Skip to main content

Cyber Insurance Basics: What Every UK Business Needs to Know

Media Cyber Insurance Basics What Every UK Business Needs to Know

Cyberpunk was attacks are no longer a risk faced only by large organisations.

Small and medium-sized businesses also rely on cloud platforms, email, online banking, customer databases, remote access and connected devices. A single compromised account, fraudulent payment request or ransomware infection can therefore create significant disruption and expense.

Strong cybersecurity controls can reduce the likelihood and impact of an attack, but no organisation can eliminate risk completely.

This is where cyber insurance can help.

Cyber insurance is designed to provide financial protection and specialist support when a business experiences certain cyber incidents. Depending on the policy, it may help pay for technical investigation, data recovery, legal advice, customer notification, business interruption and claims made by affected third parties.

However, cyber insurance is not a substitute for effective security.

Insurers increasingly expect businesses to demonstrate that appropriate protections are already in place. Coverage also varies considerably between policies, making it essential to understand exactly what is included, which conditions apply and what may be excluded.

This guide explains the basics of cyber insurance and what UK businesses should consider before purchasing or renewing a policy.

What Is Cyber Insurance?

Cyber insurance is a type of business insurance designed to cover specified losses arising from cyber events.

The Association of British Insurers describes a cyber event as an actual or suspected unauthorised system access, electronic attack or privacy breach. Cyber policies may cover direct losses suffered by the insured business as well as liabilities arising from harm to customers, suppliers or other parties. 

A cyber incident could include:

  • Ransomware
  • Data theft
  • Business email compromise
  • Fraudulent payments
  • Malware infections
  • Hacked user accounts
  • Network intrusion
  • Data corruption
  • Denial-of-service attacks
  • Accidental disclosure of personal information
  • Loss or theft of equipment containing sensitive data
  • Attacks affecting suppliers or cloud services

The precise definition of a covered incident will depend on the policy wording.

Why Might a Business Need Cyber Insurance?

Technology incidents can create several different types of cost at the same time.

For example, a ransomware attack may require the business to:

  • Engage cybersecurity specialists
  • Rebuild compromised systems
  • Restore data
  • Replace equipment
  • Investigate how the attack occurred
  • Obtain legal advice
  • Notify customers
  • Report the incident to regulators
  • Manage media enquiries
  • Compensate affected clients
  • Operate without key systems
  • Pay employees who cannot work normally

Traditional business insurance may not cover all these losses.

Professional indemnity, property and general business interruption policies serve different purposes and may contain cyber-related limitations or exclusions. A dedicated cyber policy can provide more specific cover and access to specialist incident-response services.

What Does Cyber Insurance Commonly Cover?

Coverage differs between insurers, but policies often include a combination of first-party and third-party protection.

First-Party Cover

First-party cover relates to losses suffered directly by your organisation.

It may include the following.

Incident Response

A policy may provide access to an emergency response service following a suspected incident.

This could include:

  • Cybersecurity specialists
  • Forensic investigators
  • Legal advisers
  • Data-protection experts
  • Public relations support
  • Ransomware negotiators
  • Breach-response coordinators

Access to a prepared response team can be particularly valuable when the business is under pressure and does not know who to contact.

Forensic Investigation

Digital forensic specialists may investigate:

  • How the attacker gained access
  • Which systems were affected
  • Whether data was stolen
  • How long the attacker was present
  • Whether the threat remains active
  • Which accounts or devices were compromised

The findings can guide recovery and help the organisation understand its reporting obligations.

Data and System Restoration

Some policies contribute towards restoring:

  • Servers
  • Workstations
  • Databases
  • Applications
  • Configurations
  • Digital records
  • Backups

Coverage may also include the cost of recreating data where restoration is not possible.

However, insurers may expect the business to maintain suitable, tested backups as a condition of cover.

Business Interruption

Business interruption cover may compensate the organisation for specified loss of income and additional operating expenses caused by an insured cyber event.

