Menu

Cyber Insurance

Cyber insurance, also known as cyber security insurance, is specifically designed to protect UK businesses against the cyber risks that come with using modern technology; threats that other types of business insurance won’t cover. Whether you’re facing ransomware, phishing, data breaches or social engineering, a specialist cyber insurance broker can help you find the right cover and make sure you have the incident response support in place from day one.
Adobestock 484633562
Adobestock 197218681

What is cyber insurance?

Cyber insurance is a specialist business insurance that covers the financial and legal costs that arise from cyber incidents, including data breaches, ransomware attacks, network security failures and privacy liability claims. It covers both first-party costs (the expenses your business incurs directly, such as forensic investigation, data recovery and business interruption losses) and third-party liability (claims made against your business by customers, partners or regulators, often referred to as cyber liability cover).

Cyber Liability 1 (1)

Why do UK businesses need cyber insurance?

No matter what your business size or type, cyber risk management is more important than ever. Cyber crime is growing in scale and sophistication, making cyber resilience a board-level concern for organisations across every sector.

Benefits for your business

Benefits to your business include:

Tick Icon

24/7 incident response

Tick Icon

Regulatory support

Tick Icon

Business continuity

Tick Icon

Reputation management

Tick Icon

Specialist access through a broker panel

What does cyber insurance cover?

Every policy is different. Speaking with a specialist broker means you can be clear on exactly what your cover includes and identify any gaps before you need to make a claim. Cyber Insurance can cover the following:

Data breach/privacy liability

Data breach/privacy liability

Including expenses related to the management of an incident, the investigation, the remediation, data subject notification, call management, third-party claims made against the business, credit checking for data subjects, legal costs, court attendance and regulatory fines under UK GDPR.

Multimedia/media liability

Multimedia/media liability

including third-party damages such as specific defacement of website and intellectual property rights infringement.

Extortion liability

Extortion liability

Typically involving losses due to a threat of extortion, professional fees related to dealing with the extortion.

Network security liability

Network security liability

Such as third-party damages as a result of denial of access, costs related to data on third-party suppliers and costs related to the theft of data on third-party systems.

Telephone hacking

Telephone hacking

Including costs incurred as a result of telephone hacking

Electronic funds transfer fraud

Electronic funds transfer fraud

Typically involving the fraudulent transfer of funds out of the business following a cyber incident, such as a compromised email account or fake payment instruction.

Supply chain cover

Supply chain cover

Including loss of income or additional costs incurred where a cyber incident affects a supplier, partner or outsourced service provider — sometimes known as contingent or dependent business interruption.

Business interruption

Business interruption

Including loss of income and increased costs of working as a result of network downtime caused directly by a cyber incident, such as a ransomware attack or extortion demand.

Data recovery costs

Data recovery costs

Including the costs of restoring, recreating or repairing data, systems or software following a cyber incident.

What is not covered by a standard cyber insurance policy?

While cyber insurance provides broad protection, it’s important to understand what a standard policy typically excludes. Common exclusions include:

Share price and reputational market value losses.

Share price and reputational market value losses.

A drop in share value following a cyber attack is not covered under a standard cyber policy, though where negligence by the board can be demonstrated, D&O insurance may also become relevant.

Pre-existing vulnerabilities

Pre-existing vulnerabilities

Known weaknesses that were not remediated prior to the incident may result in a claim being reduced or declined.

Physical damage to hardware

Physical damage to hardware

The cost of replacing physical equipment destroyed in an attack is generally not covered, this would fall under a standard property or equipment policy.

Let's put you in touch with a specialist

Make a call or fill in the form
Want to speak to someone?

Call this number

clear group
Thank you for getting in touch. Your enquiry has been successfully submitted. Our team will be in touch shortly to assist you with your insurance needs.
Thank you for trying to get in touch. There was an issue with your submission. Please double-check your information and ensure all required fields are completed. If the problem persists, please contact our main number 020 7280 3450 for assistance.

Frequently asked questions

Why is my business at risk of a cyber attack?

Companies store lots of sensitive customer data. A cyber-attack and a data breach could cost thousands of pounds in fines and damage the company’s reputation.

You may need Cyber-Liability Insurance if you:

  • hold customer data, including names, addresses or banking information
  • are reliant on computer systems to conduct your business
  • have a website
  • are subject to a payment card industry (PCI) merchant services agreement.

Is a cyber attack really likely to happen to my business?

Computer hacking is on the rise, according to the UK’s National Crime Agency, affecting essential services, businesses and private individuals alike. So, no business is immune.

The most common attack types affecting UK businesses include phishing emails, malware infections, ransomware attacks and social engineering scams, all of which can cause serious financial and reputational damage even when security measures are in place.

We have good cyber security software. Why do we need cyber insurance?

