Select Page

Data, systems and digital risk

Cyber Insurance

for UK organisations with data, systems and staff worth attacking

Cyber insurance is a UK business policy that pays what a cyber attack costs your organisation, from incident response to lost income, and what you owe others whose data or business was caught up in it. Any business that holds data or relies on its systems can buy it.

  • Ransomware, data breach and business interruption
  • Incident response from hour one
  • Thirteen UK sectors, plus anything else
  • FCA authorised and regulated

Quick answerCyber insurance pays the cost of an attack on your own organisation and what you owe the people whose data you lost. The part almost nobody checks is the sub-limits: extortion, network interruption and regulatory costs commonly sit far below the headline figure on the schedule, which is why two policies with the same limit can be worth very different amounts.

At a glance

Cyber Insurance at a Glance

Short answers to what UK organisations ask before they compare anything.

Cyber insurance quick answers
QuestionQuick answer
What does it actually pay for?The cost of responding to an attack on you, and what you owe the people and businesses affected by it.
Is it compulsory?No. No UK law requires it. It arrives through customer contracts, frameworks and, increasingly, procurement checklists.
What should I check first?The sub-limits. Extortion, network interruption and regulatory costs commonly sit well below the headline figure.
When does it respond?Both ways round. The liability half answers claims made against you; the rest answers incidents you discover while the policy is live.
Does it pay a ransom?Usually, with the insurer’s consent, up to a sub-limit that can be a fraction of a realistic demand.
Does it cover a data protection fine?Conditionally at best, and nobody has settled whether the law allows it. Compensation to the people affected is the part that is clearly insured.
What if my cloud provider goes down?Only if you bought the cover for it, and many wordings then carve out a regional or global outage.
What moves the price?Turnover, sector, how much personal data you hold, your security controls and your incident history.

The basics

What Is Cyber Insurance?

Cyber insurance does two jobs that have almost nothing to do with each other. It pays what an attack costs you directly, from the responders through to the income lost while you are down. And it pays what you owe everyone else whose data or business was caught up in it.

The reason it exists as a separate product is that the policies around it were built for physical events. A commercial combined policy needs damage to something you can touch before its business interruption section engages, and a general professional indemnity wording commonly excludes data protection claims by name. Neither was drafted with a ransomware note on a screen in mind. The property side of that is commercial property insurance.

What a policy has to do

  • An incident response team you can call at two in the morning
  • Your own trading losses as well as what you owe other people
  • Sub-limits you have actually read, not just a headline figure
  • Cover for the systems you depend on, not only the ones you own

Two halves, two triggers

What sits in each

  • Incident responseForensics, legal, PR, notificationYours
  • ExtortionNegotiation, and the payment itselfYours
  • Data and systemsRebuilding what was destroyedYours
  • Business interruptionIncome lost while you are downYours
  • Liability and regulatoryClaims from others, and the regulatorTheirs
The first four are your own losses. The last is what you owe everyone else

How it works

How Does Cyber Insurance Work?

You report the incident, an appointed response team takes over, and the policy pays your costs and what you owe others up to the relevant sub-limit. The liability half is claims-made; the rest responds to incidents discovered while the policy runs.

  1. You call the number, not your broker

    Almost every wording routes you to an incident response line first, and costs you run up with your own firm before you ring are usually not recoverable. Ring the number first. The consequence is normally those costs rather than the whole claim, but it is an avoidable argument.

  2. Two different triggers are running

    The liability half answers claims made against you during the policy year. Everything else answers incidents you first discover while it is live. That is why a lapse in cover bites differently on each half.

  3. The sub-limits decide the outcome

    The headline figure is not the number that answers. Extortion, network interruption and regulatory costs each have their own cap underneath it, and that cap is what you actually have.

The waiting period is the other number worth finding. Business interruption cover often does not start until you have been down for a stated number of hours, so a serious but short outage can sit entirely inside the retention and pay nothing at all.

What it covers

What Does Cyber Insurance Cover?

Incident response, extortion, rebuilding your data and systems, and the income you lose while you are down, plus what you owe customers, suppliers and the people whose data was exposed, and the cost of dealing with the regulator.

