5 Oct

Started working for yourself in 2025/26? Register for Self Assessment by Monday 5 October.New to self-employment in 2025/26? Register with HMRC by 5 October. See what to do

Cyber Insurance for Freelancers: What It Will Not Cover

What matters here: Cyber insurance is not a legal requirement, and the government’s own survey says most breaches are cheap, the middle 50% of businesses hit in 2025/26 spent between £0 and £200. Two other things matter more. The ICO data protection fee is compulsory if you use personal information and are not exempt, and a reportable breach has to reach the ICO within 72 hours whether you are insured or not. If you do want cover, Cyber Essentials certification starts at £320 plus VAT and bundles £25,000 of cyber liability insurance on an opt-in basis, but that policy will not refund money stolen by electronic means, which is the loss most freelancers are picturing.

Cyber insurance for freelancers gets sold on a feeling: your laptop holds every client file you have, and one bad morning could finish you. The feeling is reasonable. What the numbers say, and what the policies pay for, is a different conversation, and it starts with two obligations that have nothing to do with insurance at all.

Related Hub: See our full Business Insurance UK Hub for more UK guides.

The compulsory part is not cyber insurance

The ICO is blunt about who pays the data protection fee: organisations including sole traders that use personal information have to pay it, unless they are exempt. Client names and email addresses on your laptop count as personal information. The exemptions are real and some freelancers qualify, but qualifying is something you check rather than assume, the amounts and the exemption tests are in our guide to ICO registration for the self-employed.

The second duty is the one with a clock on it. If a personal data breach is likely to pose a risk to people’s rights and freedoms, the ICO expects it reported as soon as possible, and where feasible within 72 hours. If the risk to those people is high, you also have to tell them directly, without undue delay. The ICO’s own advice is to report early and update later rather than wait until you have the full picture.

That clock starts when you become aware of the breach. Not when your insurer answers. No policy removes the duty, and no policy pauses the 72 hours.

What it is for, and what actually happens to small businesses

Cyber Security Breaches Survey 2025 to 2026 figures: 43 per cent of businesses and 42 per cent of micro businesses identified a breach or attack in the last 12 months, the middle 50 per cent of those hit paid between £0 and £200, and the worst-hit 5 per cent of micro and small businesses paid £4,000

The government runs a Cyber Security Breaches Survey every year, and the 2025/26 edition was published on 30 April 2026. Two figures from it are worth holding onto.

The first: being attacked is normal. 43% of businesses identified a breach or attack in the last 12 months, 42% of micro businesses and 46% of small ones. Phishing was the most common by a distance at 38% of businesses, and the most disruptive kind for 69% of those affected. If you have had a convincing fake invoice or a login page that was not quite right, you are the average instead of the unlucky one.

The second is the one the insurance industry rarely leads with. For the middle 50% of businesses that were hit, the cost came in somewhere between £0 and £200. The worst-affected 5% of micro and small businesses paid around £4,000. Roughly 47% of businesses hold cyber cover of some kind.

So insurance here is not for the median. The median is an afternoon and a password reset. What a policy buys is the tail, the £4,000 morning, or a response team you would not otherwise know how to hire, or a client contract that will not be signed without a certificate attached. Those are all real. They are just not the same thing as protecting yourself from the ordinary case.

Cyber Essentials already bundles £25,000 of cyber insurance cover

The cyber liability cover bundled with Cyber Essentials, checked 26 August 2026: £25,000 limit if you opt in, covering incident response, legal and IT costs, extortion, regulatory investigations and data protection fines, upgradeable to £100,000 or £250,000; and £0 for money stolen by electronic means or cyber fraud, with a £1,000 excess on any claim

Cyber Essentials is the NCSC’s baseline scheme: the minimum standard of cyber security recommended by the Government, built around five controls: firewalls, secure configuration, security update management, user access control and malware protection. It is priced by organisation size and starts at £320 plus VAT.

The part that gets missed: certify fully, turn over less than £20m, be domiciled in the UK or the Crown Dependencies, and you can opt in to cyber liability insurance arranged by IASME, the scheme’s delivery partner. The limit is £25,000, upgradeable to £100,000 or £250,000 for more premium. It covers incident response (legal, IT, data recovery, notification, reputation), plus extortion threats, regulatory investigations and data protection fines, and business interruption from a network compromise.

It is opt-in rather than automatic. You are asked during the assessment, and if you skip past that question you do not have it.

