In 2024, a staggering 96% of cyberattacks targeted small and medium-sized enterprises (SMEs) in the UK, with 50% of businesses facing at least one attack, according to industry reports.
This guide explores what cyber insurance is, why it’s essential, and how UK SMEs can safeguard their operations in an increasingly dangerous digital landscape.
What is cyber security insurance?
Cyber insurance UK (also called cyber liability insurance, or cyber security insurance) protects businesses against legal and financial liability resulting from a cyber event.
These incidents include data breaches, ransomware, phishing, and system disruptions.
A cyber insurance policy typically covers costs for incident response, legal fees, data recovery, and more. This type of cyber crime insurance is becoming increasingly important for companies of all sizes.
Why is cyber security insurance important?
50% of UK businesses faced cyberattacks in 2024, costing an average of £1,205 (up to £10,830 for larger firms). This is according to an article published by The Irish Times.
In an article written by NFP, it stated that in Ireland, 90% of businesses reported financial losses from cyberattacks in the past 5 years, with cyber extortion (37%) being common. Read more about that here.
With these rising risks, more SMEs are turning to cyber insurance companies UK to help reduce exposure to threats.
How common are cyberattacks on SMEs?
Very common.
96% of cyberattacks target SMEs, and 50% of UK businesses faced at least one attack in 2024.
SMEs are vulnerable due to limited budgets and expertise, making insurance and cybersecurity critical.
What are the cybercrimes I need to protect against?
Ransomware
Malware that encrypts data, demanding payment for access. Affects 37% of Irish businesses.
Phishing
Fraudulent emails or messages tricking users into sharing sensitive data or clicking malicious links. Common in 50% of UK cyberattacks in 2024.
Data Breaches
Unauthorised access to personal or business data, often leading to GDPR fines (up to 4% of turnover).
Malware
Viruses or spyware that disrupt systems or steal data.
Distributed Denial-of-Service (DDoS)
Overwhelming servers to disrupt services, causing downtime.
Business Email Compromise (BEC)
Scammers impersonate trusted contacts to steal funds or data.
Credential Theft
Stealing login details to access systems or accounts.
Social Engineering
Manipulating individuals into divulging confidential information.
SQL Injection
Exploiting website vulnerabilities to access databases.
Insider Threats
Malicious or negligent actions by employees or contractors.
Protecting against these requires both strong cybersecurity practices and the right cyber and data insurance coverage.
What does cyber insurance cover?
First-party cyber coverage
This refers to the portion of a cyber insurance policy that covers an organisation’s own financial losses, such as data recovery and business interruption. This is sometimes referred to as business cyber insurance.
Third-party cyber liability
This term covers the costs for claims made against an organisation by others, such as customers or partners, after a cyber event.
Many cyber insurance companies offer specific cyber liability insurance UK products tailored to meet compliance requirements.
Cyber liability endorsement
This is an add-on to an existing insurance policy, such as general liability, that extends coverage to include some cyber risks.
Network business interruption coverage
This is a specific type of cyber insurance coverage that pays for lost income and extra expenses when business operations are halted due to a cyberattack.
Some cyber insurance brokers may also call this cyber attack insurance.
What does cyber insurance not cover?
Many businesses looking for business cyber insurance, might not know about these following common exclusions in a standard cyber insurance policy.
Pre-existing breaches
This doesn’t cover incidents or vulnerabilities known before the policy starts.
Outdated systems
Losses from using unsupported or unpatched software/hardware aren’t covered.
Non-cyber losses
Physical damage (e.g., fire, theft) or non-digital incidents.
Unrelated business losses
Financial losses not directly caused by a covered cyber event.
Negligence
It doesn’t cover failure to implement basic cybersecurity (e.g., no backups or updates).
What are the cyber insurance requirements?
In order to qualify for cyber insurance coverage, you have to have these following security measures in place:
Multi-factor authentication (MFA)
Multi-factor authentication (otherwise known as two-factor authentication, or 2FA), requires users to provide two or more verification factors (such as passwords, code sent to a device, or biometrics) to access systems.