Incident response

The first call, and usually the most valuable part of the policy: forensics, legal advice, notification and public relations, from an appointed panel that has done it before.

Extortion

Negotiation, and the payment itself where the insurer consents. Check the sub-limit, because it is commonly one of the smallest figures on the schedule.

Data and system restoration

Rebuilding what was encrypted, corrupted or destroyed. Note that it restores what you had, not an upgrade to what you wish you had.

Business interruption

Income lost while you are down, after a waiting period, and usually a contribution to the extra costs of working around the problem.

Liability to others

Claims from customers, suppliers and the people whose data was exposed. In a large breach this is frequently the biggest number in the file, and it is separate from professional indemnity insurance.

Regulatory costs

Responding to the regulator, which is covered, and any fine, which is covered conditionally at best because nobody has settled whether the law permits it.

Worth asking about by name

Payment card exposure

If you take cards, the amounts after a breach are not fines at all but contractual liabilities to your acquirer. Insurers treat them quite differently.

Somebody else going down

Cover for an outage at a provider you depend on. It lives only here, not in your commercial combined policy, and it varies enormously.

Non-malicious failure

Some wordings also answer an outage caused by your own systems failing rather than by an attack. Others do not, and it is not always obvious which.

Exclusions

What Isn’t Covered by Cyber Insurance?

It will not fund the security upgrade the incident proved you needed, it reaches fines only conditionally, and a systemic outage is often carved out even where a single provider failure is covered. Wordings differ sharply.

Upgrading what you should have fixed

It restores the system you had. The security improvements the incident proves you needed are a capital project, not a claim.

Fines, in several cases

Cover is conditional on the law allowing it, and nobody has decided whether it does. A firm regulated by the FCA additionally cannot insure a penalty imposed on it by the FCA, though that restriction is about its own regulator rather than about a data protection fine.

Infrastructure failing at scale

Many wordings that cover one provider going down then exclude a failure of core internet, telecoms or satellite infrastructure causing a regional or global outage.

Anything you already knew about

A vulnerability or incident you were aware of before the policy started is excluded, in the same way as on any claims-made cover such as professional indemnity.

Your own people, in some cases

Extortion by an employee is excluded on some wordings. Deliberate or dishonest acts are excluded generally, usually only once a court has actually found them proved, and most wordings keep cover running for everyone else in the business.

The one that catches people out is the ordinary business interruption section of their main policy. It needs sudden, accidental, physical damage to property before it engages, and it commonly excludes cyber causes on top of that. An outage is neither physical nor damage, so if the cover is anywhere, it is here.

Sectors

Which Sectors Buy Cyber Cover?

Professional and financial services, legal and accountancy, healthcare, retail and e-commerce, manufacturing and engineering, technology, education, logistics, hospitality, property and construction, charities and the public sector.

Professional and financial services

Client money, client data and a regulator, which is the combination underwriters price most carefully.

Legal and accountancy practices

Holding the most sensitive documents their clients own, and a favourite target for payment redirection fraud.

See professional indemnity

Healthcare and medical

Special category data, where a breach reaches the most protected class of personal information there is.

Retail and e-commerce

Card data, high transaction volumes, and exposure to the payment schemes as well as to the regulator.

Manufacturing and engineering

Where an attack stops a production line rather than an office, and the operational technology is often older than the IT.

See engineering insurance

Technology, software and SaaS

Running other people systems, which concentrates both the attack surface and the liability.

See technology insurance

Education and training

Large numbers of records, thin security budgets, and a sector repeatedly targeted in recent years.

Logistics, transport and warehousing

Where downtime is measured in stock that did not move, and systems run around the clock.

Hospitality and leisure, property and construction, charities and the public sector are all on the list too. What actually sets the price is not the sector name but three things inside it: how much personal data you hold, how much of your revenue stops if the systems do, and what you can evidence about your controls. Construction and property sit with construction company insurance for the rest of their cover.

Who it’s for

Who Needs Cyber Insurance?

UK organisations that hold personal data, take payments, depend on systems to trade, or are being asked for cover in tenders. It is written for organisations with an IT estate and staff rather than for sole traders.

