Estimated reading time: 10 minutes
The Association of British Insurers and PwC UK set out where the market has grown, where cover stops, and how much of the small business sector still buys nothing.
The Association of British Insurers has published its UK Cyber Insurance Market Assessment, produced with PwC UK, and it carries a direct statement of position. Structural constraints, the report says, mean cyber insurance “cannot, on its own, act as a national backstop for systemic cyber risk.”
The finding lands while the Cyber Security and Resilience Bill is still moving through Parliament. That legislation represents the largest expansion of Britain’s cyber regulatory framework since the Network and Information Systems Regulations of 2018, and it brings managed service providers, data centers and critical suppliers into scope for the first time.
The report frames cyber insurance as one component of national resilience rather than a complete solution, contributing through incident response, recovery services, claims payments and underwriting incentives for better cyber hygiene. Chris Bose, Director of General Insurance at the association, called cyber resilience “a shared challenge that cannot be solved by any one sector alone.”
Capacity and Appetite
The market findings are positive. Capacity available to British buyers is as large as it has ever been, following sustained expansion from 2023 to 2025. Rates have softened moderately. Policy limits have increased. Lloyd’s of London added two syndicates writing cyber cover during 2025.
Underwriting appetite is described as the broadest since before the pandemic, with a shift toward exposure-led rather than loss-led growth. That appetite is conditional. Insurers expect multi-factor authentication, immutable backups, and incident response and recovery planning. Where those controls are in place, the report notes selective removal or reduction of sub-limits and coinsurance, particularly on ransomware and incident response cover.
The report also tracks a structural change in who writes the business. Smaller specialist insurers, often managing general agents backed by established balance sheets, have pushed the market toward a service-led model built around attack surface monitoring, threat intelligence and vulnerability remediation.
Recent activity in the British market fits that pattern. Pen Underwriting doubled its small business cyber limit to £10 million in June and brought claims handling in-house. Kovrilo added cyber cover to its modular platform in July, underwritten by HSB.
Claims Severity
The report cites association data showing 642% growth in the value of the average claims settlement between 2017 and 2025.
Two points of context are worth carrying alongside that figure. The comparison spans a period in which the product itself changed substantially, from a narrow data breach cover into a broad offering combining indemnity with prevention and recovery services. The report does not state whether the figure is adjusted for inflation.
Alongside severity, the report identifies a fast-moving picture on causes of loss, with the drivers shifting year on year despite the continued prevalence of ransomware and malware. It also records a recent rise in the number of non-malicious claims, meaning losses arising from system and service failures rather than attacks.
The Claims Totals
Association member data shows insurers paid close to £200 million in cyber claims during 2024, a 230% year-on-year increase, with ransomware and malware accounting for more than half of all claims.
That figure carries a caveat worth restating. It comes from the association’s annual cyber data collection, first published in November 2025, and represents a sample drawn from participating member firms. The association’s own release states the figures are not extrapolated to market totals. The precise number was £197 million, against £59 million in 2023, with malware and ransomware at 51% of claims, up from 32%.
The collection appears to run on an annual November cycle, which means 2025 figures are not yet due. Readers comparing the £197 million against the settlement growth discussed above should note the two cover different periods.
Small Business Penetration
On the question of how many British small and medium-sized firms actually hold cover, the report gives a range rather than a figure. Somewhere between 17% and 35% purchase a standalone cyber policy. The lower number comes from the Department for Science, Innovation and Technology’s Cyber Security Breaches Survey. The higher number comes from broker Howden.
The report identifies four barriers behind that gap: limited understanding of what cyber insurance delivers in practice, inconsistent policy language, onerous underwriting data requirements, and price sensitivity. It records that 28% of small business respondents to the government survey cited a lack of knowledge or perceived lack of necessity as their reason for not buying, and that roughly 36% of uninsured small firms cited cost as the primary reason.
It also describes a structural disconnect inside buying organizations. Cyber insurance is typically procured by finance, procurement or insurance functions, while responsibility for cyber risk sits with chief information security officers, information technology leads or outsourced providers. The two groups use different vocabularies, one built around limits, triggers and exclusions, the other around threat actors, controls and vulnerabilities.
Readers tracking this figure across sources should note which edition of the government survey each number comes from. The report’s 17% is drawn from the 2025 Cyber Security Breaches Survey. The 10% of businesses holding a specific cyber policy reported alongside a 59% attack rate in May comes from the 2025/2026 edition, which is the version the association’s own press release footnotes. Howden’s 35% uses a separate methodology. Add 28% reporting a cyber incident from Capital on Tap research published this week, and the picture is four studies measuring standalone cover, bundled cover, attack, breach and incident across populations and time windows that do not align.
Our Podcast
Micro-Captive Cyber Insurance Wins in Court: What’s Next?
A federal judge just ruled against the IRS on micro-captive cyber insurance, the tool businesses use to fund cyber losses their policies won’t cover. Dustin Carlson, a named plaintiff in the case, returns to explain what has changed and what remains in legal limbo.
Cyber Essentials and Limit Adequacy
The report addresses the free insurance attached to Cyber Essentials, which starts at a £25,000 limit and can be increased toward £250,000 for a relatively low premium depending on revenue band.
