- Incident response is often more valuable than the payout itself
- Answer the application accurately — exclusions bite otherwise
- MFA, offline backups and EDR are now standard requirements
- £250k–£1m is a typical SME limit; regulated firms take more
What a modern policy includes
24/7 incident response, forensic investigation, ransomware negotiation, business-interruption cover, notification costs, and third-party liability for data-subject claims.
Common exclusions
Nation-state attacks, pre-existing vulnerabilities you knew about, and any unpatched systems flagged in your application. Answering the application accurately matters.
Controls insurers now expect
Multi-factor authentication on all admin accounts, tested backups held offline, endpoint detection and response (EDR), email filtering and regular staff phishing training.
Choosing a limit
£250k–£1m suits most SMEs; regulated firms or those holding large customer datasets usually take £2m+.
Get a tailored business insurance quote in minutes.
Answer a few short questions and we'll match you with UK-regulated providers — no obligation, no phone spam.
Start your comparison