Data, systems and digital risk
Cyber Insurance
for UK organisations with data, systems and staff worth attacking
Cyber insurance is a UK business policy that pays what a cyber attack costs your organisation, from incident response to lost income, and what you owe others whose data or business was caught up in it. Any business that holds data or relies on its systems can buy it.
- Ransomware, data breach and business interruption
- Incident response from hour one
- Thirteen UK sectors, plus anything else
- FCA authorised and regulated
Quick answerCyber insurance pays the cost of an attack on your own organisation and what you owe the people whose data you lost. The part almost nobody checks is the sub-limits: extortion, network interruption and regulatory costs commonly sit far below the headline figure on the schedule, which is why two policies with the same limit can be worth very different amounts.
At a glance
Cyber Insurance at a Glance
Short answers to what UK organisations ask before they compare anything.
| Question | Quick answer |
|---|---|
| What does it actually pay for? | The cost of responding to an attack on you, and what you owe the people and businesses affected by it. |
| Is it compulsory? | No. No UK law requires it. It arrives through customer contracts, frameworks and, increasingly, procurement checklists. |
| What should I check first? | The sub-limits. Extortion, network interruption and regulatory costs commonly sit well below the headline figure. |
| When does it respond? | Both ways round. The liability half answers claims made against you; the rest answers incidents you discover while the policy is live. |
| Does it pay a ransom? | Usually, with the insurer’s consent, up to a sub-limit that can be a fraction of a realistic demand. |
| Does it cover a data protection fine? | Conditionally at best, and nobody has settled whether the law allows it. Compensation to the people affected is the part that is clearly insured. |
| What if my cloud provider goes down? | Only if you bought the cover for it, and many wordings then carve out a regional or global outage. |
| What moves the price? | Turnover, sector, how much personal data you hold, your security controls and your incident history. |
The basics
What Is Cyber Insurance?
Cyber insurance does two jobs that have almost nothing to do with each other. It pays what an attack costs you directly, from the responders through to the income lost while you are down. And it pays what you owe everyone else whose data or business was caught up in it.
The reason it exists as a separate product is that the policies around it were built for physical events. A commercial combined policy needs damage to something you can touch before its business interruption section engages, and a general professional indemnity wording commonly excludes data protection claims by name. Neither was drafted with a ransomware note on a screen in mind. The property side of that is commercial property insurance.
What a policy has to do
- An incident response team you can call at two in the morning
- Your own trading losses as well as what you owe other people
- Sub-limits you have actually read, not just a headline figure
- Cover for the systems you depend on, not only the ones you own
Two halves, two triggers
What sits in each
- Incident responseForensics, legal, PR, notificationYours
- ExtortionNegotiation, and the payment itselfYours
- Data and systemsRebuilding what was destroyedYours
- Business interruptionIncome lost while you are downYours
- Liability and regulatoryClaims from others, and the regulatorTheirs
How it works
How Does Cyber Insurance Work?
You report the incident, an appointed response team takes over, and the policy pays your costs and what you owe others up to the relevant sub-limit. The liability half is claims-made; the rest responds to incidents discovered while the policy runs.
You call the number, not your broker
Almost every wording routes you to an incident response line first, and costs you run up with your own firm before you ring are usually not recoverable. Ring the number first. The consequence is normally those costs rather than the whole claim, but it is an avoidable argument.
Two different triggers are running
The liability half answers claims made against you during the policy year. Everything else answers incidents you first discover while it is live. That is why a lapse in cover bites differently on each half.
The sub-limits decide the outcome
The headline figure is not the number that answers. Extortion, network interruption and regulatory costs each have their own cap underneath it, and that cap is what you actually have.
The waiting period is the other number worth finding. Business interruption cover often does not start until you have been down for a stated number of hours, so a serious but short outage can sit entirely inside the retention and pay nothing at all.
What it covers
What Does Cyber Insurance Cover?
Incident response, extortion, rebuilding your data and systems, and the income you lose while you are down, plus what you owe customers, suppliers and the people whose data was exposed, and the cost of dealing with the regulator.
Incident response
The first call, and usually the most valuable part of the policy: forensics, legal advice, notification and public relations, from an appointed panel that has done it before.
Extortion
Negotiation, and the payment itself where the insurer consents. Check the sub-limit, because it is commonly one of the smallest figures on the schedule.
Data and system restoration
Rebuilding what was encrypted, corrupted or destroyed. Note that it restores what you had, not an upgrade to what you wish you had.
Business interruption
Income lost while you are down, after a waiting period, and usually a contribution to the extra costs of working around the problem.
Liability to others
Claims from customers, suppliers and the people whose data was exposed. In a large breach this is frequently the biggest number in the file, and it is separate from professional indemnity insurance.
