[nonimo]
EN
Download

Cyber insurance comparison for UK small businesses

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Almost half of UK businesses are insured against cyber risk in some way. Only one in ten holds a policy that was written for it. More than a fifth cannot say whether they have any cover at all, and that figure comes from a survey that put the question to the person in each organisation with the most responsibility for cyber security.

So the first comparison to make is between the policy you believe you bought and the document that gets read when you claim. The insurers come after that.

47 %of UK businesses insured against cyber risk in some way
10 %hold a specific cyber insurance policy
22 %do not know whether they have any cover at all
Cyber security breaches survey 2025/2026, DSIT, 30 April 2026, section 3.3

This guide compares that document across six routes to cyber insurance for small businesses in the United Kingdom, each read from the provider’s own published wording, product summary or application form on 16 September 2026, with every figure traced to the page it came from. It ends with a checklist you can take into a renewal meeting.

It does not tell you which one to buy, and the reason for that is a piece of UK law worth knowing before you read any comparison at all.

What cyber insurance for a small business costs a year

Two UK providers publish a price and the rest send you to a quote form. So the table below covers both: what is actually published, with the example it rests on, and where that puts a business of your size. The detail, and why a published price needs its footnote read, is further down.

BusinessWhat is actually publishedOur estimate, a year
Sole trader or virtual assistant, income up to £50,000£11.11 a month, about £133 a year, for £100,000 of cover with insurance premium tax included. PolicyBee, read 16 September 2026£130 to £400
2 to 20 people, professional services holding client datanothing published; every provider read for this guide sends you to a quote form£400 to £1,200
21 to 50 people, or turnover above £250,000nothing published, and Direct Line’s required backup interval tightens at £250,000 of turnover£1,200 to £4,000

The middle column is quoted from the source named in it, and the column on the right is our own estimate: not a quote, and not an insurer’s figure.

Where it comes from: it maps the published prices onto three size bands, the same three that two independent European sources use: Amrae’s LUCY study of 20,996 policies for 2025 (average premiums of €645, €1,600 and €5,000 by company size) and AIG’s own Irish service tiers (€899 or less, €900 to €4,999, €5,000 or more). Your premium comes out of your proposal form, not out of this table.

What being insured against cyber means in the UK right now

The government surveys UK organisations every year about how they handle cyber security, and the 2025/2026 edition was published on 30 April 2026. Its section on insurance is the most useful starting point there is on cyber insurance for small business, because it separates two things a quote page does not.

Of businesses overall, 37 per cent have cyber cover inside a wider insurance policy and 10 per cent have a specific cyber policy. Among micro businesses those figures are 37 and 8. Among small businesses, 40 and 15. The proportion with some form of cover has crept up from 43 per cent in 2023/2024 to 47 per cent now.

The fifth of businesses that do not know

One in five businesses, 22 per cent, told the survey they did not know whether they had any form of cyber security insurance. The survey was conducted with whoever the organisation itself named as having the most responsibility for cyber security, which makes that number a finding about documents rather than about people.

It is worth resolving before you compare anything, and your schedule will tell you in a line. If cyber appears with its own limit of indemnity and its own excess, you have a policy. If it appears as a named extension sharing the limit of the office policy around it, you have an extension, and the questions worth asking about the two are not the same.

Section on the scheduleLimit of indemnityExcess
Office contents£120,000£250
Public liability£2,000,000nil
Cyber risks£100,000£500, plus a time excess of 6 hours

Illustrative layout, figures invented. A cyber line with its own limit, its own excess and its own time excess is a policy. A cyber line reading “included” with no figures beside it is an extension of the section above.

Why an extension is not a smaller standalone policy

An extension inherits the conditions of the policy it sits inside. Direct Line for Business offers its Cyber Risks section only to Retail and Office and Professional customers, and its claims are administered by a different company from the one that handles the rest of the policy. That is not a criticism, just something you want to know before the week you need it.

A standalone policy brings its own conditions, its own definitions and usually its own incident response line. It also brings its own application form, which is where the insurer writes down what it is relying on. Firms that handle client data for a living, as many of those reading this do, tend to end up needing the second kind.

