Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Cyber Insurance Explained

Business Continuity Insurance: What Pays When Cyber Hits

By the Assured Cyber Protection team · Updated 2026 · Reviewed

If you have been quoted for business continuity insurance, the first thing to know is that no UK insurer sells a policy by that name. Brokers and IT suppliers use it loosely to mean the cover that keeps money coming in while your business cannot trade. In the actual market that job is split between two products with different triggers, and the gap between them is where most claims fail. This page sets out what each one pays, the waiting and indemnity periods that decide whether you get anything at all, and the deliberate exclusion that has sat in property policies since 2020.

The two policies people mean by “business continuity insurance”

Business interruption (BI) cover is a section of a commercial property or combined package policy. It pays lost gross profit, continuing fixed costs such as rent and payroll, and reasonable extra costs of working, but the classic trigger is physical loss or damage to insured property. Fire, flood, escape of water. No damage, no claim.

Cyber business interruption sits inside a standalone cyber policy. Its trigger is a network event rather than physical damage: ransomware, a security failure, and on wider wordings an unforced system failure or an outage at a technology supplier you depend on. It pays for the same categories of loss, lost income and increased cost of working, but it responds to downtime with nothing burnt or broken.

Some insurers and brokers also sell business continuity consultancy, which is planning rather than insurance. Useful, but it does not pay a claim. If a quote mixes the two, ask which policy section the money would come out of.

The exclusion that created the gap

The split is not an accident. In July 2019 Lloyd’s issued Market Bulletin Y5258 requiring every policy to be clear about whether it covered losses caused by a cyber event, with the deadline set out in Y5277 from January 2020. Syndicates had a choice: affirm cyber cover or exclude it. In practice, the property market overwhelmingly chose to exclude.

The result is the coverage gap that catches businesses out. Property and BI policies now cover physical perils but carve out losses originating from a cyber event. Standalone cyber policies are built around data and network exposure and usually exclude physical damage. A manufacturer whose plant is damaged because an attacker manipulated a control system can find both policies pointing at each other. If you run operational technology, that overlap needs checking clause by clause, not assumed. Our page on OT cyber security covers the technical side of the same risk.

Waiting period and indemnity period: the two numbers that decide your payout

Everything else on a cyber BI schedule is detail. These two are not.

The waiting period is the qualifying downtime before cover engages. Eight hours is the common market standard, but 12 and 24 hours are widely written and are cheaper. It works as a trigger rather than an excess on most wordings: if your policy has a 12-hour waiting period and you are down for 24 hours, the claim engages once 12 hours have passed and then applies retroactively from the start of the outage. The trap is the short incident. A ransomware attack contained in six hours pays nothing on the BI section of a policy with an eight-hour wait, no matter how much revenue you lost.

How a 12-hour waiting period decides the payout 0h 6h 12h 18h 24h 12-hour waiting period (trigger) 24h outage all 24 hours paid, back to hour zero 6h outage never reaches the trigger, nothing paid on the BI section Source: standard UK cyber BI wordings, waiting periods commonly 8 to 24 hours. Chart by Assured Cyber Protection.
Chart by Assured Cyber Protection

The indemnity period is how long the insurer keeps paying after the interruption starts. Twelve months is the usual default. Six months is the practical minimum for a business that will need to rebuild systems and win back customers; 18 or 24 months can be bought for more premium. Choose it against how long recovery would really take, not how long the outage lasts. Systems come back in weeks; revenue often does not.

Feature Property BI Cyber BI
Trigger Physical loss or damage Network security event or system failure
Cyber losses Excluded on most post-2020 wordings Covered, this is the point of it
Qualifying period An excess in time or money Waiting period, commonly 8 to 24 hours
Typical indemnity period 12 to 36 months 12 months, extendable
Supplier outage Only via named extensions Dependent business interruption, if bought

Work out what an hour of downtime is worth before you pick either number. Our downtime cost calculator does that arithmetic from your turnover and trading hours.

