Cyber insurance comparison for UK small businesses
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Almost half of UK businesses are insured against cyber risk in some way. Only one in ten holds a policy that was written for it. More than a fifth cannot say whether they have any cover at all, and that figure comes from a survey that put the question to the person in each organisation with the most responsibility for cyber security.
So the first comparison to make is between the policy you believe you bought and the document that gets read when you claim. The insurers come after that.
This guide compares that document across six routes to cyber insurance for small businesses in the United Kingdom, each read from the provider’s own published wording, product summary or application form on 16 September 2026, with every figure traced to the page it came from. It ends with a checklist you can take into a renewal meeting.
It does not tell you which one to buy, and the reason for that is a piece of UK law worth knowing before you read any comparison at all.
What cyber insurance for a small business costs a year
Two UK providers publish a price and the rest send you to a quote form. So the table below covers both: what is actually published, with the example it rests on, and where that puts a business of your size. The detail, and why a published price needs its footnote read, is further down.
| Business | What is actually published | Our estimate, a year |
|---|---|---|
| Sole trader or virtual assistant, income up to £50,000 | £11.11 a month, about £133 a year, for £100,000 of cover with insurance premium tax included. PolicyBee, read 16 September 2026 | £130 to £400 |
| 2 to 20 people, professional services holding client data | nothing published; every provider read for this guide sends you to a quote form | £400 to £1,200 |
| 21 to 50 people, or turnover above £250,000 | nothing published, and Direct Line’s required backup interval tightens at £250,000 of turnover | £1,200 to £4,000 |
The middle column is quoted from the source named in it, and the column on the right is our own estimate: not a quote, and not an insurer’s figure.
Where it comes from: it maps the published prices onto three size bands, the same three that two independent European sources use: Amrae’s LUCY study of 20,996 policies for 2025 (average premiums of €645, €1,600 and €5,000 by company size) and AIG’s own Irish service tiers (€899 or less, €900 to €4,999, €5,000 or more). Your premium comes out of your proposal form, not out of this table.
What being insured against cyber means in the UK right now
The government surveys UK organisations every year about how they handle cyber security, and the 2025/2026 edition was published on 30 April 2026. Its section on insurance is the most useful starting point there is on cyber insurance for small business, because it separates two things a quote page does not.
Of businesses overall, 37 per cent have cyber cover inside a wider insurance policy and 10 per cent have a specific cyber policy. Among micro businesses those figures are 37 and 8. Among small businesses, 40 and 15. The proportion with some form of cover has crept up from 43 per cent in 2023/2024 to 47 per cent now.
The fifth of businesses that do not know
One in five businesses, 22 per cent, told the survey they did not know whether they had any form of cyber security insurance. The survey was conducted with whoever the organisation itself named as having the most responsibility for cyber security, which makes that number a finding about documents rather than about people.
It is worth resolving before you compare anything, and your schedule will tell you in a line. If cyber appears with its own limit of indemnity and its own excess, you have a policy. If it appears as a named extension sharing the limit of the office policy around it, you have an extension, and the questions worth asking about the two are not the same.
| Section on the schedule | Limit of indemnity | Excess |
|---|---|---|
| Office contents | £120,000 | £250 |
| Public liability | £2,000,000 | nil |
| Cyber risks | £100,000 | £500, plus a time excess of 6 hours |
Illustrative layout, figures invented. A cyber line with its own limit, its own excess and its own time excess is a policy. A cyber line reading “included” with no figures beside it is an extension of the section above.
Why an extension is not a smaller standalone policy
An extension inherits the conditions of the policy it sits inside. Direct Line for Business offers its Cyber Risks section only to Retail and Office and Professional customers, and its claims are administered by a different company from the one that handles the rest of the policy. That is not a criticism, just something you want to know before the week you need it.
A standalone policy brings its own conditions, its own definitions and usually its own incident response line. It also brings its own application form, which is where the insurer writes down what it is relying on. Firms that handle client data for a living, as many of those reading this do, tend to end up needing the second kind.
Why this page compares wordings and does not recommend one
In the United Kingdom, comparing insurance is closer to a regulated activity than most people writing comparisons let on. The FCA’s own guidance says so in a table, and the table is worth quoting because it draws the line exactly where this page has to sit.
PERG 5.15.4 G lists types of activity and whether each is regulated. The row for “explanation of the terms of a particular policy or comparison of the terms of different policies” answers “possibly”, and explains that it “is likely to amount to making arrangements under article 25(2)”, with the article 72C exclusion available where the activity is only the provision of information.
Recommending is a different row in the same table
Two rows down, the guidance is not hedged at all. “Advising that a customer take out a particular policy” is a regulated activity, because it “amounts to advice on the merits of a particular policy under article 53(1)”. So is advising a customer not to take out a particular policy. Telling you to avoid something is as regulated as telling you to buy it.
That is why there is no best buy here, no star rating and no shortlist. What follows is what each document says, with the document named, so that the comparison is yours to make. When the questionnaire lands and you have to write answers rather than read them, that is a separate job with separate risks.
What the cover actually pays for
Cyber policies split into losses you suffer and claims other people bring against you. Most of the UK documents read for this guide organise cover that way, even when the section names differ, and the order the sections appear in tells you what the insurer thinks it is selling.
Hiscox CyberClear puts your own losses first and organises everything else around them. Its policy summary lists six sections: your own losses, cyber business interruption, claims and investigations against you, losses from crime, bricking, and additional covers.
| Head of cover | What it pays for | Where it is written |
|---|---|---|
| Your own losses | Forensics, legal costs, notifying data subjects and the regulator, ransom and negotiators | Hiscox policy summary, section A |
| Business interruption | Loss of income and increased cost of working, with a time excess before it starts | Hiscox section B; Direct Line, Cyber Risks |
| Claims against you | Breach of confidence, data claims, investigations including UK GDPR investigations | Hiscox section C |
| Crime | Theft of money or securities, employee dishonesty, social engineering transfers | Hiscox section D |
| Bricking | Repair or replacement of connected equipment left unusable | Hiscox section E |
| Incident response | Forensic, legal and public relations support, often a line open 24 hours | NCSC guidance; IASME summary; CFC product page |
The crime section is the one to check most carefully, because it is the one the NCSC singles out. The NCSC’s guidance puts it plainly: “some insurance policies will not cover monies lost through business email compromise fraud”. The Cyber Essentials insurance does not cover it at all, and says so in one line under what is not covered.
Incident response is also where the products diverge most. CFC describes immediate incident response at nil deductible and unlimited reinstatements; IASME’s £25,000 policy gives a helpline, open 24 hours, whose crisis management runs against that same £25,000. Both are real cover. They are not the same product, and neither is what most people mean when they say a data breach.
The exclusions to look for in a UK wording
Exclusions are where a comparison earns its keep, because a quote does not show them to you. Three are worth finding before you sign, and one of them is in your policy by market rule rather than by the insurer’s choice.
Hiscox’s policy summary lists, among others, losses due to “the use of any outdated or unsupported computer system”, losses due to “war or due to cyber operations carried out by, at the direction or under the control of a state”, and losses from “any actual or alleged monitoring, tracking or profiling of an individual without their authorisation”.
At Lloyd’s, the state backed exclusion is compulsory
On 16 August 2022 Lloyd’s issued market bulletin Y5381 requiring that all standalone cyber-attack policies in risk codes CY and CZ include a clause excluding liability for losses from any state backed cyber-attack, taking effect “from 31 March 2023 at the inception or on renewal of each policy”.
The bulletin sets five minimum requirements, including that the clause exclude attacks that “significantly impair the ability of a state to function” and that it “set out a robust basis by which the parties agree on how any state backed cyber-attack will be attributed to one or more states”. So the question at renewal is which of the LMA model clauses your policy uses for it, and how attribution is decided.
The unsupported system exclusion is the one that bites a small office
Read that Hiscox exclusion again with your own kit in mind. An unsupported operating system on the machine in reception, an old server kept alive for one legacy application, a till nobody has patched since it was installed: any of those can be the thing that turns a covered loss into an argument.
This is also the exclusion most likely to interact with whatever you promised on the application form. You do not need a security programme to deal with it. You need a list of what you run and a note of what is still getting updates, which is the same list an AI policy starts from.
Fines, and the four words that decide whether yours is paid
The three UK documents read for this guide that mention regulatory fines all attach a condition to them, and it is the same idea written three ways. Direct Line covers “fines (where insurable by law)”. The Cyber Essentials policy covers “regulatory fines (where insurable by law)”. Hiscox goes further and defines the term.
Hiscox’s wording excludes “criminal, civil or regulatory sanctions, fines, penalties” and then carves back two things: PCI charges and regulatory awards. A regulatory award is defined as sanctions and fines following a privacy investigation “if insurable in the jurisdiction where such award was first ordered”.
