Monday morning: a director finds locked files, halted invoices, and a supplier asking if customer data was exposed. The immediate issue is cash: can the business restore systems and keep trading without delaying wages, stock, or tax payments?
Self-insuring vs buying cyber insurance: small business break-even analysis compares retained losses, premiums, reserve costs, and cash available during an incident.
When cyber risk exceeds your cash capacity
A UK SME should usually buy cover when a plausible cyber loss exceeds cash available within 30 days. That cash must not harm normal trading.
Self-insurance means holding accessible money for losses instead of buying a policy. It does not mean simply going without cover.
If the same funds pay payroll, VAT, suppliers, or stock, they are not a cyber reserve.
Ransomware can stop orders and require forensic specialists. It can also trigger customer claims at the same time.
Contracts or tenders may require proof of a stated cyber limit. This can apply even when self-insurance seems cheaper.
A premium is not the full insured cost
The premium is only one part of insurance cost. You must also allow for the excess, exclusions, and losses above policy limits.
Liquidity sets the real threshold
Liquidity means money you can access quickly. Think of it as cash ready in a fire bucket, not money locked away elsewhere.
Contracts can make insurance necessary
A client contract can require cyber insurance regardless of your cash position. Check tender terms before relying on any break-even calculation.
A practical threshold: If your business cannot pay for an incident, keep trading, and rebuild reserves within 12 to 24 months, full self-insurance is unlikely to be safe.
Calculate your retained cyber cost
Expected annual loss is a planning estimate, not a forecast. Multiply incident probability by estimated net loss, then compare it with insured cost.
Net loss should include downtime, investigation, recovery, legal advice, communications, and customer liabilities. Subtract realistic recovery from backups, banks, suppliers, or contracts.
Self-insurance also has a reserve funding cost. Insurance cost includes premium, expected excess, exclusions, and losses above limits or sub-limits.
A 10% annual chance of a £30,000 net incident creates a £3,000 expected loss. The company must still survive the full £30,000 event.
Estimate chance without false precision
Use a sensible range rather than pretending certainty. Past incidents, supplier failures, and the type of data held can guide the estimate.
Apply excesses and policy limits
An excess is the amount you pay first on a claim. A policy limit is the most the insurer may pay under that section.
Treat exclusions as retained losses
An exclusion is a loss the policy does not cover. Treat that amount as your own risk when comparing options.
Use one consistent cyber loss calculation for every scenario. Start with Expected Annual Loss (EAL) = incident probability × net uninsured loss.
For self-insurance, include recovery, downtime, legal, notification, customer claims, and ransomware recovery costs. Subtract realistic recoveries and add annual reserve costs.
For insurance, calculate annual insured cost = premium + claim probability × excess + expected exclusions and over-limit loss. Use the same incident estimate in both calculations.
For example, a 15% chance of an £80,000 incident produces a £12,000 EAL before recoveries.
If a policy costs £5,000, has a £2,500 excess, and leaves £6,000 uninsured, its cost is £6,275. The calculation is £5,000 + (£2,500 × 15%) + (£6,000 × 15%).
This assessment does not remove uncertainty. It makes the break-even assumptions visible and open to testing.
Compare a reserve with a three-year policy
A reserve ties up cash that could reduce borrowing, buy stock, or protect against slow-paying customers. A policy buys defined limits and access to insurer-selected incident support.
The figures below are illustrations, not quotations. Replace them with your premium, excess, accessible cash, and severe-loss estimate.
Test ransomware, data breach, payment fraud, and supplier outage separately. Their costs, recoveries, and policy terms can differ.
A reserve that covers an average loss may still fail during a severe event. That is why many SMEs use insurance plus a retained excess.
| Business profile | Accessible cash | Plausible severe loss | Policy cost over 3 years | Reserve target | Likely approach |
|---|
| Micro trader, £120k turnover, online invoices | £12,000 | £20,000 to £35,000 | £2,400 to £4,500 plus excess | £20,000 to £35,000 | Insurance plus small reserve |
| Cloud-based service firm, £500k turnover | £60,000 | £50,000 to £150,000 | £4,500 to £9,000 plus excess | £50,000 to £150,000 | Insurance with retained excess |
| Data-heavy small company, £1m turnover | £250,000 | £150,000 to £500,000 | £9,000 to £24,000 plus excess | £150,000 to £500,000 | Higher limit and reserve |
Compare three cash profiles
The table compares accessible cash with a plausible severe loss. It shows why turnover alone cannot prove that a business can self-insure.
Price cash held in reserve
A reserve has a cost even when no incident happens. That money may otherwise reduce debt or help fund stock.
Test ransomware and outage separately
Ransomware and supplier outages can stop billing for several days. Test each event rather than relying on one average loss figure.
⭐
Selected for you
An encrypted external drive can support an offline backup copy. It may reduce data-recovery time after ransomware. It does not replace tested backups, access controls, or insurance.
- Creates a separate copy of essential records away from the main computer
- Encryption helps protect backup data if the drive is lost or stolen
- Supports a recovery test without relying solely on cloud access
View on Amazon →
A practical scenario should separate the incident route from its financial effects. Phishing may cause stolen credentials, false supplier bank changes, or unauthorised cloud access.
Ransomware may stop invoicing and operations. A data breach may create forensic, legal, notification, and third-party costs.
A supply-chain incident can interrupt an otherwise secure business. It may rely on a hosted platform, managed service provider, or payment processor.