Why this page compares wordings and does not recommend one

In the United Kingdom, comparing insurance is closer to a regulated activity than most people writing comparisons let on. The FCA’s own guidance says so in a table, and the table is worth quoting because it draws the line exactly where this page has to sit.

PERG 5.15.4 G lists types of activity and whether each is regulated. The row for “explanation of the terms of a particular policy or comparison of the terms of different policies” answers “possibly”, and explains that it “is likely to amount to making arrangements under article 25(2)”, with the article 72C exclusion available where the activity is only the provision of information.

Recommending is a different row in the same table

Two rows down, the guidance is not hedged at all. “Advising that a customer take out a particular policy” is a regulated activity, because it “amounts to advice on the merits of a particular policy under article 53(1)”. So is advising a customer not to take out a particular policy. Telling you to avoid something is as regulated as telling you to buy it.

That is why there is no best buy here, no star rating and no shortlist. What follows is what each document says, with the document named, so that the comparison is yours to make. When the questionnaire lands and you have to write answers rather than read them, that is a separate job with separate risks.

What the cover actually pays for

Cyber policies split into losses you suffer and claims other people bring against you. Most of the UK documents read for this guide organise cover that way, even when the section names differ, and the order the sections appear in tells you what the insurer thinks it is selling.

Hiscox CyberClear puts your own losses first and organises everything else around them. Its policy summary lists six sections: your own losses, cyber business interruption, claims and investigations against you, losses from crime, bricking, and additional covers.

Head of coverWhat it pays forWhere it is written
Your own lossesForensics, legal costs, notifying data subjects and the regulator, ransom and negotiatorsHiscox policy summary, section A
Business interruptionLoss of income and increased cost of working, with a time excess before it startsHiscox section B; Direct Line, Cyber Risks
Claims against youBreach of confidence, data claims, investigations including UK GDPR investigationsHiscox section C
CrimeTheft of money or securities, employee dishonesty, social engineering transfersHiscox section D
BrickingRepair or replacement of connected equipment left unusableHiscox section E
Incident responseForensic, legal and public relations support, often a line open 24 hoursNCSC guidance; IASME summary; CFC product page

The crime section is the one to check most carefully, because it is the one the NCSC singles out. The NCSC’s guidance puts it plainly: “some insurance policies will not cover monies lost through business email compromise fraud”. The Cyber Essentials insurance does not cover it at all, and says so in one line under what is not covered.

Incident response is also where the products diverge most. CFC describes immediate incident response at nil deductible and unlimited reinstatements; IASME’s £25,000 policy gives a helpline, open 24 hours, whose crisis management runs against that same £25,000. Both are real cover. They are not the same product, and neither is what most people mean when they say a data breach.

The exclusions to look for in a UK wording

Exclusions are where a comparison earns its keep, because a quote does not show them to you. Three are worth finding before you sign, and one of them is in your policy by market rule rather than by the insurer’s choice.

Hiscox’s policy summary lists, among others, losses due to “the use of any outdated or unsupported computer system”, losses due to “war or due to cyber operations carried out by, at the direction or under the control of a state”, and losses from “any actual or alleged monitoring, tracking or profiling of an individual without their authorisation”.

At Lloyd’s, the state backed exclusion is compulsory

On 16 August 2022 Lloyd’s issued market bulletin Y5381 requiring that all standalone cyber-attack policies in risk codes CY and CZ include a clause excluding liability for losses from any state backed cyber-attack, taking effect “from 31 March 2023 at the inception or on renewal of each policy”.

The bulletin sets five minimum requirements, including that the clause exclude attacks that “significantly impair the ability of a state to function” and that it “set out a robust basis by which the parties agree on how any state backed cyber-attack will be attributed to one or more states”. So the question at renewal is which of the LMA model clauses your policy uses for it, and how attribution is decided.

The unsupported system exclusion is the one that bites a small office

Read that Hiscox exclusion again with your own kit in mind. An unsupported operating system on the machine in reception, an old server kept alive for one legacy application, a till nobody has patched since it was installed: any of those can be the thing that turns a covered loss into an argument.

