A sole trader gets a phishing email that looks like a supplier invoice, clicks the link, and a payment account starts behaving strangely. By lunchtime, you are changing passwords, checking bank alerts and wondering whether a £20-a-month cyber policy would have helped, or whether you should have spent the money on better protection first.
The cheapest cyber option is not always the best value for a sole trader. The smartest approach is to compare low-cost cyber insurance with a basic security setup, then match both to your business risk. For many microbusinesses, a small annual spend can cover phishing, data loss and business interruption without paying for features you will never use.
Cheapest cyber cover: what a sole trader actually needs
The cheapest sensible option for most sole traders is a narrow cyber insurance policy with phishing, data breach and business interruption cover, plus basic security controls. If you only buy one thing, buy the cover that matches your biggest loss, not the cover with the lowest headline price.
A budget plan usually works best when you split the job in two. Insurance pays after a loss, while security tools try to stop the loss happening in the first place. Think of it like having house insurance and a smoke alarm, not one or the other.
A sole trader who uses email, online banking or client records needs cover for phishing-led fraud, not just data breach costs.
What is the minimum worth buying?
The minimum worth buying is cover for phishing, ransomware and data breach response, plus business interruption cover with clear limits and exclusions, even if the limits are modest. For a one-person business, that is often enough to deal with the most likely problems without paying for extras you may never use.
When is cheap actually too cheap?
Cheap becomes too cheap when the policy excludes social engineering, payment diversion fraud, or email compromise. Those are common ways small firms lose money, because the criminal tricks you into paying the wrong account or opening the wrong file.
Which losses matter first?
The losses that matter first are money going out, work stopping, and personal data getting exposed. In practice, that means invoice fraud, account takeover, lost access to email, and UK GDPR response costs.
Cheap cyber cover and low-cost security tools do different jobs, so compare them as a pair. A policy can help after an attack, while tools such as password managers and multi-factor authentication reduce the chance of one.
For UK sole traders, a useful comparison is not “insurance or security”, but “what am I buying to stop a loss, and what am I buying to pay for it”. The National Cyber Security Centre says simple steps like strong passwords and multi-factor authentication cut common account attacks, and that fits most microbusinesses very well. NCSC small business guidance
| Option |
Typical annual cost |
Best for |
Main gap |
| Basic cyber insurance only |
£100 to £300 |
Very small traders with limited data |
Weak if phishing or invoice fraud is excluded |
| Security tools only |
£60 to £250 |
People who can tolerate some financial risk |
No payout after a breach or fraud |
| Insurance plus basics |
£150 to £600 |
Most sole traders handling email, payments or client data |
Not enough for larger teams or sensitive data-heavy work |
Does the cheapest policy cover the same risks?
The cheapest policy rarely covers the same risks as a fuller one. Budget plans often cut out social engineering, contract disputes after a cyber event, and broad business interruption.
Is cyber essentials enough on its own?
Cyber Essentials is not insurance, but it is a useful baseline for controls like patching, device protection and basic access rules. It can help with tenders, and it gives you a clean starting point if you want low-cost protection that is not complicated.
The best pairing for many sole traders is a slim policy plus a password manager, multi-factor authentication, automatic cloud backup and a separate work device. That mix usually gives more real-world value than paying for a long list of add-ons.
Match cover to your type of work
The right low-cost setup depends on the kind of work you do, because not every sole trader faces the same cyber loss. A designer who keeps client files in cloud storage has a different risk from a sole trader who only sends the odd invoice.
Client-data businesses need more cover
Client-data businesses need cover for data breach response, legal help and third-party liability. That includes bookkeepers, consultants, therapists, VA services and anyone handling names, addresses, financial details or booking records.
E-commerce sellers need fraud checks
E-commerce sellers need strong account protection, payment checks and cover for business interruption if online sales stop. A hacked Shopify, Amazon or WooCommerce account can block sales for hours or days, and that is a direct cashflow hit.
Low-data traders can keep it lean
Low-data traders can keep it lean if they only store a few contacts and use no sensitive records. A gardener, dog walker or tradesperson may only need email protection, device cover and a small limit for recovery costs.
Which sectors should spend more?
Sole traders who should spend more are those in legal, accountancy, health, finance or client-service work with regular email exchanges. The reason is simple: one mistake can affect both your own money and someone else’s data.
For most sole traders, the cheapest useful option is not the cheapest policy, but the one that matches the work you actually do. A freelance consultant or bookkeeper may need stronger data breach response and UK GDPR response support, so a mid-range policy with phishing protection and business interruption cover is often better value than a bare-bones plan. A tradesperson or dog walker with very little client data may be fine with lean cyber insurance plus free security tools, while an online seller should prioritise small business cyber cover that includes payment fraud and recovery help for hacked accounts.