Hackers are constantly changing their tactics. High profile breaches at large enterprises such as the BBC, British Airways and Boots show that software breaches can happen even when cyber security is apparently robust.

We back up to the Cloud, so why do we need cover?

The Cloud is just another platform for hackers to breach. The sheer volume of data and number of users means that the Cloud is an attractive target for hackers.

If our cloud provider causes a data breach, won't they cover the cost?

You may have some recourse in this situation. However, this would be time-consuming, potentially costly, and wouldn't provide the immediate management you’ll need.

Is my current insurance policy likely to cover me for cyber losses?

Most standard insurance policies do not cover cyber losses. They are typically intended to cover physical losses caused by events like storms, fire, floods, or theft. While some policies may offer limited coverage for certain aspects of cyber incidents, such as legal defence for a data breach, this coverage is usually minimal. 

A standalone cyber insurance policy ensures comprehensive protection against all forms of cyber attack, such as ransomware and compromised business email, including the incident response and data recovery costs that standard policies exclude.

How can cyber insurance protect my business?

Most industries now rely on technology for smooth and efficient business operations. Any cyber incident could potentially cripple a business, leading to financial losses from liability claims, repair costs, recovery of systems, lost income, extortion expenses, and more.

For SMEs in particular, cyber insurance is often the difference between a manageable disruption and a business-ending event. Cyber policies provide the necessary support to recover from incidents, including forensic investigation, cyber security remediation, legal advice, public relations and loss of income cover.

What is the difference between first-party and third-party cyber insurance?

First-party cover in your cyber insurance policy covers the costs your business incurs as a result of a cyber-attack. Third-party cover provides defence costs and settlement costs for claims made against your business, such as allegations of failing to keep your customers' data secure.

Is my organisation responsible if there is a data breach of our computer system?

Yes, it's your organisation's responsibility to protect your customer information. You are liable for any losses and will have to pay any fines or fees resulting from legal actions. Unfortunately, even if you outsource services to other companies, your customers' data is still your responsibility.

What can I expect to happen when I make a cyber insurance claim?

Please remember that the process for making a claim can vary between insurers. Typically, you would need to call your insurer's 24/7 claims line to report the claim. After that, your insurer will gather some basic details to assess the situation. They should then call you back promptly to discuss an action plan that outlines the necessary services for your claim, which may include:

  • Forensics to assess how the attack occurred and actions needed to prevent a repeat attack (including dark web monitoring to check for compromised data)
  • Assistance with Information Commissioner's Office (ICO) notification, if necessary
  • Credit monitoring
  • Legal services/advice
  • Public relations assistance
  • Coordination with your IT provider to get you back up and running if needed.


The action plan will then be implemented, and normally, your insurer will arrange regular catch-up calls to ensure everything is proceeding as expected. Once everything is up and running, your insurer will work to reach a final settlement of the claim.

If you have experienced any loss of revenue, your insurer will need to see evidence of this. For example, a lost contract or a comparison between last year's and this year's accounts (it may take time to see losses, so this element may not be settled right away).

Unfortunately, with so many cyber claim scenarios, we can't explain how each one would work in practice. However, it's usually a condition of your policy that the first step in a cyber claim is to call and notify your insurer.

When selecting a cyber security insurer, what features and covers should I look for?

  1. 24/7 claims line: it's always a good idea to ensure your insurers offer a 24/7 claims line, as a cyber attack typically happens outside regular business hours, and not all Insurers offer this service.
  2. Outsourced service providers: not all insurance policies cover loss of income or additional costs incurred if a hacker targets your technology systems or outsourced service providers, such as a cloud provider or outsourced payroll company. If you're arranging cover, be sure to confirm that this protection is included.

If I have cyber insurance, which security practices do I no longer need to maintain?

Cyber insurance does not eliminate the need for good security practices. Consider this simple thought experiment: would you leave your doors and windows unlocked and open in your house simply because you have home insurance? Well, the same principle applies to your business. It's crucial to safeguard your digital assets. In the event that attackers breach your security measures, cyber insurance can provide a backup to help mitigate the impact.

Many insurers now require evidence of basic cyber resilience measures, such as multi-factor authentication and offline backups, before they will underwrite a policy. Your insurance broker can advise on what steps to take before you apply for cover.

Why Clear?

Industry-recognised for being people-first, our team of specialists supports start-ups, SMEs, corporates, multinationals and individuals.

Trade specialists

Trade specialists

We offer broad and bespoke sector specialist insurance solutions for peace of mind.

Chartered status

Chartered status

In recognition of our commitment to maintaining the highest standards of knowledge, ethical practice and guidance.

Exceptional service

Exceptional service

We're dedicated to providing exceptional customer service to respond proactively to the needs of our clients.