The short answer: No UK law makes a business buy cyber insurance, but most businesses that rely on email, cloud systems or customer data should seriously consider it. Almost half of UK businesses (47%) have some cover, yet only 10% hold a specific cyber policy, according to the government’s Cyber Security Breaches Survey. Before insurers quote, they will ask about your IT: multi-factor authentication, backups, endpoint protection, patching and admin access come up again and again, and wrong answers on the proposal form can reduce a claim or let the insurer refuse it.
Last updated: 6 October 2026. Checked against the Cyber Security Breaches Survey 2025/2026, NCSC guidance, IASME, the ABI and the Insurance Act 2015 on that date. We are an IT provider, not an insurer or broker: for advice on a specific policy, speak to a regulated insurance broker.
In this guide
- Do you need cyber insurance?
- What does cyber insurance cover?
- What will insurers ask about your IT?
- What does cyber insurance not cover?
- Why your answers on the proposal form matter
- Does Cyber Essentials help with cyber insurance?
- How much are insurers paying out?
- Will insurance pay a ransom?
- Before you buy or renew: a checklist
- Frequently asked questions
Do you need cyber insurance?
You are not legally required to have cyber insurance, but it is worth having if a cyber incident would cost you money you could not easily absorb: lost trading days, an IT specialist working through the weekend, legal advice, notifying customers, or a claim from a client whose data was exposed. Some larger clients and contracts also ask suppliers to hold it, so check your contracts.
Many businesses already have some cover without realising, because it is often bundled into a wider business policy. The Cyber Security Breaches Survey 2025/2026 found that 47% of businesses and 35% of charities were insured against cyber risks in some way, but “only 10% of businesses and 5% of charities had a specific cyber security insurance policy”. Bundled cover is often narrower than a standalone policy, so it is worth checking what yours actually includes.
| Business size | Covered as part of a wider policy | Specific cyber policy |
|---|---|---|
| Micro (1 to 9 staff) | 37% | 8% |
| Small (10 to 49 staff) | 40% | 15% |
| Medium (50 to 249 staff) | 36% | 24% |
| Large (250+ staff) | 22% | 32% |
| All businesses | 37% | 10% |
In total, 55% of small and 61% of medium businesses had some form of cover, and 22% of businesses did not know whether they were covered at all. The survey describes take-up as broadly consistent over recent years (43% in 2023/2024, 45% in 2024/2025 and 47% in 2025/2026). The smallest firms, which are least likely to have IT staff or spare cash to recover from an incident, are also the least likely to hold a dedicated policy.
Insurance is a backstop, not protection. The NCSC puts it plainly: “Cyber insurance will not instantly solve all of your cyber security issues, and it will not prevent a cyber breach/attack” (NCSC cyber insurance guidance). The controls that make you insurable are the same ones that protect against the most common attacks, which is why the rest of this guide focuses on them.
What does cyber insurance cover?
A cyber policy typically pays for the cost of responding to an incident, the income you lose while systems are down, and claims made against you by others. Wording varies a lot between insurers, so treat this as a guide to what to look for rather than a promise of what any policy includes. As a real example, the policy included at no extra cost with Cyber Essentials certification (described by IASME) includes these sections:
| Section | What it pays for |
|---|---|
| Incident response and event management | Specialist IT forensics, data recovery, legal advice, notifying affected people, credit monitoring and reputation management |
| Business and network interruption | Lost income while your systems are down, usually after a waiting period (a six-hour network interruption retention on the Cyber Essentials policy) |
| Extortion | Costs of dealing with a threat, such as ransomware |
| Liability | Claims against you, for example from customers whose data was exposed, and media liability |
| Regulatory investigations | Defence costs, and fines where they are insurable by law |
The NCSC suggests seven questions to ask before you buy, including “What does the cyber insurance policy cover (or not cover)?”, “Does the policy include support during (or after) a cyber security incident?” and “What must be in place to claim against (or renew) your cyber insurance policy?” The last one is the question most businesses skip, and the one that matters most if you ever claim.
What will insurers ask about your IT?
