Cyber insurance uk buyers meet, and the rules that shape what a policy must do

Cyber insurance in the United Kingdom is shaped by a different set of rules from the market it is most often compared to. The duties that make an incident expensive here come from UK data protection law and the Information Commissioner rather than from a patchwork of state notification statutes, and the insurers writing the risk are authorised firms you can look up. That changes what a policy has to do and what a buyer should check.

Who is behind the policy, and how to check

Every insurer and every broker selling cyber cover in the United Kingdom must be authorised, and the register is public. Looking up the name on the schedule takes a minute and tells you whether you are dealing with an insurer, a managing general agent writing on somebody else's paper, or an introducer. It matters at claim time, because the entity that answers the claim is the insurer, not the website that sold it.

The regulator that turns an incident into a process

A personal data breach that is likely to risk people's rights has to be reported to the Information Commissioner, and there is a short window to do it. That single duty is what drives the cost of an incident for most small businesses: the forensic work to establish what actually went, the legal advice on whether the threshold is met, the notification itself, and the correspondence afterwards. A cyber policy earns its price mostly by paying for that process and by putting people who have done it before on the telephone.

What a UK wording usually contains

First party costs: incident response, forensics, data restoration, business interruption, and in most wordings a ransom section with conditions attached. Third party liability: claims by the people whose data went, and by clients under contract. A crime or social engineering section, sometimes included and sometimes an extra. Plus a services wrapper, which varies enormously and is where cheaper policies are thinnest.

Buying direct against buying through a broker

Direct online cyber cover is quick and the cheapest quotes usually come from packaged schemes. A broker earns their keep on the proposal form, because the questions about controls are the ones that decide both the price and whether a claim is later argued. If the business has an unusual exposure, an outsourced data processor, an overseas client base or a payments role, the broker route is generally the safer one.

Questions people ask about cyber insurance uk

Is UK cyber insurance different from a US policy?

The sections look similar and the duties behind them do not. UK notification runs through the Information Commissioner under UK data protection law, while a US policy is written against state breach statutes and a different liability climate. A wording drafted for the US market can leave UK regulatory costs sitting in the wrong section.

How do I check an insurer is authorised?

Search the name on the Financial Conduct Authority register. It will tell you what the firm is permitted to do and whether it is an insurer, an agent or an intermediary.

Does a UK policy cover work I do for overseas clients?

Often, but the territorial and jurisdiction clauses decide it. A policy written for UK exposures can exclude claims brought in another country's courts, which matters if you sell into the United States.

Who do I report a cyber crime to in the UK?

Action Fraud takes reports of fraud and cyber crime, and a personal data breach is reported separately to the Information Commissioner. An insurer's incident response team will usually help you do both in the right order.

Sources

Related answers

See what insurers printCompare by trade