This could include disruption resulting from:

  • Ransomware
  • System outages
  • Network compromise
  • Malware
  • Cloud-service interruption
  • Supplier incidents

Businesses should examine the waiting period, maximum payment period and method used to calculate lost income.

Cyber Extortion

Policies may provide access to specialists who help manage ransomware and other extortion demands.

Cover may include negotiation expenses and, depending on the wording and legal circumstances, a ransom payment.

A ransom payment does not guarantee that data will be restored, that stolen information will be deleted or that attackers will not return. UK guidance supported by the National Cyber Security Centre encourages organisations and insurers to prioritise alternatives to payment and avoid rewarding criminal activity. 

Crisis Communications

A serious incident can damage trust even when the technical recovery is successful.

Cyber insurance may pay for professional communications support, including:

  • Customer notices
  • Media statements
  • Public relations advice
  • Call-centre assistance
  • Reputation management

Notification and Monitoring Costs

Where personal information has been compromised, the organisation may need to notify affected individuals.

A policy may contribute towards:

  • Identifying affected people
  • Preparing notifications
  • Posting letters
  • Establishing helplines
  • Credit or identity monitoring
  • Legal review of communications

Third-Party Cover

Third-party cover relates to claims made against the business by customers, employees, suppliers or other affected parties.

It may cover:

  • Legal defence costs
  • Compensation claims
  • Privacy-related claims
  • Breach-of-confidentiality claims
  • Certain regulatory investigation costs
  • Claims arising from transmitted malware
  • Claims linked to failure to protect information

Whether regulatory penalties are insurable will depend on the circumstances, the policy wording and applicable law. Businesses should not assume that every fine or penalty will be covered.

What May Not Be Covered?

Cyber insurance policies contain conditions, limits and exclusions.

Common areas requiring careful attention include the following.

Known Incidents

A policy will not generally cover an incident that the organisation already knew about before taking out the insurance.

Businesses should answer proposal questions honestly and disclose relevant circumstances when required.

Inaccurate Application Information

An insurer may ask whether the organisation has controls such as:

  • Multi-factor authentication
  • Endpoint protection
  • Backups
  • Security monitoring
  • Patch management
  • Staff training
  • Restricted administrator access

Incorrect answers can create serious difficulties during a claim.

It is important to confirm that the stated controls genuinely exist across all systems covered by the policy.

Failure to Maintain Security Controls

Some policies require specified security measures to remain operational throughout the insurance period.

A business may encounter problems if, for example:

  • MFA was declared but not enabled for all users
  • Backups were not running
  • Security updates were not applied
  • Endpoint protection was disabled
  • Unsupported systems remained in use
  • Former employees retained access
  • Administrator accounts were not protected

The IT provider, broker and business leadership should review application answers together rather than relying on assumptions.

Unencrypted Devices

Claims relating to lost laptops, phones or portable storage may be restricted where the equipment was not encrypted.

Full-disk encryption should be applied to business devices containing sensitive information.

Social Engineering and Payment Fraud

Not every cyber policy automatically covers money transferred voluntarily following a fraudulent email or phone call.

Business email compromise and invoice-redirection fraud can fall under:

  • Social engineering cover
  • Crime insurance
  • Funds-transfer fraud
  • Cybercrime extensions

The business should confirm whether these incidents are covered and what payment limits apply.

Contractual Liabilities

Claims arising solely from contractual promises may be excluded unless they would also have existed without the contract.

Businesses that accept substantial cybersecurity obligations in customer agreements should discuss those obligations with their broker.

Betterment and System Improvements

Insurance is generally intended to restore the organisation rather than fund a complete technology upgrade.

If old equipment is replaced with substantially better systems, the insurer may only pay the equivalent cost of restoring what existed before the incident.

War and State-Backed Attacks

Policies may contain exclusions relating to war, cyber warfare or certain state-backed attacks.

The wording can be complex, particularly where attribution is uncertain. Businesses with significant exposure should obtain specialist insurance and legal advice.

Reputational Loss

A policy may pay for public relations support but not compensate the business for every future customer it loses after an incident.

Reputational harm can be difficult to quantify and may be subject to strict limits.

How Much Cyber Insurance Does a Business Need?

There is no single suitable cover limit for every organisation.

The ABI says SME policies are generally available with limits ranging from approximately £100,000 to £5 million, although higher limits may be available for organisations with more complex exposures. 

The appropriate amount depends on factors such as:

  • Annual turnover
  • Number of employees
  • Volume of personal data
  • Sensitivity of information
  • Reliance on technology
  • Potential downtime
  • Customer contracts
  • Regulatory exposure
  • Online transaction values
  • Cost of system restoration
  • Supply-chain dependencies
  • International operations

A small business could still require substantial cover if it stores sensitive customer information or depends entirely on one online platform.

The organisation should consider a realistic worst-case incident rather than choosing the lowest available premium.

What Is an Insurance Excess?

The excess is the amount the business must pay towards a claim before the insurer contributes.

A policy might also have separate excesses for different types of incident.

For example:

  • Incident response
  • Business interruption
  • Data restoration
  • Social engineering fraud
  • Third-party claims

A higher excess may reduce the premium but could leave the organisation facing a significant initial expense.

What Is a Waiting Period?

Business interruption cover often includes a waiting period.

This means the business may need to experience disruption for a defined period before the cover begins.

For example, a policy could apply only after systems have been unavailable for a specified number of hours.

The organisation should check:

  • How long the waiting period is
  • When the clock begins
  • Whether partial disruption qualifies
  • How income loss will be calculated
  • How long payments can continue

A long waiting period may make the cover less useful for shorter but still expensive incidents.

What Will Insurers Want to Know?

Insurers commonly ask detailed questions about the organisation’s technology and cybersecurity.

These may include:

  • Is MFA enabled?
  • Are remote-access services protected?
  • Are administrator accounts separated?
  • Is endpoint detection and response deployed?
  • How frequently are security updates installed?
  • Are backups isolated or immutable?
  • When were restorations last tested?
  • Does the organisation provide staff awareness training?
  • Are phishing simulations completed?
  • Is email filtered?
  • Are privileged accounts monitored?
  • Is unsupported software present?
  • Is a formal incident-response plan available?
  • Has the business experienced previous incidents?
  • Are suppliers assessed for cyber risk?
  • Does the business hold payment-card information?
  • Is personal data encrypted?

The NCSC recommends that organisations understand which security services are provided with a policy, which incidents are covered, what obligations apply and whether the proposed coverage matches the organisation’s needs. 

Why Multi-Factor Authentication Matters

MFA requires users to provide an additional form of verification beyond a password.

Insurers frequently view MFA as a fundamental control because compromised passwords remain a common route into:

  • Microsoft 365
  • Email
  • Remote desktop services
  • VPNs
  • Cloud applications
  • Administrator accounts

MFA should ideally protect all users, with particularly strong controls for administrators and remote access.

A business should not answer “yes” to an insurance question merely because MFA has been enabled for some accounts.

Why Backups Matter to Cyber Insurance

Reliable backups can reduce the impact of ransomware, deletion, corruption and equipment failure.

However, attackers may deliberately target backup systems.

A strong backup arrangement should normally include:

  • Multiple recovery copies
  • Off-site storage
  • Encryption
  • Restricted access
  • Separate credentials
  • Immutable or offline protection
  • Monitoring
  • Regular restoration testing

The NCSC’s small-business guidance identifies backups as one of the core measures organisations should use to improve resilience. 

Insurers may ask not only whether backups exist, but whether the business could genuinely restore its systems within an acceptable period.

Does Cyber Insurance Make a Business Secure?

No.

Insurance transfers some financial risk. It does not stop an attack from happening.

It cannot prevent:

  • Customer disruption
  • Stress for employees
  • Missed deadlines
  • Loss of confidence
  • Regulatory scrutiny
  • Operational interruption
  • Theft of confidential information

The ABI describes cyber insurance as part of a broader cybersecurity journey, helping organisations prepare for, respond to and recover from attacks rather than replacing preventative measures. 

A business still needs effective:

  • Identity security
  • Multi-factor authentication
  • Endpoint protection
  • Email security
  • Backups
  • Patch management
  • Network security
  • Staff training
  • Monitoring
  • Incident response
  • Business continuity planning

Cyber Insurance and UK GDPR

A cyber insurance policy does not remove a business’s data-protection responsibilities.

Where a personal data breach is likely to create a risk to people’s rights and freedoms, the organisation must notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Where the likely risk is high, affected individuals may also need to be notified without undue delay. 

The organisation must assess the incident and document its decision, even where it concludes that notification is not required.

A cyber insurer’s legal or breach-response team may assist, but the responsibility remains with the organisation.

When Should You Notify the Insurer?

The insurer should usually be contacted as soon as the business becomes aware of a suspected covered incident.

Do not wait until the complete investigation has finished.

Policies may require the insured business to:

  • Use an approved response provider
  • Obtain consent before incurring costs
  • Avoid admitting liability
  • Preserve evidence
  • Follow the insurer’s incident process
  • Notify the insurer within a specified period

Engaging an external specialist without checking the policy could result in some expenses not being reimbursed.

Emergency contact information should be stored somewhere accessible even when the normal network is unavailable.

What Should You Do During a Cyber Incident?

The exact response will depend on the incident, but the organisation should generally:

  1. Activate its incident-response plan.
  2. Contact its IT and cybersecurity provider.
  3. Notify the cyber insurer or broker promptly.
  4. Preserve logs and other evidence.
  5. Contain compromised accounts and devices.
  6. Assess whether personal data is involved.
  7. Record decisions and actions.
  8. Obtain legal advice where appropriate.
  9. Communicate carefully with employees, customers and suppliers.
  10. Restore systems through a controlled recovery process.

Businesses should avoid wiping devices or deleting evidence before forensic specialists have advised them.

Should You Purchase Cyber Insurance Through a Broker?

Businesses can purchase cyber insurance directly from an insurer or through an insurance broker.

A specialist broker may help the organisation:

  • Compare policy wordings
  • Identify gaps
  • Select appropriate limits
  • Understand exclusions
  • Complete the application
  • Compare incident-response services
  • Coordinate claims

The ABI directs businesses seeking specialist assistance towards brokers with relevant cyber insurance experience. 

The broker should understand the organisation’s industry, technology dependencies and contractual obligations.

Questions to Ask Before Buying a Policy

Before purchasing or renewing cyber insurance, ask:

  • Which incidents are covered?
  • What is specifically excluded?
  • Does the policy include ransomware?
  • Is business email compromise covered?
  • Does it cover fraudulent payments?
  • Are cloud-service outages covered?
  • Does it include supplier incidents?
  • Is business interruption included?
  • What waiting period applies?
  • How is lost income calculated?
  • Are forensic investigation costs covered?
  • Is legal support included?
  • Are data-restoration costs covered?
  • Are public relations services included?
  • Does it cover privacy claims?
  • Which security controls must remain in place?
  • Must approved incident responders be used?
  • What excesses apply?
  • Are there sub-limits?
  • Does the cover apply internationally?
  • How quickly must an incident be reported?

The answers should be recorded and understood by both leadership and the people responsible for IT.

What Are Sub-Limits?

A policy may have a headline limit but smaller limits for particular categories.

For example, a £1 million policy might include lower limits for:

  • Social engineering fraud
  • Ransomware
  • Data recreation
  • Regulatory investigations
  • Public relations
  • Supplier interruption
  • Legal costs

The headline figure does not necessarily represent the amount available for every type of claim.

What Is Dependent Business Interruption?

Dependent business interruption cover may apply when a cyber incident affecting an important supplier disrupts your own operations.

This can be relevant where the business depends on:

  • Cloud hosting
  • Payment services
  • Software-as-a-Service applications
  • Managed IT providers
  • Logistics systems
  • Telecommunications
  • Online marketplaces
  • Critical manufacturers

The policy should define which suppliers and types of incident qualify.

Cyber Essentials and Insurance

Cyber Essentials is a UK government-backed certification scheme designed to help organisations protect themselves against common cyber attacks. 

For eligible UK organisations, Cyber Essentials certification may include a level of cyber insurance and access to an incident-response helpline, subject to the scheme’s current conditions and eligibility requirements. 

Businesses should still review whether the included limit and scope are sufficient for their circumstances.

Certification can also help demonstrate that basic technical controls have been assessed, but it does not remove the need for broader security and recovery planning.

Common Cyber Insurance Mistakes

Businesses should avoid the following mistakes.

Buying Solely on Price

The cheapest policy may have restrictive exclusions, low sub-limits or limited incident-response support.

Guessing on the Application

Insurance answers should be verified with the people managing the organisation’s systems.

Assuming the IT Provider Handles Everything

The business, its IT provider, insurer, broker, legal advisers and incident-response specialists may all have different responsibilities.

Failing to Update the Insurer

Major changes such as acquisitions, new systems, increased turnover or new international operations may affect the risk.

Ignoring Policy Conditions

Security controls stated during the application should be maintained and periodically checked.

Not Storing Emergency Details Offline

The policy number and emergency telephone number may be inaccessible if they are stored only inside a compromised email account.

Treating Insurance as a Replacement for Security

A payment after an attack cannot fully repair lost trust, stolen confidential information or prolonged disruption.

How to Improve Your Insurability

Businesses can often strengthen their position before approaching insurers by improving basic cybersecurity.

Important actions include:

  • Enabling MFA for all users
  • Protecting administrator accounts
  • Removing unsupported systems
  • Applying patches promptly
  • Deploying managed endpoint protection
  • Securing remote access
  • Maintaining isolated backups
  • Testing recovery
  • Training employees
  • Filtering email
  • Creating an incident-response plan
  • Maintaining an accurate asset register
  • Reviewing supplier risks
  • Restricting access according to job role
  • Completing Cyber Essentials

These measures can reduce risk regardless of whether they affect the premium.

How Hamilton Group Can Help

At Hamilton Group, we help UK businesses strengthen the cybersecurity controls that insurers commonly expect.

Our services can include:

  • Cybersecurity assessments
  • Cyber insurance readiness reviews
  • Multi-factor authentication
  • Microsoft Entra ID security
  • Conditional Access
  • Endpoint Detection and Response
  • Managed security monitoring
  • Email security
  • Backup and disaster recovery
  • Microsoft 365 protection
  • Vulnerability assessments
  • Penetration testing
  • Cyber Essentials support
  • Incident-response planning
  • Business continuity planning
  • Security awareness training
  • IT documentation

We can work with your business and insurance broker to help verify technical controls, identify security gaps and provide accurate information about your IT environment.

Although we cannot advise which insurance product you should purchase, we can help ensure that your cybersecurity answers reflect the systems and protections actually in place.

Protect the Business Before a Claim Is Needed

Cyber insurance can provide valuable financial support and access to experienced specialists when a serious incident occurs.

However, it should form part of a wider risk-management strategy.

The best outcome is still to prevent an attack, detect it quickly and recover without major disruption.

UK businesses should combine appropriate insurance with strong technical controls, tested backups, trained employees and a clear incident-response plan.

Before renewing a policy, confirm that your declared security measures are operating correctly and that the cover reflects the potential impact of a real incident.

To review your cybersecurity arrangements or prepare for a cyber insurance application, contact Hamilton Group on 0330 043 0069 and speak to one of our experts.

This article provides general information and does not constitute legal, regulatory or insurance advice. Policyholders should obtain advice from an appropriately authorised insurance broker, insurer or legal professional.