What matters here: Cyber insurance is not a legal requirement, and the government’s own survey says most breaches are cheap, the middle 50% of businesses hit in 2025/26 spent between £0 and £200. Two other things matter more. The ICO data protection fee is compulsory if you use personal information and are not exempt, and a reportable breach has to reach the ICO within 72 hours whether you are insured or not. If you do want cover, Cyber Essentials certification starts at £320 plus VAT and bundles £25,000 of cyber liability insurance on an opt-in basis, but that policy will not refund money stolen by electronic means, which is the loss most freelancers are picturing.
Cyber insurance for freelancers gets sold on a feeling: your laptop holds every client file you have, and one bad morning could finish you. The feeling is reasonable. What the numbers say, and what the policies pay for, is a different conversation, and it starts with two obligations that have nothing to do with insurance at all.
The compulsory part is not cyber insurance
The ICO is blunt about who pays the data protection fee: organisations including sole traders that use personal information have to pay it, unless they are exempt. Client names and email addresses on your laptop count as personal information. The exemptions are real and some freelancers qualify, but qualifying is something you check rather than assume, the amounts and the exemption tests are in our guide to ICO registration for the self-employed.
The second duty is the one with a clock on it. If a personal data breach is likely to pose a risk to people’s rights and freedoms, the ICO expects it reported as soon as possible, and where feasible within 72 hours. If the risk to those people is high, you also have to tell them directly, without undue delay. The ICO’s own advice is to report early and update later rather than wait until you have the full picture.
That clock starts when you become aware of the breach. Not when your insurer answers. No policy removes the duty, and no policy pauses the 72 hours.
What it is for, and what actually happens to small businesses

The government runs a Cyber Security Breaches Survey every year, and the 2025/26 edition was published on 30 April 2026. Two figures from it are worth holding onto.
The first: being attacked is normal. 43% of businesses identified a breach or attack in the last 12 months, 42% of micro businesses and 46% of small ones. Phishing was the most common by a distance at 38% of businesses, and the most disruptive kind for 69% of those affected. If you have had a convincing fake invoice or a login page that was not quite right, you are the average instead of the unlucky one.
The second is the one the insurance industry rarely leads with. For the middle 50% of businesses that were hit, the cost came in somewhere between £0 and £200. The worst-affected 5% of micro and small businesses paid around £4,000. Roughly 47% of businesses hold cyber cover of some kind.
So insurance here is not for the median. The median is an afternoon and a password reset. What a policy buys is the tail, the £4,000 morning, or a response team you would not otherwise know how to hire, or a client contract that will not be signed without a certificate attached. Those are all real. They are just not the same thing as protecting yourself from the ordinary case.
Cyber Essentials already bundles £25,000 of cyber insurance cover

Cyber Essentials is the NCSC’s baseline scheme: the minimum standard of cyber security recommended by the Government, built around five controls: firewalls, secure configuration, security update management, user access control and malware protection. It is priced by organisation size and starts at £320 plus VAT.
The part that gets missed: certify fully, turn over less than £20m, be domiciled in the UK or the Crown Dependencies, and you can opt in to cyber liability insurance arranged by IASME, the scheme’s delivery partner. The limit is £25,000, upgradeable to £100,000 or £250,000 for more premium. It covers incident response (legal, IT, data recovery, notification, reputation), plus extortion threats, regulatory investigations and data protection fines, and business interruption from a network compromise.
It is opt-in rather than automatic. You are asked during the assessment, and if you skip past that question you do not have it.
For a freelancer whose clients already ask for Cyber Essentials, that reframes the whole decision. The certification is the thing you are buying; the cover comes with it. Paying for the certificate and a separate policy is paying twice for the same conversation, unless the separate policy does something the bundled one does not.
What cyber insurance will not cover
Here is the exclusion to read before anything else. The bundled policy does not cover money stolen by electronic means, or cyber fraud. There is also a £1,000 excess on any claim.
Picture how a freelancer loses money to this. Your email gets compromised. An invoice goes out — your template, your logo, your wording, with somebody else’s bank details on it. The client pays it in good faith. Weeks later you chase, and the money is a month gone through three accounts.
That is the nightmare. It is also the thing this cover explicitly does not pay for. Cyber liability insurance is built to fund the clean-up after a breach: the lawyers, the notifications, the ICO investigation, the forensic bill. It is not built to make you whole on stolen funds.
Which means the protection against the loss you fear most is not a policy at all. It is multi-factor authentication on your email, and a habit of confirming any change of bank details by phone, on a number you already had, never on the number in the email asking for the change. Standalone policies vary, and some do offer limited crime or funds-transfer-fraud cover, but that is a question to put to the underwriter in writing, not to assume from the marketing page.
When standalone cyber insurance earns its place
- A client contract requires it and names a limit. This is the most common reason freelancers buy it, and it is a perfectly good one, the cover is the price of the work.
- You hold personal data at a volume where an ICO investigation is a realistic outcome rather than a theoretical one.
- You handle client payment details or hold money on their behalf.
- A four-figure bill and a fortnight of lost billable time landing in the same week would hurt.
If none of those apply, the honest answer is that your money does more work on the controls than on the premium. Backups you have restored from once. MFA everywhere. A password manager. Updates that install instead of sit in a notification.
What to buy first, and what to buy last
- Check whether you owe the ICO the data protection fee, and pay it if you do.
- Learn the 72-hour rule now, while nothing is on fire.
- Do the five Cyber Essentials controls, whether or not you certify.
- If a client asks for certification, get Cyber Essentials and opt in to the bundled cover.
- Only then price a standalone policy, and read the exclusions before you read the premium.
Cyber cover is one of several a freelancer gets offered, and it is rarely the first one that matters. What freelancers actually need puts them in order, professional indemnity is the one clients ask for most, and employers’ liability is the only one that is ever a legal requirement.
Insurance sized to a guess?
Protect the Business: Legal, IP & Insurance 2026/27. Eight modules and five working sheets built around a complete annotated freelance contract, with a negotiation note under every clause.
- Registering a trade mark yourself: searching, classes, fees and the opposition period
- UK GDPR without a consultant: the ICO fee tiers, a privacy notice, and the 72-hour breach plan
- An insurance sizing calculator by work type, and the client clauses never to sign as they stand, with the redline for each
You own the copyright in what you make until you assign it in writing. Most clients assume the opposite, and most freelance contracts are silent on it.
Buying more than one? All ten 2026/27 courses for £107, against £328 at full price.
Sources
- The data protection fee, ICO
- Personal data breaches: reporting. ICO
- Cyber Security Breaches Survey 2025/26, GOV.UK
- Cyber Essentials overview: NCSC
- Cyber liability insurance with Cyber Essentials, IASME
The breach and cost figures are from the Cyber Security Breaches Survey 2025/26, published 30 April 2026. The Cyber Essentials price and the five controls are quoted from the NCSC; the £25,000 limit, the opt-in, the £20m turnover cap, the UK domicile condition, the £1,000 excess and the stolen-money exclusion are from IASME’s own page. The ICO wording on the fee and on the 72-hour report is the ICO’s own.
All were read on 26 August 2026 and all of them can change, check before you rely on a figure. This is general information about how the rules and the schemes work; it is not insurance advice, not a recommendation to buy any policy, and no policy wording here is a substitute for the one you would actually be sold. No affiliate links on this page.
