
Short answer: many UK SMEs should consider cyber insurance, but it should sit behind the basics, not replace them. If email, Microsoft 365, your website, card payments, client files or bookings matter to your business, cyber insurance can help with response costs and business interruption after an incident.[1]
The mistake is buying a policy and assuming the risk is handled. The NCSC is blunt about this: cyber insurance will not instantly solve every cyber problem, and businesses should put basic safeguards in place before they treat insurance as the plan.[1]
Why this question is coming up more often
The UK Government's Cyber Security Breaches Survey 2025 found that 43% of businesses reported a cyber breach or attack in the previous year.[6] The same survey found that almost half of businesses reported some form of cyber insurance, with higher uptake among small and medium businesses.[6]
That makes sense. Owners are starting to treat cyber incidents like fire, theft or flood: unlikely on any given day, expensive when they happen, and awkward if nobody knows who pays for recovery.
Cyber insurance can help with incident response, business interruption, legal support and regulatory follow-up after a cyber incident.[1] For a small firm, those practical services can matter as much as the payout. When email is down and invoices cannot go out, you need people who know what to do, not a PDF full of exclusions.
What cyber insurance will not do
Cyber insurance does not patch laptops, configure MFA, test backups or remove old admin accounts. It also will not make an insurer ignore weak controls if the policy required them.
That is where SMEs get caught. A proposal form may ask whether you use multi-factor authentication, whether backups are separate from the network, whether security updates are applied, or whether staff have a way to report suspicious messages. If the answer is guessed rather than checked, the business has a problem before the incident even starts.
The NCSC's small organisation guidance starts with practical controls: secure email, protect important online accounts, protect devices, back up data and spot cyber attacks.[2] Those are the things that reduce the chance of a claim and make recovery less painful if something still gets through.
Cyber Essentials and insurance
Cyber Essentials is the UK Government recommended minimum standard for organisations of all sizes.[7] It is built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.[7]
For some UK organisations under £20m turnover, Cyber Essentials certification can also include cyber liability insurance arranged through IASME, including 24/7 incident response support.[7] That does not mean it is the right cover for every business, but it is a useful reason to look at certification before buying a separate policy.
There is another benefit too: a growing number of organisations require suppliers to be Cyber Essentials certified before they can bid for work.[7] For many SMEs, the commercial argument is just as strong as the security one.
What to check before buying a policy
Before you buy cyber insurance, ask these questions:
- What systems would stop us trading if they were unavailable for two days?
- Are Microsoft 365, admin accounts and remote access protected with MFA?
- Are backups separate from the main network, and have we tested a restore recently?
- Who would we call first if email, the website or our files were compromised?
- Does the policy cover business interruption, incident response, legal support and data recovery?
- What exclusions apply if updates, MFA or backups are not in place?
- Are suppliers, cloud systems and payment platforms part of the risk assessment?
That list is deliberately plain. If the business cannot answer it, the right next step is not shopping around for the cheapest policy. It is getting the basics checked properly.
The BMT view
Cyber insurance is worth considering for SMEs, especially if downtime would quickly cost money or damage client trust. But it should be the safety net, not the first line of defence.
A good setup looks boring: MFA on important accounts, sensible Microsoft 365 security, managed updates, restricted admin access, tested backups, website maintenance and a written recovery process. Insurance then has something solid to sit on.
BMT can help with the practical side: checking your Microsoft 365 tenant, reviewing backups, tightening admin access, checking website and hosting risks, and giving you a clean evidence pack for insurers. No scare tactics. Just the bits that decide whether a cyber incident becomes a rough morning or a very expensive week.
Practical takeaways
- Do not buy cyber insurance as a substitute for MFA, backups and updates.
- Read the exclusions before you assume an incident would be covered.
- Consider Cyber Essentials if clients ask about security or supplier assurance.
- Test backups before an insurer, client or attacker forces the issue.
- Keep evidence of your controls, because policies often depend on what you can prove.
Sources
[1] https://www.ncsc.gov.uk/guidance/cyber-insurance-guidance — NCSC cyber insurance guidance
[2] https://www.ncsc.gov.uk/collection/small-business-guide — NCSC Small Business Guide
[6] https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025 — Cyber Security Breaches Survey 2025
[7] https://www.cyberessentials.ncsc.gov.uk — Cyber Essentials overview
