Work out the number before your insurer does

· · Security Commentary

If your systems went down on Monday morning and stayed down all week, what would that cost you? Not roughly. A number, with working behind it.

Most businesses cannot answer, which is awkward, because that number is doing a lot of quiet work. It decides whether your insurance cover is the right size. It decides what you should spend on backups. And it is the number your insurer will effectively calculate on your behalf, after the event, using their assumptions rather than yours.

The gap in the research

New research from Cohesity, reported by ITPro, found that only 22% of UK business leaders believe their insurance policy would cover the costs and lost revenue from an attack. Chief executives estimated an attack would cut annual revenue by about 15% on average.

The finding that matters is the next one. One in five said their business had "never undertaken business impact modelling to understand the potential cost of an attack".

Set those side by side. Four in five leaders doubt their cover is adequate, and a large share have never worked out what adequate would look like. The doubt is not really about the insurance market. It is what not having a number feels like from the inside. You cannot judge whether a policy limit is right without an estimate of the loss, so the honest answer is unease, and unease is what the survey measured.

This is a vendor survey, and vendor surveys tend to find problems their vendor solves, so treat the percentages as a prompt rather than gospel. The underlying point stands on its own logic regardless of who funded the research.

Some context on the market. The Cyber Security Breaches Survey run by the UK government has consistently found that around half of firms hold no policy at all. Meanwhile the Association of British Insurers reported £197 million paid out to help businesses recover from incidents in 2024, a 230% year-on-year increase, with 17% more policies taken out than the previous year. Cover is growing and it does pay. The question is not whether insurance works. It is whether yours is sized to your business.

Doing the sum yourself

You do not need a consultant or a model. You need an afternoon, a spreadsheet, and a willingness to write down assumptions you are not certain about.

Pick one realistic scenario and cost it honestly. "Ransomware encrypts our main systems on a Monday and we are substantially offline for five working days" is a good default, because it is both common and disruptive.

Then work through what actually happens:

  • Lost revenue. Take your weekly turnover as the starting point. Then adjust for what is genuinely deferred rather than lost. A manufacturer usually catches up on orders. A restaurant does not get Tuesday back.
  • Wages for people who cannot work. They are still paid. If half your staff cannot do their jobs for a week, that is a real cost with no output against it.
  • Getting back up. Specialist incident response help, overtime, temporary equipment, and the price of rebuilding whatever cannot be restored cleanly.
  • The obligations you cannot postpone. Contractual penalties for missed deadlines, notifying customers, and the regulatory work if personal data was involved.
  • What follows in the months after. Customers who quietly go elsewhere, the deal that stalls because you had to disclose the incident, and the management time swallowed by all of it for a quarter.

Add it up. The total is your number. It is approximate and it will be wrong in the details, and it is still enormously more useful than the nothing you had before, because now you can hold it up against your policy limit.

Then read the policy against the number

Once you have a figure, the policy documents become readable, because you know what you are looking for. Three things worth checking, ideally with your broker on the phone:

  • The limit and the excess. Is the maximum payout in the same range as your number? What do you have to absorb before cover begins?
  • The exclusions and conditions. Cover is routinely conditional on controls you promised you had. If you said you enforce two-step verification everywhere and it turns out three systems were missed, that is the conversation you have during a claim. This is the same trap as the questionnaire that quietly becomes the policy, and the MFA scope gap is exactly how it happens in practice.
  • Business interruption specifically. Many policies pay for the response, the forensics, and the legal work far more readily than they replace lost trading income. For most small businesses, lost trading income is the bulk of the number.

The exercise usually changes behaviour more than it changes cover. Once a director has personally written down what five days offline costs, the argument for testing the backups stops being a technical request and becomes a straightforward commercial one.

What to do this quarter

  • Cost one realistic scenario, five days offline, on one side of A4.
  • Compare that figure to your policy limit, and to your excess.
  • List the controls your last insurance questionnaire committed you to, and confirm each is actually true today.
  • Ask what your insurer would need from you within the first 24 hours of an incident, and make sure someone knows where those details are without access to your systems.
  • Establish who decides, and who can authorise spending, on the day something happens.

Insurance transfers some of the financial risk. It does not restore your data, call your customers, or run your business while you recover. Knowing your number is what tells you how much of that gap you are carrying yourself.

How Steelwise can help

Working out what an incident would actually cost you, and whether your controls match what you have told your insurer, is a short piece of work that usually pays for itself at renewal. Get in touch if you would like a hand with the sums.

Further reading

← All filings