Business Insurance

Cyber Insurance for Businesses: Cover Against Data Breaches and Attacks

Cyber attacks are one of the fastest-growing threats to UK businesses of all sizes. Cyber insurance helps you cover the costs of a data breach, ransomware attack, or system failure, so a digital incident does not become a financial disaster.

  • Covers data breach response costs, legal fees, and compensation claims
  • Protects against ransomware, phishing, and system failures
  • Available for businesses of all sizes, including sole traders

What is cyber insurance?

Cyber insurance is a type of business insurance that helps you manage the financial impact of a cyber incident, such as a data breach, ransomware attack, phishing scam, or system failure. It covers the costs that arise when your digital systems or data are compromised, whether that is through a deliberate attack or an accidental exposure.

Cyber insurance typically provides two types of cover:

First-party cover

This covers your own costs as a business. It includes things like the cost of investigating the breach, notifying affected customers, restoring data and systems, business interruption losses while your systems are down, and crisis management expenses such as hiring PR consultants to manage reputational damage.

Third-party cover

This covers claims made against you by other people or organisations. If customer data is exposed and those customers sue you, or if a regulatory body such as the ICO investigates your handling of personal data, third-party cover pays for your legal defence and any compensation or fines.

Unlike professional indemnity insurance, which covers claims arising from your professional advice, cyber insurance specifically targets digital and data-related risks. Some PI policies include limited cyber cover, but a standalone cyber policy provides much broader protection.

Does your business need cyber insurance?

If your business uses computers, email, online payment systems, stores customer data, or relies on any kind of digital infrastructure, you are at risk of a cyber incident. The question is not whether your business could be targeted, but what the financial impact would be if it were.

Signs your business needs cyber insurance

  • You store personal data - Customer names, email addresses, payment details, health records, or any other personal information. Under GDPR, a breach involving personal data can trigger mandatory notification requirements and potential fines.
  • You take payments online or by card - Any business processing card payments is a target for cybercriminals. A breach of payment card data can result in significant costs and loss of customer trust.
  • You rely on IT systems to operate - If a ransomware attack locked you out of your systems tomorrow, how long could you survive without them? Cyber insurance covers the business interruption costs during recovery.
  • You send and receive sensitive information by email - Email is the most common vector for phishing attacks and business email compromise. A single fraudulent email can result in significant financial losses.
  • You are a small business - Small businesses are disproportionately targeted because attackers know they often lack dedicated IT security. The UK government's Cyber Security Breaches Survey consistently shows that a significant proportion of small businesses experience cyber attacks each year.

Even self-employed professionals and sole traders who work from a laptop and a phone have exposure to cyber risk. If your email is compromised and a fraudster uses it to redirect a client's payment, you could face a claim and the cost of investigating and resolving the incident.

What does cyber insurance cover?

Cyber insurance policies vary between providers, but most will include a core set of first-party and third-party covers. Understanding what is included, and what is not, helps you choose the right policy for your business.

First-party costs (your own losses)

  • Incident response costs - The cost of hiring forensic IT specialists to investigate the breach, identify how it happened, and close the vulnerability. This is often the largest first-party cost.
  • Data restoration - The cost of recovering or rebuilding lost or corrupted data from backups, or recreating it where backups are not available.
  • Business interruption - Lost income and additional operating expenses while your systems are down. This can include the cost of temporary workarounds, such as manual processes or temporary equipment hire.
  • Notification costs - Under GDPR, you may be required to notify affected individuals and the Information Commissioner's Office (ICO) within 72 hours. Cyber insurance covers the cost of managing this notification process at scale.
  • Crisis management and PR - Professional communications support to manage the reputational impact of a breach. This might include hiring a PR firm, setting up a customer helpline, and preparing public statements.
  • Cyber extortion - The costs associated with a ransomware demand, including negotiation with the attacker (through specialist firms), and in some cases, the ransom payment itself, though this varies by policy.

Third-party costs (claims from others)

  • Regulatory defence and fines - Legal costs of defending an investigation by the ICO or another regulatory body, and in some cases, the fines or penalties imposed.
  • Compensation claims - If customers, clients, or business partners suffer a loss because of your breach, they may sue you for compensation. Cyber insurance covers the legal defence and any settlement or award.
  • Media liability - Claims arising from defamatory content posted by a hacker on your website or social media channels.

