Business Insurance

Cyber insurance for small business

Cyber insurance has matured quickly. A modern policy is far more than reimbursement — it's the incident-response team you call at 2am when something goes wrong.

7 min readUpdated Jul 2026
Key points
  • Incident response is often more valuable than the payout itself
  • Answer the application accurately — exclusions bite otherwise
  • MFA, offline backups and EDR are now standard requirements
  • £250k–£1m is a typical SME limit; regulated firms take more

What a modern policy includes

24/7 incident response, forensic investigation, ransomware negotiation, business-interruption cover, notification costs, and third-party liability for data-subject claims.

Common exclusions

Nation-state attacks, pre-existing vulnerabilities you knew about, and any unpatched systems flagged in your application. Answering the application accurately matters.

Controls insurers now expect

Multi-factor authentication on all admin accounts, tested backups held offline, endpoint detection and response (EDR), email filtering and regular staff phishing training.

Choosing a limit

£250k–£1m suits most SMEs; regulated firms or those holding large customer datasets usually take £2m+.

Ready to compare?

Get a tailored business insurance quote in minutes.

Answer a few short questions and we'll match you with UK-regulated providers — no obligation, no phone spam.

Start your comparison