So the policy does not tell you whether an ICO penalty is covered. It tells you the answer turns on whether such a penalty can lawfully be insured, and none of the three documents says what that answer is.
That is worth knowing before anyone writes the fine down as covered in a risk register. When a broker says a policy covers ICO fines, the useful next question is what the wording means by insurable, and who decides.
It matters because ICO penalties on smaller firms are not hypothetical. DPP Law Ltd, described in its penalty notice as a law firm headquartered in Bootle with fewer than 250 staff, was required to pay £60,000 after client data reached the dark web. What happened there is worth a section of its own, further down.
Excesses, waiting periods, and the two clocks that run at once
The excess is where published limits stop being comparable. A £100,000 limit with a £1,000 excess and a £100,000 limit with a waiting period of six hours on business interruption are different products, and nothing on the quote page tells you which you are looking at.
Here is what the UK documents actually say. The Cyber Essentials policy carries “a £1,000 excess (increasing to £5,000 for claims emanating from activities in the USA or Canada) and a six hour Network Interruption retention”. Direct Line applies “£500 excess … to any claim”. PolicyBee reduces the excess by £2,500 if 80 per cent of staff finish its online training, and says that where the excess was no higher than that, it disappears.
Hiscox does something different again, and it is the line worth carrying into any comparison: “If you notify us within 72 hours of your first awareness of any actual or suspected data breach, we will waive the excess in respect of that breach”, other than for business interruption losses and losses from crime.
Two different 72 hour clocks, and only one is in your policy
That 72 hours is not the UK GDPR one, and confusing them is easy. Article 33(1) requires a controller to notify the Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach. Hiscox’s 72 hours is a commercial incentive to tell your insurer early, measured from your first awareness of an actual or suspected breach.
They can run together and they have different consequences. Miss the regulator’s clock and you have a separate infringement. Miss the insurer’s and you pay an excess you could have avoided. Whether the thing that happened is even a breach in the first place is a question with its own machinery, and the answer decides which clock you are on.
What an insurer requires before it will cover you
This is where the UK providers diverge most sharply, and it is the part of a policy you can fail without noticing. Some ask for controls. Others ask for habits. The wording of the question decides what you are promising.
CFC’s Cyber Proactive Response application form for the UK is a single page. Its entire cyber security controls section is three questions answered yes or no, and all three are about the same two things. Quoted in full:
- “Please confirm whether multi-factor authentication is enabled and enforced for all remote access to your network.”
- “Please confirm whether multi-factor authentication is enabled and enforced for remote access to all company email accounts.”
- “Please confirm whether you have offline back-ups that are fully disconnected from your live environment or cloud-based back-ups with access secured by multi-factor authentication.”
That is the whole of it. Three ticks decide whether an underwriting agency with more than 100,000 cyber customers worldwide will write your risk, and they are the same three ticks for a practice of two people and for a business turning over £200 million.
| Provider | What it requires, in its own words | Where |
|---|---|---|
| CFC | Multi-factor authentication “enabled and enforced for all remote access to your network” | UK application form v12 |
| CFC | The same for “remote access to all company email accounts”, plus disconnected or protected backups | UK application form v12 |
| Direct Line | Antivirus updated every 30 days, or every 7 above £250,000 turnover | Cyber insurance page, FAQ |
| Direct Line | Backups every 30 days, or every 7 above £250,000 turnover, and police reported promptly | Cyber insurance page, FAQ |
| Cyber Essentials policy | “Install and maintain automatically provided updates … for critical business software” | IASME insurance FAQ |
Two things stand out. First, turnover is doing real work in the Direct Line conditions: cross £250,000 and your required backup interval goes from monthly to weekly, which is a condition you can breach by growing. Second, nobody in this group asks about training, governance or suppliers, which are the questions that dominate the security questionnaires clients send.
The DPP Law gap: authentication on the VPN, not on the service account
The ICO penalty notice on DPP Law is the best worked example a UK firm has, and the detail that matters is in a single sentence of paragraph 20. At the time of the incident the firm had multi-factor authentication for connecting to its network by VPN. The administrator account, sqluser, “did not have MFA due to its role as a service-based account”.
The intruder reached that account after a user’s laptop was compromised, and there was no second factor in the way. Attempts to break into an administrator account on a legacy case management system by brute force had been running since 19 February 2022, 400 in all, and the data of 791 clients and experts ended up published on the dark web.
