A FCA review, an incident or an insurance renewal can expose the same uncomfortable gap: a firm may believe it is covered, yet find that fines, outages or third-party losses sit outside the policy. For a small regulated business, that gap can quickly turn a manageable event into a costly one.
For FCA-regulated firms, compliance cover is not a single product but the overlap between regulatory expectations, operational resilience and the right cyber insurance wording. The key question is whether the policy supports incident response, business interruption and third-party claims while the firm’s evidence shows cyber risk is being managed properly. Done well, it closes a costly gap.
Does FCA cyber cover actually protect your firm?
Yes, but only if the policy wording matches your controls and your evidence matches your story. The FCA does not usually demand a separate cyber policy, yet it does expect sound governance, clear responsibility and proof that the firm can handle a cyber event without losing control of clients, data or operations. Cyber insurance can support that, but it does not replace it.
A lot of owners think cover starts where compliance ends. That is backwards. In practice, the insurer checks whether the firm already does the basics: knows who owns cyber risk, can spot an incident, can contain it, and can show the board what happened. A policy then helps with the cost of recovery, legal help and some losses that follow.
The legal and commercial question is simple: will the policy pay when the event happens? According to the Financial Conduct Authority, firms should have systems and controls that are fit for purpose, which includes managing operational risk and outsourcing risk. See the FCA’s own guidance on cyber security and resilience: FCA cyber security and resilience guidance.
What it usually pays for
Cyber insurance usually helps with four things first. It pays for incident response costs, such as forensic work, legal support and notification costs. It also often covers business interruption, third-party claims and some data breach costs.
For an FCA-regulated SME, that can mean the cost of calling in specialists after ransomware, paying for customer notifications after a data breach, or covering lost income when a trading platform, payment system or client portal stops working. The cover is rarely unlimited. The wording sets the limits.
A useful rule of thumb is this: if the loss comes from the incident itself, there is a fair chance the policy responds. If the loss comes from weak controls, poor patching or a problem already known before renewal, the response gets weaker fast.
What it usually excludes or limits
Most policies do not act like a blank cheque. They often limit or exclude regulatory fines, penalties that the law does not allow to be insured, and losses linked to poor maintenance or known security gaps. Some also narrow cover for indirect losses, like wider business slowdown after a breach.
This is where many firms get caught. They buy cyber liability cover, then assume every outage or regulatory cost will be reimbursed. The error most often seen at claim stage is simple: the policy was bought for comfort, not for the way the business actually runs.
Coverage test: if a five-day outage stops client service, ask whether the policy covers lost income after a waiting period, or only direct response costs. Many policies use a 8 to 12 hour waiting period, and some require a named system failure.
| Loss type |
Usually covered? |
Common limit or issue |
| Incident response |
Often yes |
Panel firms, approval steps, sub-limits |
| Business interruption |
Often yes |
Waiting period, system definition, proof of loss |
| Regulatory fines |
Often no |
Uninsurable by law or limited by wording |
| Third-party liability |
Often yes |
Claims made wording, notification timing |
What the FCA expects before a claim exists
The FCA expects a firm to manage cyber risk as part of ordinary governance, not as a side issue for IT. That means named responsibility, evidence of testing, clear reporting and a plan for disruption. It also means the board knows what the material risks are and how they are watched.
For most small regulated firms, the standard is not perfection. It is proof. If the board can show it asked the right questions, challenged weak areas and tracked fixes, the firm is already in a much stronger place than one that only bought insurance at renewal.
This is where compliance and insurance start to overlap. The same records that help a supervisor understand the firm can also help an insurer trust the risk. That is why good cyber compliance cover is really a story backed by documents.
Which FCA principles matter most
The FCA Principles for Businesses are broad, but two matter a great deal here. Principle 2 asks a firm to conduct its business with due skill, care and diligence. Principle 3 expects the firm to take reasonable care to organise and control its affairs responsibly and effectively, with adequate risk management systems.
