FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Cyber insurance guide

Cyber insurance for UK businesses: what it covers and who needs it

Updated 29 September 2026

Cyber insurance is a business insurance policy that pays for the costs and claims that follow a cyber attack or data breach, subject to the policy terms. For a UK business it typically covers incident response, data restoration, business interruption, extortion demands such as ransomware, and claims and regulatory investigations after a data breach. It will not prevent an attack, as the National Cyber Security Centre (NCSC) notes, and cover for fines or ransom payments depends on the wording and the law.

In short

First-party cover pays your own costs: incident response, data restoration, business interruption and cyber extortion. Third-party cover pays claims from people whose data is exposed and, where insurable, the cost of dealing with regulators. All of it is subject to the policy terms. Fines are often uninsurable, and paying a ransom raises legal and sanctions issues. Cyber insurance works alongside professional indemnity insurance and good security such as Cyber Essentials, not instead of them.

What does cyber insurance typically cover?

Most policies split into first-party and third-party cover. Typical sections, all subject to the policy terms:

CoverWhat it typically pays for
First party: your own costs
Incident responseA breach helpline, IT forensics, legal advice and PR support.
Data restorationRestoring or recreating damaged or encrypted data and software.
Business interruptionLost income and extra costs while systems are down, usually after a waiting period.
Cyber extortionSpecialist help with a ransomware or data-leak threat. Any payment depends on the wording and the law.
Third party: claims against you
Data and privacy liabilityDefence costs and damages if people claim after their data is exposed.
Regulatory defenceLegal costs of a regulator’s investigation. Fines only where the wording includes them and the law allows.

The ICO, the UK’s data protection regulator, must be told of a reportable personal data breach as soon as possible and, where feasible, within 72 hours, so fast response matters. Some policies add cyber crime cover, but the NCSC warns that some exclude business email compromise losses. See fund-transfer fraud and what cyber insurance pays for.

Fines. Many fines cannot be insured. FCA rules, for example, bar insurance against FCA penalties, though defence costs can be insured. For other fines, including the ICO’s, it depends on the law, the facts and the wording, so do not assume a policy will pay. See data breach liability.

Ransoms. The UK government does not condone ransomware payments, and the Office of Financial Sanctions Implementation (OFSI) warns that paying anyone subject to an asset freeze breaches financial sanctions, a serious criminal offence. The government has also proposed banning payments by the public sector and regulated critical national infrastructure, and making other victims report an intended payment. So any reimbursement depends on the wording and the law. See ransomware and professional firms.

Who needs cyber insurance?

Any business that relies on email, cloud software, online payments or personal data has cyber exposure. In the government’s Cyber Security Breaches Survey 2025/26, 43% of UK businesses reported a breach or attack in the previous 12 months, rising to 65% of medium and 69% of large businesses. Phishing was the most common type, affecting 38% of businesses.

Most cyber cover sits inside wider policies: 47% of businesses had some cyber insurance, but only 10% had a specific cyber policy. Check what yours covers. See silent cyber and affirmative cover.

Cover matters most if an incident would stop you trading, you hold others’ data, or a contract asks for it. For example:

On the legal position, see is cyber insurance a legal requirement in the UK?

How is cyber insurance different from professional indemnity insurance?

Professional indemnity (PI) insurance covers claims that your advice or services were negligent. Cyber insurance covers the fallout of a cyber incident, including your own costs, which PI, as a liability policy, does not pay. Many PI wordings also exclude or limit cyber claims.

SituationCyber policyPI policy
Your own forensics, restoration and lost income after an attackTypically coveredTypically not covered
A client says your advice or work was negligentTypically not coveredTypically covered
A client claims after their data is exposed in your breachTypically coveredDepends on the wording
Your own money is paid to a fraudster after an email account is hackedOnly with cyber crime coverTypically not covered

Check both wordings together: see cyber cover versus PI and combining cyber and PI.

Do you need Cyber Essentials to get cyber insurance?

Not as a rule. Cyber Essentials is the government-recommended minimum standard, built on five technical controls. It is a certification, not insurance. Insurers set their own requirements, but the NCSC says some offer discounts where it is in place, so tell your broker. It does not guarantee cover, a discount or better terms. See Cyber Essentials and cyber insurance.

What if a contract requires cyber insurance?

Check what the clause asks for: the type of cover (cyber, PI or both), the limit and whether it applies per claim or in total, how long cover must run after the contract ends, and what evidence is needed. Send the clause with your quote request, and raise anything you cannot meet before you sign. See a contract requires cyber insurance.

Some public contracts require certification instead: under PPN 014, central government and NHS bodies must make sure suppliers meet set technical requirements on contracts involving, for example, citizens’ personal data, and Cyber Essentials certification is named as the quickest route. That is not an insurance requirement.

What affects the cost of cyber insurance?

There is no standard price. Insurers usually weigh:

The NCSC notes that most policies are reassessed every 12 months. See how much cyber insurance costs in the UK.

How do you buy cyber insurance through a broker?

A broker takes your details to insurers and compares what each wording covers and excludes. The NCSC notes that a broker may help smaller organisations assess policies.

  1. Gather the facts: your activities, turnover, data, systems, IT providers and security controls.
  2. Answer accurately. The Insurance Act 2015 requires a fair presentation of the risk before the contract is made, and the NCSC warns that an insurer may not be obliged to pay claims if security measures you describe are not in place.
  3. Compare wordings, not just prices: exclusions, limits, sub-limits, waiting periods and incident support.
  4. Fit it to what you have: match any contract clause and check it against your PI and other insurance.
  5. Keep it current: tell your insurer about changes and review cover before each renewal.

How does Apex help?

Apex arranges cyber insurance. Start a quote online or call us. It helps to have details of your business, IT set-up and security controls, plus any contract insurance clause and your current insurance schedules. Any cover is subject to the policy terms.

Sources

Frequently asked

What does cyber insurance cover?

Subject to the policy terms, it typically pays for incident response, data restoration, business interruption, help with extortion threats and claims from people whose data is exposed. Fines and ransom payments are covered only where the wording and the law allow.

Does cyber insurance pay ransomware demands?

Not automatically. Extortion cover typically pays for specialist help, but paying a ransom raises legal and sanctions issues: paying anyone subject to UK financial sanctions is a serious criminal offence. Any reimbursement depends on the wording and the law.

Does cyber insurance cover ICO fines?

Do not assume so. Many fines cannot be insured; FCA rules, for example, bar insurance against FCA penalties. Whether an ICO fine could be covered depends on the law, the facts and the wording.

Do I need cyber insurance if I have professional indemnity insurance?

They do different jobs. PI covers claims that your professional work was negligent, not your own costs of recovering from an attack, and many PI wordings exclude or limit cyber claims. Cyber insurance fills that gap.

Does my existing business insurance cover cyber attacks?

It may, but check. The NCSC notes that business interruption or property policies may give some cover for cyber-related losses, or may specifically exclude them.

How much does cyber insurance cost?

There is no standard price. It depends on your activities, turnover, data, security controls, claims history and the limit and excess chosen. See our guide to cyber insurance costs in the UK.

Talk to us about cyber insurance

Apex arranges cyber insurance for UK businesses. Tell us how the business runs and we’ll look for suitable cover. Any cover is subject to the insurer’s acceptance and the policy terms. Or call 0117 325 0027.

Get a cyber quote Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.