Anyone holding personal data at volume

A breach reaches the people in the dataset as well as the regulator, and those claims are the clearly insured half.

Businesses that stop earning when systems stop

If a day of downtime has a number attached to it, the business interruption section is the one to read first.

Organisations taking card payments

The exposure after a card breach runs through your acquirer rather than the regulator, and it is priced and covered differently.

Anyone dependent on a handful of providers

If your operation stops when somebody else has a bad day, that is the cover to ask about by name.

Employers with staff who can be tricked

Most incidents still start with a person, not a firewall, which is why underwriters ask about training as well as technology.

Firms being asked for it in tenders

Cyber cover and a recognised security certification now appear together on procurement checklists, often alongside professional indemnity and public liability limits.

The Government’s own Cyber Security Breaches Survey, published in April 2026 from a random probability sample of 2,112 UK businesses, found that 43 per cent had experienced a breach or attack in the previous twelve months. In the information and communication sector it was 63 per cent, which is why technology companies buy this alongside everything else.

The check almost nobody makes

What “We Have Cyber Cover” Usually Means

Nearly half of UK businesses say they are insured against cyber risk in some way and about one in ten holds a policy written for it. Most of the difference is cover sitting inside another policy, under sub-limits far below the headline figure.

Where the real numbers sit on a cyber schedule
What it isWhat it pays forHow it is limited
The headline limitWhat the schedule leads withThe number everybody quotes
ExtortionNegotiation and any paymentCapped separately, and sometimes very low
Network interruptionIncome lost while you are downCapped separately, behind a waiting period
Regulatory costsDealing with the regulator, and any fineCapped separately, and conditional on the law
Payment card amountsWhat your acquirer charges backSometimes shares the regulatory cap
Dependent outageA provider you rely on going downOften absent, and carved out for systemic events

Those figures are not theoretical. In the UK wordings we read, one capped ransom payments at £25,000, one capped network interruption at £50,000 behind a 24-hour waiting period, and one capped regulatory investigations, fines and payment card amounts together at £100,000. Waiting periods of eight to twelve hours are more usual, which is why a twenty-four hour one is worth arguing about. Ask for the sub-limits in writing before you compare anything else, and note that where the cover sits inside a wider commercial combined policy they are usually smaller again.

Pricing

How Much Does Cyber Insurance Cost?

Nobody can price it from the sector name. The rating follows turnover and how much of it depends on systems, the personal data and card payments you handle, what you can evidence about your controls, and your incident history.

What the organisation is

  • TurnoverAnd how much of it runs through systems.
  • SectorAnd whether it is a current target.
  • HeadcountEveryone who can click something.
  • TerritoriesWhere your data subjects are.

What you hold

  • Personal dataVolume, and how sensitive it is.
  • Card paymentsWhether you take them, and how.
  • Critical systemsWhat stops if they stop.
  • Third-party accessWho else is inside your estate.

What you can evidence

  • Multi-factor authenticationEverywhere, or nearly everywhere.
  • BackupsTested restores, not just backups.
  • Patching and endpoint coverHow fast, and how complete.
  • Incident historyIncluding the near misses.

No premium figures appear here. Nobody publishes average UK cyber premiums, so the numbers circulating come from individual brokers describing the customers they happen to write. Rate movement is published, and it has been falling: market commentary through 2026 described abundant capacity and softening terms for well-managed risks. That is not a price for your business, but it does make this a better year to argue about cover than about cost. The drivers behind a related class are in our guide to professional indemnity costs.

Before you start

What Do I Need for a Cyber Insurance Quote?

Turnover and system dependency, headcount, the personal data and card payments you handle, the providers you rely on, what you can evidence about controls, and five years of incidents including the ones that came to nothing.

About the organisation

  • Turnover, and how much depends on systems
  • Headcount including contractors
  • Where your customers and data subjects are
  • Any incidents in the last five years, including near misses

About your data and systems

  • Roughly how many personal records you hold
  • Whether any of it is special category data
  • Whether you take card payments, and how
  • Which providers you could not trade without

About your controls

  • Multi-factor authentication coverage
  • Backup regime, and when you last tested a restore
  • Patching cadence and endpoint protection
  • Any security certification you hold

The controls column is the one that moves the price. Underwriters ask about multi-factor authentication and tested backups because those two are what most often decide whether an incident becomes a claim.

