Skip to content

A Hacker Doesn't Care That You're a Startup: Why Cyber Insurance Is the Policy Most Founders Find Out About Too Late

Featured Replies

  • Administrator

a hacker doesn't care that you're a startup..

A Hacker Doesn't Care That You're a Startup: Why Cyber Insurance Is the Policy Most Founders Find Out About Too Late

Cyber insurance for UK small businesses costs between ยฃ300 and ยฃ1,500 a year for basic cover. 43% of all UK businesses experienced a cybersecurity breach in the last 12 months. The average attack costs firms with fewer than 50 employees ยฃ3,398. And 38% of small businesses still don't have cyber insurance.

Right, this one's going to piss you off.

A founder in our community got absolutely done over last year and I'm still angry about it. Not because the hack was sophisticated. It wasn't. It was a fake email. A single click. That's all it took to turn a profitable eight-person consultancy into a three-month recovery project that cost her thirty grand. Used Google Workspace, had a website, took card payments through her business bank account, stored client data in a shared drive. Normal stuff. Then one of her team clicked a link in an email that looked like it came from their accountant. It didn't come from their accountant.

Within four hours, her client database was encrypted. The ransom demand was ยฃ15,000 in Bitcoin. She didn't have cyber insurance. She didn't even know cyber insurance was a thing. She thought her public liability insurance covered "everything." It doesn't. It covers physical injury and property damage. Not ransomware. Not data breaches. Not a bloke in Belarus encrypting your client files.

She ended up paying a cybersecurity firm ยฃ8,000 to recover what they could. Lost two clients who didn't trust that their data was safe anymore. The revenue hit was about ยฃ22,000 over the following quarter. Total damage: roughly ยฃ30,000. A cyber insurance policy for her business would have cost about ยฃ400 a year.

Four hundred quid. She'd been operating without it for three years to save twelve hundred pounds total. The attack cost her twenty-five times that in a single afternoon.

what cyber insurance actually is

What Cyber Insurance Actually Is

Cyber insurance pays for the costs of dealing with a cyber attack, data breach, or digital security incident. In plain English: when something goes wrong with your technology and it costs you money, cyber insurance picks up the bill.

That includes:

The cost of investigating what happened and how they got in. Hiring forensic specialists to figure out which data was compromised. Notifying everyone whose data was affected (legally required under GDPR within 72 hours). Legal fees if someone sues you over the breach. Regulatory fines from the ICO if they decide you didn't protect data properly. Business interruption costs while your systems are down and you can't trade. Ransom payments if you're hit with ransomware (some policies cover this, some don't, check yours). PR and crisis management to stop your reputation being destroyed. Credit monitoring for affected customers. The cost of restoring your data and systems.

That's a lot of costs you probably haven't budgeted for. Because nobody budgets for "what if someone hacks us on a Tuesday." But 8.58 million cyber crimes were recorded against UK businesses in 2025 alone. That's 24,000 attacks per day. Every single day. If you think your five-person startup is too small to be a target, you're wrong. Small businesses get hit more often than big ones because their defences are weaker. Hackers aren't looking for the biggest prize. They're looking for the easiest one.

how much does cyber insurance cost for small businesses

How Much Does Cyber Insurance Cost for Small Businesses?

Less than you'd think. Definitely less than the cost of not having it.

Micro-businesses (under ยฃ500,000 turnover, 1-10 employees): ยฃ300-ยฃ700 a year for basic cover. Some policies start from about ยฃ25 a month. That's less than your Slack subscription for protection against attacks that could close your business. When you're working out how much it costs to run a startup, this should be a line item from day one.

Small businesses (ยฃ500,000-ยฃ2M turnover, 10-50 employees): ยฃ1,500-ยฃ4,000 a year for ยฃ1 million of cover. More employees means more email accounts. More email accounts means more chances for someone to click something they shouldn't. The premiums reflect that reality.

Growing businesses (ยฃ2M+ turnover, 50+ employees): ยฃ4,000-ยฃ15,000+ depending on your industry, the data you hold, and how much cover you need.

What affects the price: your industry (healthcare and finance pay more because the data is more sensitive), your annual turnover, how many customer records you hold, whether you take card payments, your existing security measures (MFA, encryption, regular backups), and whether you've been hit before.

Here's a thing I picked up from a broker at one of our events. Having Cyber Essentials certification can reduce your premium by 10-25%. It costs about ยฃ300-ยฃ500 to get certified. So the certification effectively pays for itself in premium savings within the first year, plus you get a government-backed security badge for your website. Absolute no-brainer.

Why Your Quote Is Wildly Different From Someone Else's (And What Insurers Know About You)

Something I stumbled on that completely changed how I think about cyber insurance pricing.

Some insurers run external vulnerability scans on your business before they even give you a quote. They look at your website, your email configuration, your public-facing systems, and they check for known vulnerabilities. If your website is running an outdated version of WordPress with three unpatched plugins, they know before you've finished the proposal form. If your email domain doesn't have proper SPF, DKIM, and DMARC records (the settings that stop people spoofing your email address), they know that too.

That's why two identical businesses can get quotes that differ by 40-60%. One has a properly configured website with up-to-date security. The other has a WordPress site they built in 2021 and haven't touched since. Same turnover. Same industry. Same number of employees. Completely different risk profile from the insurer's perspective.

A cybersecurity founder at one of our events ran a free external scan on three startups in the room. Live, on the spot. Two of them had critical vulnerabilities they didn't know about. One had an admin login page publicly accessible with no rate limiting. Meaning any script could guess passwords all day without being blocked. He found it in about thirty seconds. If he can find it, an insurer's automated scan definitely found it. And so can a hacker.

The practical takeaway: before you apply for cyber insurance, run a basic vulnerability scan on your own website. Tools like Qualys SSL Labs (free), SecurityHeaders.com (free), and Pentest-Tools (free tier) will show you what an insurer sees when they look at your business from the outside. Fix the obvious stuff before you apply and your premium drops. Apply with those vulnerabilities visible and you're paying a "we know you're an easy target" surcharge without realising it.

who actually needs cyber insurance cover?

Who Actually Needs Cyber Insurance?

I'm going to make this dead simple.

Do you store customer data? Email addresses, phone numbers, payment details, addresses, health information, anything personal? You need cyber insurance.

Do you take payments online or by card? You need cyber insurance.

Do you use cloud software to run your business? Google Workspace, Microsoft 365, Notion, Slack, any SaaS platform? You need cyber insurance.

Do you have a website? You need cyber insurance.

Do you have employees with email accounts? You need cyber insurance. Phishing attacks target employees, not systems. Your people are your weakest link and that's not an insult, it's a statistical fact. SMBs with 1-249 employees have a baseline phishing click rate of 24.6%. One in four employees will click a dodgy link. One.

The founders who genuinely might not need it: someone who works entirely offline with zero digital presence, no customer data, no email, no website. If that describes your business in 2026, you've got bigger problems than cyber insurance. And if you're a sole trader without limited company protection, a cyber attack hits your personal assets too.

Your biggest cyber thread isn't some genius hacker.. It's Dave from Accounts!

Your Biggest Cyber Threat Isn't Some Genius Hacker. It's Dave From Accounts.

I need to say something that sounds rude but is backed by every piece of data I've seen: the number one cyber vulnerability in your startup is your own team. Not your firewall. Not your passwords. Your people.

24.6% of employees at businesses with under 250 staff will click a phishing link. One in four. Not one in a hundred. One in four. That means if you've got eight employees, statistically two of them will click something dangerous within a year. Not because they're stupid. Because the phishing emails are genuinely good now. AI-generated, personalised, sent at 4:47pm on a Friday when everyone's tired and wants to go home. They look like they're from your bank. From HMRC. From your accountant. From your own CEO.

Here's what I've noticed from talking to founders who've been breached. It's almost never the intern who clicks the link. It's the operations manager. The finance person. The office manager. Why? Because they're the ones who receive emails from banks, from suppliers, from HMRC. They're trained to open financial emails and act on them quickly. The very skill that makes them good at their job is the same skill hackers exploit.

A cybersecurity consultant who spoke at one of our Startup Networks events put it perfectly: "Your most trusted employee with the most access to sensitive systems is your highest-risk attack surface." Not comforting. But knowing it changes how you think about security training. You don't train the intern and call it done. You train the person with the company credit card details, the bank login, and the client database access. They're the target.

Most cyber policies require annual staff cybersecurity training as a condition of cover. Do it properly. Not a ten-minute video everyone clicks through while eating lunch. Actual training with real phishing simulations. Companies like KnowBe4 and Hoxhunt run simulated phishing campaigns where they send fake phishing emails to your team and track who clicks. You find out who your weak links are before the hackers do.

the attack you've never considered: your supply chain

The Attack You've Never Considered: Your Supply Chain

Here's something that kept me up at night after a conversation with a cybersecurity founder at our London meetup.

You might have brilliant security. MFA everywhere. Staff trained. Backups running. Cyber Essentials certified. Gold star. But what about your accountant? What about your payroll provider? Your CRM platform? Your email marketing tool? Your freelance developer who has admin access to your codebase?

If any of them get breached and they hold your data or have access to your systems, you're compromised too. Through no fault of your own. Your beautiful security posture means nothing if your accountant stores your financial records on an unencrypted laptop that gets nicked from their car.

Supply chain attacks are growing faster than direct attacks. The MOVEit breach in 2023 compromised thousands of companies through a single file transfer tool. The Okta breach hit hundreds of companies through one identity provider. These weren't attacks on the end companies. They were attacks on the tools those companies relied on.

For a startup, this means asking uncomfortable questions of your suppliers. Does your accountant have Cyber Essentials? Does your payroll provider encrypt your data? Does your freelance developer use MFA on their GitHub account? Most founders never ask. Most suppliers never volunteer the information. But your cyber insurance policy doesn't care whose fault the breach was. If your client data gets exposed because your accountant got phished, your clients are coming after you, not your accountant.

Some cyber policies now include "contingent business interruption" cover which pays out if a key supplier is breached and it affects your operations. Check whether yours does. If you rely heavily on any single third-party platform or provider, this clause could be the most valuable part of your entire policy.

what it covers and what it doesnt

What Cyber Insurance Covers (And What It Doesn't)

Every policy is different and this is where founders get caught out. The name "cyber insurance" makes it sound like everything digital is covered. It's not. Read your policy. Actually read it.

Generally covered:

Data breach response costs. Investigation, notification, legal fees. This is usually the most expensive part of an incident and the most valuable part of the policy.

Business interruption. If you can't trade because your systems are down, the policy covers your lost revenue during the downtime. For an e-commerce business that relies entirely on its website, this alone justifies the premium.

Cyber extortion and ransomware. Most policies cover ransom negotiation and sometimes the ransom payment itself. This is increasingly coming with conditions though. Some insurers won't cover the ransom if you didn't have proper backups. Some won't cover it at all. Check the wording.

Third-party liability. If a client sues you because their data was compromised while in your care, the legal costs and any settlement or damages are covered.

Regulatory fines. If the ICO fines you for a data protection failure under GDPR, some policies cover this. Not all. And there's a legal grey area about whether fines are insurable in the UK. Check with your insurer specifically.

Generally NOT covered:

Attacks you knew about and didn't fix. If you were aware of a vulnerability and didn't patch it, most policies will deny the claim. This is the "non-compliance" clause that caught 17% of small businesses who filed claims in 2025.

Pre-existing breaches. If you were already compromised before the policy started, it's not covered. Some insurers do a security scan before issuing the policy specifically to check for this.

Loss of cryptocurrency. Most standard cyber policies exclude crypto-related losses. If your business holds or transacts in crypto, you need specialist cover.

War and state-sponsored attacks. The "war exclusion" is real and increasingly contentious. If the attack is attributed to a nation-state (Russia, China, North Korea), some insurers argue it falls under the war exclusion and refuse to pay. This is being tested in courts right now and the law hasn't settled. For most small businesses this isn't relevant. For defence contractors or businesses with government connections, it matters.

Reputational damage long-term. The policy covers immediate PR crisis management. It doesn't cover the slow erosion of customer trust over the following year. That cost is real but uninsurable.

Your public liability insurance does NOT cover cyber incidents. Your employers' liability does NOT cover cyber incidents. Your professional indemnity might cover some aspects of a data breach if it caused financial loss to a client, but it's not designed for it and the cover is patchy. You need a dedicated cyber policy. Separate. Specific. Don't assume your existing insurance handles this because it almost certainly doesn't.

72- hour nightmare

The 72-Hour Nightmare Nobody Talks About

Here's what actually happens when you get breached. Not the insurance theory. The reality. Because I've spoken to three founders who've been through it and the experience is consistent.

Hour 0-4: Panic. Something's wrong. Systems aren't responding. Files are encrypted. Or you get an email from someone claiming they have your customer database. Your first instinct is to fix it yourself. Don't. Call your insurer immediately. Most cyber policies have a 24/7 incident response helpline. Use it. They'll connect you with forensic specialists, legal advisors, and PR support. That's what you're paying for.

Hour 4-24: Investigation. The forensic team figures out what happened, how they got in, what data was compromised, and whether the attacker is still in your systems. This is expensive work. ยฃ200-ยฃ500 per hour for a good incident response team. Your insurance covers this.

Hour 24-72: Notification. Under GDPR, if personal data was compromised, you must notify the ICO within 72 hours of becoming aware. Not 72 hours of confirming it. 72 hours of becoming aware. If you delay, the fine increases. Your insurer's legal team handles this communication. If you haven't set up your company with proper data protection registration, this gets even messier. You also need to notify affected individuals "without undue delay." Your insurer helps draft the notifications. And report the attack to Action Fraud (the UK's national cyber crime reporting service) so it's officially logged. That report can also support your insurance claim.

Day 3-30: Recovery. Restoring systems. Rebuilding data. Dealing with customer enquiries and complaints. Managing the press if the breach makes the news. Handling any regulatory investigation from the ICO. Running your business with one hand while managing the crisis with the other.

One founder told me the worst part wasn't the financial cost. It was the shame. "I felt like I'd let everyone down. My team, my clients, my investors. I'm supposed to be running a professional operation and someone got into our systems through a fake email." That stuck with me because it's so human. Nobody talks about the emotional cost of being breached. But it's real and it's brutal.

Having insurance doesn't prevent the attack. But it turns "I don't know what to do" into "I know exactly who to call." That difference, in the first four hours, is everything.

the costs nobody puts on a spreadsheet

The Cost Nobody Puts on a Spreadsheet

Every article about cyber insurance talks about the financial cost. Investigation fees. Legal costs. Regulatory fines. Business interruption. I've done the same thing in this article. But after speaking to three founders who've been through it, I think the biggest cost is one that never appears on any invoice.

Trust.

The founder I mentioned at the start lost two clients. Not because the breach exposed their data. It didn't, as it turned out. The forensic team confirmed the attackers hadn't exfiltrated anything before encrypting it. She told her clients the truth. Two of them left anyway. Not because the data was compromised. Because their confidence was. "If it happened once, it could happen again" was the exact phrase one of them used.

That's the cost nobody can insure against. Your cyber policy will pay for the investigation, the recovery, the legal fees, the PR crisis management. It won't restore a client's belief that their data is safe with you. That's a trust problem, not a money problem. And trust takes years to build and one bad afternoon to destroy.

I don't say this to be dramatic. I say it because every founder I've spoken to who's been through a breach says the same thing: the financial cost was survivable. The emotional and reputational cost was worse. One of them told me he considered shutting the business down, not because he couldn't afford to continue, but because he felt like he'd fundamentally let people down and didn't know if he could rebuild the trust.

He didn't shut down. He got Cyber Essentials certified the following month, upgraded his security, bought proper insurance, and sent every client a personal email explaining exactly what he'd done to make sure it couldn't happen again. Most of them stayed. Some didn't. But the ones who stayed trusted him more than before because he'd been transparent about the failure and demonstrably fixed it.

The lesson from his story isn't "buy insurance and you'll be fine." It's "buy insurance so the financial cost doesn't destroy you while you're dealing with the emotional cost." They hit at the same time. Having one handled lets you focus on the other.

cyber essentials cheat code

The Cyber Essentials Cheat Code

I called this a cheat code because it genuinely feels like one. Cyber Essentials is a government-backed certification that proves your business meets five basic security controls. Firewalls, secure configuration, access control, malware protection, and patch management.

It costs ยฃ300-ยฃ500 to get certified. Here's what it gives you:

Lower insurance premiums. 10-25% reduction with most insurers. On a ยฃ1,000 annual premium, that's ยฃ100-ยฃ250 saved per year. The certification pays for itself.

Eligibility for government contracts. Many public sector tenders require Cyber Essentials as a minimum. If you're bidding for government grants or contracts, or you've raised pre-seed funding and your investors expect proper governance, you might need this anyway.

A defence against ICO fines. If you're breached and you have Cyber Essentials, you can demonstrate you took reasonable steps to protect data. That goes a long way in a regulatory investigation.

Actual security improvement. The five controls are genuinely useful. Most small businesses don't do all five consistently. Going through the certification process forces you to fix the gaps.

For a startup, Cyber Essentials is one of those rare things that's cheap, quick, and genuinely valuable. Do it before you buy cyber insurance and your premium drops. Do it after and you're still more secure than 70% of UK small businesses.

how to buy cyber insurance

How to Buy Cyber Insurance (And How Not to Get Mugged on the Policy)

I'm going to be honest about something first. Most founders buy cyber insurance the same way they buy everything else - pick the cheapest quote, skim the summary, click buy, never read the actual policy document. Then when something goes wrong they find out their ยฃ300/year bargain doesn't cover ransomware, has a ยฃ2,500 excess, and requires security measures they never implemented. The insurer denies the claim. The founder is furious. And technically the insurer is right because it was all in the document nobody read.

Don't be that person. This is one purchase where ten extra minutes of reading saves you everything.

Where to get quotes

Simply Business, Hiscox, Superscript, Aviva, CyberSmart, and GoCompare all offer cyber insurance for small businesses. The process is the same as buying any business insurance. Fill in a form - your industry, turnover, number of employees, type of data you hold, existing security measures. Get quotes. Compare.

CyberSmart is worth a specific shout because they bundle Cyber Essentials certification with cyber insurance in one package. You get certified and insured simultaneously, which saves you doing them separately and usually works out cheaper than buying the certification and a separate policy from different providers. For a startup doing both for the first time, it's the path of least resistance.

If you've already got public liability and employers' liability through Simply Business or Hiscox, check whether adding cyber to your existing policy is cheaper than buying it standalone. Bundled business insurance is almost always cheaper than three separate policies and you get one renewal date instead of three. A founder at one of our events told me bundling all three through Simply Business saved her about ยฃ180 a year versus buying them separately. That's not nothing.

The five things to check before you buy

I've spoken to enough founders who've been through claims to know that the difference between a good cyber policy and a useless one comes down to five specific things. Check all of them.

1. Ransomware: payment or negotiation only?

This is the big one. Some policies cover the actual ransom payment if you choose to pay. Others only cover the cost of hiring a negotiator and the incident response around it but explicitly exclude the payment itself. The difference matters enormously. If your systems are encrypted and the ransom is ยฃ20,000, a policy that covers negotiation but not payment leaves you deciding whether to pay out of pocket or lose your data. Ask the insurer directly. Get the answer in writing. Not in a sales chat. In the policy wording.

2. The excess.

Cyber policy excesses are typically higher than other business insurance. ยฃ500-ยฃ1,000 is common. Some cheaper policies push it to ยฃ2,500. That means you cover the first ยฃ2,500 of any claim yourself. If the average small business cyber attack costs ยฃ3,398, a ยฃ2,500 excess means your insurance is only covering ยฃ898 of the bill. At that point you're basically self-insuring and paying someone a premium for the privilege. Keep the excess at ยฃ500 or below if you can. The slightly higher premium is worth it.

3. Security requirements baked into the policy.

This is where 17% of insured businesses got burned in 2025. Their claims were denied because they didn't comply with security measures the policy mandated as conditions of cover. Common requirements include multi-factor authentication on all business accounts, regular data backups stored separately from your main systems, annual staff cybersecurity training, encryption on portable devices, and up-to-date software patching. These aren't suggestions. They're contractual conditions. If your policy says you must have MFA enabled and you don't, the insurer can legally refuse to pay your claim. Read the security requirements section of your policy before you sign. Then actually implement them. Then document that you've implemented them, screenshots, training records, backup logs. If you ever need to claim, that documentation is the difference between getting paid and getting denied.

4. The incident response service.

A good cyber policy doesn't just pay money after the fact. It gives you access to a 24/7 incident response helpline staffed by people who deal with breaches every day. When you're panicking at 11pm because your systems are encrypted, the ability to call someone who says "right, here's exactly what to do" is worth more than the financial cover itself. Ask whether the policy includes incident response. Ask who provides it. Ask whether it's 24/7 or business hours only. A breach at 2am on a Saturday doesn't wait until Monday morning for your insurer's office to open.

5. Business interruption limits and waiting periods.

Most cyber policies include business interruption cover, meaning they pay for lost revenue while your systems are down. But check the details. Some policies have a waiting period of 8-24 hours before BI cover kicks in. If your website goes down and you lose ยฃ500 in the first twelve hours, a policy with a 12-hour waiting period pays nothing for that period. Also check the daily limit and the maximum period. A policy that covers ยฃ1,000/day of lost revenue for up to 30 days is very different from one that covers ยฃ5,000/day for up to 90 days. Match it to what your business actually loses when it can't trade.

Getting multiple quotes is non-negotiable.

I know I sound like a comparison site ad but the price variation between insurers for identical cyber cover is wild. A broker at our Startup Networks events told me he'd seen quotes differ by 60% for the same business profile. Same turnover, same number of employees, same industry, same cover level. One insurer quoted ยฃ420, another quoted ยฃ680. The only difference was their internal risk models. Get at least three quotes. It takes fifteen minutes and could save you hundreds.

One more thing.

When you buy, you'll be asked to fill in a proposal form describing your business, your IT setup, and your security measures. Do not lie on this form. Do not exaggerate your security. If you say you have MFA enabled company-wide and you don't, that's a material misrepresentation. Your insurer can void the entire policy if they discover it during a claim investigation. Be honest. If your security isn't perfect, say so. A slightly higher premium based on honest answers is infinitely better than a denied claim based on lies.

The Simpsons GIF by PERFECTL00P

FAQs

How much does cyber insurance cost for a small business UK?

ยฃ300-ยฃ700 a year for micro-businesses. ยฃ1,500-ยฃ4,000 for small businesses with ยฃ500K-ยฃ2M turnover. Depends on your industry, the data you hold, and your existing security measures. Cyber Essentials certification typically reduces premiums by 10-25%.

Is cyber insurance worth it for a small business?

43% of UK businesses experienced a cyber breach last year. The average cost for firms under 50 employees is ยฃ3,398. A basic policy costs ยฃ300-ยฃ700. The maths speaks for itself. One incident without insurance costs more than a decade of premiums.

What does cyber insurance cover?

Data breach investigation and response, business interruption, cyber extortion and ransomware, third-party liability if client data is compromised, regulatory fines (some policies), and crisis PR management. Every policy is different so read the wording carefully.

Does public liability insurance cover cyber attacks?

Na. Not even slightly. Public liability covers physical injury and property damage caused by your business. A ransomware attack, data breach, or phishing scam is not covered by public liability, employers' liability, or most standard business insurance policies. You need a dedicated cyber policy.

What is Cyber Essentials and do I need it?

A government-backed cybersecurity certification covering five basic security controls. Costs ยฃ300-ยฃ500. Reduces insurance premiums, qualifies you for government contracts, and provides evidence of due diligence if you're ever investigated by the ICO. Not legally required but practically essential.

Can cyber insurance cover ransomware payments?

Some policies do. Some only cover the negotiation and response costs, not the actual payment. This is one of the most important things to check before buying. Ask the insurer directly and get it in writing.

What happens if I don't meet my policy's security requirements?

Your claim can be denied. 17% of insured businesses had claims rejected in 2025 because they didn't comply with their policy's mandated security practices. If your policy requires MFA and you don't have it enabled, the insurer can refuse to pay. Read the requirements. Meet them. Document everything.

How quickly can I get cyber insurance?

Same day. Seriously. Online providers like Simply Business, Hiscox, and CyberSmart give instant quotes and immediate cover. You fill in the form, pay, and you're insured. If you're reading this article right now and you don't have cyber insurance, you could be covered before you finish your coffee. There's genuinely no reason to put this off until tomorrow when tomorrow might be the day someone sends your finance person a very convincing fake invoice.


Written by James Beresford-Morgan, co-founder of Startup Networks. A founder in our community lost ยฃ30,000 to a cyber attack that a ยฃ400/year policy would have covered. That story is why this article exists. I don't sell insurance. I just don't want to have that conversation at another event.

This is part of our business insurance series. Public liability insurance covers injuries to the public. Sole trader public liability covers self-employed specific risks. Employers' liability is legally required when you hire. And this article covers the one that protects your digital operations. Between them, you're covered for the four main risk categories every UK startup faces.


Last updated: 27th July 2026. Cyber breach statistics from UK Government Cyber Security Breaches Survey 2025. Average attack cost (ยฃ3,398 for sub-50 employees) from Vodafone 2025 survey. 8.58 million cyber crimes from UK Government estimates. Phishing click rate (24.6%) from Kymatio 2026. Claim denial rate (17%) from SQ Magazine 2026. Insurance pricing from WS Insurance UK 2026 guide, PolicyBee, and CyberSmart. Cyber Essentials guidance from NCSC. GDPR 72-hour notification requirement from ICO guidance.

User number 1 - in 5 years this will hopefully mean something

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions โ†’ Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.