A cyber policy can pay much less than its headline limit because excesses, sublimits and coinsurance reduce the amount you actually receive. For an SME, a £1 million limit does not mean a £1 million payout: if a claim has a £10,000 excess and a £100,000 sublimit, the insurer may only pay up to that lower cap after deductions.
Cyber excesses and sublimits: how they impact SME claims is simple once you see the maths. The main limit is only the top line; business interruption, social engineering and incident response are often capped much lower, so your real payout can be far below the limit even when the claim is valid.
Why your payout can be much lower than the limit
Cyber excesses and sublimits: how they impact SME claims is simple once you see the maths. The headline limit is the roof, but the schedule often places smaller ceilings under that roof for each type of loss.
If a claim hits one of those smaller ceilings, the insurer pays no more than that figure, even if the main limit is far higher. The excess is taken off first, so it acts like the first slice of the bill you keep.
Coinsurance is different again. It comes up when the sum insured is too low for the loss, and the insurer reduces the payment to match the insured share.
| Item |
What it does |
Typical SME effect |
Claim maths example |
| Excess |
The amount you pay first on each claim |
Cuts small claims hard, but has a modest effect on large claims |
£5,000 excess on a £40,000 loss means £35,000 before other limits |
| Sub-limit |
A lower cap inside the main policy limit |
Often the real reason a £500,000 policy pays far less |
£25,000 sub-limit for incident response on a £60,000 bill means £25,000 max, then excess |
| Coinsurance |
A reduction if the insured amount is too low |
Can shrink a claim even when the loss looks covered |
If you insured £250,000 but the loss is judged at £500,000, the payment may be cut roughly in half |
A £1 million limit is not a promise that a £1 million loss will be paid in full. It only means the policy will not pay above £1 million, and many SMEs never get close to that because other caps bite first.
Excess versus sub-limit
An excess is the part you absorb before the insurer starts paying. A sub-limit is a smaller ceiling for one slice of cover, such as business interruption or social engineering fraud.
That difference matters because the excess reduces the claim at the start, but the sub-limit can stop the claim long before the main limit is reached.
Coinsurance is a separate risk
Coinsurance is not the same as an excess. It is a penalty for underinsuring, which means the policyholder bought too little cover for the size of the loss or the insured value was set too low.
In cyber, coinsurance is less common than in property insurance, but it can still appear where a policy uses declared values, revenue-based calculations or a self-insured retention.
A useful way to see the difference is to run a realistic SME claim through the policy schedule. Imagine a graphic design agency with a £1 million headline limit, but only a £25,000 sub-limit for social engineering fraud and a £50,000 sub-limit for incident response. If a finance team member is tricked into sending £80,000 to a criminal account, the business may assume the insurer will pay most of it.
In practice, the insurer may only pay £25,000 for that fraud section, then deduct the excess, even though the main limit is still mostly untouched. The result is a large shortfall that feels surprising unless you read the policy cap line by line.
For SMEs, the simplest way to separate the terms is this: an excess is the amount you pay first, a sub-limit is a smaller policy cap inside the main limit, and coinsurance is a reduction because the insured amount was set too low. In other words, the excess affects every claim at the start, the sub-limit restricts one type of loss, and coinsurance punishes underinsurance. A firm with a £5,000 excess, a £20,000 sub-limit for business interruption and a coinsurance adjustment on a £300,000 insured amount can see three different reductions on one cyber insurance claims payment.
That is why the schedule matters as much as the headline limit.
Where sub-limits usually appear in cyber cover
Sub-limits usually appear where the insurer expects frequent, messy or expensive claims.
For SMEs, this is where the surprise happens. The main loss is often not the ransom itself, but the lost trading time, the forensic work, the call centre, the legal advice and the notification letters.
Business interruption caps
Business interruption means the money lost when a cyber incident stops you trading normally.
Many SME policies cap this cover far below the total limit. A £500,000 or £1 million cyber policy may still have a business interruption sub-limit of £50,000 to £250,000, which can disappear fast if payroll, lost gross profit and extra IT costs are all counted.
What matters too is the waiting period. If the policy only starts paying after 8, 12 or 24 hours, those early losses sit with you.
Ransomware and extortion costs
Ransomware is a lock on your data, and cyber extortion is the demand for money to unlock it or stop publication.
The insurer may also cap negotiation costs, specialist advisers, restoration work and legal review. Some policies also reduce payment if the ransom is paid without prior approval, which catches owners who act fast under pressure.
A practical rule is to compare the ransom cap with the wider response cap. If one is £25,000 and the other is £50,000, the insurer may still refuse part of the claim once those buckets are full.
Incident response and breach costs
Incident response means the urgent work done after a breach, such as forensic investigation, legal advice, system cleaning and notification letters.
These costs often sit under a separate sub-limit, especially for data breach events. A small firm might see £15,000 to £50,000 here, which sounds fine until you price outside help for 3 to 6 weeks.
Regulatory and liability costs
Regulatory fines and penalties are treated carefully in England because cover depends on the wording and the law. Under the UK General Data Protection Regulation and the Data Protection Act 2018, some regulatory costs may be covered, but the policy wording matters a lot.
Third-party liability can also be limited. If a customer, supplier or partner blames your firm for the breach, the legal defence costs and any settlement may sit under a separate cap, and that cap can be lower than the headline policy limit.
The insurer usually looks at the schedule, the sub-limits, the waiting period, the excess and any endorsement exclusions before they look at the main limit.
As a result, a policy that looks rich can pay modestly if one low cap catches the whole claim.
SMEs often need to check each major claim item against the real payout risk, not just the insured amount. A practical table would show incident response, business interruption, social engineering fraud, data restoration, legal defence and notification costs, then flag where each may sit under a separate policy cap. For example, incident response might be covered up to £25,000, business interruption up to £50,000, and social engineering fraud only up to £10,000.
If the loss is larger than those figures, the claim settlement will be driven by the lowest sub-limit rather than the overall policy cap. That is why underinsurance can happen even when the SME cover looks generous on paper.
A real claim can shrink fast
A claim can shrink quickly when several small reductions stack together.
Here is a simple example for a London SME hit by ransomware and a data breach. The total loss is £120,000, but the policy has a £10,000 excess, a £25,000 incident response sub-limit, a £50,000 business interruption sub-limit and a separate £15,000 cap on notification costs.
Loss
£120,000 total
Excess
£10,000 deducted first
Incident response cap
£25,000 maximum
Business interruption: capped at £50,000, even if the trading loss is higher.
Likely result: the settlement can land around £75,000 to £90,000, depending on how each cost bucket is worded.
A worked payout example
If the incident response bill is £40,000, the policy may only pay £25,000 because of the sub-limit. If the notification work costs £18,000, only £15,000 may be paid. If business interruption is £70,000, the policy may still cap that part at £50,000.
Now add the £10,000 excess and the payment falls again. That is how a large-looking loss can produce a settlement far below the headline limit.
The maths is easier if you think of each cost bucket separately. The insurer does not usually treat the claim as one big pot unless the wording says so.
A £1 million cyber limit with a £25,000 cap on one section is still only a £25,000 limit for that section.
Which SMEs feel the pain most
SMEs with heavy digital trading feel sub-limits fastest because one outage stops sales, service and cash flow at the same time.
The smaller the margin, the quicker the damage.
High-turnover, low-margin firms
High-turnover firms with slim margins are hit hardest by business interruption caps.
A retail SME with £1.2 million annual turnover can still lose £30,000 to £60,000 in a short outage. If the BI sub-limit is £25,000, the policy may cover only part of the real gap.
Firms with sensitive data
Firms holding personal data face extra cost layers because breach response is rarely just technical.
The Information Commissioner’s Office has made clear that the response must be fast and orderly. That makes low response sub-limits risky, because the real spend often comes in the first 72 hours.
Businesses built on cloud systems, payment tools or outsourced IT can find exclusions and caps hiding in plain sight.
Lloyd’s of London market wording often distinguishes first-party losses from third-party liability. That split matters because the wrong type of loss can land in the wrong bucket and miss the bigger limit.
How to check cover before you buy
You should test the policy against a real incident, not a brochure example.
That test reveals more than the premium ever will.
Ask for the sub-limit schedule
Ask for the full schedule showing every sub-limit in pounds, not just percentages or vague notes.
If the broker cannot give that quickly, treat it as a warning sign.
Check the claim order
Check whether the excess is applied before or after other reductions.
Also ask whether one loss can trigger several caps at once. A ransomware event often involves incident response, business interruption and notification costs, so you need to know whether each part has its own ceiling.
Compare premium against payout shape
A cheaper policy is only cheap if it pays what you need.
Look for wording that narrows payment
Watch for wording that says “up to”, “subject to”, “each and every claim”, or “aggregate”.
The best check is a plain-English claim scenario. Ask the broker to show what happens on a £60,000 ransomware bill, a £40,000 business interruption loss and a £20,000 notification bill under the same policy.
Common questions about cyber insurance for UK SMEs
What is the 90 10 rule in cyber security?
The 90 10 rule usually means most breaches start with a small human mistake, often around 90% of incidents linked to user error or social engineering.
What is SME cyber insurance?
SME cyber insurance is cover for costs after a cyber event, such as forensic work, data breach response, business interruption, extortion and liability.
Can you have an additional insured on a cyber
Yes, some policies allow an additional insured or similar named party, but the wording varies a lot.
What causes 95% of all cybersecurity breaches?
Most breaches involve human error, stolen credentials, phishing or weak access control, rather than a pure “movie-style” hack.
Does a higher limit always mean better cover?
No, a higher limit can still pay less if the sub-limits are low.
What should i ask my broker before i buy?
Ask for the excess, every sub-limit and any coinsurance or self-insured retention in pounds and in plain English.
Can a claim be rejected because of wording i
Yes, a claim can be cut down or declined if the wording excludes the loss or narrows the trigger.
If you do not buy cyber cover, do not store personal data, and do not rely on digital systems to trade, these policy limits matter far less. But for most SMEs in England, even one payment run, client database or online order system makes them worth checking properly.
The safest way to buy cyber cover is to compare the real payout shape, not the headline limit. A policy that is £200 dearer but pays an extra £50,000 on the kind of loss you are likely to face is usually better value.
If you are renewing, ask your broker to show the excess, every sub-limit and one worked claim example side by side. That one request often reveals whether the policy is fit for your business or just looks good on paper.