If your systems or data are hit — a ransomware lock, a mailbox takeover, a lost laptop that holds client files — cyber insurance is the policy that pays for the response, the restore, and the downtime. It is not professional indemnity with a different label.
Meshed is an FCA-regulated UK broker. We place cyber insurance for UK limited companies and partnerships, from a panel of insurers. Broker fee is a flat 10%, with no admin add-ons.
If you are a payments, EMI, or other regulated financial-services firm, start on Fintech Insurance UK. That page owns the specialist programme, including crime and fidelity for payment fraud. For professional indemnity, use Professional Indemnity Insurance UK. For the wider “what does a UK company need” list, use the business insurance hub. This page is cyber as its own class.
Who this is for
UK limited companies and partnerships that hold data or run on digital tools, including:
Professional services and consultancies with client files
Tech, digital, and creative agencies
Retail, hospitality, offices, and studios that take bookings or cards
Contractors whose jobs run on email and shared drives
Home-based limited companies whose client data lives on a laptop
We work with limited companies and partnerships, typically up to £30 million turnover. We do not currently place cover for sole traders.
Cyber is not a legal duty in the UK. Clients, public-sector buyers, and supply-chain questionnaires increasingly make it a condition of the contract. If you use email, store customer or staff data, or would stop trading without your systems, you need it — even if you are “just email and a laptop”.
Who we have helped
We place cyber for UK limited companies and partnerships: firms whose client or framework asks for a certificate, companies that have been treating a PI sliver as if it were cyber, and businesses that have not looked at first-party response and downtime since the last incident they read about.
What cyber insurance covers
A useful cyber policy is there when your systems or data are hit. That usually includes two sides.
Your own costs (first party)
Incident response: IT forensics, legal, and PR, often through a 24/7 panel
Restoring systems and data, or recreating what cannot be restored
Business interruption: income and extra working costs if an insured cyber event stops you trading
Notifying the people and the regulator you have to tell, including call-centre and credit-monitoring costs where the wording says so
Ransomware and extortion: specialists to contain the incident, and, where the wording and the law allow, the ransom itself
Some wordings also pick up social engineering and funds-transfer fraud — someone tricks a person into sending money. That is only in scope here when it sits on the cyber policy
Claims against you (third party)
A client, customer, or other third party claiming their data was lost or their systems were affected because of your incident
Defence costs, and any damages or settlement the policy agrees to, up to the limit
Regulatory investigation costs, where the wording includes them
Exact wording varies by insurer. We show you the gaps before you bind, not after a claim. A comparison-site add-on on a liability policy is often a small combined limit with little first-party response. That is not the same product.
Payment-fraud crime and fidelity for a regulated payments or EMI firm is not this page. That sits on Fintech Insurance UK.
What it does not cover
Cyber will not pay for a client who says your advice, design, or delivery cost them money. That is professional indemnity. It will not pay for a visitor who is injured, or a damaged floor. That is public liability. It will not protect directors personally for how they ran the company. That is D&O. It will not replace the building after a fire. That is property.
It also will not usually pick up:
Something you already knew about, or did on purpose
Unsupported or unpatched systems you told the insurer were fine
Injury or physical property damage from a cyber event
Outages of national infrastructure — power, water, telecoms — that are not your systems
State-backed or warlike cyber attacks
ICO or other regulatory fines, which UK policies commonly treat as uninsurable
Insurance does not replace security. Underwriters now expect the basics: multi-factor authentication, tested backups, and patching. Cyber Essentials is the government-backed scheme they often ask about. Be honest on the proposal. A claim can fail on a control you said you had.
Controls underwriters ask about
Buying cyber in the UK is not only turnover and limit. The proposal asks what you actually run. Vague answers slow the quote, raise the premium, or shrink the wording. The questions below are the ones that most often matter — framed as insurance buying questions, not a security handbook.
Access (MFA) — Multi-factor authentication on email, administrator accounts, and remote access. Password-only admin or mailbox logins are a common load or decline trigger, even for small companies.