This is also the exclusion most likely to interact with whatever you promised on the application form. You do not need a security programme to deal with it. You need a list of what you run and a note of what is still getting updates, which is the same list an AI policy starts from.

Fines, and the four words that decide whether yours is paid

The three UK documents read for this guide that mention regulatory fines all attach a condition to them, and it is the same idea written three ways. Direct Line covers “fines (where insurable by law)”. The Cyber Essentials policy covers “regulatory fines (where insurable by law)”. Hiscox goes further and defines the term.

Hiscox’s wording excludes “criminal, civil or regulatory sanctions, fines, penalties” and then carves back two things: PCI charges and regulatory awards. A regulatory award is defined as sanctions and fines following a privacy investigation “if insurable in the jurisdiction where such award was first ordered”.

£60,000
ICO penalty on DPP Law Ltd, a law firm in Bootle, under section 155(1) of the Data Protection Act 2018

So the policy does not tell you whether an ICO penalty is covered. It tells you the answer turns on whether such a penalty can lawfully be insured, and none of the three documents says what that answer is.

That is worth knowing before anyone writes the fine down as covered in a risk register. When a broker says a policy covers ICO fines, the useful next question is what the wording means by insurable, and who decides.

It matters because ICO penalties on smaller firms are not hypothetical. DPP Law Ltd, described in its penalty notice as a law firm headquartered in Bootle with fewer than 250 staff, was required to pay £60,000 after client data reached the dark web. What happened there is worth a section of its own, further down.

Excesses, waiting periods, and the two clocks that run at once

The excess is where published limits stop being comparable. A £100,000 limit with a £1,000 excess and a £100,000 limit with a waiting period of six hours on business interruption are different products, and nothing on the quote page tells you which you are looking at.

Here is what the UK documents actually say. The Cyber Essentials policy carries “a £1,000 excess (increasing to £5,000 for claims emanating from activities in the USA or Canada) and a six hour Network Interruption retention”. Direct Line applies “£500 excess … to any claim”. PolicyBee reduces the excess by £2,500 if 80 per cent of staff finish its online training, and says that where the excess was no higher than that, it disappears.

Hiscox does something different again, and it is the line worth carrying into any comparison: “If you notify us within 72 hours of your first awareness of any actual or suspected data breach, we will waive the excess in respect of that breach”, other than for business interruption losses and losses from crime.

Two different 72 hour clocks, and only one is in your policy

That 72 hours is not the UK GDPR one, and confusing them is easy. Article 33(1) requires a controller to notify the Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach. Hiscox’s 72 hours is a commercial incentive to tell your insurer early, measured from your first awareness of an actual or suspected breach.

They can run together and they have different consequences. Miss the regulator’s clock and you have a separate infringement. Miss the insurer’s and you pay an excess you could have avoided. Whether the thing that happened is even a breach in the first place is a question with its own machinery, and the answer decides which clock you are on.

What an insurer requires before it will cover you

This is where the UK providers diverge most sharply, and it is the part of a policy you can fail without noticing. Some ask for controls. Others ask for habits. The wording of the question decides what you are promising.

CFC’s Cyber Proactive Response application form for the UK is a single page. Its entire cyber security controls section is three questions answered yes or no, and all three are about the same two things. Quoted in full:

  1. “Please confirm whether multi-factor authentication is enabled and enforced for all remote access to your network.”
  2. “Please confirm whether multi-factor authentication is enabled and enforced for remote access to all company email accounts.”
  3. “Please confirm whether you have offline back-ups that are fully disconnected from your live environment or cloud-based back-ups with access secured by multi-factor authentication.”

That is the whole of it. Three ticks decide whether an underwriting agency with more than 100,000 cyber customers worldwide will write your risk, and they are the same three ticks for a practice of two people and for a business turning over £200 million.

