
Cyber insurance covers the costs that follow a data breach or a cyber incident, and the reason small businesses increasingly need it is not dramatic hacking. It is email compromise leading to a fraudulently changed invoice, and the legal obligations that follow when customer data is exposed. Both are expensive, and neither requires you to be a large target.
Understand what a policy actually pays for before deciding whether you need one.
What policies typically cover
Investigation and forensic costs to establish what happened, notifying affected people, legal costs and regulatory penalties where insurable, business interruption while systems are down, and recovery or reconstruction of data.
Some policies extend to funds transfer fraud and extortion, but those are frequently separate add-ons rather than standard. Check specifically rather than assuming.
What they commonly exclude
Losses arising from known unpatched vulnerabilities, missing controls the insurer required, or acts by your own staff in some policies. Reputational loss is rarely covered in any meaningful way.
Insurers increasingly require specific controls as a condition: two-factor authentication on email, tested backups, and access limits. Not having them can void a claim rather than merely raising a premium.
The claim most small businesses actually make
Email compromise, where an attacker gains access to a mailbox and sends a customer or supplier changed banking details. The money leaves, and recovering it is usually impossible.
The control that prevents it costs nothing: verify any change of banking details by phoning a number you already held, never one supplied in the message requesting the change.
Your obligations exist with or without insurance
Holding personal information carries duties under the Protection of Personal Information Act, overseen by the Information Regulator, including notifying the regulator and affected people where a breach occurs.
Insurance pays for consequences; it does not discharge the obligation. Confirm any insurer or intermediary is authorised with the Financial Sector Conduct Authority before buying cover.
Frequently asked questions
What does cyber insurance actually cover?
Investigation costs, notification of affected people, legal costs, business interruption and data recovery. Fraud and extortion cover are often separate add-ons.
Do small businesses really need it?
The common claim is email compromise causing a fraudulent payment, which does not require being a large target.
What voids a claim?
Missing the controls the insurer required, such as two-factor authentication on email or tested backups.
What is the cheapest protection?
Verifying any change of banking details by phoning a number you already held rather than one supplied in the message.
Does insurance remove my legal obligations?
No. Data protection duties, including breach notification, apply regardless of whether you hold cover.
Further reading
Originally published in June 2018. Updated September 2026 to explain what cyber cover includes and excludes rather than reporting one funding round.