This reduces unauthorised access risks.
Cybersecurity training
Employees must be trained regularly to recognise threats like phishing, social engineering, and malware to minimise human error-related breaches.
Maintaining good data backups
Regular, secure, and tested backups of critical data to ensure recovery from ransomware or data loss incidents.
Identity Access Management (IAM)
Systems to control and monitor user access to sensitive data and applications, ensuring only authorised individuals have access.
Enforcing data classification
Categorising data based on sensitivity (e.g., public, confidential) to apply appropriate security controls and handling procedures.
P.S. We have a free guide on how to conduct a cybersecurity risk assessment for your business, access that post here.
Additional cyber insurance requirements
Strong password policies
Mandating complex, unique passwords, regular updates, and secure storage to prevent unauthorised access.
Antivirus or Endpoint Detection and Response Software (EDR)
Software to detect, prevent, and respond to malware and other threats on devices and networks.
Firewalls
Network security systems to monitor and control incoming and outgoing traffic, protecting against unauthorised access and networks.
Incident response plans
Network security systems to monitor and control incoming and outgoing traffic, protecting against unauthorised access and attacks.
Security risk assessments
Regular evaluations to identify vulnerabilities, assess risks, and implement mitigation strategies.
What is Cyber Essentials, and how does it relate to insurance?
Cyber Essentials is a UK government-backed certification that demonstrates basic cybersecurity practices, like secure configurations and malware protection.
Many insurers offer lower premiums for certified businesses, as it reduces the likelihood of claims.
How much does cyber insurance cost?
The cost associated with cyber risk insurance varies by business size, industry, and data sensitivity.
For example, UK SMEs with Cyber Essentials insurance certification may get £25,000 coverage, with options to increase to £250,000 for ~£224 annually.
Businesses often ask “how much does cyber insurance cost?” but the answer depends on tailored assessments from cyber insurance providers or cyber insurance brokers.
You can often request a cyber insurance quote or even a cyber insurance online quote directly from providers.
Why are cyber insurance premiums rising?
Premiums have risen due to the growing frequency and severity of cyberattacks.
Insurers are adjusting rates to account for higher risks, especially as 62% of attacks now exploit supply chains, increasing potential losses.
How can SMBs reduce cyber insurance premiums?
Obtaining certifications like Cyber Essentials can lower premiums by showing insurers you have basic cybersecurity measures in place.
Other steps include:
-
Regularly updating software and firewalls.
-
Training staff on cybersecurity best practices.
-
Implementing strong access controls and data encryption.
How do I choose the right cyber insurance policy?
Consider:
-
Your business size, industry, and data sensitivity.
-
Coverage for specific risks (e.g., ransomware, GDPR fines).
-
Policy limits and exclusions.
-
The insurer’s reputation and claim process. Consult a broker or cybersecurity expert to tailor the policy to your SME’s needs.
Cyber insurance companies UK
Here is a list of the most common cyber insurance companies in the United Kingdom;
AIG
Provides CyberEdge policies with coverage for data breaches, cyber extortion, and incident response costs.
Beazley
Offers comprehensive cyber insurance, including breach response, regulatory fines, and business interruption coverage.
Chubb
Delivers tailored cyber insurance covering ransomware, data breaches, and third-party liabilities. They emphasise financial protection and risk consulting.
CFC
Specialises in cyber insurance with coverage for cybercrime, social engineering, and incident response. They provide risk management tools.
Hiscox
Offers cyber insurance with coverage for phishing, ransomware, and crisis containment. Their focus is on insurance and risk education.
Aviva
Provides comprehensive cyber cover with 24/7 incident response support. They are partners with consultancies like CYENCE for risk assessment.
Where can I learn more about cyber insurance for SMEs?
For more details, check trusted UK resources like:
How can I secure my business against cyber criminals?
To protect your business from cybercrimes like ransomware, phishing, and data breaches, you should combine robust security practices with cyber insurance for business.
Access a free downloadable guide to cybersecurity.
This guide includes everything you need to know about cybersecurity threats + solutions.