Regulatory costs
Responding to the regulator, which is covered, and any fine, which is covered conditionally at best because nobody has settled whether the law permits it.
Worth asking about by name
Payment card exposure
If you take cards, the amounts after a breach are not fines at all but contractual liabilities to your acquirer. Insurers treat them quite differently.
Somebody else going down
Cover for an outage at a provider you depend on. It lives only here, not in your commercial combined policy, and it varies enormously.
Non-malicious failure
Some wordings also answer an outage caused by your own systems failing rather than by an attack. Others do not, and it is not always obvious which.
Exclusions
What Isn’t Covered by Cyber Insurance?
It will not fund the security upgrade the incident proved you needed, it reaches fines only conditionally, and a systemic outage is often carved out even where a single provider failure is covered. Wordings differ sharply.
Upgrading what you should have fixed
It restores the system you had. The security improvements the incident proves you needed are a capital project, not a claim.
Fines, in several cases
Cover is conditional on the law allowing it, and nobody has decided whether it does. A firm regulated by the FCA additionally cannot insure a penalty imposed on it by the FCA, though that restriction is about its own regulator rather than about a data protection fine.
Infrastructure failing at scale
Many wordings that cover one provider going down then exclude a failure of core internet, telecoms or satellite infrastructure causing a regional or global outage.
Anything you already knew about
A vulnerability or incident you were aware of before the policy started is excluded, in the same way as on any claims-made cover such as professional indemnity.
Physical damage
Property damaged in the course of an attack belongs to your commercial property insurance or your office insurance, not here.
Your own people, in some cases
Extortion by an employee is excluded on some wordings. Deliberate or dishonest acts are excluded generally, usually only once a court has actually found them proved, and most wordings keep cover running for everyone else in the business.
The one that catches people out is the ordinary business interruption section of their main policy. It needs sudden, accidental, physical damage to property before it engages, and it commonly excludes cyber causes on top of that. An outage is neither physical nor damage, so if the cover is anywhere, it is here.
Sectors
Which Sectors Buy Cyber Cover?
Professional and financial services, legal and accountancy, healthcare, retail and e-commerce, manufacturing and engineering, technology, education, logistics, hospitality, property and construction, charities and the public sector.
Professional and financial services
Client money, client data and a regulator, which is the combination underwriters price most carefully.
Legal and accountancy practices
Holding the most sensitive documents their clients own, and a favourite target for payment redirection fraud.
See professional indemnityHealthcare and medical
Special category data, where a breach reaches the most protected class of personal information there is.
Retail and e-commerce
Card data, high transaction volumes, and exposure to the payment schemes as well as to the regulator.
Manufacturing and engineering
Where an attack stops a production line rather than an office, and the operational technology is often older than the IT.
See engineering insuranceTechnology, software and SaaS
Running other people systems, which concentrates both the attack surface and the liability.
See technology insuranceEducation and training
Large numbers of records, thin security budgets, and a sector repeatedly targeted in recent years.
Logistics, transport and warehousing
Where downtime is measured in stock that did not move, and systems run around the clock.
Hospitality and leisure, property and construction, charities and the public sector are all on the list too. What actually sets the price is not the sector name but three things inside it: how much personal data you hold, how much of your revenue stops if the systems do, and what you can evidence about your controls. Construction and property sit with construction company insurance for the rest of their cover.
Who it’s for
Who Needs Cyber Insurance?
UK organisations that hold personal data, take payments, depend on systems to trade, or are being asked for cover in tenders. It is written for organisations with an IT estate and staff rather than for sole traders.
Anyone holding personal data at volume
A breach reaches the people in the dataset as well as the regulator, and those claims are the clearly insured half.
Businesses that stop earning when systems stop
If a day of downtime has a number attached to it, the business interruption section is the one to read first.
Organisations taking card payments
The exposure after a card breach runs through your acquirer rather than the regulator, and it is priced and covered differently.
Anyone dependent on a handful of providers
If your operation stops when somebody else has a bad day, that is the cover to ask about by name.
Employers with staff who can be tricked
Most incidents still start with a person, not a firewall, which is why underwriters ask about training as well as technology.
Firms being asked for it in tenders
Cyber cover and a recognised security certification now appear together on procurement checklists, often alongside professional indemnity and public liability limits.
The Government’s own Cyber Security Breaches Survey, published in April 2026 from a random probability sample of 2,112 UK businesses, found that 43 per cent had experienced a breach or attack in the previous twelve months. In the information and communication sector it was 63 per cent, which is why technology companies buy this alongside everything else.