Now read CFC’s question again with that in mind. “Enabled and enforced for all remote access to your network” is a yes or no, and a firm in DPP’s position could have answered yes in good faith while the exception that mattered sat outside the question. The condition is not wrong, just not the whole shape of the risk, and the gap between them is yours to find.
Section 11 of the Insurance Act, and the condition you broke by accident
Breaching a condition does not automatically cost you the claim, and UK law is unusually helpful here. Section 11 of the Insurance Act 2015 applies to terms that would tend to reduce the risk of loss of a particular kind, at a particular location or at a particular time.
If you breach such a term and a loss happens, the insurer “may not rely on the non-compliance to exclude, limit or discharge its liability” if you can show that the breach “could not have increased the risk of the loss which actually occurred in the circumstances in which it occurred”.
In plain terms: if your backups slipped to once every 40 days and the loss was a fraudulent payment, the late backup did not cause it. That is a real defence and worth knowing, but not an excuse to let the condition slide, because proving the negative is your job, not the insurer’s.
Fair presentation: the UK rule that turns a bad answer into a refused claim
Everything an insurer requires arrives attached to something you sign, and in the United Kingdom what you sign is governed by the Insurance Act 2015. Direct Line’s own policy summary puts it in the customer’s language: “You need to make a fair presentation of your business to us.”
Section 3(1) says the insured must make a fair presentation of the risk before the contract is entered into. Section 3(4)(a) requires disclosure of “every material circumstance which the insured knows or ought to know”. Section 3(3)(c) requires every material representation of fact to be “substantially correct”.
What the remedies are, and why they are not all or nothing
The remedies sit in Schedule 1, and they are graded. If the breach was deliberate or reckless, the insurer may avoid the contract, refuse all claims and keep the premium. If it was neither, and the insurer would not have written the risk at all, it avoids but returns the premium.
If the insurer would have written it on different terms, the contract is treated as if it carried those terms. If it would have charged more, the insurer “may reduce proportionately the amount to be paid on a claim”. Section 8(6) puts the burden on the insurer to show that a breach was deliberate or reckless.
| The breach of fair presentation | What the insurer may do |
|---|---|
| Deliberate or reckless | Avoid the contract, refuse all claims and keep the premium |
| Neither, and it would not have written the risk at all | Avoid the contract and return the premium |
| Neither, and it would have written it on different terms | Treat the contract as if it carried those terms |
| Neither, and it would have charged more | Reduce proportionately the amount paid on a claim |
Insurance Act 2015, Schedule 1: the remedies for a qualifying breach.
So the worst case is reserved for people who knew, and the ordinary case is a smaller payout on a policy you thought was whole. That is the real cost of a rushed answer on a form. What a good answer looks like, question by question, is the subject of its own guide.
What UK policies say about AI, measured rather than assumed
Eight UK cyber insurance documents were opened for this guide and searched for the words artificial intelligence, machine learning and generative. The Hiscox CyberClear policy summary and its policy wording: nothing. CFC’s UK application form and its May 2026 brochure: nothing. Direct Line’s cyber page and its policy summary of 18 pages: nothing. PolicyBee’s cyber page: nothing. Hiscox’s own cyber product page mentions artificial intelligence exactly twice, and both are entries in the dropdown list of trades it will insure.
The NCSC’s own cyber insurance guidance is in the same position, and more starkly. It runs to a little over 2,000 words, it is the government’s standard reference for UK buyers, and it has carried the same version number since it was published on 6 August 2020. It does not contain the word AI.
Chubb addresses it, and not in a wording
Chubb is the exception, and what it says is more useful than a clause would be. Its UK guide for SMEs carries the summary of its 2026 EMEA Cyber Claims Report: “Rather than creating entirely new categories of claims, AI acts as a multiplier across existing perils including Cyber, Crime, D&O and Liability.”
Read alongside the silence in the wordings, that is a coherent market position rather than an oversight. The peril is still ransomware, still fraudulent payment, still a data breach. AI changes how often and how convincingly, not what the policy is called.
Silence is not the same as cover
Do not turn that into comfort. A wording that says nothing about AI has not agreed to anything about AI, and the place the question will be decided is the definitions, not a headline. If an employee pastes a client file into a chat tool and it later appears somewhere it should not, the wording will be read for what counts as an unauthorised disclosure and whether your own act breaks the chain.
