Cyber insurance for UK commercial businesses in 2026
Who this page is for
This is the general commercial page: manufacturers, wholesalers, professional firms, retailers, hauliers, care providers, construction businesses — organisations whose product is not software but whose operations now stop entirely when the systems do. If you are a technology business the emphasis shifts, and cyber insurance for scaling tech companies and cyber insurance explained deal with that. If you are pre-Series A, start at cyber insurance for startups.
The reason cyber has become a mainstream commercial purchase is straightforward. Most businesses now depend on a small number of systems they do not host, run payroll and payments through platforms they do not control, and hold personal data they are accountable for under UK law. None of that is a technology-sector characteristic any more.
What cyber insurance actually pays for
A modern cyber policy has two halves. First-party cover pays your own costs: incident response and specialist forensics, legal advice on your notification obligations, restoring or recreating data, business interruption while systems are down, extortion handling, and the cost of managing the reputational fallout. In most real incidents this is where the money goes.
Third-party cover pays what you owe other people: liability to customers and individuals whose data was affected, defence costs, and the cost of responding to a regulatory investigation. Note carefully that responding to an investigation and paying the outcome of one are different things — see the next section.
The practical value of a good policy is often the incident response panel rather than the indemnity. A business that has never handled a ransomware event does not know who to call at two in the morning; the policy does.
What it does not reliably pay: regulatory fines
This needs stating plainly, because it is widely misunderstood. Cyber insurance does not reliably pay UK GDPR or Data Protection Act 2018 penalties issued by the Information Commissioner’s Office. Whether a regulatory fine of that kind is insurable at all under English law is legally uncertain, and many wordings deal with the uncertainty by excluding fines and penalties outright or by covering them only “where insurable by law” — which is a phrase that decides nothing and defers everything.
What cyber cover does do dependably is fund the work around a regulatory event: legal advice on whether the incident is notifiable, preparing the notification, and defending or responding to the ICO’s investigation. Those costs are real and substantial. But no responsible broker should tell you the policy pays your fine, and any proposal that implies it should be questioned.
The corollary matters for buying decisions: the case for cyber cover rests on response costs, interruption and third-party liability, not on transferring a regulatory penalty you may not be able to transfer.
Controls: what underwriters expect before they quote
Cyber underwriting has hardened into something closer to a technical assessment than a proposal form. The controls insurers ask about most consistently are multi-factor authentication on remote access, email and privileged accounts; backups that are tested, versioned and held offline or otherwise separated from the main network; a patching regime with a defined timescale for critical vulnerabilities; endpoint detection and response rather than legacy antivirus alone; email filtering and user awareness training; restricted and monitored administrator privileges; and a written, exercised incident response plan.
Two practical points. First, these answers form part of the information the insurer relies on, so they need to be accurate rather than aspirational — an answer that overstates your position is a disclosure problem, not a technicality. Second, the gap between having a control and being able to evidence it is where placements stall. If you are going to be asked to prove MFA coverage, it is better to know that in advance.
Ransomware, payments and sanctions
Extortion cover typically funds negotiation, specialist advice and, where lawful and agreed, a payment. The constraint people forget is legal rather than commercial: making a payment to a sanctioned entity is prohibited, and insurers apply sanctions clauses that override the rest of the policy. Any payment decision therefore involves screening and legal advice, and no insurer can indemnify a payment that would itself be unlawful.
In practice most of the recovery money goes on restoration and interruption rather than on a payment, which is another reason backup quality dominates both the underwriting conversation and the outcome.
Interruption — yours and your suppliers’
Cyber business interruption works differently from the property-triggered kind. There is no physical damage, the waiting period is measured in hours rather than days, and the indemnity period is usually much shorter than a traditional BI policy would allow. Read those three numbers together: a long waiting period on a business that loses money by the hour makes the cover far less useful than the limit suggests. Our business interruption insurance page explains the damage-triggered version for comparison.
The bigger exposure for most commercial businesses is dependent or contingent interruption: your systems are fine, but your hosting provider, payment processor, ERP vendor or managed service provider has been compromised and you cannot trade. Whether that is covered, and for which suppliers, is a wording question with a real answer. If you rely on an outsourced IT provider, managed service provider insurance is worth reading alongside this.
The exclusions worth reading in 2026
War and state-backed attack. The most significant wording development of recent years. Cyber wordings now commonly carve out state-backed cyber operations, and the definitions and attribution mechanics vary between insurers. This is the clause to compare when comparing quotes.
Unsupported or end-of-life software. Many wordings restrict or exclude loss arising from systems the vendor no longer supports. If you are running legacy operational technology, this needs discussing rather than discovering.
Prior known circumstances. Anything you were aware of before inception is outside the cover. An unresolved intrusion you already know about is not insurable retrospectively.
Betterment. The policy restores you to your previous position, not to an improved one. Upgrading the estate during recovery is generally at your cost.
AI-related wording. Cyber and technology wordings increasingly address artificial intelligence explicitly, sometimes by exclusion and sometimes by definition. We cover the detail on cyber insurance and AI risks and AI exclusions and clauses in insurance policies.
Cyber is not professional indemnity
These two covers answer different questions and businesses routinely assume one does the other’s job. Cyber responds when your systems or your data are attacked. Professional indemnity or technology errors and omissions responds when a client alleges that your work or your product failed and caused them financial loss. A breach caused by your own service failure can trigger both, or neither, depending on how the two wordings are drafted — which is a strong argument for placing them together rather than separately. See technology errors and omissions insurance.
Directors also have their own exposure. Where a serious incident leads to allegations of inadequate oversight, that is a management liability question rather than a cyber one (directors’ and officers’ insurance explained).
How Apex approaches cyber
We start with how the business operates: what stops if the systems stop, which third parties you depend on, what data you hold and on whose behalf, and what your customers have contractually required. From that we can size the limit, set the waiting period and indemnity period sensibly, and identify the exclusions that would actually matter to you rather than the ones that read most alarmingly. We are Bristol-based and FCA-regulated, we read the war and dependency clauses properly, and we will tell you where the cover stops — including on fines. For larger or more unusual programmes, see complex commercial insurance.
Frequently asked questions
Does cyber insurance pay ICO fines under UK GDPR?
It should not be assumed to. Whether a regulatory penalty of that kind is insurable at all under English law is legally uncertain, and many cyber wordings either exclude fines and penalties or cover them only where insurable by law. What the policy does reliably fund is the legal and forensic work around a regulatory event — assessing notifiability, preparing the notification and responding to the investigation.
What controls do underwriters expect before they will quote?
Most consistently: multi-factor authentication on remote access, email and privileged accounts; tested backups held separately from the main network; a defined patching timescale for critical vulnerabilities; endpoint detection and response; controlled administrator privileges; and a written incident response plan. Answers form part of the information the insurer relies on, so they need to be accurate and evidenced rather than aspirational.
Will cyber insurance cover an outage at our cloud or IT provider?
Only if the policy includes dependent or contingent business interruption, and only within the terms it sets — which suppliers are captured, what waiting period applies and for how long. This is one of the biggest differences between wordings for businesses that outsource their IT, and it is worth checking rather than assuming.
Is cyber insurance the same as professional indemnity?
No. Cyber responds when your own systems or data are attacked. Professional indemnity or technology errors and omissions responds when a client alleges your work or product failed and cost them money. One incident can raise both questions, which is why the two wordings are better placed together so the boundary between them is deliberate rather than accidental.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
