top of page

Cyber cover for a business that holds customer data at all

  • Aug 29
  • 3 min read

Updated: 4 days ago

Introduction


A small business is told it should consider cyber insurance and dismisses the idea. It has no technical infrastructure to speak of, no customer database worth stealing, and a belief that attackers target organisations with money.

Attackers target organisations that are easy, and small businesses are easy. The common incidents are not sophisticated: an invoice diverted after an email account is compromised, a ransomware infection from an attachment, a laptop stolen with customer records on it. Each of those produces costs that no other policy addresses. None of them requires a determined attacker or an interesting target.


1. Cyber cover for a business that holds customer data responds to costs nothing else does


Understand what it pays for.

Investigating what happened, restoring systems and data, notifying affected individuals, legal and regulatory costs, and business interruption from the outage. Property and liability policies do not cover any of that.


2. Recognise that you hold data even if you think you do not


Almost every business does.

Customer names, addresses, payment details, employee records, supplier information, email correspondence. If any of that were exposed you would have obligations, and the size of the business does not change them. Data protection obligations are not scaled to turnover.


3. Know that the response costs come before any liability


The immediate expense.

The first week involves technical investigation, restoration and legal advice, and those bills arrive regardless of whether anybody claims against you. For a small business that is frequently the larger figure.


4. Understand the regulatory exposure


Where it becomes serious.

Data protection regimes in most jurisdictions require notification within a short period, and regulators can impose penalties. Handling that badly is expensive independently of the incident itself, and the clock starts before you fully understand what happened.


5. Look closely at the fraud sections


The most common real claim.

Invoice diversion and payment fraud following an email compromise are what actually happen to small businesses. Whether these are covered, and to what limit, varies substantially between policies and is worth checking specifically.


6. Check what the insurer requires you to have


Conditions attached to cover.

Multi-factor authentication, backups, patching and staff training are increasingly required. Declaring controls you do not have puts the policy at risk, which makes the application itself a useful audit.


7. Value the incident response service


Frequently the main benefit.

These policies typically include access to specialists at the point of an incident, which a small business could not otherwise arrange at speed. In the first hours, having somebody to call matters more than the indemnity.


8. Do not treat it as a substitute for basic controls


Insurance does not prevent anything.

Backups you have tested, multi-factor authentication, access removed when staff leave, and training on how these attacks actually arrive. Most incidents at this scale are preventable by measures that cost very little.


9. Check whether existing policies exclude it


The gap that catches people.

Many general policies now specifically exclude cyber-related losses, which means the exposure has been actively removed rather than merely not mentioned. Read what your current cover says before assuming anything is included.

Ask your suppliers what happens if their systems fail, particularly anybody holding your data or processing payments for you. Their incident becomes your problem with your customers, and the contractual position on that is usually less favourable than businesses assume.


Conclusion


Recognise that small businesses are targeted for being easy rather than valuable.

Understand that this cover pays for investigation, restoration, notification and regulatory costs, accept that you hold personal data whatever the size of the business, note that response costs arrive regardless of any third-party claim, check the fraud sections because payment diversion is the common real loss, meet the security controls the policy requires, value the incident response service as much as the indemnity, keep basic controls in place because insurance prevents nothing, and check whether your existing policies now exclude cyber losses entirely.


Related reading


 
 
 

Comments


bottom of page