The check almost nobody makes
What “We Have Cyber Cover” Usually Means
Nearly half of UK businesses say they are insured against cyber risk in some way and about one in ten holds a policy written for it. Most of the difference is cover sitting inside another policy, under sub-limits far below the headline figure.
| What it is | What it pays for | How it is limited |
|---|---|---|
| The headline limit | What the schedule leads with | The number everybody quotes |
| Extortion | Negotiation and any payment | Capped separately, and sometimes very low |
| Network interruption | Income lost while you are down | Capped separately, behind a waiting period |
| Regulatory costs | Dealing with the regulator, and any fine | Capped separately, and conditional on the law |
| Payment card amounts | What your acquirer charges back | Sometimes shares the regulatory cap |
| Dependent outage | A provider you rely on going down | Often absent, and carved out for systemic events |
Those figures are not theoretical. In the UK wordings we read, one capped ransom payments at £25,000, one capped network interruption at £50,000 behind a 24-hour waiting period, and one capped regulatory investigations, fines and payment card amounts together at £100,000. Waiting periods of eight to twelve hours are more usual, which is why a twenty-four hour one is worth arguing about. Ask for the sub-limits in writing before you compare anything else, and note that where the cover sits inside a wider commercial combined policy they are usually smaller again.
Pricing
How Much Does Cyber Insurance Cost?
Nobody can price it from the sector name. The rating follows turnover and how much of it depends on systems, the personal data and card payments you handle, what you can evidence about your controls, and your incident history.
What the organisation is
- TurnoverAnd how much of it runs through systems.
- SectorAnd whether it is a current target.
- HeadcountEveryone who can click something.
- TerritoriesWhere your data subjects are.
What you hold
- Personal dataVolume, and how sensitive it is.
- Card paymentsWhether you take them, and how.
- Critical systemsWhat stops if they stop.
- Third-party accessWho else is inside your estate.
What you can evidence
- Multi-factor authenticationEverywhere, or nearly everywhere.
- BackupsTested restores, not just backups.
- Patching and endpoint coverHow fast, and how complete.
- Incident historyIncluding the near misses.
No premium figures appear here. Nobody publishes average UK cyber premiums, so the numbers circulating come from individual brokers describing the customers they happen to write. Rate movement is published, and it has been falling: market commentary through 2026 described abundant capacity and softening terms for well-managed risks. That is not a price for your business, but it does make this a better year to argue about cover than about cost. The drivers behind a related class are in our guide to professional indemnity costs.
Before you start
What Do I Need for a Cyber Insurance Quote?
Turnover and system dependency, headcount, the personal data and card payments you handle, the providers you rely on, what you can evidence about controls, and five years of incidents including the ones that came to nothing.
About the organisation
- Turnover, and how much depends on systems
- Headcount including contractors
- Where your customers and data subjects are
- Any incidents in the last five years, including near misses
About your data and systems
- Roughly how many personal records you hold
- Whether any of it is special category data
- Whether you take card payments, and how
- Which providers you could not trade without
About your controls
- Multi-factor authentication coverage
- Backup regime, and when you last tested a restore
- Patching cadence and endpoint protection
- Any security certification you hold
The controls column is the one that moves the price. Underwriters ask about multi-factor authentication and tested backups because those two are what most often decide whether an incident becomes a claim.
Compare with MyMoneyComparison.com
How to Compare Cyber Insurance Quotes
Get the sub-limits in writing, find the waiting period on business interruption, and ask who the incident response panel actually is. Those three separate two quotes far more than the headline limit does.
Get the sub-limits in writing
Extortion, network interruption and regulatory costs. Two policies with the same headline figure can differ by an order of magnitude underneath it.
Find the waiting period
Business interruption that starts after a stated number of hours down is a different product from one that starts after eight.
Ask who answers the phone
The incident response panel is most of the value. Ask who it is, how fast they engage, and what happens to costs if you bring in your own people.
Describe the organisation once and specialist UK brokers can come back to you. MyMoneyComparison.com is an introducer rather than a broker, so we do not sell the policy or recommend one. Our editorial policy sets out how we work, and our commercial combined guide explains how this sits with the rest of the cover.
Cutting costs
How Can I Reduce the Cost of Cyber Insurance?
Evidence multi-factor authentication, test a restore and say so, rehearse an incident plan, train your people and describe the estate accurately. Reviewing the retention helps once the sub-limits are right.
Evidence multi-factor authentication
Not that you have it, but where. Coverage across remote access, email and privileged accounts is what underwriters actually score.
Test a restore, then say so
Everybody has backups. Far fewer have restored from them recently, and that distinction is worth real money at renewal.
Have an incident plan you have rehearsed
A named decision-maker, a call list and a tested process. It shortens the incident, which is what the insurer is pricing.
