IT & SupportIT SupportMicrosoft 365Server SolutionsVirtualisationCyber SecurityCyber SecuritySavvy SecureEmail SolutionsAccess ControlCCTVConnectivity & CommsBusiness Phone SystemsProfessional CommunicationNetwork & WiFiMobile ConnectivityBroadband CheckerWeb & DigitalWeb DesignAll servicesCompanyLocationsKnowledge HubGuidesFAQsAboutContactGet a Quote
Cyber Security

Cyber insurance for small businesses: what it covers and what invalidates it

Business owner reviewing cyber security insurance documents

This page is for small business owners trying to understand cyber insurance without treating it as a substitute for IT security. It outlines the types of costs a policy may address, the controls insurers commonly expect, and the questions to take to an insurer or regulated insurance adviser.

What cyber insurance is for

Cyber insurance is designed to help a business deal with certain costs after a cyber incident. It is not a guarantee that every loss will be paid, and it does not prevent an attack. The policy wording, your answers when buying cover and the facts of the incident all matter. This article is general information, not regulated insurance advice or a recommendation of any insurer or policy.

For a small business, the value can be access to incident-response specialists when you are under pressure as much as the money itself. A serious incident can involve technical investigation, legal advice, customer communications and business interruption at the same time. Knowing whom to call and what the policy requires can save costly confusion.

Read the actual policy schedule and conditions, not just a comparison-site summary. Ask the insurer or your regulated adviser to explain any term you do not understand. Do this before an incident, when you can still change a setting, collect evidence or choose a policy that matches your actual business.

What policies commonly include

Cover varies, but cyber policies commonly address some combination of incident-response support, forensic investigation, legal and regulatory advice, notification costs, data restoration, business interruption, cyber extortion and liability claims from third parties. Limits, excesses, waiting periods and exclusions can be very different between policies.

Business interruption cover is easy to misunderstand. It may respond to lost income and additional costs caused by a covered incident, but it usually depends on evidence of normal trading and may not start immediately. It is not a blank cheque for every consequence of a slow system or a dispute with a supplier.

Ransomware-related support may be included, but that does not make payment automatic or advisable. The insurer may appoint specialists and require you to follow a response process. There can be sanctions, legal and practical reasons why a payment cannot be made. Our article on ransomware and recovery explains why a ransom demand is not a recovery strategy.

The security controls insurers now ask about

When applying, many insurers ask detailed questions about basic security. They are trying to understand whether a preventable account takeover or malware incident is more likely, and whether you can recover. If you answer inaccurately or let controls lapse, that can create a serious problem when you later make a claim.

  • MFA: especially for email, remote access, cloud administration and privileged accounts.
  • Backups: separate, protected copies that are tested rather than merely assumed to exist.
  • Patching: a process for applying security updates to systems and software promptly.
  • Endpoint protection: security software on devices, with alerts and response arrangements where appropriate.
  • Access control: individual accounts, limited administrator rights and prompt removal of former staff.
  • Awareness: staff who know how to report suspicious messages and unusual sign-in prompts.

The exact requirements come from your policy, not from a generic checklist. Still, these controls are sensible whether you buy cover or not. Start with multi-factor authentication and a real backup test, because both are often central to recovery and underwriting questions.

How claims can be refused or reduced

Claims can go wrong when the information given during the application is inaccurate, when a stated control was not actually in place, or when a policy condition was not followed. For example, saying MFA protects all remote access when an old administrator account has no MFA could matter. So could failing to notify the insurer promptly when the policy says you must.

Other problems include using personal email for policy communications, having no records of patching or backups, paying a ransom without following the insurer's process, or assuming a general business policy automatically covers a cyber event. Whether any of these affects a claim depends on the wording and facts, so do not rely on a blog article for a decision about a live claim.

Keep evidence proportionate. Maintain an asset list, record who administers core systems, keep reports from backup tests and retain security-policy records. You do not need a mountain of paperwork to be organised. You do need to be able to show what you said you did.

Insurance is not a security plan

Insurance may help fund the response, but it cannot undo lost time, stress, damaged trust or the operational disruption of being unable to work. It cannot guarantee that stolen data will disappear or that every customer will be unaffected. The best outcome is still to make an incident less likely and easier to contain.

A practical security plan concentrates on a small number of effective controls: MFA, supported and updated systems, endpoint protection, least-privilege access, secure backups and clear reporting of suspicious activity. Cyber Essentials provides a useful UK baseline for many organisations; our Cyber Essentials guide sets out what it covers.

Do not overlook the response plan. Decide who can shut down access, who calls the insurer, how you communicate if email is unavailable and where the policy number is stored. Test a short scenario with the people responsible, alongside the restore test in our business data backup guide. That is much more useful than discovering the policy paperwork during a crisis.

What to do next

Before renewing or buying cover, compare the security questions with what is actually configured in your business. Fix the obvious gaps, document the basics and ask a regulated insurance professional about the cover itself. TSS can offer a free, no-obligation chat about the technical controls, without recommending a policy or insurer.

Want to check your technical basics?

Book a free, no-obligation chat and we will help you review the security controls insurers commonly ask about.

Call us Get a quote