United Kingdom. Small business cyber cover

What does cyber insurance cost a small business?

Cyber premiums are not priced like other small business covers. Turnover and sector matter, but what moves a quote most is a short list of controls the insurer will ask about directly, and a business that can answer yes to them is often quoted a fraction of one that cannot. This page sets out what underwriters ask, what the policy actually pays for when something happens, and the reporting duties that run alongside it regardless of whether you are insured.

The business
  • Free, and no obligation to buy anything
  • Your details go only to the brokers who respond
  • We are not a broker and give no insurance advice

What happens next

  1. Tell us the size of the business, what data you hold and which controls are already in place. Two minutes, no account.
  2. We pass your details to insurance brokers who place cyber risks, and to no one else.
  3. They come back with terms. We do not place insurance and we do not advise you on which policy to take.

Cyber Insurance Cost is an independent introducer site operated by Ellul Solutions Ltd. We are NOT authorised or regulated by the Financial Conduct Authority, and we are not an insurer or a broker. We do not advise, arrange or recommend any policy, cover or firm: we introduce you to insurance brokers by passing your details to them, and they deal with you directly. We may be paid a commission for that introduction by the firm we introduce you to, and it never changes the premium you are quoted. Nothing here is insurance, legal, data protection or security advice. No premium is published on this site because cyber cover is rated individually on your controls, sector, data and claims history. Reporting duties under data protection law exist independently of any policy and independently of whether you claim; take your own legal advice on what applies to your organisation. Check any broker on the FCA's Financial Services Register before sharing a security questionnaire.

What UK cyber underwriters ask a small business, and why, 2026

Last updated

Cyber quotes vary more on answers than on turnover, and the questions are consistent enough to prepare for. This table sets out what gets asked, what the insurer is really testing, and what a weak answer typically does to the terms offered.

This table describes the underwriting questions commonly put to UK small businesses and what each is testing. It quotes no premium and no discount percentage, because cyber cover is rated individually on the answers, the sector, the data held and claims history, and any figure published here would be illustrative rather than an offer. The security practices referenced are those the National Cyber Security Centre publishes guidance on, and the reporting duty referenced is the ICO's, which exists independently of any insurance policy. Whether a specific duty applies to your organisation is a question for your own advisers; this page describes the landscape rather than your obligations.

What UK cyber underwriters ask a small business, and why, 2026
What the insurer asksWhat it is really testingEffect of a weak answerWhat to do before you apply
Multi-factor authentication on email and remote accessWhether the most common intrusion route is closedOften the difference between terms and no terms at allTurn it on everywhere first; it is usually free and it is the highest-value single answer
Backups, and whether you have restored from themWhether ransomware is a disruption or an extinction eventSharply higher premium or a ransomware exclusionRun a real restore and note the date you did it
Payment process for emailed instructionsExposure to invoice fraud and impersonationLow sub-limits on funds transfer fraudIntroduce a call-back to a known number and write it down
Patching and end-of-life softwareWhether known vulnerabilities are being left openConditions or exclusions on unsupported systemsList what is unsupported and have a plan for it
Personal data held, and how muchThe size of a breach response, not just the hackDrives the limit you need rather than the price aloneCount the records honestly before you are asked
Prior incidents and claimsPattern rather than bad luckLoadings, or declinature after repeat eventsDisclose them; non-disclosure is worse than the loading
Who responds at 2amWhether the insurer's incident response is your planNot priced, but decides what the cover is worthAsk what the response service actually includes
  • Multi-factor authentication and tested backups are the two answers that move UK cyber terms most for a small business.
  • A backup that has never been restored from is treated by underwriters as an untested control rather than as a control.
  • Funds transfer fraud is commonly sub-limited well below the headline policy limit, so the headline is not the number that matters for invoice fraud.
  • A personal data breach may have to be reported to the ICO independently of whether an insurance claim is made.
  • The insurer's incident response service is often the most valuable part of a small business cyber policy, and it is not what the premium comparison measures.

Cite this page

“What UK cyber underwriters ask a small business, and why, 2026”, Cyber Insurance Cost, https://cyberinsurancecost.co.uk/ (updated 2026-08-15). This table describes the underwriting questions commonly put to UK small businesses and what each is testing. It quotes no premium and no discount percentage, because cyber cover is rated individually on the answers, the sector, the data held and claims history, and any figure published here would be illustrative rather than an offer. The security practices referenced are those the National Cyber Security Centre publishes guidance on, and the reporting duty referenced is the ICO's, which exists independently of any insurance policy. Whether a specific duty applies to your organisation is a question for your own advisers; this page describes the landscape rather than your obligations.

Common questions

How much does cyber insurance cost for a small business?

We publish no premium, because cyber cover is rated on the answers you give rather than on a rate card: controls, sector, data volume and claims history all move it, and any figure on a page like this would be illustrative rather than an offer. What is worth knowing is that the biggest lever is in your hands. Multi-factor authentication and tested backups typically move terms more than turnover does, and both are usually free to implement before you apply.

What do cyber insurers ask about?

A consistent short list: multi-factor authentication on email and remote access, whether you have backups you have actually restored from, how you handle payments made on emailed instructions, patching and unsupported software, how much personal data you hold, and any prior incidents. Each maps onto a loss type the market sees repeatedly, which is why the questions barely vary between insurers.

Why does having backups not count if I have not tested them?

Because claims experience is full of businesses whose backups turned out to be incomplete, encrypted along with everything else, or unrecoverable in a useful timeframe. Underwriters distinguish between having backups and being able to restore from them. Run a real restore of something that matters, note the date, and say so on the proposal form; it turns an assertion into evidence.

What does a cyber policy actually pay for?

Broadly three things. Your own costs, which is investigation, restoring systems and data, and business interruption. Your liability to others, including defence costs and the cost of dealing with a regulator. And an incident response service, which for a business with no in-house security function is often the most valuable part, because the first hours of an incident determine most of what it eventually costs.

What is a sub-limit and why does it matter?

An inner limit that applies to a specific loss type, well below the headline policy limit. Funds transfer fraud and social engineering are the ones that catch small businesses, because they are simultaneously the most likely loss and the most commonly sub-limited. A policy described as offering £1m of cover can carry a much smaller inner limit on exactly the event you are most likely to suffer. Compare the inner limits, not the headline.

Do I have to report a cyber incident to a regulator?

Possibly, and it is a separate duty from your insurance claim. Where personal data is involved, a breach may have to be reported to the Information Commissioner's Office, and that obligation exists whether or not you are insured and whether or not you claim. The two run on different clocks with different consequences, so treat them as parallel tasks from the first hour and take legal advice rather than deciding on commercial instinct.

How do I check the broker?

Search the firm on the FCA's Financial Services Register, which is free and public, before you send a security questionnaire or pay a premium. A cyber proposal form is a detailed description of your weaknesses, so it is worth knowing who you are giving it to. The FCA also publishes scam guidance describing the pattern to watch: urgency, an upfront payment, and an entity whose name is close to but not the same as the firm you were introduced to.

Sources

  1. NCSC, advice and guidance
  2. ICO, report a personal data breach
  3. FCA, the Financial Services Register
  4. FCA, the Consumer Duty
  5. Financial Ombudsman Service
  6. Financial Services Compensation Scheme
  7. FCA, protect yourself from scams
Get quotes