Train the people, not just the network
Most incidents still start with somebody clicking something. Recorded, repeated training is a cheap thing to be able to show.
Describe the estate accurately
Under-describing what you hold gets rated cautiously. A clear picture of data, systems and dependencies usually prices better.
Review the retention
Carrying more of the smaller incidents yourself can bring the premium down, provided the sub-limits above it are worth having.
If the organisation also advises clients, the claim that your advice was wrong sits with professional indemnity insurance rather than here.
Jargon buster
Cyber Insurance Jargon, Explained
The words that decide a cyber claim, in plain English. There is a longer general list in our insurance jargon buster.
- Sub-limit
- A smaller cap sitting inside the headline limit and applying to one named cover.
- Waiting period
- The hours you must be down before business interruption cover starts paying.
- Incident response panel
- The forensics, legal and communications firms the insurer appoints. Costs outside it are often not recoverable.
- First-party loss
- What the incident costs you directly, as opposed to what you owe others.
- Third-party liability
- Claims brought against you by customers, suppliers or data subjects.
- Dependent outage
- Cover for a provider you rely on going down rather than your own systems.
- Systemic event
- A regional or global infrastructure failure, commonly carved out of the cover.
- Non-malicious failure
- An outage caused by your own systems breaking rather than by an attack.
Why MyMoneyComparison.com
Comparing Specialist Cyber Cover
MyMoneyComparison.com is an FCA-authorised UK comparison service that introduces companies to specialist brokers. We do not sell insurance and we do not give advice: the broker you choose arranges the policy. Comparing is free and there is no obligation.
Form for the whole company
Describe the organisation, what it holds and the limits it needs once, instead of repeating yourself to every broker in turn.
Advice given
We are an introducer, not a broker. We do not sell policies and we do not recommend one. Read our editorial policy.
Authorised and regulated
MyMoneyComparison.com Ltd appears on the FCA register under FRN 916241.
Comparing since
A UK company since 2013, working with specialist brokers across the country.
FAQs
Cyber Insurance FAQs
The questions UK organisations ask most.
What is cyber insurance?
What does cyber insurance actually cover?
Why do the sub-limits matter so much?
Is cyber insurance a legal requirement?
Is it claims-made like professional indemnity?
Does cyber insurance pay a ransom?
Is it legal to pay a ransom in the UK?
Has the UK banned ransom payments?
Does paying a ransom reduce a regulatory penalty?
Does cyber insurance cover a data protection fine?
Can a regulated firm insure a fine?
What about claims from the people whose data was exposed?
Are payment card penalties covered?
What happens if my cloud provider goes down rather than me?
Is cover for a provider outage standard?
What about a global outage rather than one provider?
Does my existing business insurance already cover cyber?
Does professional indemnity cover a data breach?
Are insurers excluding artificial intelligence?
How much does cyber insurance cost?
Do shops and online retailers need cyber insurance?
Do salons and small service businesses need cyber cover?
Are restaurants and hotels exposed to cyber attacks?
Does a block of flats or managing agent need cyber cover?
Ready when you are
Compare Cyber Quotes
Tell us what the organisation does, what it holds and what stops if the systems do, and specialist UK brokers can come back with quotes. Free to use, with no obligation to buy.
- Professional services through to the public sector
- Ransomware, data breach and interruption
- FCA authorised and regulated
Free to use · No obligation · UK brokers
About this page
This page sets out what cyber insurance does, how it is triggered, where its limits actually sit and what drives the price, for UK organisations with systems, staff and data rather than for sole traders. It is general information and not advice. Cyber wordings differ more than any other class we have looked at, so read your own schedule and take the questions raised here to your broker. For the claim that your advice was wrong see professional indemnity insurance, and for a technology business selling to other businesses see technology company insurance.
How we researched this page
- Four current UK cyber wordings, including one written on a Lloyd’s basis, for the insuring clauses, the sub-limits and the systemic event carve-outs
- A UK commercial combined wording, to establish what the ordinary business interruption section does and does not reach
- The Government’s Cyber Security Breaches Survey, published April 2026 from a random probability sample of 2,112 UK businesses
- The data protection regulator’s joint statement with the National Cyber Security Centre on ransom payments, and the Home Office response on ransomware reform
- Published market commentary on UK cyber capacity and pricing through 2026
No example premiums appear here, because we could find no UK body collecting and publishing average premiums for this class, though rate movement is published and has been falling. Where wordings differ we say so rather than picking one and calling it the market. Four things in wide circulation are corrected on this page: that ordinary business interruption answers a cloud outage, that cyber insurance simply covers data protection fines, that the UK has banned ransom payments, and that paying a ransom reduces a regulatory penalty.