Cyber insurance for UK businesses
Cover for data breaches, ransomware and hacks, arranged by an independent broker.
Cyber insurance protects UK businesses when data is breached, systems are hacked or ransomware strikes. As an independent FCA-authorised broker, DigiCare compares specialist cyber insurers so you end up with cover that fits your business rather than whatever the first quote happens to offer.

Independent broker · FCA-authorised · UK cover
FCA-authorised broker
Authorised and regulated by the FCA. We work for you, not one insurer.
Specialist cyber insurers
Access to specialist cyber insurers, compared side by side.
FSCS protection
Financial Services Compensation Scheme protection where you qualify (eligibility criteria apply).
FOS dispute resolution
Free access to the Financial Ombudsman Service.
DigiCare is authorised and regulated by the Financial Conduct Authority.
What is cyber insurance?
Cyber insurance, also called cyber liability insurance, cyber security insurance or cyber risk insurance, covers the financial cost when a UK business suffers a data breach, hack or ransomware attack. It pays for incident response, data recovery, legal defence and claims from affected customers, and it usually includes round-the-clock access to breach specialists.
- The insured event: a data breach
A data breach, hack or ransomware attack is the event a cyber policy responds to. Cover kicks in once your systems or data are compromised.
- First-party cover
Pays for your own direct losses: data recovery, incident response, breach notification and lost income while you are down.
- Third-party cover
Covers your liability to others, such as customers or suppliers whose data is exposed in a breach you suffer.
- One product, several names
Cyber liability, cyber security and cyber risk insurance all describe the same B2B product. Knowing what a policy actually covers makes comparing quotes far easier.
- Association of British Insurers
What does cyber insurance cover?
Cyber insurance splits into first-party cover for your own losses and third-party cover for your liability to others. Following the Association of British Insurers' seven-part cover taxonomy, a business policy runs from pre-incident support and round-the-clock incident response through to breach costs, cyber extortion and business interruption.
| Cover element | Type | What it pays for |
|---|---|---|
| Pre-incident support | First-party | Risk assessments, staff training and tools that reduce your exposure before anything goes wrong. |
| Breach and privacy costs | First-party | ICO notification support, a breach call centre and PR to manage the fallout of a data breach. |
| Incident response and forensics | First-party | Round-the-clock IT forensics, legal and PR specialists who contain the attack and restore your systems. |
| Cyber extortion | First-party | Ransom negotiation and response to a ransomware or extortion attack, subject to sanctions checks. |
| Digital-asset damage | First-party | Recovering and rebuilding data, software and systems damaged in an attack. |
| Business interruption | First-party | Lost income while systems are down. Often an optional add-on, so check the indemnity period. |
| Third-party liability and media | Third-party | Regulatory defence costs, civil damages to affected parties, and media liability such as libel or IP infringement. |
The real value is the incident-response ecosystem: forensic, legal and PR support the moment you are hit, rather than a cheque that turns up months later. Cover varies by insurer, and some terms differ between policies (how employee fraud is treated, for example), so we read the wording for you. Next: what cyber insurance excludes.
What isn't covered: cyber insurance exclusions
Cyber insurance is broad, but no policy covers everything. These are the limits to check before you buy, and where a broker earns their keep.
| Exclusion | Why it's excluded |
|---|---|
| GDPR fines and penalties | Regulatory defence costs are usually covered, but GDPR fines are not covered and the penalty itself may be uninsurable as a matter of public policy. Under UK GDPR the ICO can impose fines of up to £17.5 million or 4% of global annual turnover, whichever is higher. |
| Business email compromise | Money lost to invoice fraud or a spoofed email is often excluded unless you add financial cybercrime cover as an endorsement. |
| Deliberate or criminal acts | Losses caused on purpose by the insured are not covered. |
| Unsupported software | Running old or unpatched software with no security updates can void cover. |
| Known vulnerabilities | Incidents or weaknesses you were aware of before the policy started (prior and known) are excluded. |
| State-sponsored attacks and war | Nation-state attacks and acts of war are commonly excluded, though the wording varies by insurer. |
There is also a boundary with professional indemnity insurance. If a client sues over lost data or faulty advice, that claim may fall to professional indemnity rather than cyber, so many firms hold both. General business and liability policies also commonly exclude cyber, which is why standalone cover exists.
Do I need cyber insurance? Is it a legal requirement in the UK?
Cyber insurance is not a legal requirement in the UK, but it is strongly recommended for any business that holds customer data, takes payments or relies on IT. In the 2025/2026 Cyber Security Breaches Survey, 46% of UK small businesses reported a breach or attack in the last 12 months. Business cyber insurance funds the recovery.
You use email
Phishing and invoice fraud almost always start in the inbox, and one wrong click can drain an account.
You have a website
Public-facing systems are scanned for weaknesses every day, whether you are a household name or a sole trader.
You store customer data
A leak triggers UK GDPR duties, including reporting certain breaches to the ICO within 72 hours.
You take online payments
Card and customer-account data is a prime target, and downtime hits revenue straight away.
This page is about business cyber insurance. If you are looking for personal or family cyber protection (cover against identity theft or online fraud at home), that is a separate product, usually added to a home insurance policy, and it is not what we arrange here. Everything below is written for UK businesses, sole traders and SMEs.
How much does cyber insurance cost in the UK?
In 2026, cyber insurance in the UK typically costs from around £175 a year for a low-risk micro-business, £350 to £5,000 a year for a typical SME, and up to £10,000 a year for a high-risk corporate. Your premium depends on size, sector, cover limit and security posture, so we surface ranges and let insurers quote your exact business.
Business size and turnover
Higher turnover and headcount raise the premium, because there is more revenue and data at risk.
Sector and data volume
Holding sensitive or high-volume data (health, finance, payments) costs more to insure.
Cover limit
Limits run from £25,000 up through £50,000, £100,000, £250,000, £500,000 and £1m upwards; higher limits raise the premium.
Security posture
Strong controls (MFA, tested backups, Cyber Essentials) can lower it; weak controls raise it or block cover.
Claims history
Past incidents or a recent breach push the premium up.
Add-ons
Business interruption and financial cybercrime cover add to the base price.
UK SMEs certified to the government-backed Cyber Essentials scheme can access a free IASME cyber liability policy with a £25,000 indemnity limit. Treat it as a floor: a useful starter, usually supplemented with a fuller policy. Price bands: ICAEW, October 2025.
What insurers require before they'll cover you
Insurers now treat baseline security as an eligibility condition, not a nice-to-have. Before they quote, they check that controls like multi-factor authentication and tested backups are in place. A broker helps you meet these conditions and qualify for better terms before you apply.
Multi-factor authentication (MFA)
The baseline control on email and remote access. Many insurers will not quote without it.
Tested backups
Offline, regularly tested backups so you can recover without paying a ransom.
Endpoint protection
Up-to-date protection running on laptops, servers and devices.
Patching and supported software
Security updates applied promptly and unsupported software retired.
Staff awareness training
Trained staff are your best defence against phishing and social engineering.
Cyber Essentials
The government-backed scheme can reduce premiums, is sometimes an underwriting condition, and unlocks the free IASME cover.
Be accurate on the proposal form. The NCSC warns that if you claim security measures are in place when they are not, the insurer may not be obliged to pay a claim. Most cyber policies are re-assessed every 12 months at renewal, so keep your controls current.
Cyber insurance for small businesses and by sector
Small businesses and freelancers are targeted precisely because they rarely have in-house security, and attackers know it. Nearly half of UK small businesses reported a breach or attack in the last year, yet the cover that matters most is not the same for every trade. That is why an off-the-shelf policy, or a general policy with cyber bolted on alongside cover like public liability insurance, rarely fits. Here is how exposure differs across common UK sectors.
| Sector | Primary cyber exposure | Cover that matters most |
|---|---|---|
| Accountancy and professional services | Highly sensitive client financial data | Data-privacy liability and regulatory defence |
| Healthcare | Patient records and uptime-critical systems | Fast system restore and patient-data liability |
| Construction | Email-based invoice fraud and tender data | Financial cybercrime cover and missed-bid loss |
| Manufacturing | Operational technology and production lines | Business interruption for OT downtime |
| E-commerce | Payment-card and customer-account data | Business interruption and third-party liability |
How to get cyber insurance, and why use a broker
Getting cyber insurance takes four steps: assess your exposure, complete a short security questionnaire, compare cover limits and specialist cyber insurers, then activate cover and its incident-response ecosystem. As an FCA-authorised broker, DigiCare guides you through each step and gives plain-English advice, not an aggregator maze.
Assess your exposure
We look at the data you hold, the systems you rely on and the revenue at risk.
Complete a security questionnaire
We help you answer the underwriting questions accurately, so cover holds when you claim.
Compare cover and insurers
We compare cover limits and specialist cyber insurers, rather than tie you to one brand.
Activate cover
You get your policy and round-the-clock access to breach response.
DigiCare is an FCA-authorised insurance broker (or appointed representative of an authorised firm), authorised and regulated by the Financial Conduct Authority. Where you qualify, FSCS protection and access to the FOS may apply (eligibility criteria apply).
Prefer to talk it through? Speak to a UK cyber insurance specialist before you buy.
Get your cyber insurance quote →Chapter VI
Cyber insurance FAQs
- Is cyber insurance mandatory in the UK?
- No. Cyber insurance is not a legal requirement in the UK, unlike motor or employers' liability cover. Some client contracts and government frameworks ask for Cyber Essentials certification rather than insurance, so check what your customers actually require.
- Does cyber insurance cover GDPR fines?
- Generally no. Regulatory fines are commonly excluded and may be uninsurable. A policy funds breach response, ICO notification support, legal defence and PR. Claims from clients over lost data can fall to professional indemnity.
- How much does cyber insurance cost for a small business?
- A low-risk micro-business can start from around £175 a year, and a typical SME pays £350 to £5,000 a year. Cyber Essentials certification can reduce the premium and unlock free IASME cover.
- What is the difference between cyber insurance and cyber security?
- Cyber security is the controls you put in place, such as multi-factor authentication and tested backups. Cyber insurance is the financial and response cover for when those controls fail.
- Does my general business insurance already cover cyber?
- Usually not. General and liability policies commonly carry cyber exclusions. Standalone cyber insurance adds the incident-response ecosystem plus the first-party and third-party cover a general policy does not provide. If your work is advice-based, our guide to what professional indemnity insurance is explains the separate cover for negligent-advice claims.
DigiCare is an insurance broker, authorised and regulated by the Financial Conduct Authority. We arrange cyber insurance with specialist insurers; we are not the insurer.
- · You may be covered by the Financial Services Compensation Scheme and can refer eligible complaints to the Financial Ombudsman Service. This page is general information, not advice on a specific policy.
- · Last reviewed: July 2026