Myth-busting: answering the cyber insurance questions brokers hear most

Guidance for brokers on addressing concerns about cyber threats, costs and recovery.


When brokers talk cyber insurance with SMEs, the same questions can come up time and again. Understanding why these uncertainties exist, and having clear, confident responses, can make all the difference. Here are four of the most common queries and our advice on how to address them.


"Aren’t we too small to be a target?"

We surveyed over 1,500 SMEs and found 44% did not have cyber insurance cover, with the main reason being a low perceived risk, with 39% believing they are simply too small to be a target.

The assumption that smaller businesses fall below the radar is understandable but wrong. Cyber criminals don't distinguish between big and small; they target vulnerability. An SME with poor cyber hygiene is often an easier target than a large corporation with dedicated security teams.

The facts back this up. Government data shows that, while 69% of large businesses suffered a cyber breach in 2025/6, so did 65% of medium-sized firms and 46% of small businesses*. That’s still a significant risk.


"Won’t our IT team keep us safe?"

IT teams largely focus on prevention, which is of course necessary, but unfortunately isn’t infallible. We’ve all seen how even some of Britain’s most high-profile organisations, from the NHS to Jaguar Land Rover and Manchester Airports Group, have been unable to defend against determined cyber attackers, even with their well-resourced in-house IT teams.

IT teams prevent what they can, but when an attack gets through, insurance handles the consequences, including the costs, the recovery and the legal exposure. So, cyber insurance is complementary to IT resilience, not a replacement, providing the second layer of protection that every board needs.


“Isn’t cyber insurance expensive?"

Cost can be a barrier to firms taking out cyber insurance, with 84% of the brokers we surveyed saying that clients care most about the right level of cover at the right price.

But cost objections are often based on outdated assumptions.

The price of cyber insurance has fallen significantly, and entry-level cyber policies now exist at accessible price points, providing basic cover, including a number to call if something goes wrong.

More comprehensive protection may be appropriate, depending on an organisation’s risk profile, but either way, the cost of insurance will likely be considerably less than the cost of recovering from an uninsured breach. Calculators and stress-test tools can help quantify what a breach might actually cost a business.


"Insurance won't stop an attack anyway, will it?"

That may be true, but this argument doesn’t recognise the value of the specialist expertise and financial protection cyber insurance provides in the wake of an attack., from downtime to data recovery, legal costs, notification expenses and business interruption.

All these questions endure because many still see cyber insurance as optional or technical, rather than a way for to help boards fulfil their duty of care and build more robust, resilient businesses.

It’s time to move the conversation forward.


Markel UK's No. 1 commercial lines insurer

Insurance Times broker survey names Markel as the UK’s No.1 commercial lines insurer for service 2025/2026.