That sounds abstract until a real incident lands. A firm that cannot show patching, access control, board oversight or incident testing may struggle to prove it acted with reasonable care. The FCA does not need a perfect system. It needs a sensible one that the firm actually uses.
How SM&CR changes accountability
The Senior Managers and Certification Regime changes the tone of the whole discussion. It puts accountability in named hands. If cyber risk sits under a senior manager, that person should be able to explain the controls, the reviews and the response path without guessing.
That does not mean the senior manager must be technical. It means they must know enough to challenge the business. A board paper that says, in plain English, what systems matter, what happened last quarter and what still needs fixing is far better than a vague dashboard.
Where nikhil rathi and andrew bailey fit
The FCA under Nikhil Rathi has kept resilience high on the agenda, and Andrew Bailey at the Bank of England has long pushed the same theme from a prudential angle. The message is consistent: firms should be able to keep serving customers through disruption, not just react after it.
The practical lesson is simple. If a cyber event stops payments, client access or advice delivery, the firm should already know who decides, who speaks and who records the decision. That is what the FCA expects to see when things go wrong.
Board evidence that helps twice: the same three things support both compliance and a claim: signed minutes, incident logs and evidence of challenge. If the board asked about ransomware readiness in March 2024, keep that record.
Why operational resilience matters too
Operational resilience is the idea that a firm should keep its most important services running, or recover them quickly, after a shock. Think of it like having a spare key, a backup phone and a clear fire exit. The point is not to avoid every problem. The point is to keep the business usable.
A firm that cannot name its important business services, map key systems and test recovery will find both the regulator and the insurer asking awkward questions. In recent years, several UK firms found that the real gap was not hacking skill. It was poor recovery planning and poor evidence.
What insurers check before quoting
Insurers do not quote on hope. They usually ask about controls, recent incidents, third parties, backup practice and whether staff use sensible basic protection such as multi-factor authentication. They also look at the size of sensitive data held and the firm’s dependence on critical suppliers.
The most common underwriting mistake is to answer these questions loosely. A half-truth on the proposal form can become a claim problem later. Underwriters often compare the answers against the website, the accounts, public filings and any past incidents.
Which controls underwriters expect
Most cyber insurers want a small set of basic controls in place. These usually include multi-factor authentication, regular patching, endpoint protection, offline or immutable backups, access control by role and a tested incident response plan.
They may also ask whether the firm has email security filters, device encryption, security awareness training and logging. That sounds like a long list, but it is really just the digital version of locking the doors, keeping a spare key and knowing who to call when something breaks.
What evidence they may request
The insurer often wants more than a yes or no answer. It may ask for the incident response plan, the latest phishing test results, backup test dates, supplier contracts, penetration test summaries or board minutes showing cyber risk review.
A case that comes up again and again is this: a firm says it tests backups, but cannot show a restore test from the last 12 months. The underwriter then either adds a condition, narrows the cover or prices the risk more cautiously. That is not harsh. It is evidence-based.
Where a policy can be refused
A policy can be declined if the firm has weak controls, poor loss history or high-risk activity that it did not disclose properly. It can also be restricted if the insurer sees gaps in maintenance, no incident plan or unmanaged remote access.
This works both ways. Strong evidence can improve terms, while vague evidence can cost real money. According to the Association of British Insurers, cyber incidents remain a major source of business interruption and claims activity, which is why underwriters keep pressing on controls and response readiness.
"Cyber is now a board-level issue and a major source of losses for many firms." This is the practical message repeated across UK market guidance, including insurers and the NCSC.
How pricing changes with weak controls
Weak controls usually mean one of three things: a higher premium, a lower limit or a narrower set of covered events. Sometimes all three happen at once.
That is why a small firm with clean evidence, decent backup practice and a clear response plan can often do better than a larger firm with messy records. Size matters, but proof matters more.
1. Control
Multi-factor authentication on email, admin and remote access.
2. Proof
Policy settings, screenshots, or admin records showing it is active.
3. Review
Board or management note showing the control is checked and kept current.
4. Claim value
Lower chance of dispute when the loss follows a real incident, not a missing control.
