Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Cyber Insurance for UK Small Businesses: What It Covers and How to Avoid a Denied Claim

In short

Cyber insurance helps you recover after an attack, but a policy is not a substitute for basic security. UK insurers now verify controls like multi-factor authentication and email protection before they pay out. This guide explains what cover includes, what to have in place first, and the honest reasons claims get refused.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

What cyber insurance actually is

Cyber insurance is cover that helps your business recover after a cyber attack or data breach. Think of it the way you think about buildings or public liability insurance: it does not stop bad things happening, but it helps you pick up the pieces when they do.

For a small business, the appeal is simple. A single ransomware attack or a convincing invoice scam can cost more than many firms have sitting in the bank. A policy can cover the costs of getting back on your feet, and often gives you access to specialists who deal with these incidents every day.

But there is an honest catch, and it is the whole reason for this article: insurers have tightened up. They now check whether you have basic protections in place before they agree to pay. Get that wrong and you can be left with a policy that never pays out.

What a typical policy covers

Cover varies between insurers, so always read your own schedule. That said, most small-business cyber policies include some mix of the following:

  • Incident response — the specialists who investigate what happened, contain it, and get you running again.
  • Data recovery — the cost of restoring systems and information after an attack.
  • Business interruption — money to cover lost income while you are unable to trade.
  • Cyber extortion — support if you are hit by ransomware, though paying a ransom is strongly discouraged and may be restricted.
  • Third-party liability — claims from customers or suppliers whose data was exposed through you.
  • Regulatory support — help dealing with the Information Commissioner’s Office (ICO) if personal data is affected.

Some policies also help with the cost of notifying affected customers and managing the reputational fallout. What matters is that you understand your limits, your excess, and any conditions attached.

Why insurers now verify your controls

A few years ago, buying cyber insurance meant ticking a few boxes and paying the premium. Those days are over. After a wave of claims, insurers realised many businesses had almost no protection in place, and they responded by asking harder questions.

Two controls come up again and again on application forms.

Multi-factor authentication (MFA). This is the second check, usually a code or an app approval, that stops a stolen password being enough to log in. Because stolen passwords are behind so many attacks, MFA is now a common condition of cover, especially on email and remote access. A good password manager makes MFA and strong, unique passwords far easier for your whole team to actually use.

DMARC. This is an email setting that makes it much harder for criminals to send messages that appear to come from your business. It helps prevent the fake-invoice scams that cause real financial losses. Insurers care because email impersonation is a major driver of claims.

Insurers do not just ask about these to be thorough. They increasingly verify them after an incident. If you said you had MFA and you did not, the payout can be reduced or refused entirely.

Insurance pays out after the damage is done. Basic controls stop the damage happening in the first place, and increasingly they are the price of being insured at all.

What to have in place first

Before you even fill in an application, sort out the foundations. They lower your risk, they often lower your premium, and they mean you can answer the questions honestly.

  • MFA on email, banking, and any remote access to your systems.
  • A password manager so staff use strong, unique passwords without writing them on sticky notes.
  • Reliable, tested backups kept separate from your main systems, so ransomware cannot encrypt them too.
  • Up-to-date software with security updates applied promptly.
  • Staff awareness so people can spot a phishing email before they click.
  • DMARC and email protection configured properly on your domain.

If that list feels daunting, it is exactly the kind of groundwork a managed IT provider handles day to day. Our cyber-security service is built around getting these basics right first, because they matter far more than any single clever tool.

The common reasons claims get denied

Nobody likes reading the small print, but understanding why claims fail is the best way to make sure yours would not. The usual culprits are:

  • Misdeclaring your controls. Saying you have MFA, backups or a certain policy when you do not. This is the biggest one, and it is entirely avoidable.
  • Missing MFA where it was required. A single unprotected admin account can be enough for an insurer to argue the breach was preventable.
  • Unpatched software. If a known security flaw went unfixed for months and that is how attackers got in, expect questions.
  • Late reporting. Most policies require you to report an incident quickly. Sit on it for weeks and you may lose cover.
  • Excluded events. Some causes, like attacks linked to nation states or your own staff acting maliciously, may not be covered at all.

The theme is consistent: honesty and evidence. Keep a simple record of the controls you have in place. If the worst happens, that record is what turns a stressful claim into a straightforward one.

Insurance and good security work together

The healthiest way to think about cyber insurance is as a safety net beneath a floor you have already built. The floor is your day-to-day protection: MFA, backups, updates, trained staff. The net is the policy that catches you if something still gets through.

Buying the net without building the floor is where businesses get caught out, because that is exactly the gap insurers now check for. Working formal certification like Cyber Essentials into the mix can also make cover cheaper and easier to obtain, since it demonstrates the controls insurers want to see.

If you are not sure where you stand, or you have a policy and want to be certain you would actually be paid out, we can help. Book a free IT and security review and we will walk through your current setup in plain English, no jargon and no pressure. You can also see how we price ongoing support on our pricing page.

Frequently asked questions

Do I really need cyber insurance if I'm a small business?

If losing access to your systems, data or bank details for a few days would seriously hurt you, it is worth considering. Small firms are targeted precisely because attackers assume their defences are weaker. Cover is not a legal requirement, but it can be the difference between a bad week and a closed business. Just remember insurance pays out after an incident. It does not stop one happening, so pair it with basic controls.

Why does my insurer ask about multi-factor authentication?

Because stolen or guessed passwords are behind a large share of claims. Multi-factor authentication (MFA) adds a second check, usually a code or app approval, so a stolen password alone is not enough to get in. Many insurers now make MFA a condition of cover. If you declared you had it and you did not, they can reduce or refuse a payout.

What is DMARC and why does it matter for a policy?

DMARC is an email setting that helps stop criminals sending emails that look like they come from your business. It protects your customers and your reputation. Insurers increasingly ask about it because email impersonation drives invoice fraud. It is technical to set up, but an IT provider can configure it for you.

Can a claim really be refused over a small detail?

Yes. The most common reasons are misdeclaring your controls on the application, not having MFA where you said you did, unpatched software, or not reporting the incident quickly enough. Insurers verify the facts after an attack. Being honest on the form and keeping simple evidence of your controls is the best protection.

What should I sort out before buying a policy?

MFA on email and key systems, a password manager, reliable backups you have tested, up-to-date software, and staff who can spot a phishing email. These are the same things insurers check, so putting them in place lowers both your risk and often your premium.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.