Common exclusions

  • Losses arising from a known vulnerability that you failed to patch
  • Bodily injury or physical property damage (covered by public liability insurance)
  • Losses caused by an act of war or state-sponsored attack (often excluded under a "war exclusion" clause)
  • Infrastructure failures affecting your internet service provider or cloud provider (unless specifically covered)
  • Fraudulent transfer of funds by an employee (may be covered under a crime or fidelity policy instead)

How much does cyber insurance cost for UK businesses?

Cyber insurance premiums depend on the size of your business, the volume and sensitivity of the data you handle, your industry, and the strength of your existing cyber security measures. For small businesses, premiums can start from as little as £100 to £200 per year, while larger firms with more complex risk profiles will pay considerably more.

Compared to other types of business insurance, cyber cover is still relatively new and the market is evolving rapidly. Premiums have risen in recent years as the frequency and severity of cyber attacks has increased, but competition between insurers is also growing, which helps keep pricing in check. The best way to find competitive cover is to compare quotes from multiple providers.

The cost of a policy is typically a fraction of the cost of a single uninsured breach. The average cost of a cyber breach for a UK small business is estimated at several thousand pounds, and for larger businesses the figure can run into hundreds of thousands. The table below gives an indication of typical annual premiums based on business size and a standard cover level.

Cyber insurance costs by business size

Business size
Typical annual premium
Sole trader / freelancer
£100 - £250
Micro business (1-9 employees)
£200 - £500
Small business (10-49 employees)
£400 - £1,200
Medium business (50-249 employees)
£1,000 - £5,000
Large business (250+ employees)
£5,000 - £25,000+

Several factors will influence where your premium falls within these ranges:

  • Industry sector - Healthcare, financial services, and legal businesses tend to pay more because they handle highly sensitive personal data. Retail and hospitality businesses pay less on average but face significant risks around payment card data.
  • Volume of records held - A business with a database of 100,000 customer records will pay more than one with 1,000, because the cost of a breach response scales with the number of affected individuals.
  • Revenue and turnover - Higher turnover generally means a higher premium, as the insurer assumes a larger business has more to lose.
  • Existing security controls - Businesses that can demonstrate strong cyber security practices, such as multi-factor authentication, regular patching, encrypted backups, and staff training, will typically qualify for lower premiums.
  • Claims history - Previous cyber incidents or claims will increase your premium. A clean record works in your favour.

Comparing quotes through Money Saving Advisors helps you find competitive pricing while making sure the policy actually covers the risks that matter to your business.

Compare cyber insurance quotes for your business

Tell us about your business and we will match you with competitive cyber insurance quotes from specialist UK providers.

Compare cyber insurance cover: what to look for

Not all cyber insurance policies are created equal. When comparing quotes, look beyond the headline price and examine what each policy actually covers. The features that matter most will depend on your business, but there are several key areas that every buyer should check before committing to a policy. A thorough comparison at the quote stage can save you from discovering gaps in your cover when you need it most.

Cyber insurance is more complex than many other types of business insurance because the risks are technical and constantly evolving. A policy that looks comprehensive at first glance may contain sub-limits, exclusions, or conditions that significantly reduce the effective cover. For example, some policies exclude ransomware payments entirely, while others cap business interruption cover at a fraction of the overall limit. These details are often buried in the policy wording rather than highlighted on the summary page.

The table below lists the most important features to compare when evaluating cyber insurance quotes. Use it as a checklist when reviewing policy documents or speaking with brokers to make sure you are comparing like with like.