Recovery (backups) — Backups that sit separately from the live systems (offline or a protected cloud), plus evidence you have tested a restore. “We have backups” without a tested restore is a weak answer after ransomware.
Hygiene (patching) — Prompt updates on internet-facing and critical systems. Unsupported kit you told the insurer was fine can fail a claim later.
People (phishing) — How staff spot urgent or unusual requests, and how easy it is to report a suspicious email. Phishing remains a common entry point; insurers care about the process, not a branded tool.
Remote access — Who can reach systems over VPN or remote desktop, whether unused services are off, and whether those paths also have MFA. Exposed remote desktop with weak controls is a frequent underwriting flag.
Monitoring — Even a basic habit of reviewing unusual login or data-movement alerts helps. Perfect SOC tooling is not required for every SME; silence on “how would you notice?” is worse.
Honesty on the form still beats a perfect stack you do not have. Say what is true today, and what you will fix before bind if the market needs it.
How cyber differs from professional indemnity
Professional indemnity is for when a client says your work cost them money. Some PI wordings pick up a sliver of third-party data risk — a client claiming you lost their file. That is not a substitute for cyber.
A ransomware event, your own outage, incident response, and the cost of notifying people sit on a cyber policy. PI will not send the forensics team at 2am. We will say if PI and cyber should be placed together so one incident is not bounced between them.
The PI detail — claims-made, retroactive dates, run-off, professional-body minima — lives on Professional Indemnity Insurance UK. Do not size a PI programme from this page.
If you have to tell the ICO
This is plain English, not legal advice. Check the Information Commissioner’s Office guidance for your facts.
If personal data is lost, stolen, or accessed when it should not have been, that can be a personal data breach. Not every IT incident is one. Not every breach has to be reported.
Where a breach is likely to risk people’s rights and freedoms, UK data protection law says you tell the ICO without undue delay, and within 72 hours of becoming aware of it. The clock starts when you discover it, not when it happened. If the risk to people is high, you also tell them, without undue delay, so they can protect themselves. If you decide it is not reportable, keep a record of that assessment.
A useful cyber policy pays for the lawyers and the forensics who help you make that call, and for the notification if you have to send it. It will not usually pay an ICO fine. Paying a ransom does not count as fixing the risk to people, and it does not take the place of a report.
If you think you have an incident, tell us and the insurer before you start sending public statements. Late notification is how otherwise decent policies fail.
Ransomware
Ransomware is one of the reasons this class exists. The loss is rarely just the demand. It is the days you cannot trade, the restore, the legal advice, and the people you may have to tell.
A cyber policy that is worth having puts a response team on it: contain, investigate, restore, and decide what you say. Cover for the ransom payment itself is wording- and law-dependent. Insurers will not authorise a payment that breaks sanctions rules. The National Cyber Security Centre’s position is that paying is a last resort, and it does not fulfil your duties to the ICO.
Tested, offline backups reduce how bad the week is. They do not remove the legal, notification, or interruption costs. We will not pretend a cheap add-on with a thin extortion sub-limit is the same as a wording built for this.
What it costs
There is no single right limit. Size it to the largest realistic outage, the number of people you would have to notify, and whatever your contracts already name.
In the UK market you will usually see:
A small add-on on a liability or PI policy, often a fraction of a standalone limit. Fine as a gesture. Not fine if a week offline would hurt
£250,000 to £1 million as a common standalone range for smaller companies
£1 million or £2 million where a client, a framework, or a larger book of data sets a higher floor
Above that for companies that could not take a long outage, or that hold a lot of other people’s data
Any one incident can exhaust an aggregate. Business interruption often has its own sub-limit, waiting period, and indemnity period. Read those, not just the headline.
Premium follows risk. Insurers price the work you do, turnover, the data you hold, how you back it up, claims history, limit, and excess. A consultancy on email and a firm that stores health or payment data will not pay the same.
We will not publish a “from £X a month” number that only exists for the cheapest add-on on a comparison site.
What you can control: MFA, tested backups, a proposal that describes the systems you actually run, and a schedule that is not still written for last year’s company. Underwriters load the files that are vague.
How Meshed works
You tell us what you do: services, turnover, systems, data you hold, contracts, headcount, and current cover.
We review the documents and flag gaps in first-party response, business interruption, crime-on-cyber, PI overlap, territory, and the security questions underwriters will ask.
We go to our panel and come back with options.
You bind. We stay on for mid-term changes and renewal.
Straightforward SME risks are often quoted in minutes. Heavier data holdings, weak controls, or a claims history can take longer. We will say that up front.
FAQs
What is cyber insurance?
Cover for when your systems or data are hit. A useful policy pays for incident response, restoration, notification, and the business interruption that follows, plus claims from people whose data or systems were affected. It is not a substitute for professional indemnity.
Do I need cyber insurance in the UK?
Not as a blanket legal duty. You need it if a contract asks for it, or if a ransomware event, a mailbox takeover, or a lost laptop of client files would cost you real money. For most limited companies that use email and hold other people’s data, that is a yes.
Does cyber insurance cover ransomware?
Usually the response, the restore, and the downtime. The ransom payment itself depends on the wording and on whether a payment would be lawful. Paying a ransom does not replace a report to the ICO if one is required.
What is the difference between cyber and professional indemnity?
PI is financial loss from your advice or services. Cyber is your systems, your data, the response, and the outage. Some PI wordings pick up a sliver of third-party data risk. That is not enough. Most service firms need both. The PI page is Professional Indemnity Insurance UK.
Does cyber insurance cover ICO fines or GDPR?
It can pay for the lawyers, the forensics, and the cost of telling people. ICO administrative fines are commonly uninsurable in the UK. This is not legal advice. Use the ICO’s current guidance for whether a breach is reportable.
How much cover do I need?
Enough for the outage and the notification, and at least what your contracts specify. Many UK companies look at £250,000 to £1 million. Frameworks and larger data holdings ask for more. We size it to those, not to a comparison-site add-on.
How much does cyber insurance cost in the UK?
It depends on the work, the data, the controls, the limit, and the claims history. There is no useful average across trades. We quote the company in front of us.
I am a fintech. Is this the right page?
No. Use Fintech Insurance UK for payments, EMI, PSD2, and other regulated financial-services models, including crime and fidelity for payment fraud.
Are you an insurer?
No. Meshed is a broker. Mesh'd Limited trading as Meshed is authorised and regulated by the Financial Conduct Authority under firm reference number 1033248.
How fast can we bind?
Clean renewals and standard SME cyber can be same-week. Weak security answers, a claims history, or a wording that has to sit with PI take longer.
What security controls do UK cyber insurers ask about?
Usually MFA on email and admin accounts, how and where you back up (and whether restores are tested), patching on critical systems, who has remote access, and how phishing is handled. Cyber Essentials is often asked about as a government-backed baseline. Exact questions vary by insurer — we flag gaps before you bind.
Do I need MFA before I can buy cyber insurance?
Often yes in practice for email, admin, and remote access. Some markets will quote with a condition that MFA is on before inception. Password-only admin access is one of the fastest ways to get a load or a decline.
Do tested backups matter for cyber cover?
Yes. Underwriters want backups that are separate from the systems that ransomware would hit, and they want to know a restore has been tested. Backups reduce how long you are offline; they do not remove legal, notification, or response costs.
Does phishing training affect a cyber quote?
It can. Phishing is still a common way in. A clear report path and basic staff awareness help more than claiming you are “too small to be a target.” We will not invent Meshed claim stats — answer the proposal with what you actually do.
Will weak remote access (VPN / remote desktop) stop a cyber quote?
It can slow or load it. Unused remote services should be off; live paths need MFA and least-privilege access. If remote desktop is exposed with weak controls, expect the underwriter to ask for a fix before bind.

Vincent Liu
Co-founder & CTO



