Cyber insurance pays for the costs of a cyber attack or security failure at your business. It covers things your standard commercial policy will not, such as ransomware demands, data breach notification, and lost income while your systems are down. Most UK businesses now hold some data or rely on connected systems, so the cover has moved from a niche extra to a mainstream part of business insurance.
What a cyber policy pays for
A cyber policy splits into two parts: first-party costs you bear directly, and third-party costs you owe to others.
First-party cover
- Ransom payments and the professional fees to negotiate and recover systems.
- Investigation and forensic costs to work out how the attack happened.
- Data restoration and system repair.
- Business interruption loss while systems are offline.
- Notification costs when you must tell customers or regulators about a breach.
- Reputational support such as PR and credit monitoring for affected customers.
Third-party cover
- Liability for failing to protect customer data.
- Regulatory fines and penalties where the policy allows (note that some regimes exclude them).
- Legal defence costs and settlement of claims.
- Compensation to third parties affected by an attack that spread from your systems.
What cyber insurance does not cover
Cyber policies are narrow and exclusion-heavy. Read the wording before you rely on it.
Common gaps:
- Losses from a weakness you knew about and did not fix.
- Breaches caused by an unpatched system where the insurer required patching.
- Bodily injury or property damage, which your general liability policy handles instead.
- Losses from war or state-sponsored attack, which most policies exclude.
- Gradual data loss or poor practice that is not a single identifiable event.
- Claims arising before the policy started, including earlier unknown breaches.
The line between what is covered and what is not often turns on whether you met the security steps the policy set as a condition. That makes your own controls part of the cover, not separate from it.
How underwriters assess cyber risk
Insurers price cyber cover on your security posture, not just your turnover. They will ask about backups, multifactor authentication, staff training, and how you handle payment details. A business with tested offline backups and enforced multifactor authentication typically pays less and gets broader terms. One with weak controls may face a high excess, narrow scope, or a decline.
The market tightened after a wave of large ransomware losses. Capacity is still available, but terms are stricter than they were, and insurers expect evidence that you manage the basics. Read how insurers judge risk in our guide to how insurers calculate risk and price cover.
Does your business need it
Any business that holds customer data, takes card or bank payments, or depends on its website or systems to trade should consider cyber cover. The cost of a single breach, in notification, downtime, and lost custom, often exceeds the premium by a wide margin. Small firms are frequent targets because attackers expect weaker defences, not because they are unimportant.
If you already hold a business insurance pack, check whether it includes any cyber sub-limit or whether you need a standalone policy. Our guide to what a business insurance pack covers explains where cyber sits alongside your other commercial covers.
Sources
- Insurers — how underwriters assess and price commercial risk.
- Financial Conduct Authority (FCA) — operational resilience and cyber expectations for firms.
- Association of British Insurers (ABI) — cyber and commercial insurance guidance.
- National Cyber Security Centre (NCSC) — guidance on backups, multifactor authentication, and phishing.