ProviderWhat it requires, in its own wordsWhere
CFCMulti-factor authentication “enabled and enforced for all remote access to your network”UK application form v12
CFCThe same for “remote access to all company email accounts”, plus disconnected or protected backupsUK application form v12
Direct LineAntivirus updated every 30 days, or every 7 above £250,000 turnoverCyber insurance page, FAQ
Direct LineBackups every 30 days, or every 7 above £250,000 turnover, and police reported promptlyCyber insurance page, FAQ
Cyber Essentials policy“Install and maintain automatically provided updates … for critical business software”IASME insurance FAQ

Two things stand out. First, turnover is doing real work in the Direct Line conditions: cross £250,000 and your required backup interval goes from monthly to weekly, which is a condition you can breach by growing. Second, nobody in this group asks about training, governance or suppliers, which are the questions that dominate the security questionnaires clients send.

The DPP Law gap: authentication on the VPN, not on the service account

The ICO penalty notice on DPP Law is the best worked example a UK firm has, and the detail that matters is in a single sentence of paragraph 20. At the time of the incident the firm had multi-factor authentication for connecting to its network by VPN. The administrator account, sqluser, “did not have MFA due to its role as a service-based account”.

The intruder reached that account after a user’s laptop was compromised, and there was no second factor in the way. Attempts to break into an administrator account on a legacy case management system by brute force had been running since 19 February 2022, 400 in all, and the data of 791 clients and experts ended up published on the dark web.

Now read CFC’s question again with that in mind. “Enabled and enforced for all remote access to your network” is a yes or no, and a firm in DPP’s position could have answered yes in good faith while the exception that mattered sat outside the question. The condition is not wrong, just not the whole shape of the risk, and the gap between them is yours to find.

Section 11 of the Insurance Act, and the condition you broke by accident

Breaching a condition does not automatically cost you the claim, and UK law is unusually helpful here. Section 11 of the Insurance Act 2015 applies to terms that would tend to reduce the risk of loss of a particular kind, at a particular location or at a particular time.

If you breach such a term and a loss happens, the insurer “may not rely on the non-compliance to exclude, limit or discharge its liability” if you can show that the breach “could not have increased the risk of the loss which actually occurred in the circumstances in which it occurred”.

In plain terms: if your backups slipped to once every 40 days and the loss was a fraudulent payment, the late backup did not cause it. That is a real defence and worth knowing, but not an excuse to let the condition slide, because proving the negative is your job, not the insurer’s.

Fair presentation: the UK rule that turns a bad answer into a refused claim

Everything an insurer requires arrives attached to something you sign, and in the United Kingdom what you sign is governed by the Insurance Act 2015. Direct Line’s own policy summary puts it in the customer’s language: “You need to make a fair presentation of your business to us.”

Section 3(1) says the insured must make a fair presentation of the risk before the contract is entered into. Section 3(4)(a) requires disclosure of “every material circumstance which the insured knows or ought to know”. Section 3(3)(c) requires every material representation of fact to be “substantially correct”.

What the remedies are, and why they are not all or nothing

The remedies sit in Schedule 1, and they are graded. If the breach was deliberate or reckless, the insurer may avoid the contract, refuse all claims and keep the premium. If it was neither, and the insurer would not have written the risk at all, it avoids but returns the premium.

If the insurer would have written it on different terms, the contract is treated as if it carried those terms. If it would have charged more, the insurer “may reduce proportionately the amount to be paid on a claim”. Section 8(6) puts the burden on the insurer to show that a breach was deliberate or reckless.

The breach of fair presentationWhat the insurer may do
Deliberate or recklessAvoid the contract, refuse all claims and keep the premium
Neither, and it would not have written the risk at allAvoid the contract and return the premium
Neither, and it would have written it on different termsTreat the contract as if it carried those terms
Neither, and it would have charged moreReduce proportionately the amount paid on a claim

Insurance Act 2015, Schedule 1: the remedies for a qualifying breach.

So the worst case is reserved for people who knew, and the ordinary case is a smaller payout on a policy you thought was whole. That is the real cost of a rushed answer on a form. What a good answer looks like, question by question, is the subject of its own guide.