How to close the gap between compliance and cover
The best way to join compliance and insurance is to keep one file that proves three things: the firm knows its risks, it has basic controls, and it can respond properly if something goes wrong. That file should not be fancy. It just needs to be current, clear and easy to show.
This is where many guides get lazy. They say to "improve governance" or "review controls" and then stop. In practice, the insurer and the FCA both want dated evidence. A policy without proof is just a promise.
Board papers you should keep
Keep board or committee minutes that show cyber risk was discussed, challenged and assigned to someone. Keep the paper that lists key systems, major threats, top suppliers and open actions.
A short paper is fine if it says something useful. One page that names the most important services, the main threat, the next test date and the person responsible can beat a long, vague pack every time.
Incident response documents to retain
Keep the incident response plan, contact tree, decision log and any table-top exercise results. If the firm had a real incident, keep the timeline, the actions taken and the lessons learned.
The plan should say who calls the insurer, who talks to the FCA if needed, who checks the logs and who decides whether the issue is contained. If those names are not written down, the plan will slow down at the worst possible moment.
Third-party due diligence evidence
Keep supplier checks for any critical outsourced service. That means cloud providers, payment firms, managed IT firms, call centres and any other business that can affect client service if it fails.
The evidence can be simple: a risk note, a contract review, a security questionnaire, a service level summary and a record of who approved the supplier. The key is to show the firm did not just trust the brochure.
Training and testing records that matter
Keep training records, phishing test results and backup test notes. The NCSC consistently points firms back to basic measures, because many breaches still start with stolen credentials, weak passwords or a click on a fake email.
The date matters. A training slide from years ago will not impress anyone today. A three-hour gap between a phishing test and an updated staff reminder can make a much better story.
Paper trail that helps a claim: keep the insurer’s proposal, the wording, the schedule, the incident plan and the last backup test. If those five items disagree, a claim review gets slower.
- Checklist to keep on file
- Board or committee minutes showing cyber risk oversight and challenge.
- Incident response plan, table-top exercise results and post-incident lessons learned.
- Supplier due diligence, contract reviews and critical third-party registers.
- MFA, patching, backups, access control and monitoring evidence.
- Security awareness training logs and phishing test results.
- Data mapping and breach escalation procedures aligned to UK GDPR and the Data Protection Act 2018.
- Payment security evidence where card data is handled, including PCI DSS controls.
For FCA-regulated firms, cyber compliance cover works best when it is treated as a bridge between regulatory expectations and insurance protection. In practical terms, that means mapping each major risk to a control, an owner and a policy clause. For example, if a firm relies on a managed IT provider for email and backups, the contract should show security obligations, incident notification times and support for forensic access. If the firm handles client money or sensitive personal data, the cyber insurance should be checked for data breach costs, notification costs and third-party claims, while the compliance file should show MFA, patching, board oversight and tested incident response.
This is the difference between buying cyber insurance and proving cyber readiness.
A workable FCA compliance checklist does not need to be long, but it does need to be current and evidenced. Keep a short pack with board minutes, a risk register, an incident response plan, supplier due diligence, backup test results, phishing training records and a summary of key systems and controls. If a firm says it has operational resilience, it should be able to show the important business services, the impact tolerances, the recovery testing and the owners responsible for fixes.
If it says it has outsourcing risk under control, it should hold service levels, security questionnaires and escalation routes for critical suppliers. Those documents also help underwriters assess cyber liability cover and decide whether business interruption, incident response costs and third-party claims are insurable on the wording offered.
A strong paper trail is especially important when an incident actually happens. A board should be able to show who was told, when decisions were taken, what systems were affected and how the firm assessed customer impact. A simple incident log can record the first alert, containment steps, legal advice, insurer notification and any regulatory reporting decision. For third-party risk, the file should show whether the supplier was critical, what due diligence was completed and whether the contract allowed fast cooperation in a cyber event.
That same evidence helps in a claim review because it shows the loss was managed, not ignored. In practice, firms that can document incident response, board challenge and supplier oversight are usually better placed both with the FCA and with the insurer.