Insurers ask whether you have the basic security controls that protect against the most common attacks, and insurance broker Marsh warns that businesses which do not meet insurers’ expectations often face non-renewal or cannot get their preferred cover, with limits on ransomware cover becoming more common. Marsh lists twelve key controls and in its UK guidance notes that insurers “consistently scrutinise privileged account management”, alongside patching and endpoint detection and response. These are the twelve, with what each means for a small business:
| Control (as Marsh names it) | What it means in practice | What to have ready |
|---|---|---|
| Multifactor authentication (MFA) for remote access and privileged or administrator access | A code or app approval as well as a password, on email, Microsoft 365, remote access and every admin account | A report showing MFA is enforced for all users, not just available |
| Email filtering and web security | Scanning of incoming email and blocking of malicious links and websites | Which email security service you use and what it covers |
| Secured, encrypted, and tested backups | Backups that ransomware cannot reach or delete, including Microsoft 365 data, restored as a test | Where backups are kept, how often they run, and the date of your last test restore |
| Privileged access management (PAM) | Separate admin accounts used only for admin work, kept to as few people as possible | A list of who has admin rights, and why |
| Endpoint detection and response (EDR) | Security software on every laptop, PC and server that detects and contains suspicious behaviour, not just known viruses | The product name and confirmation it is on every device |
| Patch and vulnerability management | Security updates installed promptly on computers, servers, firewalls and apps | Patching reports, and how quickly critical updates are applied |
| Incident response plans | A written plan for who does what if you are attacked, including who to phone | The plan, and when it was last reviewed |
| Cybersecurity awareness training and phishing testing | Regular short training so staff recognise phishing and payment fraud | Training records |
| Remote desktop protocol (RDP) mitigation and other hardening techniques | No remote desktop open to the internet, default passwords changed, unnecessary services switched off | Confirmation that RDP is not exposed |
| Logging and monitoring | Sign-ins and security events recorded and watched, so problems are spotted | Who monitors alerts, and when |
| Replacement or protection of end-of-life (EOL) systems | No unsupported software, such as Windows 10 without extended updates, or isolated if it must stay | A device list showing operating system versions |
| Digital supply chain cyber risk management | Knowing which suppliers can access your systems or data, and checking they are secure | A supplier list, including your IT provider |
Questionnaires differ between insurers, and smaller policies may ask only a handful of these. MFA, backups and endpoint protection are the ones to have in place first. If your Microsoft 365 licence already includes the tools (Business Premium does), our guide to Microsoft 365 Business Premium explains what to switch on.
What does cyber insurance not cover?
Most policies have exclusions, limits and conditions that catch businesses out. These are the ones to look for in the wording before you sign:
- Money stolen through payment fraud. Losses from invoice fraud and fake bank detail changes are not always covered. The Cyber Essentials policy, for example, excludes “money stolen by electronic means or cyber fraud”. If this matters to you, ask specifically whether social engineering or funds transfer fraud is covered and at what limit. Our guide to invoice fraud and business email compromise explains how these scams work.
- State-backed attacks. Since 31 March 2023, Lloyd’s has required standalone cyber policies written in its market to exclude losses from state-backed cyber attacks that significantly impair a state’s ability to function or its security capabilities (Lloyd’s Market Bulletin Y5381). Policies outside Lloyd’s may have their own war or state-backed exclusions, so check the wording.
- The excess and waiting period. The Cyber Essentials policy has a £1,000 excess and a six-hour network interruption retention (a waiting period before that cover applies). Other policies will differ, so check both.
- Controls you said you had but did not. If you told the insurer MFA was on for everyone and it was not, the claim may be reduced or refused. See the next section.
- Limits that are too low. A £25,000 limit can be used up quickly by forensic investigators and lost income. Ask your broker how the limit compares with what a week of downtime would cost you.
- Improvements. Ask whether the policy pays to replace old systems with better ones after an incident, or only to restore what you had.
Why your answers on the proposal form matter
Under the Insurance Act 2015, a business buying insurance must make “a fair presentation of the risk” before the contract starts, and every material statement of fact must be “substantially correct” (section 3). Ticking “yes” to MFA or tested backups when that is not true is the kind of statement that can come back to bite you.
What happens if an answer turns out to be wrong depends on how serious it was. Under Schedule 1 of the Act, the insurer has remedies where it would not have offered the same terms had it been told the truth. If the misstatement was deliberate or reckless the insurer can avoid the policy, refuse all claims and keep the premium. If it was an honest mistake, the remedy depends on what the insurer would have done had it known: refuse cover altogether (returning the premium), apply different terms, or pay only a proportion of the claim if it would have charged more.
Policies also contain ongoing conditions, such as keeping MFA switched on or backing up regularly. These are separate from your answers on the form. Section 11 stops an insurer relying on a breach of this kind of condition if you can show the breach could not have increased the risk of the loss that actually happened. It does not help if the missing control is relevant to how the incident happened, and business policies can vary some of these default rules, so the wording of your policy matters.
The practical lesson: answer the IT questions with whoever runs your IT, and fix the gaps before you sign rather than after. Your IT provider should be able to tell you, with evidence, which answers are true today.
Does Cyber Essentials help with cyber insurance?
Yes. Insurance data reported by the government shows that “organisations with Cyber Essentials are 92% less likely to make a claim on their insurance than those without it” (the then cyber security minister Feryal Clark, 23 October 2024). The NCSC Annual Review 2025 attributes the figure to data from the Cyber Essentials insurance provider. It shows that certified organisations claim less, not that the certificate alone caused the difference. The five Cyber Essentials controls (firewalls, secure configuration, user access control, malware protection and security updates) also overlap heavily with what insurers ask, and since 27 April 2026 missing MFA on cloud services, or not installing high-risk or critical updates within 14 days, is an automatic fail.
Certification also includes cyber cover at no extra cost for eligible organisations who opt in. According to IASME:
| Feature | Cyber Essentials cyber liability insurance |
|---|---|
| Limit | £25,000 total |
| Who is eligible | UK or Crown Dependency organisations with turnover under £20 million that certify the whole organisation |
| How you get it | Opt in when you complete the Cyber Essentials assessment |
| Insurer | AIG, administered by Sutcliffe & Co Insurance Brokers |
| Incident support | A 24-hour helpline for crisis management and incident response, within the £25,000 limit |
| Excess | £1,000 (£5,000 for claims in the USA or Canada) |
| Main exclusion to note | Money stolen by electronic means or cyber fraud |
| How long it lasts | 12 months from certification; it renews only when you renew Cyber Essentials |
| Higher limits | £100,000 or £250,000 available at extra cost |
For a very small business, that may be a sensible starting point. For many businesses with more than a handful of staff, £25,000 is a floor rather than enough, and a standalone policy arranged through a broker is worth pricing. Our Cyber Essentials requirements guide explains the 2026 rules, and our Cyber Essentials cost guide sets out the fees.
How much are cyber insurers paying out?
Payouts are rising sharply. Data from insurers in the Association of British Insurers’ data collection shows that “£197 million was paid out to help businesses recover from cyber incidents in 2024”, a 230% increase on the amount paid in 2023 (ABI, November 2025). Malware and ransomware accounted for 51% of claims, up from 32% the year before, and 17% more policies were taken out than in the previous year.
With malware and ransomware now behind half of claims, it is no surprise that insurers focus so heavily on backups and MFA. An attacker who gets in through an account without MFA and then finds backups they can delete can turn a bad day into weeks of disruption.
Will cyber insurance pay a ransom?
Some policies include extortion cover, but whether a ransom can be paid is not just a question for the insurer. In July 2025 the government announced plans to ban public sector bodies and critical national infrastructure operators from paying ransoms, to require other businesses to notify the government before paying, and to introduce mandatory reporting of ransomware incidents. At the time of writing (October 2026) these measures have not yet become law, so check the current position, and your policy wording, before relying on extortion cover.
Either way, paying is no guarantee of getting your data back. The surest route to recovery is backups that the attackers cannot reach.
Before you buy or renew: a checklist
- Find out what you already have. Check whether your existing business policy includes any cyber cover, and what it excludes.
- Get the questionnaire early. Ask your broker for the insurer’s IT questions a month or two before renewal, not the week before.
- Go through it with your IT provider. Answer each question with evidence, not memory.
- Fix the gaps first. MFA everywhere, backups that are separate and tested, endpoint protection on every device, patching up to date and admin rights cut back.
- Check the exclusions. Especially payment fraud, the excess, waiting periods and any conditions you must keep meeting.
- Check the limit. Work out roughly what a week without your systems would cost, and compare it with the cover.
- Know who to call. Keep the insurer’s incident helpline number somewhere you can reach it if your email and files are down.
- Consider Cyber Essentials. It proves the basics are in place and, for eligible smaller businesses that opt in, includes £25,000 of cover.
How ATS Connection helps
We do not sell insurance or advise on policies. What we do is run the IT that insurers ask about, so you can answer the questionnaire honestly and meet its requirements. Our Core support package (from £30 per user per month) includes patching, endpoint protection, 24/7 proactive monitoring and staff onboarding and offboarding. Complete IT and security (from £55 per user per month) adds managed cyber security, Microsoft 365 management, backup and disaster recovery, and Cyber Essentials guidance. See our IT support packages and pricing for the detail.
We are Cyber Essentials certified ourselves, and supported Cyber Essentials certification costs £510 plus VAT for businesses with up to 9 employees. If your renewal is coming up, book a free IT review and bring the insurer’s questions with you: we will tell you which answers are true today and what needs fixing. You can also read more about our cyber security services or our plain-English guide to what cyber security covers.
Frequently asked questions
Is cyber insurance a legal requirement in the UK?
No. No UK law requires businesses to hold cyber insurance. Some clients and contracts ask suppliers to have it, so check your contracts, and consider it if a cyber incident would cost more than you could comfortably absorb.
How many UK businesses have cyber insurance?
The Cyber Security Breaches Survey 2025/2026 found that 47% of UK businesses were insured against cyber risks in some way, but only 10% had a specific cyber security insurance policy. Among micro businesses, only 8% had a specific cyber policy.
What do cyber insurers ask about your IT?
Most ask about multi-factor authentication, backups, endpoint protection, patching, admin access, email security, staff training and incident response plans. Insurance broker Marsh lists twelve key controls that underwriters look for.
What does cyber insurance not cover?
Common gaps include money stolen through payment or invoice fraud, some state-backed attacks (Lloyd’s policies must exclude the most severe), losses during the waiting period, the excess, and claims where the business said it had security controls that were not actually in place. Policies differ, so read the exclusions before you buy.
Does Cyber Essentials include cyber insurance?
Yes, for eligible organisations. Organisations in the UK or Crown Dependencies with turnover under £20 million that certify the whole organisation can opt in to £25,000 of cyber liability insurance from AIG at no extra cost. It lasts 12 months and renews with the certificate.
Can an insurer refuse a cyber claim if my answers were wrong?
Yes. Under the Insurance Act 2015, where the insurer would not have offered the same terms had it known the truth: if a wrong answer was deliberate or reckless the insurer can refuse all claims and keep the premium. If it was an honest mistake, the insurer can refuse cover, change the terms or reduce the claim proportionately, depending on what it would have done had it known.
Does cyber insurance stop a cyber attack?
No. The NCSC says cyber insurance will not prevent a breach or attack. It helps pay for recovery. The security controls insurers ask about are what reduce the chance of an attack succeeding.
Sources
- DSIT: Cyber Security Breaches Survey 2025/2026
- NCSC: Cyber insurance guidance
- Marsh: Cyber resilience, twelve key controls to strengthen your security
- Marsh: Cyber hygiene controls critical as cyber threats intensify
- Marsh UK: A CISO’s guide to cyber risk, making cyber more insurable
- IASME: Cyber Essentials cyber liability insurance
- NCSC Annual Review 2025: empowering organisations
- GOV.UK: Cyber Essentials 10 years on, speech by Feryal Clark MP
- ABI: Nearly £200 million paid in cyber claims to help UK businesses recover
- Lloyd’s Market Bulletin Y5381: state-backed cyber-attack exclusions
- Insurance Act 2015, section 3: the duty of fair presentation
- Insurance Act 2015, Schedule 1: insurer’s remedies
- Insurance Act 2015, section 11: terms not relevant to the actual loss
- GOV.UK: UK to lead crackdown on cyber criminals with ransomware measures
Free • 12 minutes • Written PDF report
Who actually holds the keys to your systems?
List the systems your business runs, answer plain-English questions about how they are controlled, and get a report with a red, amber and green rating for every area and what to fix first. Nothing on your systems is touched.
Cyber Essentials certified · Microsoft Partner · rated 5.0 on Google