What happened to the file before that depends on the tool. In ChatGPT, who your data controller is depends on where the firm sits. With Microsoft the answer changes by product, and four of them share the Copilot name. Google prints a sentence on the subject, and what that sentence means for a firm is not what it first suggests.
The gap between adoption and control is measurable and it is wide. The same government survey found that 31 per cent of businesses are using AI, adopting it or considering it, and that among those, only 24 per cent have security practices in place to manage the risks. A further 31 per cent have no plans to introduce any. One of those practices costs nothing: switching off model training in the AI tools your staff already use, Claude included.
That last figure is the one an underwriter will eventually start asking about, whatever the regulatory calendar does next. Until then, the answer you give about AI belongs in your own written record, not in a clause that does not exist yet.
Six routes to cyber cover in the UK, compared
Below is what the six routes look like when you read their documents rather than their headlines. Limits are what each provider publishes; conditions are quoted from the source named in the row.
| Route | Limit published | Key condition | How you buy it |
|---|---|---|---|
| Hiscox CyberClear | £25,000 crisis containment as standard, rest in the schedule | Excess waived if you notify within 72 hours | Online quote, and through brokers |
| Direct Line for Business | £25,000, £50,000 or £100,000 | Antivirus and backup intervals by turnover | Online, as an extension |
| CFC Cyber Proactive Response | Not published; written for revenues £0 to £250m | Authentication on remote access and email | Broker only, traded on Connect |
| PolicyBee | £100,000 cyber; £50,000 cybercrime | Cyber Essentials may earn a discount | Online, under two minutes |
| Cyber Essentials policy | £25,000 total limit of indemnity | Turnover under £20m, domiciled in the UK, self-certified | Comes with certification |
| AXA | Does not offer cyber directly | Not applicable | Referral to InSync, a broker |
Sources, in row order: the Hiscox cyber and data insurance page and policy summary reference 19029; the Direct Line cyber insurance page; the CFC product page and UK application form v12; the PolicyBee cyber page; the IASME cyber liability insurance page; the AXA cyber insurance page. All read on 16 September 2026.
The £25,000 that arrives with a certificate
IASME states that an organisation domiciled in the UK with turnover under £20 million that achieves self-assessed Cyber Essentials certification covering the whole organisation is entitled to cyber liability insurance, underwritten by American International Group UK Limited and administered by Sutcliffe and Co.
IASME is candid about the size of it: the £25,000 limit “might be sufficient for a small breach or incident but inadequate for a serious problem or more than one incident”. Take it as a floor that comes free with a certification you may want anyway, not as the answer. Only 5 per cent of UK businesses hold Cyber Essentials at all, so for most firms this is a door they have not opened.
Where AXA and Aviva actually send you
One of the household names says it does not sell this directly. The other simply does not list it. AXA’s cyber insurance page carries the line in a footnote: “While AXA does not directly offer cyber insurance, our trusted partner can assist you in finding the right protection.” The partner is InSync Insurance, a broker.
Aviva is quieter about it. Its UK business insurance page lists its direct products and then the ones “available through a broker”, and cyber is not in either list. Its cyber material sits inside Aviva Risk Management Solutions, which is written for brokers and larger clients.
Neither of these is a failing, but it does save you an afternoon hunting for a quote form that is not there, and it is a reminder that a broker is part of this market, not an optional extra.
What is published about price, and what a published price means
Of the providers read for this guide, two publish a figure and the rest send you to a quote form. There is a reason for that: a cyber premium turns on turnover, sector, data held, controls and claims history, so a number without its example means nothing.
PolicyBee publishes two, with the example stated: cyber insurance “from £11.11 a month for £100,000 cover” and cybercrime cover at “£6.89 a month” for a £50,000 limit, “based on a quote for a virtual assistant with an annual income of up to £50,000”, with all prices including insurance premium tax at 12 per cent. Those are the figures its page showed on 16 September 2026.
Hiscox publishes one too, and it is the kind that needs its footnote read. Its cyber page says business insurance quotes “start from £7.20” a month, and the asterisk explains that the figure is “based on an average of all business insurance policies sold to at least 10% of our customer base between August 2025 and August 2026”. That is a floor across everything it sells, not a cyber price.
Take three things from that. The PolicyBee example is a sole worker with modest income, which is the cheapest shape of risk there is. The figure includes the tax, and not every quote does. And a price that starts with the word from is a quote for somebody else until you have run your own.
