Cyber Insurance for Small Businesses: Worth It or Not?
Is cyber insurance worth it for a UK small business? The real 2026 breach numbers, what cover costs, exclusions to check, and a £300 alternative.
Priti has run a florist’s in Coventry for nine years. Last spring an email arrived from her wholesaler — same logo, same signature, same friendly tone — saying their bank details had changed. She paid the month’s invoice, £3,800, and only discovered the truth when the real wholesaler rang to chase payment. The money was gone. No masked hacker, no dramatic ransomware screen; just one convincing email on a busy Tuesday. That’s what a cyber attack on a small business usually looks like, and it’s why the question “is cyber insurance for a small business worth it?” deserves a more honest answer than insurers or sceptics usually give. Here it is, with the real 2026 numbers.
Cyber Insurance at a Glance
| Small businesses attacked in the last year | 46% (43% of all UK businesses) |
| Most common attack | Phishing — 38% of businesses |
| Median cost of the worst breach | £0 — but the worst-hit 5% lose £4,000+ |
| Typical add-on cover | From about £15 a month for £25,000 of cover |
| Standalone policies | Roughly £500 – £3,500 a year depending on turnover and data |
| The lesser-known alternative | Cyber Essentials certification (~£300) includes £25,000 of free cyber cover |
The Honest Numbers: Most Attacks Cost Nothing, a Few Cost Everything
The government’s Cyber Security Breaches Survey, published in April 2026, says 46% of small businesses were hit by a breach or attack in the past year — around 612,000 UK organisations in total. That’s the number the insurance adverts quote. Here’s the part they don’t: the median cost of the most disruptive breach was £0, and for the middle half of businesses it fell between £0 and £200, because most attacks are blocked phishing emails and nothing more. So why insure at all? Because the distribution has a nasty tail. The worst-hit 5% of small firms lost £4,000 or more, the share of breaches causing lost revenue more than doubled this year, and cases like Priti’s — a single fraudulent transfer — routinely run into thousands. Cyber insurance isn’t for the average attack. It’s for the one that isn’t average.
What Cyber Insurance Actually Covers
A typical small-business policy does four jobs. It reimburses cyber crime losses — hacking, phishing, fraudulent fund transfers like Priti’s, even telecoms fraud. It pays the breach response costs when customer data leaks: forensic investigators, legal advice, notifying the people affected, handling the Information Commissioner’s Office. It covers cyber liability — claims from clients whose data or systems were harmed through you. And it gives you a 24/7 incident helpline, which owners who’ve used one often call the most valuable part, because at 7am on the worst morning of your business life, you want a number to ring. Now the exclusions that surprise people: most small-business policies won’t pay ransoms, won’t cover cryptocurrency, won’t pay to upgrade your systems afterwards, and may refuse fraud claims on transfers over a set amount if you didn’t phone the supplier to verify. Read that list before you buy, not after.
What It Costs a Small Business in 2026
There are two price brackets, and confusing them causes most of the “is it worth it” arguments. The cheap bracket is the add-on: Simply Business, for example, sells cyber cover at £14.78 a month — about £156 a year — bolted onto a public liability or professional indemnity policy, with a £25,000 annual limit, for businesses under ten staff and £1 million turnover. That’s proportionate protection for a florist, a consultant or an online seller. The expensive bracket is standalone cyber insurance with limits of £100,000 to £1 million, which runs from around £500 to £3,500 a year depending on turnover, industry and how much data you hold. An e-commerce firm processing thousands of card payments belongs in the second bracket; most micro businesses don’t. Whether you trade as a limited company or sole trader makes little difference to the price — your data and turnover do.
The £300 Alternative Most Owners Haven’t Heard Of
Here’s the piece of this puzzle that rarely makes the comparison sites. Cyber Essentials is the government-backed security certification: a self-assessment against five basic controls, costing from £300 plus VAT for a micro business. Pass it, and if your turnover is under £20 million, the certificate comes with £25,000 of cyber liability insurance included — the same headline limit as many paid add-ons, for a one-off fee that also makes an attack less likely in the first place. Only 5% of UK businesses hold the certificate, and just 12% of small firms, yet it’s increasingly demanded in council and corporate tenders anyway. For many small businesses the smartest sequence is certification first, then top-up insurance if the data you hold justifies it. It’s the rare case where the free insurance comes with better security attached.