For a £500,000-turnover firm, five lost working days can hurt badly. Business interruption and emergency manual work may cost more than technical repair.
Testing each threat separately stops a low average estimate from hiding a cash-draining event. That event could exhaust cash before insurance payments or customer receipts arrive.
When self-insurance is not viable
Self-insurance fails when one plausible event would breach accessible cash, break a contract, or stop essential payments. A business needs more than money shown in its bank balance.
A company may have £40,000 in the bank. If £30,000 is committed to wages, VAT, and subcontractors, only £10,000 remains for an incident.
Ring-fenced money must be documented and quickly available. Selling investments, chasing late invoices, or arranging emergency lending means you have retained a funding problem.
Regulatory investigation, legal advice, and breach communications can create costs beyond any fine.
Ring-fenced money must be usable
A genuine reserve must be separate from daily trading cash. It must also be available when an incident starts.
Client clauses can override maths
A client clause can make insurance necessary even if self-insurance appears cheaper. The contract may state a minimum limit or name specific cover types.
Regulation creates costs beyond fines
A breach can create legal and communication costs before any regulator decides on a fine. These costs can arise even where no fine is issued.
The most frequent mistake is counting all bank cash as incident cash. Only funds that remain available after essential commitments belong in the calculation.
Check terms before relying on a limit
A cyber policy is worth its likely payable claim, not its headline limit. Read the schedule, wording, and endorsements together.
Identify excesses, waiting periods, sub-limits, exclusions, and security duties. These details decide what may be paid after an incident.
Business interruption may start only after 6, 12, or 24 hours. Smaller caps may apply to payment fraud, data restoration, extortion, or public relations support.
Many policies require multi-factor authentication, tested backups, and timely patching. After an incident, the business may need proof that it met those conditions.
Use identical facts when seeking quotations. This makes limits and terms easier to compare fairly.
Waiting periods can leave a gap
A waiting period is time that must pass before cover starts. A short outage may fall entirely within that unpaid period.
Sub-limits restrict key services
A sub-limit is a smaller cap within the overall limit. It can apply to extortion, data restoration, or payment fraud.
Security duties affect a claim
Security duties are steps the insurer expects you to maintain. Examples include multi-factor authentication, backups, and software updates.
This analysis is incomplete where a customer, tender, lender, or contract requires stated insurance. It also cannot interpret policy wording. Review contractual requirements and insurer documents with an authorised insurance professional. It matters less for firms with minimal digital exposure, no personal data, no online payments, and no operational system reliance.
Cyber insurance for small businesses often combines first-party and third-party protection. The wording matters more than the policy label.
First-party cover may help with forensics, data restoration, ransomware recovery, and incident response. It may also cover legal advice, notification, public relations, and insured business interruption.
Liability cover may respond to some customer or third-party claims. Those claims must follow a data breach or security failure covered by the wording.
Cyber insurance exclusions can leave you responsible for known weaknesses or unapproved payment transfers. They can also exclude added contractual liability, waiting-period losses, and costs above limits.
A £100,000 headline limit is not £100,000 of usable protection for every event. The excess, cover section, and wording decide the likely payment.
What people ask
Can a small business self-insure cyber risk?
A small business can self-insure only with an accessible reserve for a severe plausible incident. If cash is needed for payroll, VAT, or suppliers, the business is uninsured.
Is cyber insurance worth it for a small business?
Cyber insurance is worth considering when one incident could exceed cash or interrupt trading. Compare premium, excess, exclusions, and limits with reserves rebuilt within 12 to 24 months.
How do I calculate cyber insurance break-even?
Multiply incident probability by net loss, then add reserve funding cost. Compare this with premium, expected excess, excluded costs, and likely over-limit losses.
Does cyber insurance cover ransomware?
Cyber insurance may cover ransomware response, recovery, and extortion costs when the wording includes them. Check sub-limits, security conditions, excesses, waiting periods, and supplier controls.
Are GDPR fines covered by cyber insurance?
GDPR-related costs and fines are not automatically covered by cyber insurance. Cover depends on UK law, the policy wording, and whether the cost is legally insurable.
What excess should a small business choose?
Choose an excess the firm can pay immediately without harming wages, tax, suppliers, or recovery work. A higher excess may cut premium but increases retained claim costs.
Do clients require cyber insurance in England?
Some English clients require cyber cover through contracts or tenders. Read the clause because cyber liability, professional indemnity, and crime cover are not interchangeable.
What is the cheapest way to reduce cyber risk?
The cheapest steps often include multi-factor authentication, tested backups, and payment-change checks. These steps reduce loss severity but cannot remove all ransomware, fraud, or third-party liability.
Choose the approach your cash can support
A hybrid approach often makes sense. Insure the loss that could threaten continuity and retain a manageable excess in a protected reserve.
Full self-insurance suits firms with strong cash, low digital reliance, and no contract requirement. Even then, test a severe event rather than an average incident.
Do not compare a premium with zero. Compare it with holding enough accessible money for the event you least want to fund yourself.
Lo esencial:- A cyber reserve is real only when it is ring-fenced, quickly available, and large enough for a severe plausible loss.
- Insurance cost includes premium, excess, exclusions, and over-limit losses, not premium alone.
- Client contracts and limited 30-day cash can make self-insurance impractical despite expected-loss calculations.
- Check waiting periods, sub-limits, and security duties before relying on a headline policy limit.
Further reading
If you want to learn more about this topic, these sources may interest you: