colleagues working on a computer
colleagues working on a computer
Blog

Cyber insurance VS cybersecurity: what’s the difference and why do businesses need both?

August 04, 2026

Key takeaways 

  • Cybersecurity reduces the chance and impact of a cyber incident. 
  • Cyber insurance gives you practical and financial support to respond to and recover from a cyber incident. 
  • Cyber resilience isn’t just important for large businesses. The Government Cyber Security Breaches Survey 2025/2026 found that over 40% of small and micro businesses had experienced an attack or breach in the last 12 months. 
  • To be cyber-resilient, you need cybersecurity and cyber insurance. 

Speak to us about your cyber risks

If you’d like to understand how emerging cyber threats could affect your organisation, or review whether your current cyber insurance arrangements remain fit for purpose, speak to the Macbeth team.

Call us on 0118 916 5480 or get in touch with our team.


 

We have cybersecurity, so do we really need cyber insurance?” 

It’s a common (and very good) question. If you have cybersecurity software, policies and processes in place, surely the risk of a cyber-attack is far lower? So why pay out for cyber insurance as well? 

It’s helpful to start with the difference between cyber insurance and cybersecurity: cybersecurity protects your digital devices, networks and data from a cyber-attack and reduces the likelihood of a cyber incident. But cybersecurity isn’t guaranteed to prevent an attack (the attacks on M&S, Co-op and Qantas are proof of this). Cyber insurance provides emergency support following a breach and helps your business respond, recover and manage the financial impact.  

In summary, cybersecurity is the prevention and cyber insurance is the cure.    

Don’t cyber-attacks just happen to large businesses though? 

The latest Government Cyber Security Breaches Survey carried out between August and December 2025 (commissioned by DSIT; the Department for Science, Innovation and Technology) reported that 43% of businesses and 28% of charities reported a cybersecurity breach or attack in the last 12 months. And, whilst the figures show that medium and large business are more likely to experience an attack, 42% of micro businesses and 46% of small businesses still experienced an attempted breach or attack.  

SMEs (especially technology companies) are common victims of cyber-attacks, because small businesses act as a gateway into larger ones, employees are more vulnerable to social engineering and phishing scams, and smaller companies are more likely to pay ransoms.  

To be cyber resilient, businesses need a combination of preventative tactics (cybersecurity) and a post-attack strategy (cyber insurance). 

 

Cybersecurity and cyber insurance are not the same thing 

Cybersecurity gives your business the controls and processes to prevent and detect an attack, whereas cyber insurance gives your business the support and finances to deal with an attack.  

Even with the best cybersecurity software, policies, procedures and staff training, you can’t eliminate cyber risk, because software doesn’t stop human error (clicking on a deceptive email or message) or social engineering (where attackers use human psychology to manipulate people into taking unsafe action). In fact, the cyber-attack on M&S happened because attackers tricked a help-desk contractor into resetting account credentials which then gave the hackers ‘legitimate’ logins. And that’s where cyber insurance comes in; if there’s an attack, your policy will provide breach response and practical support along with financial support to keep your business going.  

Cybersecurity and cyber insurance often work hand in hand; some insurers will even ask about your cybersecurity and expect you to have certain cyber controls in place. 

 

What does cybersecurity do? 

Broadly speaking, cybersecurity falls into three areas: controls, prevention and detection. 

Controls: 

Cybersecurity controls are safeguards that reduce risk and exposure. They include tools like: 

  • Multi-factor authentication: requiring people to prove their identity with two or more pieces of information when logging into a system or application. Common MFA methods include inputting a code sent to another device or confirming access using biometric data (finger or face). 
  • Privileged account management: controlling administrative access to sensitive systems, data and applications. 
  • Password management: generating and storing critical, data-sensitive passwords. 

Prevention: 

Cybersecurity prevention methods include: 

  • Firewalls and virus protection software: these act as a network barrier or gatekeeper (like a digital security guard) to decide what data comes in and goes out.   
  • Identity and access governance: access controls give the right people access to the right systems and the right data at the right time. In other words, these controls help ensure employees can access only the systems and data they need to perform their role. 
  • Policies and training: robust policies and regular employee training can help employees spot and report phishing attacks and prevent employees being socially engineered (psychologically manipulated) into giving hackers access.  

Detection:  

  • Identity threat detection: a cybersecurity framework that monitors identities and detects stolen credentials. 
  • Real-time breach-alerting software: continuous monitoring of system logs and user behaviour to flag anomalies that might indicate an attack, leak or unauthorised access.   

If you’re a tech company, cybersecurity is especially important if you host platforms, process client data, manage software or provide outsourced IT services. 

And if you’re an SME, even relatively simple controls like MFA and training can reduce the risk of phishing and compromised email accounts.

 

What does cyber insurance do? 

Cyber insurance gives you financial support in the event of an attack and immediate, practical emergency support within a few hours of a breach:   

First and third-party financial support: 

  • Financial cover for damage or business interruption caused by a data breach, or hacking attempt.  
  • Third party claims (also known as cyber liability): financial cover for damage to your customers or other third parties as a result of a breach. Damage could include loss of sensitive customer information, financial damages or a lawsuit. 

You can also add on cyber-crime insurance: 

  • Cyber-crime insurance pays out for damage caused by cyber-crimes like phishing (but isn’t always included in stand-alone cyber insurance policies).  

Breach response:  

  • Data breach response: if there’s been a data breach, your insurer can get credit monitoring specialists on board to help identify credit profile changes, which might be a sign of identity theft or fraud. 
  • Extortion response: if there’s been an extortion attempt, you’ll get support with how to deal with it and the money to pay it (if the decision is taken to pay). 
  • Crisis communications: your insurer will have PR experts on standby in case of potential damage to your reputation. 
  • IT forensics: your insurer will arrange for your IT infrastructure to be forensically checked to close any loopholes or access points and make sure that hackers aren’t still in your system. 
  • Legal support: your insurer will also have legal experts ready to advise and guide you on any legal issues. 

Exact cover and protection depend on your cyber insurance policy, insurer, selected limits, extensions, terms, conditions and exclusions.

 

Cybersecurity vs cyber insurance: a simple comparison 

  Cybersecurity  Cyber insurance 
Purpose  Reduce cyber risk.  Give your business practical and financial support after an incident. 
Focus  Controls, prevention and detection.  Financial cover, emergency response support, operational support.  
Examples  MFA, firewalls, virus protection, identity and access governance, training, password management, threat detection software.  1st and 3rd party costs, breach response, IT forensics, legal and PR support. 
Limitations  Can’t stop every incident, especially breaches caused by human error or social engineering.  Doesn’t stop incidents happening and can’t replace cyber controls. 
Best used for:  Reducing the chance and impact of attacks.  Managing disruption and paying for damage. 

 

Why cybersecurity alone may not be enough 

Cybersecurity reduces your risk, but it doesn’t reduce the financial, legal or operational consequences of an incident. 

If you’re the victim of a cyber-attack, there’s likely to be a direct impact on your business and there may also be a ripple effect on your customers or suppliers too. 

Let’s look at some specific examples where cybersecurity wouldn’t stop an attack: 

An employee clicks a convincing email (phishing) 

You haven’t got around to testing staff with mock phishing exercises and an employee clicks a link they think is harmless. Ransomware is installed on your system, and you have to temporarily stop trading.   

An attacker spoofs the CEO’s email address (whaling) 

The payroll department get an email from the ‘CEO’ instructing them to set up a new employee for payment or amend the details of an existing employee. Or, accounts payable receive an email from the marketing department instructing a payment for a ‘new supplier’. A lump sum is transferred out of your business. 

Impersonation (social engineering) 

An employee gets a call from someone impersonating a senior member of staff, pretending they’re locked out of a system. They unwittingly give out data that enables hackers to gain access to your system. Your customer database is stolen, and you’re asked to pay a ransom to stop it being leaked. 

Someone gains unauthorised access to your building (social engineering) 

Someone pretends to be a cleaner or delivery driver and asks an employee to “hold the door”. Not wanting to be rude, the employee lets the imposter in. Critical data is stolen via a USB drive and your reputation is at risk.  

Fake IT support (vishing) 

Someone calls pretending to be IT support and gains enough information to ‘take over’ a computer and install ransomware.

 

Why cyber insurance alone may not be enough 

Cyber insurance helps you minimise loss and get back to business quickly after an attack, but it doesn’t stop an attack happening in the first place. Insurance is only one part of a business risk strategy and is most effective when it sits alongside preventative tools, policies and systems.  

Cyber insurance isn’t a substitute for basic cyber hygiene 

You wouldn’t rely on malaria tablets while ignoring a mosquito net. The same principle applies to cybersecurity. Cyber insurance can help your business recover from an incident, but you still need effective controls, training and security measures to help prevent one in the first place. 

Insurance is often dependent on cyber security controls 

Even if you do have cyber insurance, your insurer will probably expect you to have certain cybersecurity policies and controls in place.

 

How cyber insurance and cybersecurity work together 

The biggest risks of a cyber-attack on your business are lost revenue, business interruption, data loss and reputational damage. And the best way to minimise loss is to combine cybersecurity best practice with cyber insurance. 

Let’s take our earlier phishing scenario where an employee clicks a link in an email…  

The belt and braces approach  

  1. Staff training makes employees suspicious of emails with links. The employee checks the email for spelling mistakes and clumsy, unprofessional logo imitations. This would stop some attacks (CYBERSECURITY at work). 
  2. Meanwhile, several other attacks are rejected via a firewall (CYBERSECURITY at work).
  3. The employee is satisfied the email is real and clicks the link. Unfortunately, it’s a phishing email and the employee enters a username and password, unwittingly giving attackers access to confidential company data (the ATTACK). 
  4. Data is backed up and the employee only has partial access to data thanks to identity and access governance (CYBERSECURITY at work). 
  5. Unfortunately, the access is enough to allow the hackers to install ransomware and make a ransom request (the ATTACK). 
  6. Real-time breach-alerting software kicks in and IT are alerted to the breach (CYBERSECURITY at work). 
  7. IT alert the insurers and emergency breach response is launched (CYBER INSURANCE at work). 
  8. IT forensics and PR support are on standby (CYBER INSURANCE at work). 
  9. The insurer provides specialist extortion-response support and guidance, helping the business make informed decisions and recover as quickly as possible (CYBER INSURANCE at work). 

Together, cybersecurity and cyber insurance give you the best possible form of protection against a cyber-attack.

 

What should SMEs and tech firms consider when choosing cyber insurance? 

Cyber-attacks can result in tangible losses to your business (data, income, money) and / or liability claims from employees or third parties affected by the breach. So, when you’re evaluating your cyber risk and choosing insurance, consider the overall impact an attack could have, not just the immediate lost revenue. 

Things to consider: 

  1. What systems and data does your business rely on? Consider implementing a three-random-word password policy for ALL your systems. Make sure you have backups in place. And you might want to consider Privileged Access Management for anyone with password admin rights. This limits users that can access administrative functions and gives just-in-time access via one-off passwords for additional layers of protection. 

Things to tell your broker or insurer: 

  1. Whether your business stores personal, payment, financial or sensitive data (you’re more at risk if you use the internet to trade or if you hold confidential or sensitive data). 
  2. Whether your business provides technology services to clients. 