It calls this a positive move toward closing the protection gap. It then adds a caution: coverage at those levels risks providing false reassurance to businesses that do not understand their exposure, and the limit may be exhausted quickly in the event of a loss.
That sits within a broader finding on underinsurance, which the report treats as a governance issue. Where boards do not sufficiently understand their cyber exposures, incident scenarios and recovery requirements, purchasing decisions may not reflect the organization’s actual risk profile. British government engagement on this has been mixed before, as the response to the Cyber Resilience Pledge showed.
Where Cover Stops
The report sets out several areas where the market cannot sustainably insure.
Systemic supply chain exposure sits at the top. Insurers offer contingent and customer business interruption cover. However, they typically restrict, sub-limit or exclude it, particularly for cloud services. Insurers cover operational technology and cyber-physical risks inconsistently. They developed policy wordings around data breaches and often assume a clear boundary between computer systems and physical operations. Insurers generally exclude bodily injury and property damage.
The infrastructure exclusion is described as the one point of clear consistency across the market, limiting cover for failures of large-scale shared systems such as utilities. The report notes an open question here. The Cyber Security and Resilience Bill widens the definition of critical infrastructure, which means the exclusion may reach further without any change to policy language. That interacts with the war exclusion questions raised in our coverage of critical national infrastructure and the concentration risk mapped in the Cyber Monitoring Centre’s cloud outage analysis.
Business email compromise and social engineering fall into a gap between cyber and crime policies. The report cites Coalition data showing that 29% of business email compromise events led to funds transfer fraud. It also says small business buyers often assume their policies cover these losses, although some policies may exclude them.
Silent Artificial Intelligence
The report draws a distinction between artificial intelligence used as a tool in an otherwise conventional cyber event, such as assisted phishing or deepfake impersonation, and losses arising from the operation of an artificial intelligence system itself, such as autonomous decision-making, defective output, or algorithmic error.
The first may fall within existing cyber wordings. The second is more likely to be addressed through technology errors and omissions cover, professional indemnity, or specific endorsements and exclusions.
Where wordings say nothing either way, the report uses the term “silent artificial intelligence” and treats it as analogous to the non-affirmative cyber problem the market spent years resolving. It characterizes current exclusionary language as a clarification phase rather than a settled market standard. That framing connects directly to the agentic liability questions we have been tracking through 2026.
What Happens Next
The report sets out six priorities:
- Reducing the protection gap,
- Aligning cover with public policy and forthcoming regulation.
- Improving data sharing and transparency.
- Supporting standardization including the Cyber Monitoring Centre’s event categorization scale.
- Exploring the range of possible public-private mechanisms.
- And continuing the shift toward prevention.
On a formal backstop, the report is explicit that no market consensus currently exists on its role or structure, and treats it as an exploratory consideration rather than an immediate priority. The nearer-term opportunity, it argues, lies in strengthening dialogue between government and the market before a significant systemic event forces the question.
Martin Murphy, Corporate Insurance Strategy Lead at PwC UK, framed the underlying shift: “cyber insurance is increasingly doing much more than paying claims. Insurers are helping organisations strengthen their defences, respond more effectively when incidents occur and recover more quickly afterwards.”
The association published a companion document the same day, From Prevention to Resilience, setting out the cybersecurity controls its members regard as good practice. Developed with cyber insurers and government partners, it covers staff training, offline backups, incident response planning, multi-factor authentication, logging and monitoring, encryption, and supplier checks. We will cover it separately.
FAQ – UK Cyber Insurance
The Association of British Insurers and PwC UK published this strategic review of the British cyber insurance market in August 2026. It covers market structure, capacity, coverage gaps, exclusions, barriers to adoption, and the sector’s role in national cyber resilience.
No. It states that structural constraints mean a cyber insurance policy cannot, on its own, act as a national backstop for systemic cyber risk. It describes a formal public-private backstop as an exploratory consideration with no current market consensus on its role or structure.
The report gives a range rather than a single figure. Between 17% and 35% of small and medium-sized firms hold a standalone cyber policy. The lower figure comes from the Department for Science, Innovation and Technology’s Cyber Security Breaches Survey, the higher from broker Howden.
It is the reported growth in the value of the average cyber claims settlement between 2017 and 2025, using Association of British Insurers member data. The report does not say whether its authors adjusted the figure for inflation. Separately, the report gives an aggregate claims total of close to £200 million for 2024, a 230% year-on-year increase.
It describes the free cover attached to Cyber Essentials, starting at £25,000 and rising toward £250,000 by revenue band, as a positive move toward closing the protection gap. It also warns that coverage at those levels may falsely reassure buyers and run out quickly after a loss.
Related Cyber Insurance Posts
- Crime Is Crime. The Invoice Is Not. New UK Research Puts Cyber Incidents At 28% Of Businesses
- Could a Fed Backstop for Cyber Insurance Harm the Industry? (Opens in a new browser tab)
- Must Read: Skeptical Analysis of a Potential Federal Cyber Insurance Backstop, From Lawfare(Opens in a new browser tab)
- Cowbell Joins ABI to Strengthen UK Cyber Insurance Sector(Opens in a new browser tab)
- Manufacturing Cybersecurity: 60% Breached Despite Training, And An MSP Question Underwriters Should Not Skip(Opens in a new browser tab)