Shared account security means separate log-ins. It does not mean one password shared by several relatives.
Test payment checks regularly. Make sure staff can spot suspicious supplier bank-detail requests. They should know how to raise concerns without delaying real trade.
What people ask
Is cyber insurance worth it for a family-owned business?
Cyber insurance is worth considering when a business relies on email, online banking, customer data, or cloud systems. It can fund covered response costs. Check fraud and payment cover separately.
Does a business policy cover a director’s personal email?
A business policy may respond when personal email causes a covered company loss. Cover depends on the insured definition, affected business data, and policy exclusions.
Are shared home devices covered by cyber insurance?
Shared home devices can fall within scope when they access company systems or information. The policy may still require multi-factor authentication, supported software, and reasonable security controls.
Do I need to report every cyber incident to the ICO?
No, not every incident needs ICO reporting. Report within 72 hours when a personal-data breach may risk people’s rights and freedoms.
The essentials:- Private accounts can create company exposure, but ownership alone does not decide insurance cover.
- Invoice fraud often needs separate social engineering or funds-transfer fraud cover.
- Named access, multi-factor authentication, and call-back checks reduce risks created by family trust.
- Family exits and bereavement should trigger a 24-hour review of banking, recovery, and administrator access.