What is cyber insurance, and does a small business really need it?
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-05
Most small firms assume cyber criminals only go after large corporations. In practice the opposite is often true: attackers favour smaller businesses precisely because their defences tend to be lighter. A single phishing email, a stolen laptop or a compromised supplier login can trigger costs that run well beyond what many owners expect. Cyber insurance exists to absorb those costs and, just as importantly, to put expert help on the phone within hours.
What cyber insurance actually covers
Cyber cover is usually split into two halves. First-party cover pays for the damage done to your own business. Third-party cover pays for claims made against you by other people — customers, suppliers or regulators — because of a breach. A good policy includes both, plus a 24/7 incident response service that co-ordinates IT forensics, legal advice and PR.
| First-party (your own losses) | Third-party (claims against you) |
|---|---|
| Restoring or rebuilding hacked systems and data | Compensation to customers whose data was exposed |
| Ransomware negotiation and, where lawful, extortion payments | Defence costs if you are investigated by the ICO |
| Lost income while you are unable to trade (business interruption) | Legal claims arising from a privacy or security failure |
| Notification and credit-monitoring costs after a breach | Liability where your systems pass malware to a client |
The costs it steps in for
The headline cost of an attack is rarely the ransom itself. It is the sprawl of expenses that follow. A typical incident can involve several of these at once:
- Breach response. IT forensics to find out what happened, contain it, and prove your systems are clean before you go back online. This specialist work is expensive and usually urgent.
- Ransomware. Whether you pay or not, you face the cost of rebuilding systems from backups, lost trading time, and negotiators who understand how these attacks work.
- Notification costs. Under the UK GDPR and the Data Protection Act 2018, a personal data breach that poses a risk to individuals must be reported to the Information Commissioner's Office (ICO) within 72 hours, and affected people may need to be told directly. Drafting notifications, running a helpline and offering credit monitoring all cost money.
- Regulatory exposure. The ICO can investigate and, in serious cases, impose penalties. Cyber policies can fund your legal defence and, where the law permits, cover certain fines.
- Business interruption. If your booking system, e-commerce site or client database is down for days, the lost revenue can dwarf the technical repair bill.
For a small firm without a dedicated IT team, the value of cyber cover often lies less in the payout and more in the response line — a single number that connects you to people who have handled hundreds of these incidents. The National Cyber Security Centre (NCSC) publishes free guidance and its Cyber Essentials scheme, both worth using alongside any policy.
Worried a breach could take your business offline? We compare cyber cover from UK insurers so you get the right limit at the right price.
Get a cyber quote →Am I too small to need it?
Almost certainly not. If you store customer names and addresses, take card payments, hold health or financial records, use cloud accounting, or simply rely on email to run the business, you have digital assets worth protecting. Sole traders and micro-businesses are frequently targeted through automated attacks that do not care how big you are. The question is rarely "am I a target" but "how would I cope with the bill and the disruption on my own".
A short gut check: could your business survive a week offline? Could you fund an emergency IT investigation out of cash flow? Do you know your legal duties if customer data leaks? If any answer is "no", cyber insurance is worth pricing. Limits are usually offered as generic tiers — for example £1m, £2m or £5m — and the right level depends on how much data you hold and how much income depends on your systems. Tell us about your business and we will suggest a sensible starting point.
Where cyber overlaps with professional indemnity
This is where many owners get caught out. Professional indemnity (PI) insurance covers claims that you gave negligent advice or delivered work that fell below a professional standard. Cyber insurance covers the technical, regulatory and privacy fallout of a security incident. They sound similar but they are not interchangeable.
The confusion arises because one event can touch both. Imagine a consultancy suffers a breach that exposes a client's confidential project files. The cost of the forensic clean-up, ICO notification and system recovery is a cyber matter. But if that client then sues, arguing you failed in your professional duty to keep their information safe, that allegation can stray into PI territory. Neither policy is designed to be a full substitute for the other:
- PI answers: did you do your professional job badly?
- Cyber answers: was your data or systems compromised, and what does it cost to put right?
Some PI policies include a narrow amount of data or cyber-related cover, but it is often capped and rarely includes the round-the-clock incident response, ransomware handling and notification support of a standalone cyber policy. If your work involves handling client data, it is worth checking exactly where one policy stops and the other should begin — a gap between the two is precisely where an uninsured loss hides.
Common questions
Does cyber insurance cover human error, not just hackers?
Usually yes. Most policies respond to accidental data loss and mistakes — an employee emailing a spreadsheet to the wrong person, or losing an unencrypted laptop — as well as deliberate attacks. Human error causes a large share of real-world breaches, so this cover matters.
Will insurers pay a ransomware demand?
Cover for extortion exists, but payment is a last resort and only where it is lawful to do so. Insurers focus first on recovering your systems from backups. Making a payment can be legally sensitive, which is one reason the included expert response team is so valuable.
Do I still need cyber cover if I use Cyber Essentials and strong IT security?
Good security reduces your risk and can make cover cheaper and easier to obtain, but no defence is perfect. Certification schemes like Cyber Essentials protect against common threats; insurance protects against the cost when something still gets through. The two work together, not instead of each other.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for your policy wording.