Key features to compare across policies

Feature
What to check
Incident response service
Does the policy include a 24/7 breach response hotline with access to forensic IT, legal, and PR specialists? A rapid response can dramatically reduce the impact of a breach.
Business interruption
Is lost revenue covered while your systems are down? Check the waiting period (deductible period) before the cover kicks in, and the maximum indemnity period.
Ransomware and cyber extortion
Does the policy cover ransom payments, negotiation costs, and the cost of restoring systems after a ransomware attack? Some policies exclude ransom payments.
Regulatory defence and fines
Are ICO investigation costs and GDPR fines covered? Check whether the policy covers fines where legally insurable, and whether regulatory defence costs have their own sub-limit.
Social engineering fraud
Are losses from phishing and business email compromise covered? This is one of the most common types of cyber loss but is not always included in standard policies.
System failure cover
Does the policy respond to accidental system failures as well as malicious attacks? Some policies only cover losses caused by external attacks, not internal IT failures.
Retroactive date
When does the cover start? A full retroactive date means the policy covers breaches that occurred before the policy inception but were discovered during the policy period.
Sub-limits and aggregates
Does the policy apply sub-limits to specific cover areas (e.g. ransomware capped at a fraction of the total limit)? Sub-limits can significantly reduce the effective cover available.

When you receive quotes, ask each insurer or broker to provide a summary of these features so you can compare them side by side. A cheaper policy that excludes business interruption or ransomware cover may not provide the protection you actually need. The goal is to find a policy that matches your specific risk profile at a competitive price, rather than simply choosing the cheapest option available.

It is also worth asking whether the insurer offers any added-value services, such as free cyber security training for your staff, vulnerability scanning, or access to an online security portal. These extras can help you strengthen your defences and may reduce the likelihood of needing to make a claim in the first place. Some insurers also offer pre-breach planning services that help you prepare a response plan before an incident occurs.

If your business handles particularly sensitive data, such as health records, financial information, or children's data, make sure the policy does not exclude or limit cover for breaches involving these categories. Some policies apply higher excesses or lower sub-limits for high-sensitivity data. Similarly, if you process payment card information, check that the policy covers Payment Card Industry (PCI) fines and assessment costs, as these can be substantial.

How a cyber insurance claim works in practice

Understanding how a cyber insurance claim plays out in a real scenario helps illustrate the value of the cover. Here is a worked example based on a common type of incident.

Scenario: ransomware attack on a small accountancy firm

A 12-person accountancy firm receives a phishing email that appears to come from a client. An employee clicks the link, and ransomware encrypts the firm's server within hours. The attackers demand £40,000 in cryptocurrency to provide the decryption key. The firm cannot access client records, tax returns in progress, or their email system.

How the claim unfolds

  • Day 1: Incident reported - The firm calls their cyber insurer's 24/7 breach response line. The insurer immediately assigns a forensic IT team, a legal adviser, and a crisis communications specialist.
  • Days 2-3: Investigation - The forensic team identifies the attack vector (the phishing email), confirms the extent of the encryption, and checks whether any data was exfiltrated before the encryption. They also assess whether backups are viable for restoring the data.
  • Days 3-5: Negotiation and recovery - The insurer's specialist negotiation firm communicates with the attackers. In parallel, the IT team begins restoring data from backups. The firm is able to recover most of their data without paying the ransom.
  • Days 5-14: Remediation and notification - The IT team rebuilds the server with improved security controls. The legal adviser helps the firm determine whether they need to notify the ICO and affected clients under GDPR. Notification letters are prepared and sent.
  • Ongoing: Business interruption claim - The firm was unable to operate normally for 10 working days. The insurer reimburses lost fee income and the cost of temporary manual processes.

Total claim cost

Forensic investigation: £15,000. System restoration: £8,000. Legal and GDPR advice: £6,000. Business interruption: £22,000. Client notification: £3,000. Total: £54,000, covered in full under the policy minus the £500 excess.

How to reduce your cyber insurance premium

Insurers reward businesses that take cyber security seriously. By strengthening your defences before you apply for cover, you can often secure a lower premium and improve your overall risk profile at the same time. Here are the most effective steps you can take.

