Cyber insurance cost · Updated September 2026
Advertised cyber cover starts at about £5 to £11 a month in the UK, but those prices belong to the entry tier at the smallest limits — for a business with real turnover, customer data and a limit that matches its exposure, the premium is set by underwriting on turnover, data, sector and security controls, not by a rate card.
Part of: Commercial insurance at Apex
In short
Cyber insurance in the UK is advertised from £5 a month (Markel Direct: turnover under £25,000, £50,000 limit), £10.79 a month (Superscript, no basis stated) and £11.11 a month for £100,000 of cover (PolicyBee: a virtual assistant earning up to £50,000, including 12% IPT), all checked on 6 September 2026. Those are entry prices for micro-businesses at limits that would not fund a serious incident. An established business is underwritten on turnover, the volume and sensitivity of its data, its sector, the security controls it can evidence (multi-factor authentication, tested backups, endpoint detection, patching), prior incidents, and the limit, sub-limits and business-interruption waiting period it chooses. Apex is an independent Bristol broker, established 2009, with access to over 30 markets including Lloyd’s, and usually returns three or four competing quotes set out like for like.
£5 a month
Markel Direct — its basis: turnover under £25,000 and a £50,000 cyber limit£10.79 a month
Superscript — in its page title; no basis stated£11.11 a month
PolicyBee, £100,000 limit — a virtual assistant earning up to £50,000, including 12% IPT£7.20 a month
Hiscox — on its cyber page, but footnoted as an average across all its business insurance policiesEvery one of those figures is real and every one is a floor: the least a very small business can pay for a small limit. They were checked on the providers’ own pages on 6 September 2026.
| Provider | Advertised price | Stated basis | Source |
|---|---|---|---|
| Markel Direct | from £5 a month | “based on a turnover under £25,000 a year and a £50,000 level of cyber insurance cover” | markeluk.com |
| Superscript | from £10.79 a month | Page title only; no basis, limit or period given | gosuperscript.com |
| PolicyBee | from £11.11 a month for £100,000 cover | “Based on a quote for a virtual assistant with an annual income of up to £50,000. All prices include IPT at 12%”; cybercrime cover is a separate add-on from £6.89 a month for £50,000 | policybee.co.uk |
| Hiscox | from £7.20 a month | “an average of all business insurance policies sold to at least 10% of our customer base between April 2025 and April 2026” — not a cyber-specific figure | hiscox.co.uk |
Unless a provider says otherwise, check whether its figure includes Insurance Premium Tax at 12%; any premium you are quoted will carry it. There is no neutral published average for UK cyber premiums that we could verify, so this page does not print one. The Government’s Cyber Security Breaches Survey 2025/26 (30 April 2026) shows how cover is held instead: 47% of UK businesses have some cyber insurance, but only 10% hold a standalone policy; 37% rely on cover inside a broader policy, usually a small sub-limit on an office or professional indemnity package. The same survey found 43% of businesses identified a breach or attack in the previous year.
The entry-tier price rests on a tiny turnover, a small aggregate limit (£50,000 to £100,000 above), a narrower set of covers and standard interruption terms. A real incident draws on all of the following, and each is paid from the same limit:
A £50,000 limit shared across that list can be consumed by the forensic and legal response alone. For a sole trader with a laptop and a few client emails the entry products may be exactly right; the from-price is a price for that business, not yours.
Cyber is underwritten, not read off a rate card. These factors decide which insurers will quote and at what rate; most are questions on every proposal form.
| Factor | Why it matters, and what you will be asked |
|---|---|
| Turnover | Proxy for the size of an interruption loss and the volume of records, and the rating base for most insurers. Last year’s and projected turnover, split by activity. |
| Data volume and type | Personal, card, health and financial data raise notification, liability and regulatory exposure. Records held; card payments; special-category data. |
| Industry | Professional services hold confidential client data and client money; healthcare holds special-category data; e-commerce processes cards; MSPs and IT firms hold access to client systems, which aggregates risk. |
| Security controls | MFA, backups, endpoint detection and patching decide whether an attack becomes a loss. MFA on email, remote access and privileged accounts; backup method and testing; EDR; patch cadence; end-of-life software. |
| Prior incidents | A previous breach, ransomware event or funds-transfer fraud, and what changed afterwards. |
| Limit and sub-limits | The aggregate limit, and the lower sub-limits that often apply to cybercrime, extortion, PCI and regulatory heads; any limit a contract requires. |
| Business-interruption terms | The waiting period before interruption cover starts and the indemnity period it runs for; dependence on cloud or outsourced providers. |
| Alongside PI or standalone | A cyber extension on a PI policy shares the PI limit and rarely has a breach-response panel; a standalone policy has its own limit and panel, and the two wordings must fit at the edges. |
None of these has a published price tag. They sort you into the insurers that will quote, the rate tier you land in, and the conditions attached — and the conditions can matter more than the premium.
A standalone UK cyber policy has a first-party side (your own losses) and a third-party side (claims against you). Wordings vary; this is the shape of the cover, not a promise about any policy.
Usually covered:
Usually not covered:
No insurer publishes a discount table for these, so we do not quantify them; they decide whether you are quoted, by whom and in which rate tier. The breaches survey found only 47% of UK businesses use two-factor authentication and 5% hold Cyber Essentials, so the basics still set you apart.
Be accurate about what you have. Under the Insurance Act 2015 you have a duty of fair presentation, and declared controls are often warranted; overstating them turns a paid claim into a disputed one.
Buying direct or online is fine if you are a sole trader or micro-business, hold little personal data, take no card payments, have no contract asking for a specific limit, have had no incident, and are content with a small limit. The entry products above exist for that buyer and the price is hard to beat.
