Cyber protection insurance, and the prevention services bundled into a policy

Cyber protection insurance is the marketing name for something real: UK insurers now bundle prevention services into the policy, because a claim they help you avoid costs them nothing. For a small business with no security budget and no in house expertise, those services are sometimes worth more than the indemnity, and they are almost never compared when quotes are lined up on price.

What is commonly included before anything goes wrong

External vulnerability scanning of the domain and public facing systems. Monitoring for the firm's email addresses appearing in leaked credential dumps. Phishing simulation and staff training modules. Template incident response plans. A helpline for a question that is not yet a claim. Coverage varies widely: some insurers include all of it, some include a portal nobody logs into, and some include nothing at all.

Why insurers give it away

The controls that prevent claims are cheap relative to the claims, and insurers have better data than any individual buyer about which ones matter. Bundling the services is also how an insurer keeps its own underwriting current: a firm whose scan shows an exposed remote access port is a firm the insurer wants to talk to before renewal rather than after an incident.

How to judge whether the services are real

Ask three questions before buying. Is the incident line answered by the insurer's own response team or by a general claims desk. Are the prevention services delivered by a named provider, and can you see what the report looks like. Is there a cost to using any of it. A policy that answers those clearly is offering something; one that describes risk management services in a sentence usually is not.

Where the services stop and your own work starts

None of this replaces backups, patching or multi factor authentication, and the policy conditions will still require them. Treat the bundled services as a free second opinion and a way to find the obvious holes, not as a managed security service. The business remains responsible for the controls it declared on the proposal form.

Questions people ask about cyber protection insurance

Are the prevention services free?

Usually included in the premium, occasionally with a fair use limit on training seats or scans. Ask whether using the helpline counts as notifying a claim, because that is a distinction worth knowing in advance.

Will a vulnerability scan report be used against me?

Insurers use it to help you fix things and to inform renewal. If it finds something serious, expect a conversation. Fixing what it finds is the point, and an unfixed reported vulnerability is a common exclusion.

Do I still need my own IT support?

Yes. The services are periodic checks and training, not day to day management. They are a supplement to whoever keeps your systems running.

Does using the services reduce my premium?

Not usually as an automatic discount, but improving the controls they reveal does, because the proposal form answers change at renewal.

Sources

Related answers

See what insurers printCompare by trade