Business guide

Cyber insurance, what it actually covers.

A plain guide for UK small businesses. The two sides of the cover, the real-world scenarios, and the bits people assume their IT already handles.

careless™ · 8 min read · 23 June 2026

It usually starts on a normal morning. Someone clicks a link that looked fine, an invoice gets paid to the wrong bank account, or every screen in the office throws up the same ransom message at once. Whatever the trigger, the next few hours are the same: nobody can work, nobody is quite sure what was taken, and the bills are already starting to stack up while the clock runs.

Cyber insurance is the cover for that morning. Not for stopping the attack, your IT setup does some of that, but for paying to put it right and seeing you through the fallout. This guide is the honest version of what it actually covers, where it stops, and why "we're too small to be a target" is exactly the assumption that gets small businesses hit.

The one thing to understand first

There are two sides to cyber cover, and most confusion comes from only knowing one of them.

The first-party side covers your own costs: getting an expert team in the moment something goes wrong, recovering your systems and data, and replacing the income you lose while you're down. The third-party side covers other people's claims: the customers, suppliers and partners whose data was caught up in a breach, plus the cost of defending yourself if a regulator comes knocking.

A real incident almost always hits both sides at once. Your systems are down (first party) and your customers' data is exposed (third party), in the same afternoon. Good Cyber cover responds to the whole picture, not just the part you were worrying about.

One thing to be clear on up front. Cyber is an opt-in Section of one modular policy. You choose it alongside the other covers that fit your business, and there's no policy that quietly bundles everything in. The covers below are the ones you select, sized to the work you actually do.

What the first-party side pays for

This is the cover that gets you back on your feet.

  • Incident response. The moment a breach or attack is confirmed, expert help kicks in: IT forensics to work out what happened, legal advice on your obligations, customer notification, and PR if the story gets out. You're not figuring it out alone at 9pm.
  • Recovering your systems and data. The cost of cleaning out the attacker, restoring what was lost or corrupted, and getting you operating again. A clean rebuild after ransomware is rarely a quick job, and it's rarely cheap.
  • Business interruption. While you're down, you're not earning. This covers the income you lose during the outage, so a few days offline doesn't turn into a cash-flow crisis on top of everything else. A short waiting period applies before it starts, so the very first hours sit outside it.
  • Cyber extortion and ransomware costs, where it's lawful to pay them, alongside the work of restoring your data so you're not negotiating from a corner.

The point of the first-party side is that the response matters as much as the payout. A small business that has never handled a breach before gets a team that has handled hundreds.

What the third-party side pays for

This is the cover for when the incident lands on someone else.

If you hold customer data, take payments, or store supplier details, a breach can leave other people out of pocket or exposed. The third-party side covers the claims that follow: compensation to people whose personal data was lost or stolen, the legal costs of defending those claims, and the cost of dealing with the regulator. Under UK data-protection rules a serious breach can mean notifying everyone affected and the ICO, and that process alone has real costs attached before any claim is even made.

In plain terms, the first-party side fixes your problem, and the third-party side handles their problem when it becomes your liability.

The 24/7 incident helpline

One feature is worth calling out on its own. Select Cyber and a 24/7 cyber incident helpline comes with it, no separate add-on. The moment you suspect something is wrong, day or night, weekend or bank holiday, there's a number to call and a specialist on the other end telling you what to do next.

That matters because the first hour of a cyber incident is where most of the damage is either contained or made worse. Knowing not to pay the spoofed invoice, not to wipe the machine, and exactly who to notify is the difference between a bad day and a much worse week. The helpline is included once Cyber is on your policy, not a paid add-on.

What it looks like in real life

The covers make more sense against the kind of thing that actually happens.

Ransomware lockout. Your team arrives on Monday and every system is locked behind a ransom demand. Cover steps in for the specialist response, restoring your data and systems, and the income lost while you're down. The helpline guides you through the first decisions before anything gets worse.

Business email compromise. A finance email is spoofed, an invoice looks legitimate, and a payment goes out to a fraudster's account. Cyber crime cover responds to the funds lost to the deception, and the helpline talks you through the recovery and reporting steps.

Account takeover. A login is compromised and an attacker is inside your systems sending messages, moving money or harvesting data as you. Cover responds to the investigation, locking it down, and the cost of putting right what they touched.

A data breach. Customer data is exposed and you're legally required to notify everyone affected. The cost of notifying customers and the regulator is covered, along with any claims that follow from the people whose data was caught up in it.

"Doesn't my IT provider or antivirus already cover this?"

This is the honest bit, and it trips up a lot of owners.

Your IT provider, your antivirus, your firewall and your backups all do real work. They reduce the chance of an incident. What none of them do is pay for the incident once something gets through. No security is perfect, and the whole reason cyber insurance exists is for the day something gets past good defences anyway.

Think of it like a burglar alarm. The alarm makes a break-in less likely. It does not replace what's stolen, repair the damage, or cover you while you're shut. That's a different job, and for cyber, this is the cover that does it. Strong IT and cyber insurance are not alternatives, they work together: one lowers the odds, the other handles the fallout.

Why small businesses are targeted

"We're too small to be worth attacking" is the most common, and most costly, assumption.

The opposite is closer to the truth. Smaller businesses are targeted precisely because their defences are lighter. Most attacks aren't a hacker hand-picking a victim, they're automated, scanning for whichever door is easiest to push open. A small firm with no dedicated security team is often that door. And when an incident does land, the cost, from recovery to lost trading to notifying customers, hits a small business just as hard as a large one, often harder, because there's less slack to absorb it.

If your business holds data or leans on systems and email to function, the exposure is real regardless of headcount.

What cyber insurance does not cover

Knowing the edges keeps you from assuming you're protected when you're not. The main exclusions:

  • State-backed cyberwar and acts of terrorism. Attacks attributed to a government or carried out as terrorism sit outside the cover.
  • Pre-existing breaches you already knew about. Cover responds to new incidents, not ones you were already aware of when you took it out.
  • Unpatched known vulnerabilities, subject to underwriting, where a flaw you'd been warned about was left open.
  • The very first hours of lost income, because a short waiting period applies before business interruption starts.

None of these should put you off. They're the normal boundaries of the cover, and the everyday risks, the ransomware, the spoofed invoice, the breach, are squarely what it's built for.

Where this sits among your other covers

Cyber handles digital risk. The physical and professional risks are separate Sections you choose alongside it. If equipment is stolen or damaged that's Business Contents; if a client is injured or their property damaged that's Public Liability; and the moment you employ anyone, Employers' Liability is a legal requirement.

If you run an agency or work as a creator and hold a lot of sensitive client or audience data, cyber risk is often higher than you'd expect, so it's worth reading insurance for talent and management agencies and our content creator insurance guide alongside this. And if your real question is what all this costs, we break the numbers down in how much business insurance costs in the UK.

What it costs, and how it's arranged

We don't hide the number behind a form. What you pay depends on your business, the data you hold, and the cover you select. Cover is sold in plans with a single £25 admin fee, the only one, and you see your price before you commit.

Getting covered is three quick steps: answer a few questions, see your price, and you're covered the same day. caremate™ builds your quote in minutes, in plain English, no broker hold music. Cover is arranged with Kovrilo and underwritten by established insurers, so it pays out when it should. We quote businesses from £50k turnover upwards.

Where careless™ fits

A cyber incident is the kind of thing you can't see coming and can't fix alone. You don't need a lecture on threat vectors, you need cover that pays to put it right and a real person to call the moment it kicks off.

That's the whole idea. The 24/7 helpline answers when something goes wrong, the cover handles the recovery and the claims that follow, and you get back to running the business. See your price in a few minutes, no obligation: get a quote, or start with Cyber cover.

Questions, answered.

Two sides. The first-party side covers your own costs: expert incident response, recovering your systems and data, and the income you lose while you're down. The third-party side covers other people's claims: compensation to those whose data was exposed, plus the cost of defending yourself against the regulator. A real incident usually hits both at once, and the response matters as much as the payout.

Smaller businesses are targeted precisely because their defences are lighter, and most attacks are automated, looking for the easiest door rather than a specific victim. When an incident lands, the cost of recovery, lost trading and notifying customers hits a small business just as hard. If you hold data or depend on systems and email, the exposure is real regardless of size.

They reduce the chance of an incident but don't pay for one. No security is perfect, and cyber insurance covers what happens when something gets through, which IT support and software alone don't. Think of it like a burglar alarm: it makes a break-in less likely, but it doesn't replace what's stolen or cover you while you're shut. Strong IT and cyber insurance work together.

Yes. The helpline comes with Cyber once you select it, at no extra charge: a 24/7 cyber incident line you can call the moment you suspect something is wrong, day or night, where a specialist tells you what to do next. The first hour of an incident is where damage is either contained or made worse, so having someone to call matters. It comes with Cyber once you select it, not a paid add-on.

Cyber extortion and ransomware costs can be covered where it's lawful to do so, alongside the work of recovering your data and systems so you're not negotiating from a corner. Known, unresolved breaches you were already aware of, and unpatched vulnerabilities you'd been warned about, are excluded.

Cyber covers the fallout of an attack or breach, but a few things sit outside it: state-backed cyberwar and acts of terrorism, pre-existing breaches you already knew about, unpatched known vulnerabilities (subject to underwriting), and the very first hours of lost income, because a short waiting period applies before business interruption starts. The everyday risks, ransomware, spoofed invoices and breaches, are squarely what it's built for.

See your price before you commit

Answer a few quick questions and your quote lands in minutes. No broker calls, no obligation.