What does cyber insurance actually pay for? A breach-cost breakdown
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-05
Most business owners picture cyber insurance as a cheque that lands after a hack. In practice, the money mostly goes on getting you back on your feet — hiring the specialists, lawyers and PR people you would otherwise have to source and pay for in the middle of a crisis. Below is what a typical UK cyber policy actually funds, cost head by cost head.
The core costs a cyber policy pays for
Cyber cover splits broadly into first-party costs (losses you incur directly) and third-party costs (claims made against you by others). A breach usually triggers several of the following at once.
| Cost head | What it covers |
|---|---|
| Incident response | A 24/7 breach team to coordinate the whole response from hour one. |
| IT forensics | Investigators who find how attackers got in, what they took, and how to remove them. |
| Legal & regulatory | Advice on your duties, and support if the ICO investigates. |
| Notification | Telling affected individuals, plus call-centre and monitoring costs. |
| Ransom & extortion | Specialist negotiation and, where lawful, ransom payment handling. |
| Business interruption | Lost income and extra costs while systems are down. |
| Third-party liability | Damages and defence if customers or partners sue you. |
Ransom: negotiation first, payment last
Ransomware locks or steals your data and demands payment. A cyber policy rarely just hands over a ransom. It funds a specialist extortion team who verify the threat, buy time, and negotiate — often reducing the demand substantially or recovering data another way. Where a payment is made, it is handled under strict legal checks, because paying certain sanctioned groups is unlawful in the UK. The cover also pays for the forensic clean-up afterwards, which is frequently the larger bill.
Forensics: finding out what actually happened
You cannot notify anyone, or safely reopen, until you know the scope of the breach. Forensic investigators image affected systems, trace the attacker's route, confirm what personal data was accessed, and certify that the intruder is out. This is skilled, expensive work — and it is one of the most valuable parts of a policy, because the breach team calls in trusted firms immediately rather than you scrambling for a supplier mid-crisis.
Notification and the regulator
Under the UK GDPR and the Data Protection Act 2018, a personal-data breach that poses a risk to individuals generally must be reported to the Information Commissioner's Office (ICO) within 72 hours, and affected people must be told where the risk is high. Cyber cover pays the legal advice on whether and how to report, the cost of contacting potentially thousands of customers, setting up a helpline, and providing credit or identity-monitoring services. It can also fund PR support to protect your reputation.
Cover contributes to defending an ICO investigation and associated legal costs. Note that regulatory fines themselves are often not insurable under UK law — a broker will confirm what a specific wording does and does not include.
Business interruption: the loss you can't see
When systems go down, so does income. Cyber business-interruption cover replaces the profit you lose while you cannot trade normally, plus the extra costs of working around the outage — overtime, temporary systems, expedited recovery. For many firms this is the single largest element of a claim, because a serious ransomware event can stop trading for days or weeks. Cover usually applies after a short waiting period and up to your chosen limit.
See what breach response and business-interruption cover would cost for your business.
Get a cyber insurance quote →Already have a current schedule? Email it to info@apexinsurancebrokers.co.uk and a named broker will come back to you.
Third-party liability: when others come after you
If a breach exposes a client's data, or a supplier's systems are hit through you, you may face claims for damages. Cyber cover funds your legal defence and any settlement or award, up to your limit. This is where the difference between first-party (your own costs) and third-party (others' claims) cover matters — a good policy carries both.
Putting the numbers in context
Cover limits are usually offered in tiers — commonly options such as £1m, £2m or £5m — and the right level depends on how much data you hold, your turnover, and how badly downtime would hurt. The point to grasp is that a single incident rarely produces one cost. A ransomware attack might simultaneously trigger forensics, a ransom negotiation, ICO notification, weeks of business interruption and a customer claim. That combination is exactly what the policy is built to absorb.
If you are unsure which limit fits, an Apex adviser can size it against your actual data exposure and revenue rather than a generic figure.
Common questions
Does cyber insurance pay the ransom directly?
It can, but only after specialist negotiation and legal checks, because paying certain sanctioned groups is unlawful in the UK. Most of the value is in negotiation, data recovery and clean-up rather than the payment itself.
Are ICO fines covered?
Regulatory fines are frequently not insurable under UK law, though the cover usually pays the legal costs of responding to and defending an ICO investigation. Your policy wording confirms the exact position.
What is usually the biggest part of a claim?
For many firms it is business interruption — the income lost and extra costs incurred while systems are offline — followed by forensic investigation and notification.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for your policy wording.
