Cyber Insurance for UK Small Businesses: What Actually Needs Covering in 2026

UK insurers have tightened cyber cover since 2023 with state-backed attack exclusions and ransomware sub-limits. Here is what a standard small-business policy actually pays for in 2026 — and where the gaps sit.

Cyber Insurance for UK Small Businesses: What Actually Needs Covering in 2026

UK insurers have narrowed what a standard cyber insurance policy pays out for since 2023, adding state-backed attack exclusions, ransomware sub-limits and stricter security requirements before cover is bound. For small businesses shopping for a policy through a broker or a comparison site, the practical effect is that two products both marketed as "cyber insurance" can cover entirely different sets of losses. The Lloyd's market, which underwrites a significant share of global cyber risk, mandated the exclusion changes for every syndicate writing the class from March 2023, and the wording has since filtered through to the wider London and regional insurance market.

What a standard policy actually pays for

Cyber insurance splits into two broad categories of cost. First-party costs cover the policyholder's own losses: forensic investigation to establish how an attacker got in, the expense of notifying affected customers, data recovery and reconstruction, lost income during downtime, and — where the insurer agrees to include it — the ransom payment itself. Third-party costs cover claims brought against the business by customers, suppliers or regulators, along with the legal costs of defending an investigation.

Most standard SME policies bought through comparison routes bundle these into a single limit, commonly between £50,000 and £1 million depending on turnover and sector, with individual costs such as ransomware negotiation or notification services carrying their own sub-limit inside that figure. Regulatory fines are a separate matter: insurers in the UK generally exclude cover for the fine itself, since indemnifying a punitive penalty is treated as contrary to public policy, while still covering the legal costs of responding to an Information Commissioner's Office investigation.

State-backed attack exclusions narrowed cover in 2023

The most significant change to the market came from the Lloyd's Market Association, which introduced a set of clauses — numbered LMA5564 to LMA5567 — requiring every Lloyd's syndicate to exclude losses from state-backed cyber attacks on new and renewed cyber policies from 1 March 2023. The clauses distinguish between attacks a government formally attributes to a nation state and everyday cyber-crime, but attribution is rarely straightforward. Ransomware groups operating from Russian-speaking jurisdictions are widely understood to work with a degree of state tolerance without being formally state-directed, which leaves room for disagreement over whether a specific incident falls inside or outside the exclusion.

Attribution is the sticking point

For a UK small business, the practical risk is a claim being contested months after an incident, once a government or intelligence agency publicly attributes the attack to a state actor. Insurers are not obliged to wait for that attribution before applying the exclusion, and policy wording varies between insurers on how much certainty is required to trigger it.

Ransomware payment caps — and the sanctions problem

Even where a policy covers ransom payments, insurers increasingly apply a sub-limit distinct from the overall cover, commonly a fraction of the total policy limit rather than the full amount. The National Cyber Security Centre and the National Crime Agency both advise against paying ransoms, on the grounds that payment funds further criminal activity and provides no guarantee that stolen data will be deleted or systems fully restored.

There is also a legal constraint that catches some businesses by surprise: paying a ransom to an individual, group or jurisdiction subject to UK financial sanctions is itself a breach of sanctions law, enforced by the Office of Financial Sanctions Implementation. Insurers and the specialist ransomware-response firms on their panels screen recipients against sanctions lists before any payment is authorised, which can add days to a negotiation that ransomware gangs typically try to compress into hours.

The 72-hour clock and what it means for cover

Under UK GDPR and the Data Protection Act 2018, an organisation that suffers a personal data breach likely to risk individuals' rights and freedoms must notify the Information Commissioner's Office within 72 hours of becoming aware of it. The ICO can fine an organisation up to £17.5 million or 4% of annual global turnover, whichever is higher, for the most serious breaches, though penalties at that scale are reserved for large organisations with systemic failures rather than small businesses reporting a single incident.

Cyber policies typically give access to a panel of breach lawyers and forensic investigators who handle the notification process, and using a provider outside that panel can reduce or void reimbursement for the associated costs. For a business with no dedicated IT security function, that panel access is often the most immediately useful part of the policy, more so than the indemnity limit itself, which many smaller claims never come close to exhausting.

Supply-chain cover is often the biggest gap

Contingent business interruption — the loss a business suffers when a third party it depends on, such as a cloud hosting provider, payment processor or logistics partner, is knocked offline by a cyber attack — is frequently excluded from standard SME policies or capped at a fraction of the business's own business-interruption limit. Insurers price this cover separately because a single cloud outage or payment-processor breach can generate thousands of simultaneous claims, concentrating risk in a way that is harder to model than an attack on one policyholder alone.

For a small business that outsources its point-of-sale system, accounting software or customer database to a handful of cloud providers, that gap can matter more than any other clause in the policy. A retailer whose card payments stop working because its payment processor was hit by ransomware may find the resulting loss of trading income falls outside a standard policy's core cover entirely, unless contingent business interruption was purchased as a separate extension.

What insurers now expect before they'll bind cover

Underwriting requirements have tightened alongside the exclusions. Multi-factor authentication on remote access and email accounts has moved from a discount criterion to close to a universal condition of cover following the wave of ransomware claims in 2021 and 2022. Insurers writing higher limits, or cover for businesses handling sensitive customer data, increasingly ask for evidence of Cyber Essentials or Cyber Essentials Plus certification — the National Cyber Security Centre-backed scheme that verifies a set of baseline technical controls — before binding a policy, rather than treating it as optional evidence of good practice.

Offline, tested backups remain a recurring underwriting question, not because insurers expect every business to survive an attack unscathed, but because a business that can restore from backup within days rather than weeks produces a far smaller business-interruption claim. That difference shows up directly in renewal pricing the following year.

The gap between what a policy's marketing summary promises and what its schedule of exclusions actually delivers is where most coverage disputes begin — and, increasingly, it is a gap insurers are widening rather than closing.