What drives the cost of cyber insurance for tech firms?
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06
If you run an IT business — a software house, a managed service provider, a SaaS firm, a consultancy or an independent contractor — "how much does cyber insurance cost?" is rarely the right first question. There is no fixed price, and any broker quoting one before understanding your business is guessing. Cyber premiums are built from your own risk profile: what you hold, what you do, and how well you protect it. This page walks through the factors insurers actually look at, so you can see where the number comes from and where you have real influence over it.
Why is there no fixed price for cyber insurance?
Cyber is one of the most individually rated products a technology firm will buy. Two businesses with identical turnover can be offered very different terms because the thing being priced is the likelihood and potential severity of a data breach, ransomware event or system outage — and that depends on details a headline figure can't capture.
Underwriters build a picture of your exposure from a proposal form and, increasingly, from an outside-in scan of your internet-facing systems. They are asking, in effect: if this firm were hit tomorrow, how bad would it be, how likely is it, and how much would we have to pay to put it right? Because technology companies often sit at the centre of their clients' operations — hosting data, running systems, pushing code into production — the potential knock-on cost of an incident is higher than for many other sectors. That is exactly why doing this properly, with a broker who understands tech risk, tends to pay off. It is also why the same conversation naturally overlaps with technology professional indemnity insurance, which responds when a client alleges your work caused them a loss.
How much does the data you hold affect the cost?
Data is usually the single biggest driver. Insurers care about both volume and sensitivity. Holding a handful of business contact details is a very different proposition from processing payment card data, health records, children's data, or large volumes of personal information on behalf of your clients.
For technology firms this cuts two ways. You hold your own data, and you very often process or store data belonging to your customers. A managed service provider or SaaS platform may be custodian of information for hundreds of client organisations at once, which concentrates risk: a single breach can cascade across many parties. The more sensitive and the more voluminous the data, the greater the potential cost of notifying people, managing the fallout and handling third-party claims — and the higher the exposure the insurer is pricing. For how this changes round by round, see insurance as your company scales.
This is also where UK data-protection law sits in the background. Under the UK GDPR and the Data Protection Act 2018, you have obligations around personal data, and a serious breach may need to be reported to the Information Commissioner's Office (ICO). A common misconception is that cyber insurance simply "pays your fine" if the ICO takes action. It does not work that cleanly: the insurability of regulatory fines under UK law is legally uncertain and is often excluded or restricted. What good cyber cover reliably funds is the response — the breach-management costs, legal and forensic support, notification, and any third-party liability — rather than a guaranteed payment of a regulatory penalty. It is an important distinction to be clear-eyed about.
Do my security controls really change the premium?
Yes — and this is the factor most within your control. Over the past few years the cyber market has hardened its expectations, and insurers now treat a baseline set of controls as close to non-negotiable. Firms that can demonstrate them tend to secure broader cover on better terms; firms that can't may find cover limited, loaded, or hard to place at all.
The controls underwriters ask about most often include:
- Multi-factor authentication (MFA) on email, remote access and privileged accounts — often a genuine deal-breaker if absent.
- Backups that are regular, tested, and held separately (ideally offline or immutable) so ransomware can't encrypt them too.
- Patching and vulnerability management — keeping systems, especially internet-facing ones, up to date within sensible timeframes.
- Endpoint detection and response and up-to-date protection across devices.
- Access management — least-privilege permissions, prompt offboarding of leavers, and control over admin rights.
- Staff awareness around phishing and social engineering, which remain a leading route in.
For a technology firm this is usually familiar territory — you may already run tighter security than most of your clients. The value is in evidencing it clearly on your proposal, because underwriters price what they can see. As a broker, part of our job is helping you present those controls in the way underwriters weigh them, so you get credit for the work you've already done. If you're weighing this against your professional-services exposure too, our note on professional indemnity vs cyber insurance for tech companies is a useful companion read.
Not sure how your controls would look to an underwriter? Talk it through with an Apex technology specialist and we'll help you present your risk in its best light.
Get a tailored quote →How do revenue, size and sector feed into the cost?
Revenue is a proxy for scale of exposure. A larger turnover usually means more data, more clients, more systems and a bigger potential loss if operations stop — so it tends to correlate with higher premiums and, often, a need for higher limits. But size alone doesn't tell the story: a lean SaaS business handling sensitive data for enterprise clients can carry more concentrated risk than a larger firm doing lower-stakes work.
Sector and the kind of technology work you do matter too. A firm building payment systems, handling health data, or providing critical infrastructure to regulated clients presents a different profile from a web design studio. Dependency on your own systems also counts: if a day of downtime would halt your revenue and your clients' operations, business interruption exposure — a core part of what cyber cover funds — rises accordingly. Your client base plays in as well; contracts with large or regulated customers often bring stricter security and cover expectations, which shapes both what you need and how you're rated.