Who Genuinely Needs It — and Who Can Probably Skip It
Strip away the fear marketing and the test is about what flows through your business. You’re a strong candidate for cyber cover if you hold customer or client data beyond a name and email — payment details, health notes, HR files; if money moves on your instructions by bank transfer; if your trading depends on an online shop or booking system; or if clients would sue you when their data leaked through your systems. That describes most consultants, agencies, e-commerce sellers, accountants and letting agents. You can more comfortably skip it if you’re a sole trader whose “data” is a phone full of first names, who takes card payments only through a processor like Square or SumUp, and whose laptop could be wiped tomorrow without a client noticing. Be honest about which you are — and remember the survey finding that only 25% of businesses have any written plan for a cyber incident. The plan matters as much as the policy.
The Conditions: Where Cyber Claims Go Wrong
Cyber policies come with homework, and skipping it is the classic way to pay premiums and still get nothing. Insurers typically require that your software and operating systems are kept updated, that multi-factor authentication is switched on for email, and that staff have basic awareness of phishing — conditions written into the policy, not friendly suggestions. Some add a “callback” clause: any new or changed bank details over a threshold must be verified by phone before payment, which is precisely the check that would have saved Priti. Report incidents immediately, too; discovering a breach in March and mentioning it at renewal in June is a declined claim. None of this is onerous — MFA takes an afternoon — but treat the conditions as the price of the cover, because your insurer certainly will.
How to Decide in Ten Minutes
Sit down with four questions. One: what’s the worst email that could arrive tomorrow — a fake supplier invoice, a locked booking system, a client database in the wrong hands — and what would it cost in money and lost days? Two: could you absorb that figure, the way you’d absorb a £200 hit but not a £4,000 one? Three: have you done the free-and-cheap layer — MFA everywhere, updates on, staff warned, and ideally Cyber Essentials with its bundled £25,000 of cover? Four: does anything about your business (card data, client files, contractual promises) push you into standalone territory? If the answers point to real exposure, a £15-a-month add-on is one of the cheapest risks-removed-per-pound in your whole insurance stack, alongside covers like business interruption insurance. If they don’t, spend the money on the security itself and revisit next year.
The Bottom Line
Priti got £3,300 of her £3,800 back — her bank recovered part, and the cyber add-on she’d bought eight months earlier paid the rest and a specialist to check her systems. Was it worth it? For her, obviously. For you, the answer to “is cyber insurance for a small business worth it” comes down to arithmetic, not anxiety: a 46% chance of being attacked, a small chance of it really hurting, £150 a year to cap the damage, and a £300 certificate that shrinks the risk and includes cover of its own. Do the security basics this week, price an add-on against Cyber Essentials, and make the decision with the real numbers in front of you. Our complete guide to small business insurance shows where cyber fits among the rest.
Frequently Asked Questions
What is cyber insurance for a small business?
It’s cover that pays for cyber crime losses, data breach response costs and claims from affected clients, usually with a 24/7 incident helpline included.
How much does cyber insurance cost in the UK?
Add-on cover starts around £15 a month for a £25,000 limit. Standalone policies with higher limits typically cost £500 to £3,500 a year depending on turnover and data.
Is cyber insurance worth it for a sole trader?
Only if you hold meaningful customer data or move money by transfer. Otherwise, basic security plus Cyber Essentials certification often gives better value than a policy.
What does cyber insurance not cover?
Commonly excluded: ransom payments, cryptocurrency, the cost of upgrading systems afterwards, and fraud losses where required verification steps weren’t followed. Always check the policy wording.
Why do cyber insurance claims get refused?
Usually because policy conditions weren’t met — no multi-factor authentication, unpatched software, missed callback checks on payments, or late reporting of the incident.
Disclaimer: This article is general information, not financial advice. Statistics are from the government’s Cyber Security Breaches Survey 2025/26; prices are 2026 insurer figures and vary with your business. Check policy wordings and speak to an FCA-authorised insurer or broker before buying cover.
Sign up to our news alerts
The day's business headlines in your inbox each morning.
Unsubscribe from any email.


