Cyber insurance · UK · 2026
Short version: no single law forces you to buy it — but a growing stack of regulation and contracts effectively requires it, or the security behind it.
In short
There is no general law that makes a UK business buy cyber insurance. But several rules and commercial realities push hard in that direction: UK GDPR breach duties enforced by the ICO; Cyber Essentials, which many public-sector and larger contracts now demand (and which bundles £25,000 of cyber cover for smaller firms); PCI DSS if you take card payments; the NIS Regulations for essential-service and digital providers; and cyber clauses written into ordinary client contracts. Cyber insurance isn't mandatory — but for most businesses, going without it is now a regulatory and commercial risk rather than a saving.
| Requirement source | Who it applies to | What it actually means |
|---|---|---|
| UK GDPR / Data Protection Act 2018 (regulator: ICO) | Any organisation that handles personal data | A personal-data breach that poses a likely risk to people must be reported to the ICO within 72 hours. Maximum fines reach £17.5m or 4% of global annual turnover, whichever is higher. Insurance isn't compliance — but breach-response cover is standard. |
| Cyber Essentials / Cyber Essentials Plus (NCSC scheme, run by IASME) | Bidders for many government and enterprise contracts, and their supply chains | A government-backed certification, often contractually required to win work. Standard Cyber Essentials self-certification includes £25,000 of cyber liability cover for UK-domiciled organisations under £20m turnover that certify the whole organisation and opt in. |
| PCI DSS (card-scheme standard) | Any business that takes card payments | Contractual, not law — imposed via your acquirer/payment provider. Requires defined security controls; non-compliance and breach costs can flow back as scheme fines. |
| NIS Regulations 2018 (+ Cyber Security and Resilience Bill, before Parliament 2026) | Operators of essential services and relevant digital service providers | Security and incident-reporting duties enforced by sector regulators. The Cyber Security and Resilience Bill, progressing through Parliament in 2026, is set to widen who this covers. |
| Client & commercial contracts | Almost any supplier or contractor | Increasingly the real driver: contracts specify a required cyber limit and/or Cyber Essentials. Commonly requested limits run £1m–£5m. |
Figures are minimum standards and commonly-required limits, not price quotes.
No — there is no statutory duty to buy cyber insurance. What the law requires is that you protect personal data and report serious breaches; contracts and certification schemes are what most often make cover, in practice, unavoidable.
Often not reliably. Regulatory fines may be uninsurable as a matter of public policy, or excluded by the wording. Cyber policies typically respond to breach-response costs, defence costs and third-party liability rather than the fine itself.
Cyber Essentials certification includes £25,000 of cover for eligible smaller firms, which is useful but a low limit. Most businesses handling meaningful volumes of data, or bound by client contracts, need a higher standalone policy on top.
Not by general law — but it is frequently required to bid for public-sector work and is increasingly a condition in private supply chains.
PI covers claims that you gave negligent professional advice or work; cyber covers breaches, hacks, ransomware and the data-protection fallout. Technology firms usually need both.
There's no legal minimum. The right limit is driven by how much personal data you hold, your turnover, and what your contracts demand — commonly £1m–£5m.
Figures verified from primary sources, current at September 2026:
This page is general information, not legal or regulatory advice.
A named Apex broker will size a cyber policy to your data, turnover and client requirements.
Get a cyber quote → Request a callbackApex Insurance Brokers is authorised and regulated by the Financial Conduct Authority (FRN 724952).