Use a broker when a contract or client questionnaire specifies a limit or wording; when you hold volumes of personal, card or health data; when you are an MSP, software or IT services firm with access to client systems (see our MSP cyber page); when you trade online; when you have had an incident or been declined; when cyber and professional indemnity need to fit together; or when the online forms stop quoting once your turnover, data or sector goes in.
Comparison sites are built around packaged liability products: MoneySuperMarket states it “has a commercial partnership with Simply Business” and its business insurance prices are Simply Business data (moneysupermarket.com, reviewed 24 August 2026). That is one panel, and cyber is not what those journeys were designed around.
Apex Insurance Brokers is an independent insurance broker established in 2009 and based in Bristol, owned entirely by its directors and directly authorised by the FCA since 2016, placing professional indemnity insurance for professional firms and small businesses across the UK. It is one of the longest-established independently owned professional indemnity specialists in the UK, and it is not for sale: we have declined approaches to buy the firm. We are not tied to any single insurer or professional-body scheme, we do not run our own policy or underwriting, and we have no placement quotas. We have access to over 30 markets, including Lloyd’s syndicates via wholesale, and we usually return three or four competing quotes set out so you can compare them like for like. Every client has a named broker — the same person from first quote to renewal — and every claim notification gets director-level attention rather than a call-centre queue.
For cyber we ask the questions the underwriters ask before we approach anyone — turnover, records, controls, incidents and any contract wording you have to meet — because a well-presented risk gets better terms than a bare proposal form. Where you already hold professional indemnity with us, we read the two wordings together so a data claim from a client has one clear home. Start with the cyber insurance quote page, which lists what we need.
The lowest advertised UK prices on 6 September 2026 were Markel Direct’s from £5 a month (turnover under £25,000, £50,000 limit), Superscript’s from £10.79 a month (no basis stated) and PolicyBee’s from £11.11 a month for £100,000 (a virtual assistant earning up to £50,000, including IPT). Those are entry tiers; a business with staff, customer records and a limit sized to a real incident is underwritten on turnover, data, sector and controls.
We could not verify a neutral published UK average, so we do not print one; the from-prices in search results are smallest-limit figures, not averages. The Cyber Security Breaches Survey 2025/26 reports that 47% of businesses hold some cyber insurance and 10% a standalone policy, but publishes no premiums. Treat any “average” without a stated data source with caution.
Direct and online routes include Hiscox and Markel Direct (insurers) and PolicyBee and Superscript (digital brokers); AXA’s cyber page says AXA does not offer cyber insurance directly and refers customers to a partner broker, InSync Insurance. Through a broker you also reach the specialist cyber markets and Lloyd’s syndicates that do not sell online, where larger limits, MSP and e-commerce risks and post-incident cases are usually placed.
The Cyber Security Breaches Survey 2025/26 found 43% of UK businesses identified a breach or attack in the previous year. Whether the premium is worth paying depends on what an incident would cost you in downtime, restoration and notification, and whether you could fund that yourself. For many small firms the most valuable part is the breach-response panel: a forensic and legal team on the phone within hours.
Standalone policies normally include cyber extortion cover: negotiation, payment of a ransom where lawful and agreed by the insurer, and the restoration and interruption costs that follow. Check the sub-limit, the requirement to involve the insurer’s panel before paying anything, sanctions conditions, and any condition tied to backups or MFA. The survey put ransomware at 1% of UK businesses in 2025/26, but it remains the incident most likely to exhaust a small limit.
Premiums for insurance bought for the purposes of the business are normally an allowable expense under HMRC’s “wholly and exclusively” test; HMRC’s Business Income Manual covers insurance deductions from BIM45501 onwards. Cyber cover for a trading business will usually qualify. Confirm the treatment with your accountant, particularly if a policy also covers the owner’s personal devices or data.
Usually not. Professional indemnity responds to claims that your professional work caused a client a financial loss; it does not pay your own incident-response, ransom, restoration or interruption costs. Some PI policies add a cyber extension, typically with a modest sub-limit and no breach-response panel. If you hold both, the wordings need reading together so a client claim arising from a data incident has a clear home.
Start from what an incident would cost: days of downtime multiplied by daily gross profit, the records you would have to notify, and the client contract you could lose. Then check what your contracts require, because a specified limit is a specified limit. The entry products above are priced at £50,000 to £100,000; larger limits are available, mostly through brokers, who can show the price step between two limits.
Policies generally cover regulatory investigation and defence costs, and fines only “where insurable at law”. Whether a UK GDPR fine is insurable is unsettled: PolicyBee says its policy would not pay GDPR fines, and Superscript states GDPR penalties are uninsurable as a matter of public policy. The ICO’s higher maximum is £17.5 million or 4% of total worldwide annual turnover (ICO fining guidance). Buy cyber for the response, liability and interruption costs, not for fine cover.
At the entry tier, for a very small business, some online products do not ask. For any business with staff, remote access or meaningful data, most insurers now ask about MFA on email, remote access and privileged accounts before quoting; without it expect a decline, a higher rate, or an exclusion for losses MFA would have prevented. Putting MFA in place before you apply is the single change most likely to widen the choice of insurers.
Tell us your turnover, the data you hold and the controls you have in place, and a named broker will approach the markets that fit. Or call 0117 325 0027.
Get a cyber quote Start a commercial proposalApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms. Every premium figure on it is a third party’s own published figure, reproduced with the basis and date that provider states; none is an Apex quote or a typical price, and Apex holds no placement data for this class.