Cost is not the main reason firms go without
The survey asked businesses without cyber insurance why, and the answers are not the ones the market assumes. Not being aware of cyber insurance came first at 39 per cent. Not a budgetary priority came second at 34 per cent, and leadership not being interested third at 27 per cent. Too expensive was fourth, at 19 per cent.
Only 8 per cent said the cover was not broad enough. So buyers are not rejecting cyber insurance after reading the exclusions. Most of them have not got as far as the documents, which is the gap guides like this one exist to close.
The checklist to take into your renewal
What follows is the whole of this guide compressed into fifteen questions, in the order the documents answer them, each with the document that answers it and what a good answer looks like. Written for a UK business buying or renewing cover: take it to the meeting and write the answer next to each one from your own schedule and wording, not from a quote summary.
Nothing in it is specific to a provider, and none of it requires buying anything. Several of the answers will be in documents you already hold, and the ones that are not are the ones worth an email before you renew. It is free to use and you do not have to give us an email address for it, as with the rest of our guides.
| Where the answer is | What it settles | Questions |
|---|---|---|
| The schedule | Standalone or extension, the limit, the money excess and the time excess | 1 to 4 |
| The policy wording | Crime cover, fines, the state backed and unsupported system exclusions, notification, AI | 5 to 8, plus 13 and 14 |
| The application form and its declaration | The controls you promise, their exceptions, the fair presentation | 9 to 11 |
| The policy summary or product page | The incident line, and who underwrites and administers the claim | 12 and 15 |
The fifteen questions below, grouped by the document that answers them.
- Is this a standalone cyber policy or an extension of another policy? Cyber security breaches survey 2025/2026, section 3.3: 37 per cent of businesses have cyber inside a wider policy, 10 per cent a policy of its own. Look for: a cyber section with its own limit and its own excess. Keep: the schedule page that states both.
- What is the limit of indemnity, and is it the total for the year? Hiscox pays “up to the overall limit of indemnity shown in the schedule for the total of all claims under each section”. Look for: whether inner limits apply to individual covers. Keep: the schedule and the how much we will pay clause.
- What is the excess, and is there more than one? The Cyber Essentials policy has “a £1,000 excess … and a six hour Network Interruption retention”. Direct Line applies £500 to any claim. Look for: a money excess and a separate time excess. Keep: both, written down, before you compare two quotes.
- Is business interruption covered, and from what hour does it run? A time excess is the period after the incident for which you are not covered. It can be hours, and it decides whether you recover anything. Look for: the time excess in the schedule. Keep: your own estimate of what one day offline costs you.
- Is theft of money covered, or only the cost of the attack? The NCSC warns that “some insurance policies will not cover monies lost through business email compromise fraud”. Look for: a crime or cybercrime section, and whether it is an add-on. Keep: the section name and its own limit.
- Does the policy cover regulatory fines, and on what condition? Direct Line covers “fines (where insurable by law)”. Hiscox pays a regulatory award “if insurable in the jurisdiction”. Look for: those words, then ask what the insurer means by them. Keep: the definition, not the marketing sentence.
- Which state backed cyber-attack exclusion does the policy use? Lloyd’s market bulletin Y5381 has required one in standalone policies since 31 March 2023, and the LMA publishes four model clauses. Look for: which model clause, and how attribution is decided. Keep: the clause reference for your file.
- Is there an exclusion for outdated or unsupported systems? Hiscox excludes losses due to “the use of any outdated or unsupported computer system”. Look for: the wording, then check it against your own inventory. Keep: a list of what you run and what is still supported.
- What security controls does the insurer require, exactly? CFC’s UK application asks three questions: authentication on remote network access, the same on email, and disconnected backups. Look for: conditions that scale with turnover, as Direct Line’s do. Keep: evidence that each one is true today, not last year.
- Does any required control have an exception nobody has written down? DPP Law had authentication on its VPN. The service account did not, and that was the way in. The ICO penalty was £60,000. Look for: service accounts, legacy systems, contractors, shared logins. Keep: the list of exceptions, and a date to close each one.
- Who signs the fair presentation, and have they seen the answers? Section 3 of the Insurance Act 2015 requires disclosure of every material circumstance the insured knows or ought to know. Look for: the declaration at the end of the form. Keep: the completed form, with the evidence for each answer attached.
- Is there an incident line open 24 hours, and who answers it? CFC provides immediate incident response at nil deductible. The Cyber Essentials helpline runs against the same £25,000 total limit. Look for: whether response costs erode the limit. Keep: the number, offline, where you can reach it without your network.
