Policy wordings to avoid for UK SMEs: exclusions that bite can include clauses that narrow or block an expected cyber claim. This can happen despite a seemingly adequate headline limit. Before buying or renewing, check ransomware, payment fraud, supplier failures and business interruption wording. Ask what triggers each restriction and how it applies to your firm.
Read the schedule before relying on the limit
A cyber policy limit does not promise cover for every loss up to that amount. The schedule is the policy-specific page. It shows your limit, excess, dates and selected extensions.
An endorsement is an attached clause that changes the standard wording. Read it with the schedule. Think of it as a note that changes the rules printed on the main ticket.
A £1m limit may contain £25k caps
A sublimit is a smaller maximum payment for one type of loss. It sits inside the overall policy limit. An excess, sometimes called a deductible, is what your business pays first.
Compare each cap with a realistic fraud, forensic or recovery loss. A £1m headline limit can feel safe. A £25,000 fraud cap may not be enough.
| Policy feature | Effect on payment | SME example | Question before purchase |
|---|
| Fraud sublimit | Caps one fraud loss | £60,000 fake supplier payment, £25,000 cap | What is the limit for invoice redirection? |
| Excess | Business pays first | £7,500 forensic bill, £5,000 excess | Does a separate excess apply to each section? |
| Forensic-cost cap | Limits investigation spend | External experts identify the breach after £30,000 has been spent | Is forensic work inside or outside the main limit? |
| Retroactive date | May exclude older acts | A 2023 breach is found in 2026 | Does the date match my previous cover? |
Waiting periods erase short outages
A waiting period is the time an outage must last before interruption cover starts. Policies often use periods between 8 and 24 hours. A ten-hour cloud outage brings no payment under a 12-hour waiting period.
This can apply even when online sales stopped. Ask if cover measures lost gross profit or income. Also ask if it pays necessary extra costs.
Check four pages together: The main wording states the basic promise. The schedule shows limits and excesses. Endorsements alter that promise. The statement of fact records what the insurer relied on. Resolve any conflict in writing before inception.
Do not treat every restriction as the same thing: An exclusion removes a stated type of loss. A condition precedent makes cover depend on a specified act or control. A warranty may impose a strict promise.
The effect depends on the wording and insurance law. A retention or policy excess is the amount kept by the insured. Cyber insurance sublimits and forensic cost caps limit the insurer's payment for particular costs.
A waiting period delays when the insurer can pay interruption losses. Compare each restriction with its insuring clause, not just the headline limit. This is where many claim restrictions appear before a loss.
Exclusions and conditions can defeat different claims
Exclusions remove stated losses. Conditions precedent require compliance before the insurer pays under the policy's exact terms.
The difference matters when a claim occurs. An exclusion can remove a loss category. A failed condition can stop cover for a claim that otherwise looked insured.
“Maintain security” needs a definition
A failure to maintain security exclusion is risky when it uses vague terms. Examples include “appropriate”, “adequate” or “industry standard”. Ask for required controls, evidence and consequences in writing.
NCSC guidance can help you understand sensible security steps. It does not automatically meet an insurer's separate condition. Think of NCSC guidance as a map, not your insurer's own rulebook.
Prior knowledge can void new cover
A prior known circumstances exclusion may apply when a business knew facts likely to lead to a claim. It can also apply when it reasonably should have known them. This must have occurred before the policy starts.
Notify suspicious events promptly under the current policy. Waiting until renewal can create a separate cover dispute. The most common error here is treating a suspected breach as too minor to report.
Wordings that need a closer reading: A cyber war exclusion may apply only to a narrowly defined hostile operation. It may also need state backing. The definition, attribution test and evidence burden matter more than the label.
Contractual liability wording can remove liabilities accepted only under a customer contract. The same liability might still have existed in negligence. Professional services exclusions can affect an IT consultancy after malware transmission or client misconfiguration.
They can also affect a missed security duty. Ask the broker to identify each exact exclusion. Ask whether a carve-back restores cover.
Confirm how each clause applies to your contracts and services. Written answers are easier to rely on later.
Fraud and third-party outages need named cover
Business email compromise, invoice redirection, employee fraud and cloud outages are not always insured as “cyber crime”. Compare the responding clause, controls, sublimit and waiting period. Do this before a fraudster changes bank details or a provider fails.