What the M&S attack showed about the sums involved

Marks and Spencer was hit by ransomware over the Easter weekend in April 2025 and told the market the incident would cost it in the region of £300 million in operating profit across the financial year, before insurance recoveries. Its cyber insurance claim was reported at up to around £100 million, one of the largest UK corporate cyber claims made. Online ordering was suspended for weeks, and disruption ran into the summer.

Two lessons scale down to a business of any size. First, the operational loss dwarfed the cost of the incident response itself, which is exactly the pattern cyber BI exists for. Second, the insurance recovered a fraction of the hit, because indemnity periods, sub-limits and the point at which loss stops being attributable all bite. We covered the wider pattern in cyber attacks on UK retailers.

Does the FCA test case help a cyber claim?

Sometimes it is cited as though it does. The Supreme Court judgment in FCA v Arch Insurance (UK) Ltd on 15 January 2021 dealt with non-damage extensions in property BI policies during the pandemic: disease clauses, prevention of access, hybrid wordings. It did not consider cyber cover.

What travels across is the reasoning rather than the outcome. The court’s approach to concurrent causes, and its refusal to let insurers use a wider uninsured event to cut down cover the policy plainly gave, applies to any argument about causation in a BI claim. What does not travel is any assumption that a property policy will respond to a cyber loss. Post-2020 wordings say the opposite in plain terms.

What to check on your own schedule this week

  1. Find the cyber exclusion in your property or package policy and read it. If it excludes losses “arising from a cyber act or cyber incident”, your BI section will not respond to ransomware.
  2. Check the waiting period on your cyber policy. If it is 24 hours, ask what it costs to get to eight, then compare that against your hourly downtime figure.
  3. Check the indemnity period and whether the BI limit is the full policy limit or a sub-limit. Sub-limits on the BI section are common and rarely highlighted.
  4. Check whether dependent business interruption is included and whether it names your cloud and payment providers. Most SME outages start at a supplier, not on your own kit.
  5. Check whether system failure, meaning an unforced IT outage with no attacker, is covered or excluded. It is one of the most common declines.
  6. Confirm what proof of loss the insurer wants. Management accounts, EPOS data and order records make or break the quantum, and you need them to survive the incident that caused the claim.

For the wider policy structure, first-party versus third-party cyber cover explains where BI sits, and how to read a cyber insurance policy walks through a schedule line by line. Guidance on the security controls insurers now expect before they will quote is on the NCSC’s small business guidance.

Frequently asked questions

Is business continuity insurance a real product? Not under that name in the UK. The cover people mean is business interruption insurance, sold inside a property or package policy, and cyber business interruption, sold inside a standalone cyber policy. Ask a broker which section of which policy would pay before comparing quotes.

Does business interruption insurance cover a cyber attack? Usually not. Since Lloyd’s Market Bulletin Y5258 in 2019 and its January 2020 implementation, property policies have had to be explicit about cyber, and most syndicates excluded it. Cover for downtime caused by an attack normally has to come from a standalone cyber policy.

What is a waiting period in cyber insurance? It is the minimum downtime before the business interruption section engages, commonly eight hours, sometimes 12 or 24. On most wordings it acts as a trigger rather than a deduction, so once the outage passes the threshold the claim is calculated from the moment it began.

How long should the indemnity period be? Twelve months is the usual default and a reasonable floor for most SMEs. Pick it by how long revenue would take to recover rather than how long systems take to restore, because customer loss outlasts the outage. Longer periods of 18 or 24 months cost more premium.

Does cyber BI cover an outage at my cloud provider? Only if dependent business interruption, sometimes called contingent BI, is included, and the wording covers the type of provider involved. Some policies name specific providers or exclude outages that are not caused by a security failure. Check this if your trading depends on a single platform.

What about business income insurance? Is that the same thing? Business income insurance is the American term for what the UK calls business interruption. If a policy or quote uses it, you are looking at the same category of cover, but always check whether the wording is UK or US, because the triggers and the treatment of cyber losses differ.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.