Questions to ask your broker: 

  1. Does the policy include first-party and third-party cover? 
  2. When does business interruption cover kick-in and how it is triggered? 
  3. Can I add on cyber-crime insurance to cover against phishing and social engineering 
  4. What does the insurer’s breach response service include?  
  5. Who does the insurer partner with for IT forensics and breach response?  
  6. What are the policy limits and excesses? 
  7. Are past breaches or attacks covered if they come to light after the policy is in place? 
  8. Are there any geographic limits or exclusions?  
  9. Does the policy cover contractual requirements with my clients and suppliers? 
  10. Are there any mandatory cybersecurity controls or policies I need to have in place? 
  11. Do you offer an in-house claims service? Macbeth offers this service to all clients for free, but not all brokers do. 

At Macbeth, we feel so strongly about the importance of Cyber insurance that we’re happy to offer advice about cyber risks even if you don’t choose us as your broker. 

We can audit your cyber risk, work out your biggest risks and advise on the best cover. And we can help you work out if you need cyber liability insurance or whether you also need crime insurance so you’re covered against phishing and social engineering attacks. We can also advise you about the specific cybersecurity controls insurers might ask you to put in place.

 

Where does Cyber Essentials Plus fit in? 

Cyber Essentials is a government-backed scheme detailing a set of standard technical controls that organisations should have in place to protect themselves against common online security threats. You can apply for a Cyber Essentials certificate via the government website following a verified self-assessment.  

Cyber Essentials Plus is an audited, higher-level tier of the government scheme. Instead of completing a self-assessment, an accredited auditor evaluates your company’s cybersecurity measures against five baseline criteria. 

Cyber Essentials and Cyber Essentials Plus are both great ways to implement and demonstrate stronger cyber controls (and can show your insurer that you take cybersecurity seriously). They help you become more cyber resilient but they don’t replace the need for cyber insurance. 

At Macbeth, we’re proud to have the Cyber Essentials Plus accreditation, it strengthens our own cyber defence and means we’re better informed to help you mitigate cyber risk too.

 

Cyber insurance for technology businesses 

At Macbeth, we work with lots of specialist technology businesses. We know that if you’re a SaaS, software, telecoms, web or gaming provider, you’re processing high levels of customer data, hosting platforms or applications and managing systems or infrastructure. And because clients are outsourcing their IT or digital services to you, you have contractual obligations around security and service continuity. All of this means technology businesses have a higher exposure to risk; 

  • An attack or breach in your business also puts your clients at risk  
  • Your business could be a targeted gateway to gain access to a client’s business 
  • Specialist technology risks often fall outside standard insurance policies 

As a technology business, you probably already have strong cybersecurity measures in place, because you already understand the importance of managing cyber risk. But it’s also worth considering technology insurance in case of an attack. And if you already have technology insurance, check for grey areas in your policy – not all policies cover all the possible professional indemnity risks, and some contract types aren’t covered either.

 

Speak to Macbeth about strengthening your cyber resilience 

If you’re worried about an attack and want to find out more about reducing your cyber risk, chat to one of our specialist cyber advisers. We’re a chartered insurance broker, we offer independent advice and we’re human (no bots at Macbeth). Ask about our free in-house claims service too – it’s included with every policy.  

“The question is no longer whether a cyber incident could happen, but how quickly and effectively your business can recover when one does.  As the old saying goes, ‘Hope for the best, prepare for the worst.’ Cybersecurity is designed to prevent attacks, while cyber insurance helps ensure that when the unexpected happens, expert support and financial protection are already in place”. Gareth Roberts, Corporate Client Adviser 

Want to reduce your cyber risk and learn more about the difference between cyber insurance and cyber-crime insurance?

Call 0118 923 5090to speak to our cyber experts Theo, James or Gareth 

Want to reduce your cyber risk

Call us on 0118 916 5480

Get in touch

Want to reduce your cyber risk

Call us on 0118 916 5480

Get in touch

Related insights

Related insights

View all
Combined Shape
Combined Shape
Group CEO sitting in high back chair looking to camera and smiling
Group CEO sitting in high back chair looking to camera and smiling

Question about technology insurance. Talk to one of the Macbeth team.

Send us a message