A Monday morning phishing email can lock your mailbox as invoices fall due. Customers may also need replies.
With only a few people in the business, work stops quickly. Payments may be delayed, and client data may need checking. You may need forensic help before you know what happened.
Cyber insurance for microbusinesses (1–5 employees): cost vs benefit can be worthwhile when one serious event costs more than the premium and excess. Its value often lies in incident-response support, not only a payout.
Cyber cover for 1–5 staff: when it pays
Cyber cover can help when your firm cannot fund the full recovery bill and keep trading. First-party cyber cover pays for your direct losses. These can include forensic work, data recovery and lost income.
Third-party liability cover deals with claims or legal defence. It applies when someone says your breach harmed them.
Calculate a loss you could really fund
Use gross profit, not turnover alone. Gross profit is closer to the cash lost when orders cannot be completed.
- Lost gross profit: Daily gross profit multiplied by likely days offline.
- Response costs: Forensic checks, IT recovery, breach lawyers and customer contact.
- Extra trading costs: Temporary devices, overtime, manual order handling or a replacement website.
- Policy gap: The excess, plus any loss outside the policy wording.
Self-insurance means keeping money aside instead of buying cover. It can make sense when a business uses few digital systems.
It may also suit firms with no meaningful personal data or online payments, provided they can work manually.
A practical break-even test: Add your annual premium and excess. Compare that total with one plausible incident. Allow three to five days of lost gross profit. Allow £1,500 to £5,000 for urgent technical and legal support. Add the cost of telling affected customers. These are planning ranges, not insurer quotes.
Price the policy on like-for-like terms. A microbusiness cyber cover quote can look cheap because its limit is lower. It may also have a higher excess.
It may have a long business-interruption waiting period. It may also have small caps for ransomware or social-engineering fraud.
Ask each insurer to show the annual insurance premium and excess. Ask for the aggregate limit and downtime waiting period.
Also ask about separate caps for forensic work, data recovery and business interruption. These details change the real value of cover.
A £300 quote may have a £1,000 excess and a 24-hour wait. That may suit some firms poorly.
A £600 quote may have a £500 excess and immediate incident-response support. It may also have a higher lost-gross-profit limit.
Small business insurance should be compared by retained loss after a claim. Premium alone does not show the full cost.
Downtime often costs more than a GDPR fine
For most English microbusinesses, downtime and response work create the first large bill. A regulatory penalty is often not the first cost.
Business interruption means lost income and extra costs after an insured event stops normal trading. Think of it like a shop forced to close unexpectedly.
The bill during a five-day outage
A five-day outage is rarely five quiet days. Email can stop and accounting access may fail.
Online orders can queue up. Staff may answer worried customers instead of doing paid work.
Lost time can quickly become lost income.
Ransomware is not just a ransom demand
Ransomware is harmful software that blocks files or threatens to publish them. Criminals demand money to restore access or stay silent.
A policy may cover parts of cyber extortion. Payment is never guaranteed.
Insurers may need to check legal and sanctions issues first. This can delay any decision about payment.
For a microbusiness, incident-response support can matter as much as the indemnity limit. It gives the owner technical, legal and customer communication help on day one.
Treat data protection as an incident-response task, not only an insurance question. A personal-data breach may create risk to people’s rights and freedoms. A UK organisation must then consider notifying the ICO.
The report should be made without undue delay. Where feasible, it should be made within 72 hours of awareness.
Higher-risk cases may also need contact with affected people. Cyber liability insurance may fund breach lawyers and forensic evidence.
It may also fund notification costs and call-centre support. It does not remove the business’s accountability.
The business must still decide what happened. It must also record that decision.
Cyber Essentials does not replace insurance or GDPR compliance. Its controls can still give a small firm a useful starting point.
These controls include secure settings, updates, access control, malware protection and firewalls. They can help when talking with insurers and clients.
Choose limits from your worst workable day
Choose the indemnity limit from likely outage and response costs. The indemnity limit is the most an insurer can pay for a covered claim.
For many microbusinesses, £50,000 to £250,000 is a useful range to discuss. Choosing the lowest option only because of staff numbers can mislead.
| Microbusiness profile | Starting limit to discuss | Downtime tolerance | Main cost drivers |
|---|
| Independent consultant | £50,000 to £100,000 | 1 to 3 working days | Email compromise, client files, invoice fraud |
| Creative or marketing agency | £100,000 to £250,000 | 1 to 2 working days | Deadlines, shared cloud files, client data |
| E-commerce seller | £100,000 to £250,000 | Hours rather than days | Website, orders, payment access, customer contact |
| Local retailer with online payments | £50,000 to £150,000 | 1 to 3 days | Till systems, card payments, supplier orders |
| Sensitive personal-data handler | £250,000 and above | Less than 1 day | Notification, legal defence, restoration, claims |
Use four questions before a quote
Ask how many hours you can lose email, sales and payment access. Ask what data you hold.