What UK policies say about AI, measured rather than assumed

Eight UK cyber insurance documents were opened for this guide and searched for the words artificial intelligence, machine learning and generative. The Hiscox CyberClear policy summary and its policy wording: nothing. CFC’s UK application form and its May 2026 brochure: nothing. Direct Line’s cyber page and its policy summary of 18 pages: nothing. PolicyBee’s cyber page: nothing. Hiscox’s own cyber product page mentions artificial intelligence exactly twice, and both are entries in the dropdown list of trades it will insure.

0
times AI is named as a risk, a cover or an exclusion in eight UK cyber insurance documents, read 16 September 2026

The NCSC’s own cyber insurance guidance is in the same position, and more starkly. It runs to a little over 2,000 words, it is the government’s standard reference for UK buyers, and it has carried the same version number since it was published on 6 August 2020. It does not contain the word AI.

Chubb addresses it, and not in a wording

Chubb is the exception, and what it says is more useful than a clause would be. Its UK guide for SMEs carries the summary of its 2026 EMEA Cyber Claims Report: “Rather than creating entirely new categories of claims, AI acts as a multiplier across existing perils including Cyber, Crime, D&O and Liability.”

Read alongside the silence in the wordings, that is a coherent market position rather than an oversight. The peril is still ransomware, still fraudulent payment, still a data breach. AI changes how often and how convincingly, not what the policy is called.

Silence is not the same as cover

Do not turn that into comfort. A wording that says nothing about AI has not agreed to anything about AI, and the place the question will be decided is the definitions, not a headline. If an employee pastes a client file into a chat tool and it later appears somewhere it should not, the wording will be read for what counts as an unauthorised disclosure and whether your own act breaks the chain.

What happened to the file before that depends on the tool. In ChatGPT, who your data controller is depends on where the firm sits. With Microsoft the answer changes by product, and four of them share the Copilot name. Google prints a sentence on the subject, and what that sentence means for a firm is not what it first suggests.

The gap between adoption and control is measurable and it is wide. The same government survey found that 31 per cent of businesses are using AI, adopting it or considering it, and that among those, only 24 per cent have security practices in place to manage the risks. A further 31 per cent have no plans to introduce any. One of those practices costs nothing: switching off model training in the AI tools your staff already use, Claude included.

31 %of businesses use AI, are adopting it or are considering it
24 %of those have practices to manage the risks
31 %of those have no plans to introduce any
Cyber security breaches survey 2025/2026, section 3.11, a section new this year

That last figure is the one an underwriter will eventually start asking about, whatever the regulatory calendar does next. Until then, the answer you give about AI belongs in your own written record, not in a clause that does not exist yet.

Six routes to cyber cover in the UK, compared

Below is what the six routes look like when you read their documents rather than their headlines. Limits are what each provider publishes; conditions are quoted from the source named in the row.

RouteLimit publishedKey conditionHow you buy it
Hiscox CyberClear£25,000 crisis containment as standard, rest in the scheduleExcess waived if you notify within 72 hoursOnline quote, and through brokers
Direct Line for Business£25,000, £50,000 or £100,000Antivirus and backup intervals by turnoverOnline, as an extension
CFC Cyber Proactive ResponseNot published; written for revenues £0 to £250mAuthentication on remote access and emailBroker only, traded on Connect
PolicyBee£100,000 cyber; £50,000 cybercrimeCyber Essentials may earn a discountOnline, under two minutes
Cyber Essentials policy£25,000 total limit of indemnityTurnover under £20m, domiciled in the UK, self-certifiedComes with certification
AXADoes not offer cyber directlyNot applicableReferral to InSync, a broker

Sources, in row order: the Hiscox cyber and data insurance page and policy summary reference 19029; the Direct Line cyber insurance page; the CFC product page and UK application form v12; the PolicyBee cyber page; the IASME cyber liability insurance page; the AXA cyber insurance page. All read on 16 September 2026.

The £25,000 that arrives with a certificate

IASME states that an organisation domiciled in the UK with turnover under £20 million that achieves self-assessed Cyber Essentials certification covering the whole organisation is entitled to cyber liability insurance, underwritten by American International Group UK Limited and administered by Sutcliffe and Co.

5 %
of UK businesses hold Cyber Essentials, up from 3 per cent the previous year. Cyber security breaches survey 2025/2026

IASME is candid about the size of it: the £25,000 limit “might be sufficient for a small breach or incident but inadequate for a serious problem or more than one incident”. Take it as a floor that comes free with a certification you may want anyway, not as the answer. Only 5 per cent of UK businesses hold Cyber Essentials at all, so for most firms this is a door they have not opened.

Where AXA and Aviva actually send you

One of the household names says it does not sell this directly. The other simply does not list it. AXA’s cyber insurance page carries the line in a footnote: “While AXA does not directly offer cyber insurance, our trusted partner can assist you in finding the right protection.” The partner is InSync Insurance, a broker.

Aviva is quieter about it. Its UK business insurance page lists its direct products and then the ones “available through a broker”, and cyber is not in either list. Its cyber material sits inside Aviva Risk Management Solutions, which is written for brokers and larger clients.

Neither of these is a failing, but it does save you an afternoon hunting for a quote form that is not there, and it is a reminder that a broker is part of this market, not an optional extra.

What is published about price, and what a published price means

Of the providers read for this guide, two publish a figure and the rest send you to a quote form. There is a reason for that: a cyber premium turns on turnover, sector, data held, controls and claims history, so a number without its example means nothing.

PolicyBee publishes two, with the example stated: cyber insurance “from £11.11 a month for £100,000 cover” and cybercrime cover at “£6.89 a month” for a £50,000 limit, “based on a quote for a virtual assistant with an annual income of up to £50,000”, with all prices including insurance premium tax at 12 per cent. Those are the figures its page showed on 16 September 2026.

Hiscox publishes one too, and it is the kind that needs its footnote read. Its cyber page says business insurance quotes “start from £7.20” a month, and the asterisk explains that the figure is “based on an average of all business insurance policies sold to at least 10% of our customer base between August 2025 and August 2026”. That is a floor across everything it sells, not a cyber price.

Take three things from that. The PolicyBee example is a sole worker with modest income, which is the cheapest shape of risk there is. The figure includes the tax, and not every quote does. And a price that starts with the word from is a quote for somebody else until you have run your own.

Cost is not the main reason firms go without

The survey asked businesses without cyber insurance why, and the answers are not the ones the market assumes. Not being aware of cyber insurance came first at 39 per cent. Not a budgetary priority came second at 34 per cent, and leadership not being interested third at 27 per cent. Too expensive was fourth, at 19 per cent.

Not aware of it39 %
Not a budgetary priority34 %
Leadership not interested27 %
Too expensive19 %
Why UK businesses have no cyber insurance. Cyber security breaches survey 2025/2026, figure 3.5, base 267

Only 8 per cent said the cover was not broad enough. So buyers are not rejecting cyber insurance after reading the exclusions. Most of them have not got as far as the documents, which is the gap guides like this one exist to close.

The checklist to take into your renewal

What follows is the whole of this guide compressed into fifteen questions, in the order the documents answer them, each with the document that answers it and what a good answer looks like. Written for a UK business buying or renewing cover: take it to the meeting and write the answer next to each one from your own schedule and wording, not from a quote summary.

Nothing in it is specific to a provider, and none of it requires buying anything. Several of the answers will be in documents you already hold, and the ones that are not are the ones worth an email before you renew. It is free to use and you do not have to give us an email address for it, as with the rest of our guides.

Where the answer isWhat it settlesQuestions
The scheduleStandalone or extension, the limit, the money excess and the time excess1 to 4
The policy wordingCrime cover, fines, the state backed and unsupported system exclusions, notification, AI5 to 8, plus 13 and 14
The application form and its declarationThe controls you promise, their exceptions, the fair presentation9 to 11
The policy summary or product pageThe incident line, and who underwrites and administers the claim12 and 15

The fifteen questions below, grouped by the document that answers them.

  1. Is this a standalone cyber policy or an extension of another policy? Cyber security breaches survey 2025/2026, section 3.3: 37 per cent of businesses have cyber inside a wider policy, 10 per cent a policy of its own. Look for: a cyber section with its own limit and its own excess. Keep: the schedule page that states both.
  2. What is the limit of indemnity, and is it the total for the year? Hiscox pays “up to the overall limit of indemnity shown in the schedule for the total of all claims under each section”. Look for: whether inner limits apply to individual covers. Keep: the schedule and the how much we will pay clause.
  3. What is the excess, and is there more than one? The Cyber Essentials policy has “a £1,000 excess … and a six hour Network Interruption retention”. Direct Line applies £500 to any claim. Look for: a money excess and a separate time excess. Keep: both, written down, before you compare two quotes.
  4. Is business interruption covered, and from what hour does it run? A time excess is the period after the incident for which you are not covered. It can be hours, and it decides whether you recover anything. Look for: the time excess in the schedule. Keep: your own estimate of what one day offline costs you.
  5. Is theft of money covered, or only the cost of the attack? The NCSC warns that “some insurance policies will not cover monies lost through business email compromise fraud”. Look for: a crime or cybercrime section, and whether it is an add-on. Keep: the section name and its own limit.
  6. Does the policy cover regulatory fines, and on what condition? Direct Line covers “fines (where insurable by law)”. Hiscox pays a regulatory award “if insurable in the jurisdiction”. Look for: those words, then ask what the insurer means by them. Keep: the definition, not the marketing sentence.
  7. Which state backed cyber-attack exclusion does the policy use? Lloyd’s market bulletin Y5381 has required one in standalone policies since 31 March 2023, and the LMA publishes four model clauses. Look for: which model clause, and how attribution is decided. Keep: the clause reference for your file.
  8. Is there an exclusion for outdated or unsupported systems? Hiscox excludes losses due to “the use of any outdated or unsupported computer system”. Look for: the wording, then check it against your own inventory. Keep: a list of what you run and what is still supported.
  9. What security controls does the insurer require, exactly? CFC’s UK application asks three questions: authentication on remote network access, the same on email, and disconnected backups. Look for: conditions that scale with turnover, as Direct Line’s do. Keep: evidence that each one is true today, not last year.
  10. Does any required control have an exception nobody has written down? DPP Law had authentication on its VPN. The service account did not, and that was the way in. The ICO penalty was £60,000. Look for: service accounts, legacy systems, contractors, shared logins. Keep: the list of exceptions, and a date to close each one.
  11. Who signs the fair presentation, and have they seen the answers? Section 3 of the Insurance Act 2015 requires disclosure of every material circumstance the insured knows or ought to know. Look for: the declaration at the end of the form. Keep: the completed form, with the evidence for each answer attached.
  12. Is there an incident line open 24 hours, and who answers it? CFC provides immediate incident response at nil deductible. The Cyber Essentials helpline runs against the same £25,000 total limit. Look for: whether response costs erode the limit. Keep: the number, offline, where you can reach it without your network.
  13. How long do you have to notify, and does early notice buy anything? Hiscox waives the excess if you notify within 72 hours of first awareness, other than for business interruption and crime. Look for: the notification clause, and its starting point. Keep: it next to your Article 33 breach procedure. They are not the same.
The regulator's clock · UK GDPR, Article 33(1)

Tell the Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach. Miss it and you have a separate infringement.

The insurer's clock · Hiscox

Notify within 72 hours of first awareness of an actual or suspected breach and the excess is waived, other than for business interruption and crime. Miss it and you pay the excess.

Two 72 hour clocks that can run at once. UK GDPR Article 33(1) and the Hiscox CyberClear policy summary
  1. Does anything in the wording mention artificial intelligence? None of the eight UK cyber insurance documents opened on 16 September 2026 names it as a risk, a cover or an exclusion. Chubb addresses it in a claims report, not in a wording. Look for: definitions of unauthorised disclosure and of your own act. Keep: your written record of which AI tools staff are allowed to use.
  2. Who is the insurer, and who handles the claim? Direct Line’s Cyber Risks claims “are administered by HSB Engineering Insurance Limited”. The Cyber Essentials policy is underwritten by AIG UK. Look for: the underwriter, the administrator and the broker separately. Keep: all three names in one place before you need any of them.

