Cyber quote · UK businesses · Updated September 2026
What a cyber insurer asks before it quotes, what the policy actually pays for, how to choose a limit, and how Apex arranges cyber on its own or alongside professional indemnity.
Part of: Commercial insurance at Apex
In short
To quote cyber insurance, underwriters ask about turnover, how many individuals’ records you hold, whether multi-factor authentication is on email and remote access, how backups are separated from the network, whether every machine runs endpoint protection, how card payments are handled, and whether you have had an incident in the last five years. A cyber policy typically funds breach response (legal, forensic and PR specialists), business interruption, cyber extortion, third-party privacy liability and regulatory investigation costs. Apex Insurance Brokers, an independent Bristol broker established in 2009 and directly authorised by the FCA since 2016, arranges cyber on its own or alongside professional indemnity where contracts demand both, with a named broker and access to over 30 markets.
These are the questions on our own cyber proposal, and every market asks them in some form. Many insurers also scan your public-facing domain.
“Not yet” with a plan reads better than an answer that unravels at claim time; the Insurance Act 2015 duty of fair presentation applies.
Wordings differ, so this is the shape of the product rather than a promise about any one policy.
Under UK GDPR a personal-data breach likely to risk people’s rights must be reported to the ICO within 72 hours of your becoming aware of it (ICO guide to personal data breaches). The breach-response section is what makes that deadline workable.
There is no regulator’s minimum for cyber, so the limit is a judgement. What should drive it:
Our online cyber proposal offers £250,000, £500,000, £1m, £2m and £5m, or a figure of your own, and labels £1m as the most common choice, £2m as usual for data-heavy firms and £5m for contract-driven ones. If you are unsure, pick the nearest and we advise. For scale, the Cyber Essentials scheme’s included policy carries a £25,000 limit (iasme.co.uk), which IASME itself says could be inadequate for a serious incident.
Contracts in IT, consultancy and design often ask for both. Professional indemnity responds when a client claims your work or advice caused them a loss; cyber responds to your own incident — the breach response, the downtime, the extortion demand — and to the privacy claims that follow it. A client whose data you lost may have a claim under either, so the boundary between the two wordings has to be read, not assumed.
One presentation can go to insurers that write both lines. See the broker pages for IT consultants and management consultants, and PI, cyber or commercial combined.
The headline prices are real. Read the basis first.
Direct is usually fine when you are a one-person business or a very small firm, you hold under 1,000 individuals’ records, no card payments touch your own systems, no contract names a limit, you have had no incident, and a modest limit will do. The online policies above are priced for that business, and at that level one is a sensible buy.
A broker earns their place when you have staff, remote access and a client database, card payments run through your systems, a contract names a £1m limit, you are an MSP or IT-services firm with access to client systems, cyber has to fit alongside professional indemnity, or you have had an incident or a decline. Insurance Premium Tax is charged at 12% on general insurance premiums; when you compare figures from different sources, check whether each is shown before or after IPT. Premium drivers are on what cyber insurance costs in the UK.
Apex Insurance Brokers is an independent insurance broker established in 2009 and based in Bristol, owned entirely by its directors and directly authorised by the FCA since 2016, placing professional indemnity insurance for professional firms, and cyber cover alongside it, across the UK. It is one of the longest-established independently owned professional indemnity specialists in the UK, and it is not for sale: we have declined approaches to buy the firm. We are not tied to any single insurer or professional-body scheme, we do not run our own policy or underwriting, and we have no placement quotas. We have access to over 30 markets, including Lloyd’s syndicates via wholesale, and we usually return three or four competing quotes set out so you can compare them like for like. Every client has a named broker — the same person from first quote to renewal — and every claim notification gets director-level attention rather than a call-centre queue.
It depends on turnover, the records you hold, your controls (MFA, backups, endpoint protection), card handling, incident history and the limit. The online from-prices describe very small businesses: PolicyBee’s £11.11 a month is £100,000 of cover for a virtual assistant earning up to £50,000; Hiscox’s £7.20 is a business-insurance-wide figure, not a cyber price; Markel Direct’s £5 a month is for a turnover under £25,000 and a £50,000 limit (markeluk.com, checked 6 September 2026).
Turnover and staff numbers, how many individuals’ records you hold and whether any are sensitive, how card payments are processed, who runs your IT, and honest answers on MFA, backups, patching, endpoint protection and payment verification. Then any incidents in the last five years, any ICO contact and any previous cyber policy.
No. Insurers ask about the controls themselves — MFA, separated backups, patching, endpoint protection — rather than the certificate. Cyber Essentials is a good way to put those controls in place and evidence them; certified UK organisations under £20m turnover can also opt in to the £25,000-limit policy that comes with it.
If you hold client or customer data, take card payments, rely on email to run, or hold credentials for anyone else’s systems, the exposure is real and the response costs arrive in the first 72 hours, while the ICO clock is running. The most useful part is often the panel of lawyers, forensic IT and PR who have handled the same thing before.
Cyber extortion sections can fund negotiation, specialist advice and, where lawful and appropriate, a payment. Payment can be blocked by UK sanctions rules, and no insurer will fund one that would breach them. The more valuable parts are the negotiators and the restoration cover; separated, tested backups decide whether you pay at all.
Usually only a sliver, if that. PI responds to a client’s claim that your work or advice caused them a loss. It does not fund your own breach response, downtime or an extortion demand, and many PI wordings now carry a cyber exclusion. Where a client’s data is lost, either policy might be engaged, so the two wordings should be read together.
Yes. Insurers ask what happened, what it cost and, above all, what changed afterwards. A business that has had an incident and now runs MFA everywhere, separated backups and a tested restore is often a better risk on paper than one that has never been tested. Disclose it fully: an undisclosed incident puts the whole policy at risk.
Only where the law allows a fine to be insured, and the position on UK GDPR penalties is unsettled; do not buy the policy for that. What it reliably pays is the cost of dealing with the regulator — investigation, legal representation, notification — and the third-party claims that can follow.
Pick Cyber on the quote page, or send us your current documents through the commercial proposal. A named broker reads every submission. Or call 0117 325 0027.
Get a cyber quote Start the commercial proposal formApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms. Third-party prices quoted are those providers’ own advertised figures on the dates stated, shown with the basis each provider publishes; they are not quotes and not typical premiums.