  • Get Cyber Essentials certified - Cyber Essentials is a UK government-backed certification that demonstrates your business meets a baseline standard of cyber security. Many insurers offer discounts to businesses that hold Cyber Essentials or Cyber Essentials Plus certification.
  • Implement multi-factor authentication (MFA) - MFA is one of the single most effective controls you can put in place. Requiring a second factor, such as a code from an authentication app, for email, remote access, and admin systems significantly reduces the risk of account compromise.
  • Regular staff training - Human error is the cause of most cyber incidents. Running regular phishing simulations and cyber awareness training helps your team recognise and avoid common threats. Insurers view staff training favourably when assessing your risk.
  • Patch and update systems promptly - Keeping your operating systems, software, and firmware up to date closes known vulnerabilities that attackers exploit. Some policies specifically exclude losses arising from unpatched systems.
  • Maintain encrypted backups - Regularly back up your data, keep at least one copy offline or in a separate cloud environment, and test your restore process. Good backups are your last line of defence against ransomware and can dramatically reduce the cost and duration of a claim.
  • Use endpoint protection - Modern endpoint detection and response (EDR) software provides better protection than traditional antivirus. Insurers are increasingly asking about the specific tools you use.

Taking these steps before seeking quotes through Money Saving Advisors will help you demonstrate a strong security posture and access the best available pricing from contractors and specialist cyber insurers alike.

Frequently asked questions about cyber insurance

No, cyber insurance is not a legal requirement. However, GDPR requires you to protect personal data, and the costs of failing to do so can be substantial. Cyber insurance helps you manage those costs. Some contracts, particularly in the public sector and financial services, may require you to hold cyber cover as a condition of the agreement.

Many cyber insurance policies cover GDPR-related costs, including the cost of defending an ICO investigation and, in some cases, fines imposed by the ICO, where those fines are legally insurable. However, the insurability of regulatory fines varies, and some policies exclude fines entirely. Check your policy wording carefully.

Some cyber insurance policies cover ransomware payments, while others exclude them or cap them at a sub-limit. Even where payment is covered, insurers will typically explore every alternative, including data restoration from backups, before considering a ransom payment. The policy will usually cover negotiation costs and system recovery regardless.

Professional indemnity insurance covers claims arising from your professional advice or services, such as errors in a report or negligent recommendations. Cyber insurance covers losses specifically related to data breaches, cyber attacks, and system failures. There is some overlap where a cyber incident causes a client to suffer a loss from your professional services, but standalone cyber cover is much broader for digital risks.

Yes. Cyber insurance is available for businesses of all sizes, including sole traders and freelancers. If you store client data on your laptop, use cloud services, or take online payments, you have cyber exposure. Premiums for sole traders typically start from around £100 to £250 per year depending on the level of cover.

Many cyber insurance policies cover losses from social engineering and phishing attacks, but it is not always included as standard. Some policies offer it as an optional extension with its own sub-limit. Given that phishing is one of the most common ways businesses suffer cyber losses, it is worth checking that your policy includes this cover and that the limit is adequate.

What our clients say

Reviews from real customers

"Clear, Thorough and Empathetic"

Shortly after I spoke with Anna, she was also very helpful and made it effortless and a nice experience.

5/5
Tyler Elsworthy

"Helped us make an informed decision"

Had a really good experience regarding arranging a secured loan. They introduced me to a great advisor. Thanks for the help.

5/5
Dana Huggins

"Highly recommnded"

For once a loan transaction without stress and complications. Very impressed and highly recommended.

5/5
Alex Pearce

"Exceptional service from start to finish"

Thrilled to share my exceptional experience with Money Saving Advisors. The website made it incredibly simple and easy to connect with an advisor. They helped me find the best deal on my remortgage and secured a very competitive interest rate!

5/5
Aaron Humphreys
GB

"Great advice and money saved"

Great advice and money saved on mortgage.

5/5
Ace
GB

"Amazing service!"

I have previously declined a loan of the value I needed from various brokers, but this website found me a reputable broker with surprisingly decent rates.

5/5
Alex Jones
GB

This article was written by:

Lawrence Howlett
Lawrence Howlett

Founder of Money Saving Advisors

Lawrence Howlett brings a results-driven mindset to his writing, shaped by over a decade of experience across finance, legal, and energy sectors. As the founder of Moneysavingadvisors, he’s built a reputation for turning complex financial concepts into clear, actionable insights for consumers. His writing stands out for its clarity, structure, and focus on delivering value.

Article last updated 19 July 2026

Reviewed by Nick McDonald on 19 July 2026