Microbusinesses under £1m turnover should size cyber cover around their worst plausible outage and data-breach bill. Turnover alone is a poor guide. The real risk is a five-day trading halt.
Why firms below £1m still need cyber cover
Low turnover does not always mean low risk.
Low turnover can hide high exposure
Risk rises when one person holds key passwords, approves payments and deals with customers. This is common in e-commerce shops, recruiters, accountants, clinics and consultants.
These firms may hold financial, health or identity information. That data can create large costs after an attack.
A commercial policy can cover incident response. This means urgent specialist work to find, contain and fix an attack.
It can also cover data recovery, legal advice, customer notices and public relations support. It may also pay business interruption losses.
A microbusiness cyber cover policy works alongside other business insurance. It does not automatically replace every other policy.
Cyber liability cover can pay data-breach costs, response work and customer notices. It can also cover some third-party privacy claims after a cyber event.
Professional indemnity can address claims about negligent advice, design or professional services. Public liability usually covers accidental injury or property damage.
For example, an accountant's email account may be compromised. Cyber cover may pay for forensic work and customer notices.
A separate professional indemnity policy may matter if a client alleges negligent professional work. Each policy has a different role.
Check the wording before relying on two policies for one loss.
Set your limit from a bad week
Estimate the cost if your main systems failed for five working days. Then add the bills that arrive before normal trading returns.
Add the likely incident costs
List forensic IT help, urgent legal advice, customer notices and password resets. Add data restoration and replacement devices.
Then estimate lost gross profit and temporary operating costs. Gross profit is income left after direct costs.
A design agency with five staff might face £12,000 for response and recovery. It might lose £18,000 in margin.
It could spend £10,000 rebuilding files and face a £15,000 client claim. That totals £55,000 before any excess.
The error most firms make is choosing a limit from turnover alone. A modest firm can face a large bill within days.
Match the limit to your business
| Business profile | Main exposure | Illustrative limit to assess |
|---|
| Local trades firm using email and cloud accounts | Invoices, supplier access, short outage | £50,000 to £100,000 |
| Online retailer taking customer payments | Continuous trading and customer data | £100,000 to £250,000 |
| Recruiter, adviser or clinic | Sensitive records and client claims | £250,000 or more |
Build a cyber cover figure in four parts
1. Incident response
IT, legal, notices
2. Trading loss
Margin and extra costs
3. Recovery
Files and systems
4. Liability
Client or customer claims
Add the four figures. Then check whether the policy limit and its sub-limits can cover them.
A suitable limit must cover all four cost types at once. The next section shows where low-cost policies can fall short.
Check exclusions before comparing premiums
Compare sub-limits, excess, outage definitions and indemnity periods. Do not compare only the premium and headline limit.
Check the parts most likely to bite
Check whether interruption starts after a waiting period. This is often between 12 and 24 hours.
Check whether cloud supplier outages count. Also check separate limits for social engineering, cyber extortion and stolen funds.
A policy excess is the amount your business pays first. The insurer pays only after that amount.
A low premium can hide a low fraud limit. It can also exclude the cloud outage that stops sales.
Cyber essentials is not full cover
Cyber Essentials certification includes cyber insurance for eligible UK organisations. The cover can be up to £25,000.
That sum may not cover long downtime, contractual liability or every fraud loss. Treat it as a security baseline and limited protection.
It is not a substitute for wider cover, particularly when online sales stop for several days.
✅Our recommendation
An encrypted external drive can keep a separate copy of essential files. It helps while cloud recovery is under way.
It works only when backups stay current. You must also test file restoration.
- Keeps an encrypted copy away from the day-to-day cloud account
- Helps restore priority documents after ransomware blocks normal access
- Supports tested-backup evidence many insurers ask for before a claim
Check availability →
This approach is not enough for firms processing health records, sensitive financial data or international data. Seek advice where sector rules apply. Also seek advice if a contract demands a specific limit. A broker, insurer, solicitor or cyber security specialist can assess these cases. The same applies when one platform drives most income.
However, check Cyber Essentials insurance against the current policy documents. Do not assume certification makes cover automatic or sufficient.
Eligibility can depend on organisation type, turnover and scheme conditions. The policy can also impose an excess, reporting duties and exclusions.
Even where Cyber Essentials insurance is available, it may have a much lower limit. A cloud outage, online-sales halt or social engineering fraud can cost more.
A retailer unable to process orders for several days may exhaust a modest limit. Lost gross profit, technical recovery and support costs can do this alone.
Compare the included protection with commercial small business cyber insurance. Check limits, business interruption cover and fraud sub-limits.
Your questions answered
Do I need cyber insurance below £1m turnover?
Cyber insurance is not compulsory for most UK microbusinesses, but it is sensible when an attack could stop trading or expose customer data.
How much cyber cover should a small business buy?
Buy enough cover for one realistic outage, recovery bill and third-party claim. Simple firms may assess £50,000 to £100,000. Data-sensitive firms may need more.
Does cyber essentials include cyber insurance?
Eligible Cyber Essentials-certified UK organisations receive insurance with up to £25,000. That may not cover a long outage or high liability exposure.
What does business interruption mean in cyber
Business interruption pays defined lost income and extra costs during a covered cyber event. Check waiting periods and cloud-provider cover.
Will a policy pay a ransomware demand?
A policy may cover cyber extortion costs when its wording includes them and conditions are met. Sanctions or legal restrictions can prevent payment.
Is phishing fraud covered by cyber insurance?
Phishing losses are covered only when the policy includes the relevant fraud section. Check social engineering, invoice fraud and funds-transfer limits separately.
What security controls do insurers expect?
Insurers commonly expect MFA, patched software, protected email and tested backups. A failed stated policy condition can affect a claim.
What to do before requesting quotes
Choose a loss scenario first.
Write down your likely five-day outage cost and the data you hold. Also note your largest client obligation and the systems needed each morning.
Then request matching quotes with the same limit and excess. Match ransomware sub-limits and interruption periods too.
The essentials:- Size cover around a credible incident bill, not turnover alone.
- Check sub-limits and outage wording before comparing premiums.
- Cyber Essentials cover can help, but its £25,000 limit may not suit a serious interruption.
- Prepare MFA, tested backups and email controls before seeking quotes.
Prepare a short evidence pack before seeking UK cyber insurance quotes. Do not answer security questions from memory.
Confirm that multi-factor authentication protects email, cloud administration and remote access. Check that systems, browsers and business software receive updates promptly.
Confirm that email filtering, anti-malware and payment checks are in place. These controls can reduce fraud and support a claim.
Keep backups separate from daily administrator accounts. Use immutable or offline backups where practical.
Test whether priority files can actually be restored. A backup that cannot restore is not useful.
Insurers may ask about turnover and personal data volumes. They may also ask about card payments and past incidents.
They can ask about outsourced IT and reliance on one cloud platform. These details can affect eligibility, premium, excess and offered limits.
Related sources
These articles can help you explore the topic in more depth: