Employers' liability: what the law requires
Why almost every UK employer must hold at least £5 million of cover, and what happens if you don't.
Read guideProtect your business against ransomware, data breaches and online fraud. Compare UK cyber insurance covering response costs, lost income and third-party claims.
Compare cyber insurance quotesRun a full market comparison before you commit. It takes about five minutes and there's no obligation to apply.
Cyber insurance covers the costs of a data breach or cyber attack, including forensic investigation, ransom negotiation, notifying affected customers and legal claims that follow.
It also typically covers business interruption caused by an attack — the income you lose while systems are down — which is often the largest part of a claim.
With UK small businesses facing a growing volume of phishing, ransomware and invoice fraud attempts, insurers now build policies around incident response as much as compensation.
Most policies include an incident line and forensic team on call.
Specialist negotiators and, where lawful, ransom payments are covered.
Covers income lost while systems are down after an attack.
Indicative annual premiums for cyber cover including breach response and interruption, excluding IPT.
| Business size | Typical limit | Annual premium |
|---|---|---|
| Sole trader / freelancer | £50,000 | £100 - £250 |
| Micro business, 1-9 staff | £250,000 | £250 - £600 |
| Small business, 10-49 staff | £500,000 | £500 - £1,400 |
| Retailer taking online payments | £500,000 | £600 - £1,600 |
| Business holding health/financial data | £1,000,000 | £1,200 - £3,000 |
Typical cost for a small business with under 20 staff and standard IT systems.
| Cover limit | Suits | Typical annual cost |
|---|---|---|
| £100,000 | Very small businesses, minimal data held | £150 - £400 |
| £250,000 | Small businesses with customer data | £300 - £700 |
| £500,000 | Growing businesses, e-commerce | £500 - £1,200 |
| £1,000,000 | Larger client contracts, sensitive data | £900 - £2,500 |
Our team reviews UK commercial insurers, policy wordings and typical premiums throughout the year.
“Cyber insurance now behaves more like a service than a payout — the value is in the incident response team you get on the phone within the hour, not just the compensation.”
Cover limits and exclusions vary a lot between insurers. Check these points before you buy.
Most insurers require basic controls such as multi-factor authentication and regular backups — missing them can void a claim.
Some policies distinguish between external attacks and employee error — check both are covered.
This is how long the policy will keep paying for lost income after an attack — three months is common, but some businesses need longer.
24/7 access to forensics and legal support in the first hours often matters more than the payout itself.
See what's available for your business today. It takes just minutes.
It takes a couple of minutes and there is no obligation to buy.
Trade, turnover, headcount and the cover limits you need.
We shortlist UK insurers and brokers who actually cover your trade.
Premium, excess, cover limits and exclusions — not just the headline price.
Most policies can be arranged online with your certificate issued the same day.
Failing to maintain basic security controls, such as multi-factor authentication, is one of the most common reasons cyber claims are declined.
Ransom payments involving sanctioned entities cannot lawfully be covered — check how your insurer handles this.
Cover often excludes losses from unsupported software still running past its end-of-life date.
We compare cyber insurance from established UK insurers and brokers so you can see premiums, limits and exclusions side by side.
Comparing is free, and we will say plainly when your existing policy already looks like good value.
Start comparing four to six weeks before renewal so you don't auto-renew onto a higher price.
Insurers will ask about claims from the last three to five years.
Contracts and clients often set minimum limits you must hold.
We compare a broad range of UK providers so you can find the option that actually fits how your business operates.
We work hard to bring you exclusive deals, switching incentives and cashback where they're available.
It takes just a few minutes to compare with us — and the deal you find could be well below what you pay today.
The right policy depends on your trade, size and the contracts you work under.
Covers your own costs — forensics, notification, ransom, and lost income.
Covers claims from customers or partners affected by a breach of their data.
Covers financial loss from invoice fraud, social engineering and payment diversion.
Covers fines and costs if a card payment data breach occurs.
Logos are shown for identification. We are not affiliated with every insurer listed and do not compare the whole market.
“After a ransomware attack, the insurer's forensics team had us back trading within three days.”
Owen, e-commerce retailer, Sheffield
Why almost every UK employer must hold at least £5 million of cover, and what happens if you don't.
Read guideThe everyday incidents — a spilt drink, a dropped tool, a tripped customer — that lead to six-figure claims.
Read guideWhat a typical cyber insurance claim pays for, from forensics to ransom negotiation and lost income.
Read guideYes — small businesses are frequent targets precisely because their defences are weaker, and the average ransomware or fraud incident can cost thousands in lost trading time alone.
Many policies cover ransom negotiation and payment where lawful, but insurers will usually try to avoid payment through backups and negotiation first.
Possibly not. Most insurers require basic controls like multi-factor authentication as a condition of cover, and a claim can be reduced or declined without them.
Yes, if you add cyber crime cover, which covers losses from social engineering, payment diversion and fraudulent invoices.
Written by the Grow Your Business editorial team · Updated 26 July 2026