Compare with MyMoneyComparison.com

How to Compare Cyber Insurance Quotes

Get the sub-limits in writing, find the waiting period on business interruption, and ask who the incident response panel actually is. Those three separate two quotes far more than the headline limit does.

  1. Get the sub-limits in writing

    Extortion, network interruption and regulatory costs. Two policies with the same headline figure can differ by an order of magnitude underneath it.

  2. Find the waiting period

    Business interruption that starts after a stated number of hours down is a different product from one that starts after eight.

  3. Ask who answers the phone

    The incident response panel is most of the value. Ask who it is, how fast they engage, and what happens to costs if you bring in your own people.

Describe the organisation once and specialist UK brokers can come back to you. MyMoneyComparison.com is an introducer rather than a broker, so we do not sell the policy or recommend one. Our editorial policy sets out how we work, and our commercial combined guide explains how this sits with the rest of the cover.

Cutting costs

How Can I Reduce the Cost of Cyber Insurance?

Evidence multi-factor authentication, test a restore and say so, rehearse an incident plan, train your people and describe the estate accurately. Reviewing the retention helps once the sub-limits are right.

Evidence multi-factor authentication

Not that you have it, but where. Coverage across remote access, email and privileged accounts is what underwriters actually score.

Test a restore, then say so

Everybody has backups. Far fewer have restored from them recently, and that distinction is worth real money at renewal.

Have an incident plan you have rehearsed

A named decision-maker, a call list and a tested process. It shortens the incident, which is what the insurer is pricing.

Train the people, not just the network

Most incidents still start with somebody clicking something. Recorded, repeated training is a cheap thing to be able to show.

Describe the estate accurately

Under-describing what you hold gets rated cautiously. A clear picture of data, systems and dependencies usually prices better.

Review the retention

Carrying more of the smaller incidents yourself can bring the premium down, provided the sub-limits above it are worth having.

If the organisation also advises clients, the claim that your advice was wrong sits with professional indemnity insurance rather than here.

Jargon buster

Cyber Insurance Jargon, Explained

The words that decide a cyber claim, in plain English. There is a longer general list in our insurance jargon buster.

Sub-limit
A smaller cap sitting inside the headline limit and applying to one named cover.
Waiting period
The hours you must be down before business interruption cover starts paying.
Incident response panel
The forensics, legal and communications firms the insurer appoints. Costs outside it are often not recoverable.
First-party loss
What the incident costs you directly, as opposed to what you owe others.
Third-party liability
Claims brought against you by customers, suppliers or data subjects.
Dependent outage
Cover for a provider you rely on going down rather than your own systems.
Systemic event
A regional or global infrastructure failure, commonly carved out of the cover.
Non-malicious failure
An outage caused by your own systems breaking rather than by an attack.

Why MyMoneyComparison.com

Comparing Specialist Cyber Cover

MyMoneyComparison.com is an FCA-authorised UK comparison service that introduces companies to specialist brokers. We do not sell insurance and we do not give advice: the broker you choose arranges the policy. Comparing is free and there is no obligation.

1

Form for the whole company

Describe the organisation, what it holds and the limits it needs once, instead of repeating yourself to every broker in turn.

0

Advice given

We are an introducer, not a broker. We do not sell policies and we do not recommend one. Read our editorial policy.

FCA

Authorised and regulated

MyMoneyComparison.com Ltd appears on the FCA register under FRN 916241.

2013

Comparing since

A UK company since 2013, working with specialist brokers across the country.

Read our customer reviewsSee what people say about us on Trustpilot

FAQs

Cyber Insurance FAQs

The questions UK organisations ask most.

What is cyber insurance?

It is cover for what a cyber attack costs your own organisation and for what you owe everybody else affected by it. The first half pays incident response, extortion, rebuilding data and systems, and the income lost while you are down. The second pays claims from customers, suppliers and the people whose data was exposed, along with the cost of dealing with the regulator.

What does cyber insurance actually cover?

