INSIGHTS & NEWS

Cyber liability insurance: what SMEs need to know

September 25, 2026 I London, UK

Cyberattacks are no longer a problem reserved for large corporations. For an SME, a ransomware attack, data breach or prolonged system outage can disrupt operations just as effectively, and the financial consequences can be harder to absorb. Cyber liability insurance can help cover those costs. But it is not simply a matter of buying a policy and forgetting about cyber risk. Insurers increasingly want to see that businesses have sensible security measures in place before they’ll provide cover.

Cyber liability insurance is specialist cover designed to protect a business against financial losses arising from cyber incidents, including data breaches, ransomware and network security failures. It can cover both the costs a business incurs itself and certain claims made against it by others. That can include everything from investigating an attack and restoring systems to dealing with legal claims or lost income while the business is unable to operate normally. It differs from data breach security in that data breach insurance is narrower, generally focusing on the costs associated with compromised personal or sensitive information, while cyber liability insurance can also cover risks such as ransomware, business interruption, system recovery and cybercrime.

General liability insurance is designed mainly for conventional risks such as physical injury or property damage. Most commercial property and general liability policies do not provide comprehensive cover for cyber risks. If they do, it is unlikely to address the full range of costs associated with a serious cyber incident. The reason is fairly straightforward. A cyber incident can create losses that have no physical component at all, from stolen customer data to business interruption and the cost of repairing software.

Yes, if a business relies on digital systems, holds sensitive information or would struggle financially if its operations were interrupted. Being small does not mean being low-risk. It can mean having fewer resources to recover when something goes wrong.

Policies differ, but cyber insurance can cover several costs associated with an incident, including:

  • Investigating and responding to a breach
  • Restoring damaged or compromised data and systems
  • Business interruption and lost income
  • Legal and regulatory costs
  • Claims from customers or other third parties
  • Certain cybercrime and fraud losses

The exact combination depends on the policy. Cyber insurance is highly customised, so businesses need to look beyond the basic level of cover.

Cyber insurance doesn’t cover every loss associated with a digital incident. Policies can contain exclusions, deductibles, sub-limits and conditions relating to security controls or the circumstances of the attack. Also, cover may depend on the business having appropriate measures in place.

Cyber insurance premiums rose sharply as insurers faced more frequent and expensive claims, particularly from ransomware. But the market has changed considerably.

Marsh reported that global cyber insurance rates fell 4% in Q2 2026, the twelfth consecutive quarterly decline. That doesn’t mean cyber insurance is suddenly cheap or that insurers have stopped scrutinising risk. It means the market has become more competitive while underwriting remains selective.

There’s no standard amount that suits every SME. The right level depends on the potential financial impact of an incident, including lost revenue, recovery costs, regulatory exposure and claims from customers or partners.

A useful starting point is to ask:

  1. How much would a week without our key systems cost?
  2. What data would we need to recover or notify people about?
  3. What could a serious incident cost in legal, technical and operational terms?

Good cybersecurity can reduce risk and may improve the terms an insurer is prepared to offer.Practical measures such as keeping software updated, controlling access to systems, securing backups, training employees and having a plan for responding to incidents can all have an impact. Of course, these are useful whether or not a business ultimately buys insurance.

Start with the risks that could genuinely hurt the business, then compare policies against them.

Look at the limits, exclusions, deductibles, waiting periods and sub-limits, rather than comparing premiums alone. Check whether business interruption, cybercrime, third-party claims and incidents involving suppliers are covered.

It’s also worth asking what happens when you make a claim. Access to forensic specialists, legal advice and incident-response support can be just as important as the eventual financial reimbursement.

JENOA is an end-to-end digital broker providing reinsurance, risk advisory, InsurTech and Sharia-compliant solutions to help businesses manage risk as they grow.

For businesses considering cyber liability insurance, the important point is that insurance should sit alongside good cybersecurity, not replace it.