
Cyber insurance: an honest guide
Every business now runs on systems and data, exluding perhaps the most traditional of high street stores.
Whether you're the person who founded it, the one who operates it, or the finance director who owns the insurance decisions, the exposure is the same: the day someone locks you out of your own systems, or walks off with your customers' data, the bill starts running immediately.
Unfortunately the chances of that day coming is getting more likely, not less. In its 2025 Annual Review, the UK's National Cyber Security Centre reported that its incident team "faced a record number of nationally significant incidents", and warned that threat actors are "using AI to increase the efficiency, effectiveness, and frequency of their cyber intrusions."
In plain terms: AI is making attacks cheaper to run and easier to scale, so more businesses are getting hit.
This guide explains what cyber insurance does, what it doesn't, what it costs, and how to decide whether you need it.
What is cyber insurance?
Cyber and Data insurance covers the financial fallout when your business is hit by a digital attack or a data breach.
That splits into two halves:
First-party cover pays for your own losses: getting systems back up, recovering data, lost income while you're down, ransom negotiation, and the cost of telling everyone what happened.
Third-party cover pays for claims made against you by others, typically customers or partners whose data was exposed, plus the legal costs of defending those claims and dealing with regulators.
Most cyber incidents trigger both halves at once. A ransomware attack stops you trading (first-party) and may expose customer data at the same time (third-party).
A good policy is built to handle the whole event.
Won't my other insurance cover a cyber attack?
Usually not, and sadly this catches people out the first time it happens to them. General liability, professional indemnity, property policies and so on were written for a physical world.
Most of these policies now carry explicit exclusions for cyber events, partly because insurers don't want the same loss paid twice, and partly because cyber risk is large enough to need its own pricing.
The really honest answer: assume your existing policies won't cover a hack unless a broker has confirmed in writing that they do. If someone tells you you're "probably covered", ask them to show you where!
Cyber vs Tech E&O: what's the difference?
If you run a software, SaaS or IT services business, you've likely come across Technology Errors & Omissions (Tech E&O). It's professional indemnity built for technology companies, and it's often what a US client's contract insists on. It's easy to assume it does the job of cyber cover. But it doesn’t.
Tech E&O covers claims that your product or service failed to do what you promised: errors in your code, a flawed system design, or an outage that causes a client a financial loss. It's about your professional performance.
Cyber covers what happens when you're attacked: ransomware, a breach of the data you hold, business interruption, extortion, and the incident response. It's about the security event, not the service failure.
Tech E&O does not cover data breaches, hacking and other cyber incidents; that's what a cyber policy is for. And cyber won't pay a client who's suing because your app miscalculated their invoices. If you sell technology, you usually need both, and you should be able to see where each one starts and stops.
Apologies for making it even more complicated, but it’s also important to separate our Tech E&O from Professional Indemnity. More on that here. But back to Cyber…
What's covered by Cyber Insurance?
Cover varies by policy, but a solid cyber policy typically includes:
- Incident response. A specialist team (forensics, IT, legal, PR) on call to contain the attack and get you trading again. For most businesses this is the single most valuable part.
- Business interruption. Lost income while your systems are down, including the slow ramp back to normal.
- Cyber extortion / ransomware. Ransom negotiation and, where lawful, payment, plus the cost of restoring encrypted data.
- Data breach response. Notifying affected people, credit monitoring where relevant, and managing the ICO.
- Third-party liability. Claims from customers or partners whose data was compromised, and the legal defence costs.
- Regulatory defence. The cost of responding to an ICO investigation, and any fine that is legally insurable.
What's not covered by Cyber Insurance?
Just as important, and where honesty matters most:
- Known issues. A breach you were already aware of, or a vulnerability you'd been warned about and ignored, generally won't be covered.
- Poor security hygiene. Many policies require basic controls (multi-factor authentication, patching, backups). If you claimed to have them and didn't, cover can be voided.
- Fines that can't legally be insured. Some regulatory penalties are uninsurable by law. A policy that promises to pay every fine is over-promising.
- Physical damage and bodily injury. Those sit with your property and liability cover, not here.
- War and state-backed attacks. This is a live issue. Insurers are increasingly excluding attacks attributed to nation states, and attribution is contested. Read this clause carefully; it's where a lot of the argument now happens. Tricky!
When it isn't really "your fault": supply chain attacks
A growing share of breaches don't start with you. They come through a supplier: your accounting software, your payroll provider, a cloud tool your team uses daily. When their system is compromised, your data can go with it.
With the increase in usage of of APIs and third-party connectors (Zapier, IFTT etc), this issue is becoming even more prevalent.
Cyber policies increasingly address this, but the detail really matters. Some cover you for a supplier's failure; some don't. If a chunk of your business runs through third-party platforms, and for most businesses it does, this is a question to ask before you buy.
What does Cyber Insurance cost?
