FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Cyber insurance · UK · 2026

Is cyber insurance a legal requirement in the UK?

Short version: no single law forces you to buy it — but a growing stack of regulation and contracts effectively requires it, or the security behind it.

In short

There is no general law that makes a UK business buy cyber insurance. But several rules and commercial realities push hard in that direction: UK GDPR breach duties enforced by the ICO; Cyber Essentials, which many public-sector and larger contracts now demand (and which bundles £25,000 of cyber cover for smaller firms); PCI DSS if you take card payments; the NIS Regulations for essential-service and digital providers; and cyber clauses written into ordinary client contracts. Cyber insurance isn't mandatory — but for most businesses, going without it is now a regulatory and commercial risk rather than a saving.

What can require cyber cover — or the controls behind it

Requirement sourceWho it applies toWhat it actually means
UK GDPR / Data Protection Act 2018 (regulator: ICO)Any organisation that handles personal dataA personal-data breach that poses a likely risk to people must be reported to the ICO within 72 hours. Maximum fines reach £17.5m or 4% of global annual turnover, whichever is higher. Insurance isn't compliance — but breach-response cover is standard.
Cyber Essentials / Cyber Essentials Plus (NCSC scheme, run by IASME)Bidders for many government and enterprise contracts, and their supply chainsA government-backed certification, often contractually required to win work. Standard Cyber Essentials self-certification includes £25,000 of cyber liability cover for UK-domiciled organisations under £20m turnover that certify the whole organisation and opt in.
PCI DSS (card-scheme standard)Any business that takes card paymentsContractual, not law — imposed via your acquirer/payment provider. Requires defined security controls; non-compliance and breach costs can flow back as scheme fines.
NIS Regulations 2018 (+ Cyber Security and Resilience Bill, before Parliament 2026)Operators of essential services and relevant digital service providersSecurity and incident-reporting duties enforced by sector regulators. The Cyber Security and Resilience Bill, progressing through Parliament in 2026, is set to widen who this covers.
Client & commercial contractsAlmost any supplier or contractorIncreasingly the real driver: contracts specify a required cyber limit and/or Cyber Essentials. Commonly requested limits run £1m–£5m.

Figures are minimum standards and commonly-required limits, not price quotes.

Frequently asked

Is cyber insurance a legal requirement in the UK?

No — there is no statutory duty to buy cyber insurance. What the law requires is that you protect personal data and report serious breaches; contracts and certification schemes are what most often make cover, in practice, unavoidable.

Does cyber insurance pay ICO or GDPR fines?

Often not reliably. Regulatory fines may be uninsurable as a matter of public policy, or excluded by the wording. Cyber policies typically respond to breach-response costs, defence costs and third-party liability rather than the fine itself.

If I have Cyber Essentials, do I still need cyber insurance?

Cyber Essentials certification includes £25,000 of cover for eligible smaller firms, which is useful but a low limit. Most businesses handling meaningful volumes of data, or bound by client contracts, need a higher standalone policy on top.

Is Cyber Essentials itself mandatory?

Not by general law — but it is frequently required to bid for public-sector work and is increasingly a condition in private supply chains.

How is cyber insurance different from professional indemnity?

PI covers claims that you gave negligent professional advice or work; cyber covers breaches, hacks, ransomware and the data-protection fallout. Technology firms usually need both.

How much cyber cover does a business need?

There's no legal minimum. The right limit is driven by how much personal data you hold, your turnover, and what your contracts demand — commonly £1m–£5m.

Sources & method

Figures verified from primary sources, current at September 2026:

  • ICO — personal-data breach reporting (72 hours) and the UK GDPR / DPA 2018 fining ceiling (£17.5m or 4% of global turnover).
  • NCSC / IASME — Cyber Essentials scheme and the included cyber liability insurance terms.
  • PCI Security Standards Council — PCI DSS as a card-scheme contractual standard.
  • NIS Regulations 2018 and the Cyber Security and Resilience Bill (before Parliament, 2026).

This page is general information, not legal or regulatory advice.

Not sure what cyber cover your contracts actually need?

A named Apex broker will size a cyber policy to your data, turnover and client requirements.

Get a cyber quote → Request a callback

Apex Insurance Brokers is authorised and regulated by the Financial Conduct Authority (FRN 724952).