Business cyber insurance

Cyber insurance for UK businesses

Cover for data breaches, ransomware and hacks, arranged by an independent broker.

Cyber insurance protects UK businesses when data is breached, systems are hacked or ransomware strikes. As an independent FCA-authorised broker, DigiCare compares specialist cyber insurers so you end up with cover that fits your business rather than whatever the first quote happens to offer.

Authorised and regulated by the FCAFSCS protection may applyFOS dispute resolution
Padlock and shield over a UK business network, representing cyber insurance protection for British businesses

Independent broker · FCA-authorised · UK cover

  • FCA-authorised broker

    Authorised and regulated by the FCA. We work for you, not one insurer.

  • Specialist cyber insurers

    Access to specialist cyber insurers, compared side by side.

  • FSCS protection

    Financial Services Compensation Scheme protection where you qualify (eligibility criteria apply).

  • FOS dispute resolution

    Free access to the Financial Ombudsman Service.

DigiCare is authorised and regulated by the Financial Conduct Authority.

What is cyber insurance?

Cyber insurance, also called cyber liability insurance, cyber security insurance or cyber risk insurance, covers the financial cost when a UK business suffers a data breach, hack or ransomware attack. It pays for incident response, data recovery, legal defence and claims from affected customers, and it usually includes round-the-clock access to breach specialists.

Find your route
  1. The insured event: a data breach

    A data breach, hack or ransomware attack is the event a cyber policy responds to. Cover kicks in once your systems or data are compromised.

  2. First-party cover

    Pays for your own direct losses: data recovery, incident response, breach notification and lost income while you are down.

  3. Third-party cover

    Covers your liability to others, such as customers or suppliers whose data is exposed in a breach you suffer.

  4. One product, several names

    Cyber liability, cyber security and cyber risk insurance all describe the same B2B product. Knowing what a policy actually covers makes comparing quotes far easier.

Sources

What does cyber insurance cover?

Cyber insurance splits into first-party cover for your own losses and third-party cover for your liability to others. Following the Association of British Insurers' seven-part cover taxonomy, a business policy runs from pre-incident support and round-the-clock incident response through to breach costs, cyber extortion and business interruption.

Cover elementTypeWhat it pays for
Pre-incident supportFirst-partyRisk assessments, staff training and tools that reduce your exposure before anything goes wrong.
Breach and privacy costsFirst-partyICO notification support, a breach call centre and PR to manage the fallout of a data breach.
Incident response and forensicsFirst-partyRound-the-clock IT forensics, legal and PR specialists who contain the attack and restore your systems.
Cyber extortionFirst-partyRansom negotiation and response to a ransomware or extortion attack, subject to sanctions checks.
Digital-asset damageFirst-partyRecovering and rebuilding data, software and systems damaged in an attack.
Business interruptionFirst-partyLost income while systems are down. Often an optional add-on, so check the indemnity period.
Third-party liability and mediaThird-partyRegulatory defence costs, civil damages to affected parties, and media liability such as libel or IP infringement.

The real value is the incident-response ecosystem: forensic, legal and PR support the moment you are hit, rather than a cheque that turns up months later. Cover varies by insurer, and some terms differ between policies (how employee fraud is treated, for example), so we read the wording for you. Next: what cyber insurance excludes.

What isn't covered: cyber insurance exclusions

Cyber insurance is broad, but no policy covers everything. These are the limits to check before you buy, and where a broker earns their keep.

ExclusionWhy it's excluded
GDPR fines and penaltiesRegulatory defence costs are usually covered, but GDPR fines are not covered and the penalty itself may be uninsurable as a matter of public policy. Under UK GDPR the ICO can impose fines of up to £17.5 million or 4% of global annual turnover, whichever is higher.
Business email compromiseMoney lost to invoice fraud or a spoofed email is often excluded unless you add financial cybercrime cover as an endorsement.
Deliberate or criminal actsLosses caused on purpose by the insured are not covered.
Unsupported softwareRunning old or unpatched software with no security updates can void cover.
Known vulnerabilitiesIncidents or weaknesses you were aware of before the policy started (prior and known) are excluded.
State-sponsored attacks and warNation-state attacks and acts of war are commonly excluded, though the wording varies by insurer.

There is also a boundary with professional indemnity insurance. If a client sues over lost data or faulty advice, that claim may fall to professional indemnity rather than cyber, so many firms hold both. General business and liability policies also commonly exclude cyber, which is why standalone cover exists.

Who needs cyber insurance?

Do I need cyber insurance? Is it a legal requirement in the UK?

Cyber insurance is not a legal requirement in the UK, but it is strongly recommended for any business that holds customer data, takes payments or relies on IT. In the 2025/2026 Cyber Security Breaches Survey, 46% of UK small businesses reported a breach or attack in the last 12 months. Business cyber insurance funds the recovery.

You use email

Phishing and invoice fraud almost always start in the inbox, and one wrong click can drain an account.

You have a website

Public-facing systems are scanned for weaknesses every day, whether you are a household name or a sole trader.

You store customer data

A leak triggers UK GDPR duties, including reporting certain breaches to the ICO within 72 hours.

You take online payments

Card and customer-account data is a prime target, and downtime hits revenue straight away.

This page is about business cyber insurance. If you are looking for personal or family cyber protection (cover against identity theft or online fraud at home), that is a separate product, usually added to a home insurance policy, and it is not what we arrange here. Everything below is written for UK businesses, sole traders and SMEs.

Pricing

How much does cyber insurance cost in the UK?

In 2026, cyber insurance in the UK typically costs from around £175 a year for a low-risk micro-business, £350 to £5,000 a year for a typical SME, and up to £10,000 a year for a high-risk corporate. Your premium depends on size, sector, cover limit and security posture, so we surface ranges and let insurers quote your exact business.

Business size and turnover

Higher turnover and headcount raise the premium, because there is more revenue and data at risk.

Sector and data volume

Holding sensitive or high-volume data (health, finance, payments) costs more to insure.

Cover limit

Limits run from £25,000 up through £50,000, £100,000, £250,000, £500,000 and £1m upwards; higher limits raise the premium.

Security posture

Strong controls (MFA, tested backups, Cyber Essentials) can lower it; weak controls raise it or block cover.

Claims history

Past incidents or a recent breach push the premium up.

Add-ons

Business interruption and financial cybercrime cover add to the base price.

UK SMEs certified to the government-backed Cyber Essentials scheme can access a free IASME cyber liability policy with a £25,000 indemnity limit. Treat it as a floor: a useful starter, usually supplemented with a fuller policy. Price bands: ICAEW, October 2025.

What insurers require

What insurers require before they'll cover you

Insurers now treat baseline security as an eligibility condition, not a nice-to-have. Before they quote, they check that controls like multi-factor authentication and tested backups are in place. A broker helps you meet these conditions and qualify for better terms before you apply.

Multi-factor authentication (MFA)

The baseline control on email and remote access. Many insurers will not quote without it.

Tested backups

Offline, regularly tested backups so you can recover without paying a ransom.

Endpoint protection

Up-to-date protection running on laptops, servers and devices.

Patching and supported software

Security updates applied promptly and unsupported software retired.

Staff awareness training

Trained staff are your best defence against phishing and social engineering.

Cyber Essentials

The government-backed scheme can reduce premiums, is sometimes an underwriting condition, and unlocks the free IASME cover.

Be accurate on the proposal form. The NCSC warns that if you claim security measures are in place when they are not, the insurer may not be obliged to pay a claim. Most cyber policies are re-assessed every 12 months at renewal, so keep your controls current.

Cyber insurance for small businesses and by sector

Small businesses and freelancers are targeted precisely because they rarely have in-house security, and attackers know it. Nearly half of UK small businesses reported a breach or attack in the last year, yet the cover that matters most is not the same for every trade. That is why an off-the-shelf policy, or a general policy with cyber bolted on alongside cover like public liability insurance, rarely fits. Here is how exposure differs across common UK sectors.

SectorPrimary cyber exposureCover that matters most
Accountancy and professional servicesHighly sensitive client financial dataData-privacy liability and regulatory defence
HealthcarePatient records and uptime-critical systemsFast system restore and patient-data liability
ConstructionEmail-based invoice fraud and tender dataFinancial cybercrime cover and missed-bid loss
ManufacturingOperational technology and production linesBusiness interruption for OT downtime
E-commercePayment-card and customer-account dataBusiness interruption and third-party liability
Getting covered

How to get cyber insurance, and why use a broker

Getting cyber insurance takes four steps: assess your exposure, complete a short security questionnaire, compare cover limits and specialist cyber insurers, then activate cover and its incident-response ecosystem. As an FCA-authorised broker, DigiCare guides you through each step and gives plain-English advice, not an aggregator maze.

  1. Assess your exposure

    We look at the data you hold, the systems you rely on and the revenue at risk.

  2. Complete a security questionnaire

    We help you answer the underwriting questions accurately, so cover holds when you claim.

  3. Compare cover and insurers

    We compare cover limits and specialist cyber insurers, rather than tie you to one brand.

  4. Activate cover

    You get your policy and round-the-clock access to breach response.

DigiCare is an FCA-authorised insurance broker (or appointed representative of an authorised firm), authorised and regulated by the Financial Conduct Authority. Where you qualify, FSCS protection and access to the FOS may apply (eligibility criteria apply).

Prefer to talk it through? Speak to a UK cyber insurance specialist before you buy.

Get your cyber insurance quote

Chapter VI

Cyber insurance FAQs

Is cyber insurance mandatory in the UK?
No. Cyber insurance is not a legal requirement in the UK, unlike motor or employers' liability cover. Some client contracts and government frameworks ask for Cyber Essentials certification rather than insurance, so check what your customers actually require.
Does cyber insurance cover GDPR fines?
Generally no. Regulatory fines are commonly excluded and may be uninsurable. A policy funds breach response, ICO notification support, legal defence and PR. Claims from clients over lost data can fall to professional indemnity.
How much does cyber insurance cost for a small business?
A low-risk micro-business can start from around £175 a year, and a typical SME pays £350 to £5,000 a year. Cyber Essentials certification can reduce the premium and unlock free IASME cover.
What is the difference between cyber insurance and cyber security?
Cyber security is the controls you put in place, such as multi-factor authentication and tested backups. Cyber insurance is the financial and response cover for when those controls fail.
Does my general business insurance already cover cyber?
Usually not. General and liability policies commonly carry cyber exclusions. Standalone cyber insurance adds the incident-response ecosystem plus the first-party and third-party cover a general policy does not provide. If your work is advice-based, our guide to what professional indemnity insurance is explains the separate cover for negligent-advice claims.

DigiCare is an insurance broker, authorised and regulated by the Financial Conduct Authority. We arrange cyber insurance with specialist insurers; we are not the insurer.

  • · You may be covered by the Financial Services Compensation Scheme and can refer eligible complaints to the Financial Ombudsman Service. This page is general information, not advice on a specific policy.
  • · Last reviewed: July 2026