Does my claims and incident history matter?
It does. Underwriters will ask whether you've had prior incidents, breaches, ransomware events or claims, and how you handled them. A clean record helps. But a past incident isn't automatically a black mark — what insurers really want to see is what you learned and changed. A firm that suffered a phishing compromise, then rolled out MFA across the board, tightened access and improved monitoring, can often present a stronger risk than one that has never been tested and can't show the same maturity.
Honesty here is essential. Cyber proposals rely on you disclosing known incidents and vulnerabilities accurately. Getting this wrong — or leaving things out — can jeopardise a claim later, which defeats the entire purpose of the cover. If you're unsure how to frame a previous incident, that's a conversation to have with your broker rather than a box to gloss over.
How do the limits and cover I choose change the price?
Finally, the cover itself. The limit of indemnity — the maximum the policy will pay — is a direct lever on cost. Illustrative options such as £1m, £5m or £10m are common starting points, and the right figure depends on the size of the losses you could realistically face, the value of the contracts you hold, and any minimum limits your clients require of you. Higher limits mean more premium, but under-insuring to save money can leave a damaging gap exactly when you need the cover most.
Beyond the headline limit, the breadth of cover shapes the price: whether you include business interruption and system failure, the strength of the incident-response and breach-management service, cover for social engineering and cyber crime, and any sub-limits or excesses. Cyber is often bought alongside tech PI, and many firms find a combined technology insurance package covering tech PI and cyber gives cleaner cover and avoids arguments over which policy responds. Worth remembering: technology professional indemnity and technology errors & omissions (E&O) are broadly the same cover — "E&O" is simply the American term for it — so don't be confused into thinking they're separate products you need both of.
Which UK business covers are compulsory, and on what authority
Cyber cover is bought by choice rather than by statute, unlike one of the covers in the table below.
| Cover | Compulsory in the UK? | Statutory minimum | Authority |
|---|---|---|---|
| Employers' liability | Yes, for most employers | £5m for any one occurrence, including costs and expenses | Employers' Liability (Compulsory Insurance) Regulations 1998, reg 3 |
| Professional indemnity | Not by general statute, but mandatory under several regulators | Set by the regulator — for example £2m or £3m under the SRA Minimum Terms, £250,000 under ARB guidance | SRA Minimum Terms and Conditions; ARB PII Guidance |
| Public liability | Not compulsory as a matter of general law | None | No general statutory requirement |
| Directors and officers | Not compulsory | None | Companies Act 2006 s.233 permits a company to purchase and maintain insurance for a director |
| Cyber | Not compulsory | None | No general statutory requirement |
Sources: Employers’ Liability (Compulsory Insurance) Regulations 1998 reg 3 (legislation.gov.uk); Companies Act 2006 s.233 (legislation.gov.uk); SRA Minimum Terms and Conditions (sra.org.uk); ARB PII Guidance (arb.org.uk). Sector-specific statutory requirements may apply in addition.
A quick word on what cyber insurance is not
Because cost questions often arrive tangled up with other worries, two clarifications help. First, professional indemnity (and by extension tech PI) is almost never a statutory legal requirement for IT firms — it is a contractual one, demanded by clients, agencies or frameworks you work through. Cyber can sit in the same contractual requirement, so check what your customers actually stipulate before you settle on limits. Second, if you employ staff, Employers' Liability insurance is a legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969, with only narrow exceptions — that's a separate obligation from anything cyber-related.
And on a point that trips up a lot of contractors: insurance has no bearing whatsoever on your IR35 position. IR35 is a tax matter — the off-payroll working rules about your employment status for tax — and no policy changes or determines it. For your IR35 status, speak to a qualified accountant or tax adviser, not your insurer. For a broader map of what your business needs, our guide to what insurance an IT company needs pulls the pieces together.
So how do I get an accurate figure?
The only way to know what cyber insurance will cost your business is to have your specific risk assessed. That means sharing your revenue, the nature and volume of the data you handle, your security controls, your sector and client profile, any incident history, and the limits and cover you want. From there a broker can approach the right insurers and shape terms around your actual risk rather than a generic bracket — and, crucially, help you strengthen the parts of your profile that improve the offer. If you'd like to understand the underlying product first, our cyber insurance explained guide is a good place to start.
At Apex, technology firms are our focus, and we spend our days translating good security practice into better insurance terms. When you're ready, you can start a tailored quote online, or speak to one of our specialists if you'd rather talk it through — cyber cover is one of those areas where a short conversation often gets you to the right answer faster than a form.
Get cyber cover priced around your real risk — and your real defences — by a broker who works with technology firms every day.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
