Cyber Insurance for Small Businesses: Do You Really Need It?

GlennHassler

cyber insurance for small businesses

Cyber insurance is no longer a niche product for technology companies. In the UK government’s 2025/2026 Cyber Security Breaches Survey, 43% of businesses said they had identified a cyber breach or attack in the previous 12 months, rising to 46% among small businesses. Allianz’s 2026 Risk Barometer also ranked cyber incidents as the leading business risk globally for the fifth year running. For a small company that relies on email, cloud software, online banking or customer data, the real question is whether it could absorb the cost and disruption of a serious incident.

That does not mean every SME needs the same policy. Cyber insurance works best as part of a wider security and continuity plan, not as a substitute for basic protection.

What cyber insurance usually covers

A cyber liability policy can combine first-party cover for your own losses with third-party cover for claims against the business. Exact wording varies, but UK policies commonly focus on response and recovery costs.

Data breach response

Data breach insurance can help pay for forensic investigation, legal advice, customer notification and public relations support after personal or commercially sensitive information is exposed. This matters particularly for firms holding customer, employee, payment or health-related data.

Business interruption

If ransomware, malware or another covered incident stops you trading, cyber business interruption cover may compensate for lost income and certain extra costs while systems are restored. Waiting periods, limits and calculation methods differ between policies.

Cyber extortion and ransomware

Some policies include ransomware insurance cover for specialist response, negotiation and certain extortion-related costs. A ransom payment is not automatically covered and should not be treated as the first response. The ABI advises businesses to involve law enforcement and speak to the insurer before any payment decision.

Liability and legal defence

If customers, employees or others allege that your business failed to protect information, a policy may cover legal defence costs and certain compensation payments. Regulatory investigation support may also be included, although fines and penalties are not automatically insurable.

What cyber insurance does not replace

Insurance does not stop phishing emails, patch vulnerable software or restore a backup that was never created. The National Cyber Security Centre warns that cyber insurance is not a replacement for fundamental security controls. Insurers may also expect declared controls to remain in place throughout the policy period.

Common exclusions or restrictions can include known incidents that began before the policy, unsupported software, failure to meet stated security requirements, certain infrastructure outages and some contractual liabilities. Never assume a general business policy already includes meaningful cyber cover.

How much does SME cyber insurance cost in the UK?

There is no dependable single average premium because insurers price the actual risk. A small consultancy using cloud systems and storing limited personal data may pay far less than an online retailer, healthcare provider or financial firm handling large volumes of sensitive records.

Quotes can run from the low hundreds of pounds a year for lower-risk micro businesses to several thousand pounds or more for firms with higher turnover, sensitive data, larger limits or weaker controls. Treat online price ranges as illustrations, not guaranteed market averages. The ABI notes that SME policy limits are commonly available from around £100,000 to £5 million, with higher limits for more complex risks.

Premiums are commonly influenced by turnover, sector, data sensitivity, previous incidents, cover limit, excess, third-party dependencies and the security controls already in place.

Which small businesses have the strongest case for cover?

Cyber insurance deserves serious consideration if losing access to systems for even a day would materially affect revenue, or if the business stores information that would be costly to investigate and notify after a breach. That includes online retailers, professional services firms, healthcare businesses, accountants, agencies and any SME heavily dependent on cloud platforms.

Consider a 12-person accountancy firm whose Microsoft 365 accounts are compromised through phishing. Attackers access client information and send fraudulent emails from a genuine mailbox. Even if access is restored quickly, the firm may still need forensic support, legal guidance, client communication and reputation management. Many policies provide an incident-response team that a small company would otherwise have to find during a crisis.

How to reduce risk before buying cover

Use multi-factor authentication

Protect email, cloud storage, finance systems, administrator accounts and other important services with multi-factor or two-step verification. Account takeover remains a major route into small businesses.

Maintain tested backups

The NCSC recommends keeping copies of the data your business needs to operate and testing that those backups can be restored. Separate or protected backups are especially important for ransomware resilience.

Patch systems and remove unsupported software

Keep operating systems, applications, routers and business platforms updated. Remove software that is no longer supported or needed, particularly on devices that can access company data.

Consider Cyber Essentials

Cyber Essentials is the UK government-backed certification scheme covering core protections against common attacks. Government guidance published in late 2025 said organisations with Cyber Essentials were 92% less likely to make a cyber insurance claim. Certification may also include cyber insurance for eligible organisations under the scheme’s terms.

Questions to ask before choosing a policy

Ask whether the policy covers your own losses as well as third-party claims, how business interruption is calculated, whether incidents involving cloud providers are covered, what ransomware conditions apply, and which response specialists you must use. Check the excess, waiting periods, sub-limits and exclusions rather than comparing headline premiums alone.

Also confirm what security controls you have promised to maintain. If an application says multi-factor authentication is enabled everywhere but it is not, that discrepancy can create problems during a claim.

Frequently asked questions

Is cyber insurance legally required for UK small businesses?

Generally, no. Cyber insurance is not a standard legal requirement in the way employers’ liability insurance can be for businesses with employees. However, a client, lender or contract may require a certain level of cyber cover.

Does normal business insurance cover cyber attacks?

Sometimes a package includes limited cyber protection, but many traditional property, liability and business interruption policies restrict or exclude cyber losses. Check the wording rather than assuming you are covered.

Will cyber insurance pay after a ransomware attack?

It may cover incident response, recovery, interruption and certain extortion costs, depending on the wording. Coverage for any payment to an attacker is conditional and should be discussed with the insurer and law enforcement before action is taken.

Can a very small business benefit from cyber insurance?

Yes, particularly if it depends on digital systems or holds customer data. The right decision depends on how much financial loss, downtime and specialist response cost the business could absorb without insurance.

So, do you really need it?

For many UK SMEs, cyber insurance is becoming a practical resilience tool rather than an optional technology add-on. The strongest case is where a breach could interrupt trading, expose sensitive data or create recovery costs the business could not comfortably fund. Secure the basics first, understand the losses that would hurt most, then compare policies on coverage and response support rather than price alone. Insurance cannot make a business breach-proof, but the right cover can make a serious incident far more survivable.