What claims usually fail, and why
Claims often fail for boring reasons, which is the frustrating part. The loss may be real, but the policy may still reject it because the firm did not keep the right evidence, missed a notice deadline or failed to maintain the control it said it had.
A lot of people assume the insurer wants to avoid paying. Sometimes that is not the real issue. The real issue is that the policy was written around a certain level of care, and the firm did not meet it.
Are ransomware payments always covered
Ransomware payments are not always covered, and they are not always sensible either. Some policies help with negotiation, forensic work and recovery costs, while others limit or exclude the actual payment.
The issue gets messy fast when sanctions rules, criminal links or payment approval are in play. A firm should never assume that because ransomware is common, the insurer will simply reimburse it. The wording and the law both matter.
Do outages count as business interruption
Outages can count as business interruption if the wording covers them and the trigger is met. That may mean a cloud failure, a malware event or a system outage caused by a covered incident.
The trap is that some wordings only cover outages linked to a direct security event. If the cloud provider has a general outage not tied to a covered cyber event, the policy may not respond. This is where the exact wording wins over the sales summary.
Will regulatory fines be reimbursed
Regulatory fines are often excluded, limited or left unaddressed because the law may not allow some penalties to be insured. Under UK rules, the position can depend on the nature of the fine, the wording and the underlying conduct.
That is why firms should not buy a policy hoping it will make an enforcement problem disappear. Under the UK GDPR and Data Protection Act 2018, the Information Commissioner's Office can still investigate, and the policy may only help with defence costs or associated expenses.
When third-party liability still applies
Third-party liability can help if a client, supplier or partner claims the firm caused a loss through a breach or outage. That may include data exposure, service failure or negligent handling of information.
The catch is timing and proof. The claim must fall within the policy period and the firm must show a covered event. If the loss came from poor contract wording or a missed notification step, the response can be narrower than expected.
Special cases for regulated SMEs
Some regulated SMEs need more careful wording because their risks are not standard office risks. Payment firms, advisory firms, firms handling special category data and businesses with heavy outsourcing often face more insurer questions and more exposure if something goes wrong.
The principle is the same, though. The firm should match its policy to the way it really works, not to the brochure version of itself.
How payment firms differ
Payment firms often face extra scrutiny where card data, payment flows or real-time services are involved. That can bring PCI DSS into the picture, along with stronger expectations around access control and monitoring.
If a payment system fails, the loss may be larger than the direct fix. Chargebacks, client distrust and service disruption can follow. The policy needs to be checked for those knock-on losses, not just the first repair bill.
When professional indemnity interacts
Professional indemnity insurance can sit beside cyber cover, but they do different jobs. Cyber cover usually deals with the event, the breach and the recovery. Professional indemnity usually deals with professional advice or service failure.
A claim can straddle both. For example, a breach might expose client data and also interrupt a regulated advice service. The firm should check which policy leads, which excludes the other, and how notification works between them.
What changes if you handle health data
If the firm handles health data, the breach risk becomes more sensitive and the reporting burden can rise quickly. That is because health data is usually special category data under UK GDPR, which the ICO treats carefully.
A small firm that holds medical evidence, suitability notes or health-related client information should treat access control and retention with extra care. It does not need giant systems. It does need tight permissions and good records.
When outsourcing creates hidden exposure
Outsourcing creates hidden exposure when the third party becomes the weak point. If a cloud service, IT provider or outsourced call centre fails, the regulator will still ask how the firm chose, reviewed and watched that supplier.
A case that comes up often is a firm that outsources nearly everything, then discovers the contract does not say who handles incident notice, logs or recovery cost. The result is delay, blame and a slower claim. That is avoidable with basic due diligence.
Questions to ask before renewal
Before renewal, ask whether the policy follows the real shape of the business. A cheap policy that misses your biggest outage or breach scenario can be more expensive than a stronger one.