- How long do you have to notify, and does early notice buy anything? Hiscox waives the excess if you notify within 72 hours of first awareness, other than for business interruption and crime. Look for: the notification clause, and its starting point. Keep: it next to your Article 33 breach procedure. They are not the same.
Tell the Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach. Miss it and you have a separate infringement.
Notify within 72 hours of first awareness of an actual or suspected breach and the excess is waived, other than for business interruption and crime. Miss it and you pay the excess.
- Does anything in the wording mention artificial intelligence? None of the eight UK cyber insurance documents opened on 16 September 2026 names it as a risk, a cover or an exclusion. Chubb addresses it in a claims report, not in a wording. Look for: definitions of unauthorised disclosure and of your own act. Keep: your written record of which AI tools staff are allowed to use.
- Who is the insurer, and who handles the claim? Direct Line’s Cyber Risks claims “are administered by HSB Engineering Insurance Limited”. The Cyber Essentials policy is underwritten by AIG UK. Look for: the underwriter, the administrator and the broker separately. Keep: all three names in one place before you need any of them.
Before you sign: read the schedule and the wording together. The schedule holds the numbers and the wording holds the meaning, and a quote summary holds neither. This is general information about UK insurance documents, not advice about whether any particular policy suits your business.
Where a masking tool sits in this, and where it does not
We build Nonimo, which masks names and identifiers in text on the machine before you paste it anywhere, so it would suit us if cyber underwriters asked about that. On the evidence read here, they do not. The one UK application form read for this guide, CFC’s, has no question about masking, redaction or data minimisation in outbound text, and neither does anything else read here.
What it speaks to is narrower and worth saying precisely. It reduces what leaves your office in a prompt. What the app keeps on your computer, and the daily usage count it sends without a word of your text, are set out on Nonimo’s security page. A policy that requires authentication on remote access is asking about something else entirely, and no honest answer to that question improves because you run our software.
So for most readers of this page the correct conclusion is to buy nothing from us, and instead to open your schedule, work through the fifteen questions, and send the three you cannot answer to your broker. If after that you decide the outbound text is a real exposure in your organisation, that is the conversation where a tool like ours belongs, and not before.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account, and your client’s details never leave your machine.
Sources
Every document below was opened and read on 16 September 2026. Where a figure is quoted, the section or page it came from is named.
- Cyber security breaches survey 2025/2026, Department for Science, Innovation and Technology, published 30 April 2026. Sections 3.3 and 3.11, figures 3.4, 3.5 and 3.15. Source of the 47, 37 and 10 per cent split, the 22 per cent who do not know, the rise from 43 per cent in 2023/2024, the reasons for going without, the Cyber Essentials holding of 5 per cent, and the AI adoption and control figures.
- FCA Handbook, PERG 5.15.4 G, illustrative tables, last updated 1 January 2021. Source of how comparing the terms of different policies is treated under article 25(2) with the article 72C exclusion, and of advising for or against a particular policy under article 53(1).
- Insurance Act 2015, section 3, the duty of fair presentation. Source of the disclosure standard and the substantially correct test.
- Insurance Act 2015, Schedule 1, insurers’ remedies for qualifying breaches. Source of avoidance, of deemed different terms, and of proportionate reduction of a claim.
- Insurance Act 2015, section 11, terms not relevant to the actual loss. Source of the defence where the breach could not have increased the risk of the loss that occurred.
- NCSC, Cyber insurance guidance, published 6 August 2020, version 1.0. Source of the business email compromise warning, the reassessment every twelve months, the Cyber Essentials insurance reference, and the measured absence of any mention of artificial intelligence.
- ICO, Penalty Notice to DPP Law Ltd (PDF), £60,000 under section 155(1) of the Data Protection Act 2018. Source of the service account without multi-factor authentication at paragraph 20, the 400 attempts by brute force from 19 February 2022, the 791 affected individuals, and the Article 33(1) finding on late notification.
- Lloyd’s, Market Bulletin Y5381 (PDF), state backed cyber-attack exclusions, 16 August 2022. Source of the requirement in risk codes CY and CZ, the five minimum contents, the LMA model clauses and the 31 March 2023 effective date.
- IASME, Cyber Liability Insurance. Source of the £20 million turnover threshold, the £25,000 limit of indemnity, the AIG UK underwriting, the £1,000 excess and the retention of six hours, the exclusion of money stolen electronically, and the automatic updates condition.