A named extension can make a major difference. “Cyber crime” is a broad label. It is like buying a rail ticket without checking which train routes it permits.
Authorised payments are often excluded
A BEC scam impersonates a director, supplier or customer to prompt payment. Standard computer crime cover may require an unauthorised transfer. It may not pay when staff approve payment after deception.
Seek named social engineering, funds transfer or invoice redirection cover. Check call-back and dual approval requirements. A call-back means confirming changed bank details through a trusted phone number.
A cloud outage may not be cyber damage
Dependent business interruption can cover income loss from an outside provider's interruption. This might be a cloud host, payment processor or MSP. An MSP is an IT firm that manages systems for clients.
Confirm that the provider and outage type qualify. Ordinary business interruption may require your own systems to suffer a covered security failure. Cover may not apply if the policy lists only named providers and yours is absent.
| Incident | Named cover to find | Common obstacle | Question to ask |
|---|
| Ransomware | Cyber extortion and restoration | MFA condition or sanctions issue | Are ransom, forensics and restoration separately capped? |
| Invoice redirection | Social engineering fraud | No independent call-back | Is a verified call-back compulsory? |
| Cloud outage | Dependent business interruption | 12-hour wait or provider exclusion | Does cover apply to this provider and outage type? |
| Employee theft | Employee dishonesty extension | Deliberate acts exclusion | Is internal fraud included and at what limit? |
Use this renewal check before signing
Use it to get written answers. Keep the answers with your policy papers.
- Match the policy wording version to the schedule and every endorsement.
- Record sublimits, excesses and waiting periods for fraud, forensics, restoration and interruption.
- Confirm the retroactive date and disclose known incidents or suspicious events.
- List every mandatory control, including MFA, backups, patching and payment checks.
- Confirm whether your cloud host, MSP and payment processor meet the dependent interruption definition.
- Separate ICO defence costs from regulatory fines and penalties, which depend on law and wording.
- Keep the statement of fact, proposal answers and evidence supporting each answer.
This check does not replace reviewing a live policy after an incident. It cannot decide if a particular claim will be accepted. Follow the policy's notification requirements immediately. Seek guidance from your broker, insurer or another qualified professional. Although the check may matter less for firms with little digital reliance or data, payment fraud can still affect them.
Incident response is part of the cover, not an afterthought: After a suspected breach, preserve evidence and take sensible steps to limit loss. Notify the insurer through the route and timescale stated in the policy. The insurer may appoint or require approval for forensic, legal, public relations and ransom-negotiation providers.
Starting expensive work without consent can cause a dispute. This may differ where immediate action was necessary. An MSP can help with logs, containment and restoration.
Its involvement does not transfer the policyholder's notification duties. Confirm whether ransomware and payment fraud cover include a 24-hour response service. Also confirm whether the insurer chooses suppliers.
Ask whether legal and forensic costs reduce the applicable limit. These details can decide what remains for recovery.
Common questions
What are common cyber insurance exclusions?
Common exclusions include cyber war, terrorism, prior known circumstances, deliberate acts, contractual liability and professional services. Their application depends on precise definitions and evidence. It does not depend only on a widespread attack.
What does cyber insurance not cover?
Cyber insurance does not automatically cover every loss linked to an email, outage or breach. Authorised payments, contractual penalties, employee fraud and third-party outages often need named extensions or sublimits.
Does cyber insurance cover ransomware?
Cyber insurance may cover extortion response, forensic work, data restoration and business interruption where clauses apply. Ransom payment can face sanctions, insurer consent, cyber war wording, a sublimit or an unmet MFA condition.
Does cyber insurance cover social engineering?
Social engineering fraud is covered only where the policy expressly includes it. Suitable funds transfer fraud cover can also apply. Many wordings require a call-back or dual approval before bank details change.
Does cyber insurance cover an ICO fine?
An ICO fine is not automatically covered. The result depends on law, insurability and wording. Defence costs for an ICO investigation may be insured even when the financial penalty is excluded.
How long must an outage last before insurance cover starts?
An outage must exceed the policy's waiting period before business interruption cover starts. This period is often between 8 and 24 hours. Dependent interruption may also require the cloud or MSP failure to meet a defined provider test.