A sensible renewal review should link three things: the FCA’s expectations, the insurer’s underwriting questions and the firm’s actual evidence file. If those three do not line up, the policy may look fine and still disappoint when used.
Does this policy match our controls
Ask whether the policy assumes controls that the firm really has. If the policy expects MFA, logging, patching and tested backups, the evidence should show those controls are live, not just promised.
If the answer is weak, fix the controls before renewal or ask the broker to show how the wording changes when a control is missing. That is better than discovering the gap after an incident.
What evidence would a claim need
Ask what evidence the insurer would want after a breach or outage. That usually includes logs, incident timelines, backup test records, supplier records and proof that the incident response plan was used.
A short evidence pack is enough if it is complete. A long pile of unrelated files can slow things down. Keep the useful items together from the start.
How often should we re-test this
A firm should test its response at least once a year, and after any major system or supplier change. Many firms also do a lighter tabletop exercise every six months, which is often enough for a small team.
If nothing changes, yearly may be enough. If the firm adds a new platform, new processor or new office setup, test sooner. The policy should keep up with the business, not the other way round.
This advice does not fit every business. It is less relevant if the firm is not FCA-regulated and only wants a standard cyber policy for general business risk. It is also less useful where a dedicated compliance team already manages policy wording, controls and regulatory mapping in detail.
Frequently asked questions
Do FCA-regulated firms have to buy cyber
No, not usually. The FCA does not normally force a regulated firm to buy a specific cyber insurance policy. It does expect the firm to manage cyber risk properly, though. That means governance, controls, incident response and operational resilience. Cyber compliance cover is useful because it helps fund the response, but it does not replace the duty to control the risk.
Does cyber insurance cover FCA fines?
Usually not in full. Many policies exclude fines, limit them, or only cover defence costs around an investigation. Some penalties are not insurable under law. A firm should read the wording carefully and check how the insurer treats regulatory action, especially where the issue involves data breach, governance failings or delayed reporting.
Will a ransomware attack be covered?
Often, yes, but not always the whole loss. Many policies help with forensic work, recovery, negotiation and some business interruption. The ransom payment itself may be limited or excluded. The insurer will also look at whether the firm used basic controls, such as MFA and patching, before the attack.
Does UK GDPR change what cyber insurance should
Yes. UK GDPR and the Data Protection Act 2018 shape breach response, notification and possible claims after a data breach. The policy should help with legal advice, notification costs and response work. It may not cover any fine. The Information Commissioner's Office can still investigate even when insurance is in place.
What evidence do insurers ask for at renewal?
They often ask for proof of MFA, backup testing, incident response planning, training and supplier checks. Some will also ask for recent incident history, patching practice and board oversight records. The better the evidence, the easier it is to defend the wording and the price at renewal.
How does operational resilience affect cyber
Operational resilience affects the size and shape of the risk. If a firm depends on one platform, one supplier or one payment route, an outage can hit hard and fast. Insurers want to see that the firm knows its important services, tests recovery and keeps evidence. The FCA expects the same kind of discipline.
Can professional indemnity insurance replace
No. They cover different problems. Professional indemnity insurance usually deals with advice or service mistakes. Cyber cover deals with incidents like ransomware, data breach, system failure and third-party liability tied to a cyber event. Some losses may touch both policies, so the firm should check how each one responds.
What to do before the next breach
The simplest way to avoid a bad surprise is to treat cyber cover as part of the firm’s control set, not a standalone purchase. The policy should match the way the business works, the evidence should show the controls are real, and the board should be able to explain both without hesitation.
If the wording, the controls and the records line up, claims are easier and renewals are calmer. If they do not, the firm may still be insured on paper and exposed in practice. That is the gap to close now, before the next incident forces the issue.
Which exclusions would hurt us most
Ask which exclusions would hit the firm hardest. For many FCA-regulated SMEs, the big ones are ransomware payment limits, business interruption waiting periods, third-party system exclusions and regulatory fine exclusions.
The best question is simple: if our main system failed for three days, what part of the bill would this policy actually pay? If the answer is fuzzy, the wording needs another look.