Cyber premiums are driven by a handful of factors, so there’s no blanket answer;
- Revenue. Insurance for higher turnover businesses typically costs more in £ value, but usually represents a lower % of turnover the bigger a business gets.
- Sector. Data-heavy sectors or sectors holding sensitive data (healthcare, finance, e-commerce) also tend to increase costs.
- The data you hold. Volume and sensitivity of personal or payment data.
- Your security controls. MFA, backups, patching and staff training move the price. Insurers reward good hygiene.
- Limit and excess. How much cover you want, and how much risk you keep yourself.
Cyber is one of the few policies where improving your real-life security lowers your premium. The money you spend on MFA and backups often pays for itself twice, once in protection and once in a cheaper policy!
What happens when you're attacked
Speed is the whole game with cyber. The value isn't just the payout, it's the response on day zero.
A typical claim runs like this: someone notices something wrong (systems locked, data missing, a ransom note) and calls the incident line, usually 24/7.
A response team is engaged within hours. They contain the attack, work out what was taken, and start recovery. In parallel, legal and PR help you meet your obligations, including the 72-hour ICO notification window for reportable breaches. Business interruption losses are assessed as you get back on your feet.
When businesses come through a cyber event well, it's usually less about the size of their limit and more about how fast they got expert help when an incident occurs.
Who is targeted by cyber crime?
The most obvious targets are software, SaaS and IT businesses. They hold large volumes of customer data, they're deeply connected to their clients' systems, and a breach at one can cascade to many. If that's you, cyber cover isn't really optional.
But cyber isn't only a tech-company problem, and treating it that way is how non-tech businesses get caught out.
Any business that holds customer data, takes payments online, relies on software to operate, or would lose money if its systems went down for a week is exposed. That's a law firm, a manufacturer, a charity, a retailer. Attackers don't check your sector; they check whether you'll pay and look for a vulnerability.
If a week of downtime would threaten payroll, we need to chat cyber insurance.
A real-world example: NotPetya and Maersk
In 2017, the NotPetya malware spread through a compromised piece of Ukrainian accounting software and tore through companies worldwide. Shipping giant Maersk was collateral damage: roughly 45,000 PCs and 4,000 servers wiped in hours.
They reinstalled their entire global network from a single surviving copy of a domain controller that happened to be offline, thanks to a power cut in Ghana, during the attack. The reported cost was around $300 million.
Maersk is not an SME, but the mechanics are identical at smaller scale. Most businesses don't have a lucky offline backup to fall back on.
A note on UK breaches and the ICO
In the UK, personal data breaches are governed by UK GDPR and the Data Protection Act 2018, overseen by the Information Commissioner's Office.
Reportable breaches must be notified to the ICO within 72 hours of you becoming aware. Fines can reach up to £17.5 million or 4% of global annual turnover, whichever is higher, though most SME penalties are far smaller.
The clock starts the moment you know, and the reporting obligation exists whether or not you're insured. Cover that includes regulatory support helps you get the notification right under pressure.
Do I need cyber insurance?
Ask three honest questions. Would a week without systems cost you real money? Do you hold data that others would care about losing? Would funding a specialist response team hurt cash flow? If the answers are yes, the case makes itself.
Cyber cover isn't a substitute for good security, and any broker who sells it that way is selling fear. It's the backstop for the day your security isn't enough, which, as attacks get cheaper and more frequent, more businesses will face.
Frequently asked questions
How much does cyber insurance cost?
It depends on your turnover, sector, the data you hold and your security controls. Strong security lowers the price.
Isn't this covered by my other business insurance?
Almost never. Most general policies now exclude cyber events explicitly. Get it confirmed in writing before you rely on it.
I already have Tech E&O. Do I still need cyber?
Yes. Tech E&O covers claims that your product or service failed; cyber covers attacks on your business and the data you hold. We keep them separate on purpose, and tech firms usually need both.
Do I need it if I'm not a tech business?
If you hold customer data or depend on systems to trade, yes. Software firms are the obvious targets, but attackers go after anyone worth attacking.
Does it cover ransomware?
Yes, typically including negotiation, payment where lawful, and data recovery. Whether paying a ransom is wise is a separate question your response team will advise on.
What if the breach came through one of my suppliers?
Many policies cover supply chain attacks, but not all. If you rely heavily on third-party software, check this specifically.
Will it pay ICO fines?
It covers fines that are legally insurable and the cost of responding to an investigation. Some penalties can't be insured by law, and any policy claiming to cover every fine is overselling.
How fast is the response?
Good policies offer a 24/7 incident line with experts engaged within hours. For cyber, speed matters more than the size of the limit.
Are we covered against state-backed attacks?
This is contested. Many insurers now exclude nation-state attacks, and attribution is disputed. Read this clause closely and ask us to explain it.
Related articles
Get honest insurance
Join thousands of businesses who trust Really Honest.