In practice, that means comparing annual premiums against likely loss, not just the headline monthly price.
Build a cheap protection stack
A cheap protection stack should be built in a set order: secure the account, protect the device, back up the data, then buy the insurance. That order keeps you from paying for cover while leaving easy holes open.
Buy multi-factor authentication, a password manager and automatic updates first. These three steps stop a lot of low-effort attacks because they make stolen passwords far less useful.
What is worth paying for?
It is worth paying for a work phone or work laptop if you mix business and personal use. A separate device makes it easier to keep work files clean and to wipe the device if it is lost or infected.
What can stay free?
Free tools can cover a lot if you are disciplined. Browser password saving, built-in antivirus, a basic cloud backup tier and free account alerts from your bank are often enough to start.
What should the annual total be?
A realistic annual total for many sole traders is between £150 and £600. That usually includes a modest cyber policy, a password manager, backup storage and a few paid security extras if needed.
The cheapest pack that still works
The cheapest pack that still works is usually one policy, one password manager, multi-factor authentication on all business accounts, and cloud backup for the files you truly need. That mix is small, but it covers the most common pain points for a sole trader.
A useful rule is to buy for the thing that can stop work or create a client dispute. If the product does not reduce that risk, or pay for it later, leave it out.
What belongs in the minimum pack?
The minimum pack should include cyber insurance with phishing and business interruption cover, a password manager, multi-factor authentication, and a backup copy stored away from your main laptop. That is the point where cheap starts to become sensible.
What should you not pay for?
You should not pay for endpoint suites, dark web monitoring, or 24/7 security centres unless your work is sensitive or your turnover justifies it. Those products can be useful, but they are often too much for a one-person business.
When does cyber essentials help?
Cyber Essentials helps when you want a recognised baseline and a simple way to show good hygiene. It can support tenders, reassure clients, and make your setup easier to explain if you are asked about controls.
A sensible minimum pack for a microbusiness should include cyber insurance, a password manager, multi-factor authentication, automatic backups and bank alerts, but not necessarily premium endpoint suites or 24/7 monitoring. If you rely on online banking, make sure the pack also protects against social engineering fraud and account takeover, because criminals often target the person rather than the device. What you should leave out are expensive extras that do not reduce your main risk, such as dark web monitoring, unless you handle highly sensitive records or have a turnover that makes the extra support worthwhile.
This keeps the pack focused on phishing protection, data breach response and business interruption cover, which are the most common low-cost priorities for sole traders.
Questions & answers about cyber cover
What is the 90/10 rule in cybersecurity?
The 90/10 rule means most protection comes from a small number of basic steps. For sole traders, that usually means multi-factor authentication, updates, backups and a sensible policy.
What is the best app for a sole trader?
The best app is usually a password manager, because weak or reused passwords are still a common entry point. Pick one that works on your phone and laptop, and use it for every business login.
What are 5 disadvantages of a sole trader?
The main disadvantages are personal liability, harder access to some contracts, less separation between work and private life, more pressure on cashflow, and limited spare capacity if you are ill. Cyber-wise, the big issue is that one inbox or one device may hold everything.
Is 25 too late for cyber security?
No, 25 is not too late, and neither is 55. Security can start with one afternoon of fixes, and the first win is usually stronger passwords plus multi-factor authentication.
Does public liability cover cyber incidents?
No, public liability usually does not cover cyber incidents. It is for physical injury and property damage, so you still need separate cyber cover if email fraud, data loss or ransomware is a concern.
Can i get cheap cyber insurance without a broker?
Yes, you can buy direct, and that can work for simple needs. A broker becomes more useful if you handle client data, need help reading exclusions, or want to compare social engineering cover properly.
What should i check before i buy?
Check the excess, the phishing wording, the ransomware response help, and whether business interruption is based on actual loss or a narrow trigger. Also check if the policy requires Cyber Essentials or other controls before it will pay.
The safest low-cost choice for most sole traders
The safest low-cost choice for most sole traders is a narrow cyber policy plus a very small set of controls that block the common mistakes. That usually means phishing protection, email security, backups and one policy that clearly names fraud, breach response and interruption.
If your work is light, keep the cover lean and the tools free or cheap. If your work depends on client records or online payments, spend a bit more, because the cost of one bad email can be higher than a year of protection.
The clearest rule is this: buy the minimum that covers your most likely loss, then add only the tools that reduce that loss before it happens. For a sole trader in England, that is usually better value than chasing the lowest premium alone.