- Hiscox, CyberClear policy summary (PDF), reference 19029 WD-PIP-UK-CCLEAR(6). Source of the six sections of cover, the outdated system, state operations and profiling exclusions, and the waiver of the excess for notice within 72 hours.
- Hiscox, cyber and data insurance. Source of the £25,000 crisis containment cover as standard, the online quote in five minutes, the £7.20 a month figure with its footnote about all business insurance policies, and the two mentions of artificial intelligence in the list of trades it insures.
- Hiscox, CyberClear policy wording (PDF), reference 19029. Source of the fines exclusion, the exception it carves back for PCI charges and regulatory awards, and the definition of a regulatory award as insurable in the jurisdiction that ordered it.
- Direct Line for Business, cyber insurance, and its policy summary (PDF), reference DL4BKF. Source of the three published limits, the £500 excess, the antivirus and backup intervals by turnover, the police reporting condition, the HSB claims administration, and the fair presentation wording.
- CFC, Cyber Proactive Response application form, UK v12 (PDF), and its product page. Source of the three security questions quoted in full, the revenue band, the nil deductible incident response, and the broker distribution.
- PolicyBee, cyber insurance. Source of the published monthly prices with their stated example, the insurance premium tax at 12 per cent, the excess reduction for staff training, and the Cyber Essentials discount.
- AXA, cyber insurance. Source of the statement that AXA does not directly offer cyber insurance and refers customers to InSync Insurance.
- Aviva, business insurance. Source of the measured absence of cyber from its list of direct products and its list of products available through a broker.
- Chubb, cybersecurity and cyber insurance guide for SMEs. Source of the 2026 EMEA Cyber Claims Report position that AI acts as a multiplier across existing perils rather than creating new categories of claims.
This page is general information about how UK cyber insurance documents are written. It is not a recommendation to buy or to avoid any policy, and it is not advice about whether a particular policy suits your business.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
How do I compare cyber insurance for a small business in the UK?
Compare the documents, not the sales pages. Read the schedule for the limit and the excess, the wording for the exclusions and the conditions, and the application form for what the insurer will hold you to. The checklist at the end of this guide lists the questions in order.
Do most UK small businesses have cyber insurance?
Almost half have some form of cover. The government's Cyber security breaches survey 2025/2026 found 47 per cent of businesses insured against cyber risk in some way, but only 10 per cent held a specific cyber policy. The rest have cover inside a wider policy.
Does cyber insurance cover an ICO fine?
Only where the law allows a fine to be insured, and UK wordings say so in those words. Hiscox pays a regulatory award only if it is insurable in the jurisdiction that ordered it. Direct Line covers fines where insurable by law. The policy does not settle the question.
What do insurers require before they will cover a small firm?
Most often multi-factor authentication on remote access and on email, plus backups that are disconnected or separately protected. CFC's UK application, a single page, asks those three things and nothing else about security. Direct Line instead sets antivirus and backup intervals.
Is cyber insurance included with Cyber Essentials?
For some organisations. IASME states that an organisation domiciled in the UK with turnover under £20 million that self-certifies to Cyber Essentials across the whole organisation is entitled to cyber liability insurance with a £25,000 limit of indemnity, underwritten by AIG UK.
How much does cyber insurance cost for a small UK business?
Published prices exist but always rest on a named example. PolicyBee publishes cyber cover from £11.11 a month for a £100,000 limit, based on a quote for a virtual assistant with an annual income of up to £50,000, with insurance premium tax included.
Do cyber policies mention artificial intelligence?
Not in the ones we read. None of the eight UK cyber insurance documents opened on 16 September 2026, including two Hiscox policy documents and CFC's application form, names AI as a risk, a cover or an exclusion. Chubb addresses it in a claims report rather than in a wording.
What is a fair presentation of the risk?
The duty in section 3 of the Insurance Act 2015 to disclose every material circumstance you know or ought to know, clearly enough for a prudent insurer. Get it wrong and Schedule 1 lets the insurer avoid the policy, rewrite the terms or cut the payout.
Does a cyber policy cover money stolen by fraud?
Not always, and this is the gap that surprises people. The NCSC warns that some policies will not cover money lost through business email compromise. The Cyber Essentials insurance does not cover money stolen by electronic means at all.
Is standalone cyber cover better than an extension?
They are different products, not two sizes of one. An extension usually shares its limit and its conditions with the policy it sits inside. Read the schedule: if cyber does not have its own limit and its own excess, it is an extension.