For a freelancer whose clients already ask for Cyber Essentials, that reframes the whole decision. The certification is the thing you are buying; the cover comes with it. Paying for the certificate and a separate policy is paying twice for the same conversation, unless the separate policy does something the bundled one does not.

What cyber insurance will not cover

Here is the exclusion to read before anything else. The bundled policy does not cover money stolen by electronic means, or cyber fraud. There is also a £1,000 excess on any claim.

Picture how a freelancer loses money to this. Your email gets compromised. An invoice goes out — your template, your logo, your wording, with somebody else’s bank details on it. The client pays it in good faith. Weeks later you chase, and the money is a month gone through three accounts.

That is the nightmare. It is also the thing this cover explicitly does not pay for. Cyber liability insurance is built to fund the clean-up after a breach: the lawyers, the notifications, the ICO investigation, the forensic bill. It is not built to make you whole on stolen funds.

Which means the protection against the loss you fear most is not a policy at all. It is multi-factor authentication on your email, and a habit of confirming any change of bank details by phone, on a number you already had, never on the number in the email asking for the change. Standalone policies vary, and some do offer limited crime or funds-transfer-fraud cover, but that is a question to put to the underwriter in writing, not to assume from the marketing page.

When standalone cyber insurance earns its place

  • A client contract requires it and names a limit. This is the most common reason freelancers buy it, and it is a perfectly good one, the cover is the price of the work.
  • You hold personal data at a volume where an ICO investigation is a realistic outcome rather than a theoretical one.
  • You handle client payment details or hold money on their behalf.
  • A four-figure bill and a fortnight of lost billable time landing in the same week would hurt.

If none of those apply, the honest answer is that your money does more work on the controls than on the premium. Backups you have restored from once. MFA everywhere. A password manager. Updates that install instead of sit in a notification.

What to buy first, and what to buy last

  1. Check whether you owe the ICO the data protection fee, and pay it if you do.
  2. Learn the 72-hour rule now, while nothing is on fire.
  3. Do the five Cyber Essentials controls, whether or not you certify.
  4. If a client asks for certification, get Cyber Essentials and opt in to the bundled cover.
  5. Only then price a standalone policy, and read the exclusions before you read the premium.

Cyber cover is one of several a freelancer gets offered, and it is rarely the first one that matters. What freelancers actually need puts them in order, professional indemnity is the one clients ask for most, and employers’ liability is the only one that is ever a legal requirement.

Course · Edition 2026/27 · Instant download

Insurance sized to a guess?

Protect the Business: Legal, IP & Insurance 2026/27. Eight modules and five working sheets built around a complete annotated freelance contract, with a negotiation note under every clause.

  • Registering a trade mark yourself: searching, classes, fees and the opposition period
  • UK GDPR without a consultant: the ICO fee tiers, a privacy notice, and the 72-hour breach plan
  • An insurance sizing calculator by work type, and the client clauses never to sign as they stand, with the redline for each

You own the copyright in what you make until you assign it in writing. Most clients assume the opposite, and most freelance contracts are silent on it.

Get it for £26£29 £26 · 30-day no-questions refund · free updated edition at every Budget

Buying more than one? All ten 2026/27 courses for £107, against £328 at full price.

Sources

The breach and cost figures are from the Cyber Security Breaches Survey 2025/26, published 30 April 2026. The Cyber Essentials price and the five controls are quoted from the NCSC; the £25,000 limit, the opt-in, the £20m turnover cap, the UK domicile condition, the £1,000 excess and the stolen-money exclusion are from IASME’s own page. The ICO wording on the fee and on the 72-hour report is the ICO’s own.

All were read on 26 August 2026 and all of them can change, check before you rely on a figure. This is general information about how the rules and the schemes work; it is not insurance advice, not a recommendation to buy any policy, and no policy wording here is a substitute for the one you would actually be sold. No affiliate links on this page.

About the author

Syed Esrak Ahmmed researches and writes The Paid Hour. He isn’t an accountant, a tax adviser or an insurance broker. Every guide here is built from published guidance and each provider’s own documentation, with every figure linked back to its source so you can check it yourself. Anything time-sensitive carries the date it was last verified.

Spotted something wrong or out of date? Tell us, corrections get made quickly and noted on the page. More on how these guides get put together in the editorial policy.

Follow The Paid HourYouTubeLinkedInPinterest

Editorial standards: Every figure on this page is checked against GOV.UK and HMRC published guidance. This is general information, not personalised tax, legal or financial advice -- always confirm your situation with GOV.UK or a qualified accountant.