Before you sign: read the schedule and the wording together. The schedule holds the numbers and the wording holds the meaning, and a quote summary holds neither. This is general information about UK insurance documents, not advice about whether any particular policy suits your business.

Where a masking tool sits in this, and where it does not

We build Nonimo, which masks names and identifiers in text on the machine before you paste it anywhere, so it would suit us if cyber underwriters asked about that. On the evidence read here, they do not. The one UK application form read for this guide, CFC’s, has no question about masking, redaction or data minimisation in outbound text, and neither does anything else read here.

What it speaks to is narrower and worth saying precisely. It reduces what leaves your office in a prompt. What the app keeps on your computer, and the daily usage count it sends without a word of your text, are set out on Nonimo’s security page. A policy that requires authentication on remote access is asking about something else entirely, and no honest answer to that question improves because you run our software.

So for most readers of this page the correct conclusion is to buy nothing from us, and instead to open your schedule, work through the fifteen questions, and send the three you cannot answer to your broker. If after that you decide the outbound text is a real exposure in your organisation, that is the conversation where a tool like ours belongs, and not before.


Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account, and your client’s details never leave your machine.

Sources

Every document below was opened and read on 16 September 2026. Where a figure is quoted, the section or page it came from is named.

This page is general information about how UK cyber insurance documents are written. It is not a recommendation to buy or to avoid any policy, and it is not advice about whether a particular policy suits your business.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

How do I compare cyber insurance for a small business in the UK?

Compare the documents, not the sales pages. Read the schedule for the limit and the excess, the wording for the exclusions and the conditions, and the application form for what the insurer will hold you to. The checklist at the end of this guide lists the questions in order.

Do most UK small businesses have cyber insurance?

Almost half have some form of cover. The government's Cyber security breaches survey 2025/2026 found 47 per cent of businesses insured against cyber risk in some way, but only 10 per cent held a specific cyber policy. The rest have cover inside a wider policy.

Does cyber insurance cover an ICO fine?

Only where the law allows a fine to be insured, and UK wordings say so in those words. Hiscox pays a regulatory award only if it is insurable in the jurisdiction that ordered it. Direct Line covers fines where insurable by law. The policy does not settle the question.

What do insurers require before they will cover a small firm?

Most often multi-factor authentication on remote access and on email, plus backups that are disconnected or separately protected. CFC's UK application, a single page, asks those three things and nothing else about security. Direct Line instead sets antivirus and backup intervals.

Is cyber insurance included with Cyber Essentials?

For some organisations. IASME states that an organisation domiciled in the UK with turnover under £20 million that self-certifies to Cyber Essentials across the whole organisation is entitled to cyber liability insurance with a £25,000 limit of indemnity, underwritten by AIG UK.

How much does cyber insurance cost for a small UK business?

Published prices exist but always rest on a named example. PolicyBee publishes cyber cover from £11.11 a month for a £100,000 limit, based on a quote for a virtual assistant with an annual income of up to £50,000, with insurance premium tax included.

Do cyber policies mention artificial intelligence?

Not in the ones we read. None of the eight UK cyber insurance documents opened on 16 September 2026, including two Hiscox policy documents and CFC's application form, names AI as a risk, a cover or an exclusion. Chubb addresses it in a claims report rather than in a wording.

What is a fair presentation of the risk?

The duty in section 3 of the Insurance Act 2015 to disclose every material circumstance you know or ought to know, clearly enough for a prudent insurer. Get it wrong and Schedule 1 lets the insurer avoid the policy, rewrite the terms or cut the payout.

Does a cyber policy cover money stolen by fraud?

Not always, and this is the gap that surprises people. The NCSC warns that some policies will not cover money lost through business email compromise. The Cyber Essentials insurance does not cover money stolen by electronic means at all.

Is standalone cyber cover better than an extension?

They are different products, not two sizes of one. An extension usually shares its limit and its conditions with the policy it sits inside. Read the schedule: if cyber does not have its own limit and its own excess, it is an extension.