Cyber insurance for small businesses is a different purchase from the corporate version, and copying the corporate structure is how small firms end up paying for limits they will never use while leaving the section they need at a token figure. At this scale the losses are concentrated: a fortnight of disruption, a diverted payment, and the professional fees around telling people their data went. Everything else is theoretical.
Size the sections, not the headline
Start with the three realistic numbers. How much revenue would be lost if the business could not operate for two weeks. What is the largest payment the business could be tricked into making. How many individuals would have to be notified if the client file went. Those give you business interruption, crime and liability respectively, and they will rarely be equal. A quote that puts a large aggregate limit above a crime sub limit of a few thousand pounds has not been sized for you.
What a small business can reasonably skip
Media liability, cover for large scale system failure at a global provider, and very high aggregate limits are priced for organisations with different exposures. So is a bespoke wording. Where the business is genuinely small, a packaged policy from a recognised insurer with a proper incident line and a crime section added is usually the right buy, and the effort is better spent on the controls.
The controls that pay for themselves at this size
Multi factor authentication on email costs nothing and removes the most common route in. A backup that is not reachable from the live system removes most of the leverage a ransomware attack has. A rule that any change to a supplier's bank details is confirmed by telephone to a number already held removes the most common route money leaves. Those three changes improve the quote and reduce the chance of needing it.
Buying it alongside the cover you already hold
Most small firms already carry public liability and often professional indemnity. Adding cyber with the same insurer keeps the wordings from arguing and usually simplifies the claim. Where the existing package already includes a small cyber section, the question at renewal is whether to raise it or replace it, and the answer depends entirely on the three numbers above.
Questions people ask about cyber insurance for small businesses
Is cyber insurance worth it for a sole trader?
If you hold client data or invoice by email, the premium at that scale is small and the response service is the main value. If you take cash for physical work and hold almost nothing, the case is weaker and the honest answer may be no.
What is the cheapest way to reduce the premium?
Turn on multi factor authentication, separate and test the backups, and write down a payment verification rule. Those three answers change the proposal form more than shopping the quote does.
Can I add cyber mid term?
Usually yes, as an addition to an existing business policy or as a standalone policy running alongside. Cover starts when it starts, so an incident already under way is not brought in.
Does my accountant or IT provider carry cover that protects me?
Theirs protects them and answers their liability to you, subject to their limits and their contract. It is not your cover and it will not pay your costs directly.