Ask who can approve payments. Ask whether one cloud supplier could stop your work.
Sensitive records change the calculation
Health information, financial details and children’s data can cause greater harm when exposed. They can raise notification, legal advice and customer support costs.
Data sensitivity can matter more than headcount.
Standalone, add-on or self-insure?
A standalone policy, a cyber extension and self-insurance are not the same. The key differences are often support, sub-limits and exclusions.
The label “cyber insurance” does not tell you enough. Read the wording and compare the actual cover.
| Route | Typical limit structure | Incident support | Cash retained by business |
|---|
| Standalone cyber policy | Dedicated indemnity limit | Often specialist panel, subject to wording | Excess and exclusions |
| Business-policy cyber extension | Often smaller sub-limit | Check if included | Excess, sub-limit and exclusions |
| Self-insurance | No insurer limit | Arrange and pay directly | All losses and response costs |
Check fraud cover separately
Social engineering fraud occurs when a criminal tricks an employee into sending money. A fake supplier invoice is one common example.
An impersonated director email is another common example. This cover may need a named extension.
It may also require strict checks for changed bank details. A policy may reject a claim without those checks.
Ask about supplier failure
Your web host, payment service or payroll platform can be a critical supplier. A managed IT firm can also be critical.
Cover for supplier outages varies. It may require direct damage to your own system.
Controls and exclusions to check before buying
Controls affect both risk and insurability. Multi-factor authentication, or MFA, adds a second sign-in check after your password.
The second check might be an authenticator app or security key. MFA should protect email, banking, accounting, remote access and administrator accounts.
Prove your backups can restore
A backup helps only when it restores the files and systems you need. Test recovery every three to six months.
Keep one copy separate from the main network where practical. This reduces the chance that one attack reaches every copy.
A backup that cannot restore is not a backup.
⭐
Picked for you
A USB security key can add a second sign-in check for compatible important accounts. It can back up email and administrator access. It does not replace tested recovery plans.
- Helps protect a business email account from password-only sign-ins
- Can reduce phishing risk where the service supports security keys
- Gives a named owner a physical second factor for critical accounts
View on Amazon →
Read these exclusions word for word
Check prior acts and undeclared systems or data. Check stated control requirements and unpatched software.
Also check provider outages, ransomware payments, fraud and interruption limits. These points can change whether cover responds.
Cyber insurance may not be a priority when your business barely uses digital systems. This may apply if you hold no personal data or payments, can work manually during an outage and have enough cash to absorb the full plausible loss. Even then, UK GDPR duties and basic security steps still matter.
Before asking for quotes, list daily gross profit and maximum tolerable outage. List systems holding personal data and payment permissions.
List your tested backups too. This makes quote comparisons more useful.
Make insurability routine, not a last-minute questionnaire. Insurers often look for more than MFA and a backup. They may ask about automatic security updates and unused administrator accounts.
They may also ask about phishing training and separate bank-payment approval. A process for checking supplier bank-detail changes can reduce preventable loss.
Keep a simple record of who manages email and cloud storage. Also record who manages accounting software and your website.
Ask managed IT providers about monitoring and patching. Ask what breach-notification commitments they give.
A supplier’s security failure can still stop your work. This can happen even when your own devices are well protected.
These controls can support a better insurance premium. They can also show that minimum-control conditions were met after a claim.
FAQs
Is cyber insurance worth it for a one-person business?
Cyber insurance can be worthwhile if email, payments or client data are needed to trade. A sole operator has no colleague to keep work moving during an outage.
How much does cyber insurance cost in the UK?
UK cyber insurance cost depends on turnover, held data, controls, limit, excess and fraud extensions. Compare annual cost with a realistic loss of three to five trading days.
Does cyber insurance cover GDPR fines?
Cyber insurance may cover regulatory defence costs. Cover for GDPR fines depends on wording and legal insurability.
Does cyber insurance cover invoice fraud?
Invoice fraud may be covered only when social engineering fraud is named. Many policies require checks before accepting changed bank details.
What does a cyber policy cover for a small business?
A cyber policy can cover forensics, recovery, legal advice, notification and business interruption. It may also cover liability claims, subject to terms and limits.
Do I need MFA to buy cyber insurance?
Many insurers expect MFA on email, remote access and privileged accounts. The exact requirement varies between insurers.
Is a cyber extension on business insurance enough?
A business-policy extension can be enough if its limit and support match likely loss. Check business interruption, ransomware, fraud and critical supplier failure.
What matters most:- Compare premium plus excess with interruption and response costs, not only a possible GDPR fine.
- Choose limits from lost gross profit, payment access, data sensitivity and outage tolerance.
- Check fraud, supplier failure, waiting periods and minimum-control clauses before buying.
- MFA and tested backups can reduce incidents and the risk of a disputed claim.
Learn more
Here are some additional resources on this subject: