You're reading The SME Security Brief, practical IT, cyber security and technology advice for Irish and UK businesses. No jargon. No scare tactics. Just what you need to know, every week.
If someone forwarded this to you, you can subscribe at thesmesecuritybrief.com.
THIS WEEK'S THREAT 🔴
The insurance gap most SMEs do not know they have
A business owner gets the call on a Tuesday morning. Their systems are locked. A ransomware attack has encrypted everything. They call their insurance broker. The broker pulls up the policy. Business interruption cover, yes. Property, yes. Public liability, yes.
Cyber incident? Not covered.
This conversation is happening more and more across Ireland and the UK. Standard business insurance policies were written before cyber risk existed as a meaningful threat to SMEs. The vast majority do not cover cyber incidents unless you have specifically added cyber cover or taken out a standalone cyber insurance policy.
The cost of recovering from a cyber incident can run into tens of thousands of euro for an SME and for many SMEs, the cost of basic cyber cover is significantly less than the cost of a single incident
Cyber insurance will not stop an attack. But it can be the difference between a business that survives one and a business that does not.
What you should do this week:
Pull out your current business insurance policy and check whether it includes any cyber cover. Look specifically for terms like "cyber liability," "data breach," or "cyber incident response."
If it is not there, call your broker and ask what it would cost to add it. For many SMEs the answer is a few hundred euro a year.
Before you call, make sure you can answer the questions insurers will ask , we cover those below.
THIS WEEK'S TIP 💡
What cyber insurance actually covers, and what it does not
Cyber insurance policies vary significantly, so it is worth understanding what you are buying. Here is what a good SME cyber policy typically covers:
What is usually included:
Incident response costs , the cost of bringing in a cyber security firm to investigate and contain the breach
Recovery costs , restoring systems, rebuilding data, and getting back to normal operations
Business interruption , lost revenue during the period your systems are down
Ransomware payments , some policies cover the ransom payment itself, though this is increasingly controversial and subject to conditions
Legal and regulatory costs , including GDPR notification requirements, legal advice, and potential regulatory fines
Reputational damage , PR and crisis communications support
What is often not covered:
Incidents caused by unpatched software you knew about but did not fix
Incidents involving systems or software past end of life
Insider threats caused by negligence rather than malice, depending on the policy
Losses covered by other policies such as property or professional indemnity
What insurers will ask before they cover you:
This is the part most businesses are not prepared for. Cyber insurers now ask detailed questions about your security posture before issuing a policy. Common questions include: Do you have MFA enabled on email and remote access? Do you have a backup and recovery plan? Do you have endpoint protection on all devices? Do you have a patch management process?
If the answer to these is no, you may be refused cover or charged significantly higher premiums. This is where the basics we have covered in previous issues directly affect your insurability.
THIS WEEK'S TOOL 🛠️
How to assess whether you need cyber insurance
Not every SME needs a standalone cyber insurance policy, but most should at least consider it. Here is a simple framework for assessing your risk:
Higher risk , cyber insurance is strongly recommended if:
You store customer personal data, financial data, or health data
You process online payments
You rely heavily on your systems being available to generate revenue
You work with larger clients or the public sector who may require it contractually
You are in a regulated sector such as financial services, healthcare, or legal
Lower risk , basic cover may be sufficient if:
You have minimal customer data and limited online presence
Your operations could continue manually for a period if systems went down
You have robust backups, MFA, and endpoint protection already in place
For UK businesses, achieving Cyber Essentials certification includes £25,000 cyber liability insurance at no extra cost, with the option to increase cover to £100,000 for around £306 per year for businesses under £10m in revenue (via the IASME Consortium). For Irish businesses, speak to your existing broker, as cyber cover can often be added to an existing policy at a fraction of the cost of standalone cover.
When comparing policies, look specifically at the incident response provision , the ability to call a dedicated cyber response team at any hour is often the most valuable element of a policy when something goes wrong.
QUICK COMPLIANCE CHECKLIST
Five questions before you speak to your broker:
Does your current business insurance policy include any cyber cover?
Do you have MFA enabled on email and remote access systems?
Do you have a tested backup and recovery process in place?
Do you have endpoint protection running on all business devices?
Do you know what personal or sensitive data your business holds and where it is stored?
BEFORE YOU GO
Cyber insurance is not a substitute for good security practice. An insurer will not pay out if you ignored known vulnerabilities or failed to take basic precautions. But for a business that has done the basics and still gets hit, it can be the safety net that makes recovery possible.
Think of it the same way you think about any other business insurance. You hope you never need it. But you would not run a business without it.
See you next week.
The SME Security Brief