Incident response first, which is usually the most valuable part: forensics, legal advice, notification and public relations from a panel that has done it before. Then extortion, data and system restoration, business interruption after a waiting period, liability to other people, and regulatory costs. Each of those has its own cap underneath the headline limit.

Why do the sub-limits matter so much?

Because the headline figure is not the number that answers. In UK wordings we read, one capped ransom payments at £25,000, one capped network interruption at £50,000 behind a 24-hour waiting period, and one capped regulatory investigations, fines and card amounts together at £100,000. All three sat inside policies a buyer would describe as cyber cover.

Is cyber insurance a legal requirement?

No. No UK law requires an organisation to hold it. The requirement arrives through customer contracts, through public sector frameworks, and increasingly through procurement checklists that ask for cover and a recognised security certification together. There is no minimum and no default, which is why the sub-limits are worth reading rather than assuming.

Is it claims-made like professional indemnity?

Half of it. The liability sections answer claims first made against you during the policy year, in the same way as professional indemnity. The first-party sections respond instead to an incident you first discover while the policy is live. That matters at renewal, because letting cover lapse bites differently on each half.

Does cyber insurance pay a ransom?

Usually, up to the extortion sub-limit and with the insurer’s prior consent. The consent requirement is not bureaucracy. It is a criminal offence for an insurer to reimburse a payment it has reasonable cause to suspect went to terrorism, and sanctions law sits alongside, so the insurer needs control of the decision.

Is it legal to pay a ransom in the UK?

Paying is not in itself unlawful, but sanctions law sits around it and a payment to a designated person is a serious matter. Government guidance indicates that ransomware payments are unlikely to be considered appropriate for a licence, so there is no way to obtain advance permission. This is a decision to take with your insurer and your lawyers, not alone.

Has the UK banned ransom payments?

Not yet, and the distinction matters if you are in the public sector. The government has said it intends to go ahead with a ban on payments by public sector bodies and operators of critical national infrastructure, a duty to notify before paying, and mandatory incident reporting. It has not legislated, so none of it is law today. Separate cyber resilience legislation is before Parliament and has not received Royal Assent either. Worth checking where both have got to before you rely on this.

Does paying a ransom reduce a regulatory penalty?

No. The UK data protection regulator and the National Cyber Security Centre said jointly that paying attackers is not treated as reducing the risk to individuals and will not be counted as mitigation. What the regulator does recognise is understanding what happened, learning from it, reporting to the right bodies and following recognised guidance.

Does cyber insurance cover a data protection fine?

Conditionally at best. Wordings promise to pay a fine where it is insurable by law, or where it is legally permissible to insure against the payment. No English court has decided the point, and there is a long-standing legal principle against insuring your way out of a penalty, so the uncertainty sits with you rather than the insurer. Some professional indemnity wordings exclude fines outright with no such carve-back.

Can a regulated firm insure a fine?

Not one imposed by its own regulator. A firm authorised by the FCA is prohibited from insuring, or claiming on insurance for, a financial penalty the FCA imposes on it. That restriction is specifically about FCA penalties: a data protection fine sits in the same uncertain position for a regulated firm as for anyone else. What it can always insure is the cost of defending the enforcement action.

What about claims from the people whose data was exposed?

Those are ordinary civil liability and are insured under the third-party side of the policy as a matter of course. Keep them separate in your head from the fine, because the insurance position on each is completely different, and in a large breach the compensation can be the larger of the two numbers.

Are payment card penalties covered?

Usually yes, and they are not really penalties. After a card data breach what you face is a contractual liability to your acquiring bank under your merchant services agreement, covering scheme assessments, case management fees, fraud recoveries, card re-issuance and the forensic investigator you are required to appoint. Insurers cover that affirmatively where they will only conditionally cover a regulator’s fine.

What happens if my cloud provider goes down rather than me?

Only the cyber policy can help, and only if you bought the cover. Ordinary business interruption needs sudden, accidental, physical damage to property before it engages, and an outage is none of those things. The same section commonly excludes cyber causes as well, so both gates are shut.

Is cover for a provider outage standard?

It has become common rather than rare, but the spread is wide and that is where the money is. One wording wrote the cloud provider straight into the business interruption trigger. Another had no dependent cover at all, responding only where the insured’s own equipment was attacked, behind a waiting period and a sub-limit far below the headline.

