Contact
Cyber insurance has gone from a niche product that mostly large enterprises bought, to something brokers are routinely recommending to businesses of every size. If you haven't been asked about it yet, you probably will be soon.
The short answer to whether you need it: almost certainly yes, if your business depends on its systems, holds customer data, or would struggle to absorb the cost of a serious incident. The more useful question is whether you'd actually be covered if something went wrong.
.png)
Cyber insurance has gone from a niche product that mostly large enterprises bought, to something brokers are routinely recommending to businesses of every size. If you haven't been asked about it yet, you probably will be soon.
The short answer to whether you need it: almost certainly yes, if your business depends on its systems, holds customer data, or would struggle to absorb the cost of a serious incident. The more useful question is whether you'd actually be covered if something went wrong.
Policies vary, but a reasonable cyber insurance product will typically cover some combination of the following:
Incident response costs. Bringing in specialists to investigate and contain a breach, which can run into tens of thousands of pounds even for a small business.
Business interruption. Lost revenue during downtime caused by a cyber incident. This is often the biggest number.
Data recovery. Restoring systems and data after ransomware or a destructive attack.
Legal and regulatory costs. Defending a claim, notifying affected individuals, dealing with an ICO investigation.
Reputational management. PR support following a public incident, which sounds like a luxury until you need it.
What most policies won't cover: incidents caused by negligence you knew about and didn't fix, or pre-existing vulnerabilities that were never addressed. This is where the qualifying question becomes important.
A few years ago, cyber insurance questionnaires were fairly superficial. That's changed. Insurers have paid out on enough claims to know exactly where the risk lives, and their underwriting now reflects it.
You will almost certainly be asked about:
Multi-factor authentication (MFA). Is it enabled for email, remote access, and admin accounts? If the answer is no, some insurers will decline to cover you, or exclude incidents that MFA would have prevented.
Backups. Do you have them, how often do you run them, are they tested, and — critically — are they stored somewhere that ransomware can't reach? An offsite or cloud backup that's disconnected from your main systems is what they're looking for. Backups on a drive plugged into the same server don't count for much.
Patch management. Are your systems kept up to date? Known vulnerabilities in unpatched software are one of the most common attack vectors, and insurers know it.
Endpoint protection. Basic antivirus is increasingly insufficient. Insurers are starting to ask specifically about more advanced threat detection tools.
Staff training. Have your employees had any phishing awareness training? Human error remains the leading cause of breaches, and insurers factor that in.
Here's the problem: a lot of small businesses answer these questions optimistically. They have some form of backup, so they tick the box. They have antivirus, so they tick that box too. The policy gets issued.
Then something goes wrong, the insurer investigates, and it turns out the backups hadn't been tested in eighteen months and the antivirus hadn't updated because nobody noticed the licence had lapsed. The claim gets disputed or reduced.
This isn't a rare edge case. It's a known pattern.
The way to avoid it is to make sure your IT setup actually does what you think it does, not just in principle but in practice. That means someone is monitoring it, testing it, and able to confirm it to you — and to an insurer if it comes to that.
If you're looking at cyber insurance for the first time, talk to your broker but also talk to your IT provider. A good MSP should be able to tell you clearly what controls are in place, whether they meet typical insurer requirements, and where the gaps are.
If your IT provider can't answer those questions, that's worth knowing before you fill in an insurance questionnaire.
Mercury Maynard can give you a clear picture of where your business stands. If there are gaps, we'll tell you what they are and what it would take to close them.
Revolutionise business communication with unified solutions, connectivity and reliable hardware options.
Get IT problems sorted quickly with a trusted team of experts.
Move your business to new heights with our flexible and secure Cloud Services.
Stay connected and boost your online presence with our reliable Network Solutions.
Protect your business from cyber threats with our cutting-edge Cyber Security services.
Unlock the full potential of your technology with our expert IT Advisory Services.