What about a global outage rather than one provider?

Check for a systemic event carve-out. Several policies that do cover a single provider failing then exclude a failure of core internet, telecoms or satellite infrastructure causing a regional, countrywide or global outage, which is the scenario most people actually have in mind when they ask about cloud cover.

Does my existing business insurance already cover cyber?

Probably not in the way you think. Nearly half of UK businesses report being insured against cyber risk in some way, while about one in ten holds a policy written for it. Most of the difference is a limited extension sitting inside another policy, under sub-limits that were never meant to carry a serious incident.

Does professional indemnity cover a data breach?

Partly, and the line is worth getting right. Several general professional indemnity policies exclude breach of data protection law by name, but what they exclude is usually your own first-party cost. A client claim against you arising from the same breach often still stands, because compulsory wordings in some professions preserve civil liability. Technology wordings go further and insure personal data claims outright. The gap is the cost of responding, not the liability.

Are insurers excluding artificial intelligence?

Not in this market, on what UK wordings currently say. The movement in London has been towards affirmative AI cover with conditions rather than exclusion, and those conditions increasingly mean a sub-limit, which brings you back to the question this page opened on. The live issue is the opposite of exclusion: policies that say nothing about AI either way. Ask explicitly.

How much does cyber insurance cost?

We quote no figure, because nothing independent is published for UK cyber pricing and the averages in circulation come from individual brokers describing their own customers. Your number turns on turnover and system dependency, the data and payments you handle, what you can evidence about controls, and your incident history.

Do shops and online retailers need cyber insurance?

Any shop that takes card payments, runs an online store or keeps customer details holds what attackers go after. A cyber policy sits alongside the shop’s property and liability cover rather than replacing it. See our shop insurance page.

Do salons and small service businesses need cyber cover?

Often more than they expect. Online booking systems, client records and card terminals are all targets, and a locked booking system stops the day’s work. Cyber cover pays for the response and the lost income. See our salon insurance page.

Are restaurants and hotels exposed to cyber attacks?

Yes. Booking platforms, guest records and payment terminals make hospitality a common target, and an attack at a busy time can stop reservations altogether. See our restaurant insurance and hotel insurance pages.

Does a block of flats or managing agent need cyber cover?

A managing agent or residents’ company holding personal and bank details, and running service charge accounts, has the same data exposure as any business. The buildings policy covers physical damage, not data. See our block of flats insurance page.

Ready when you are

Compare Cyber Quotes

Tell us what the organisation does, what it holds and what stops if the systems do, and specialist UK brokers can come back with quotes. Free to use, with no obligation to buy.

  • Professional services through to the public sector
  • Ransomware, data breach and interruption
  • FCA authorised and regulated

Free to use · No obligation · UK brokers

About this page

This page sets out what cyber insurance does, how it is triggered, where its limits actually sit and what drives the price, for UK organisations with systems, staff and data rather than for sole traders. It is general information and not advice. Cyber wordings differ more than any other class we have looked at, so read your own schedule and take the questions raised here to your broker. For the claim that your advice was wrong see professional indemnity insurance, and for a technology business selling to other businesses see technology company insurance.

How we researched this page

  • Four current UK cyber wordings, including one written on a Lloyd’s basis, for the insuring clauses, the sub-limits and the systemic event carve-outs
  • A UK commercial combined wording, to establish what the ordinary business interruption section does and does not reach
  • The Government’s Cyber Security Breaches Survey, published April 2026 from a random probability sample of 2,112 UK businesses
  • The data protection regulator’s joint statement with the National Cyber Security Centre on ransom payments, and the Home Office response on ransomware reform
  • Published market commentary on UK cyber capacity and pricing through 2026

No example premiums appear here, because we could find no UK body collecting and publishing average premiums for this class, though rate movement is published and has been falling. Where wordings differ we say so rather than picking one and calling it the market. Four things in wide circulation are corrected on this page: that ordinary business interruption answers a cloud outage, that cyber insurance simply covers data protection fines, that the UK has banned ransom payments, and that paying a ransom reduces a regulatory penalty.