Directors in the Crosshairs: Closing the Cyber Insurance Gap Before It Costs You Everything
Photo: UK business director reviewing documents at boardroom table cybersecurity risk, via armourcyber.io
For many British directors, cyber insurance sits somewhere between a footnote in the annual risk review and a box ticked during renewal season. It is purchased, filed, and largely forgotten — until the moment it is needed most. That moment, increasingly, is arriving sooner than anticipated, and when it does, a significant number of UK business leaders are discovering that their coverage falls dramatically short of their actual exposure.
The consequences are not merely financial inconvenience. They can include personal liability, regulatory censure, and reputational damage that outlasts any single incident by years.
The Accountability Shift That Many Boards Have Missed
The landscape of director responsibility around cyber risk has shifted markedly over the past three years. The Information Commissioner's Office (ICO) has moved from issuing guidance to levying substantial fines, and the Companies Act's duty of care provisions are increasingly being interpreted by courts and regulators to encompass digital governance. Crucially, the National Cyber Security Centre (NCSC) published updated guidance in 2023 making explicit that boards — not IT departments — bear ultimate accountability for an organisation's cyber posture.
Yet a 2024 survey by the Association of British Insurers found that fewer than a third of UK SME directors had reviewed their cyber policy wording in the preceding twelve months. Many had never read it at all. This matters because the gap between what directors assume their policy covers and what it actually covers is, in practice, wide enough to swallow a company whole.
What Standard Policies Typically Miss
A conventional cyber insurance policy purchased off-the-shelf will generally cover first-party losses: the cost of incident response, data recovery, business interruption, and perhaps ransomware payments. What it frequently does not cover — and what directors often fail to appreciate — includes the following:
Regulatory fines and penalties. Under UK GDPR, the ICO can impose fines of up to £17.5 million or four per cent of global annual turnover. Many standard cyber policies explicitly exclude regulatory fines, or cover them only in limited circumstances. Directors who assume otherwise are mistaken.
Personal liability claims. Where a breach results from demonstrable board negligence — a failure to implement reasonable security measures despite known risks — shareholders or affected third parties may pursue directors personally. Directors and Officers (D&O) insurance does not automatically extend to cyber-related negligence unless specifically endorsed.
Supply chain incidents. If a breach originates with a third-party supplier, some policies treat this as an excluded event or apply significantly reduced sub-limits. For businesses with complex procurement networks, this is a material gap.
Reputational harm costs. The long-tail cost of a data breach — lost contracts, reduced customer confidence, PR consultancy — is rarely covered comprehensively, yet it often represents the largest financial impact over a two-to-three-year horizon.
Case Studies: When the Policy Didn't Stretch Far Enough
Consider the case of a mid-sized professional services firm in the West Midlands. Following a ransomware attack in late 2022, the company submitted a claim for approximately £340,000, covering business interruption and recovery costs. The insurer partially settled, but excluded £110,000 relating to a regulatory investigation triggered by the ICO after the firm failed to notify affected clients within the 72-hour window required under UK GDPR. The directors had assumed notification management was covered. It was not.
In a separate incident, a Scottish manufacturing business suffered a breach traced to a compromised supplier portal. The firm's cyber policy contained a clause limiting third-party-originated claims to £50,000 — a sub-limit buried in the schedule. Actual losses exceeded £280,000. The shortfall fell to the directors personally, triggering a dispute with the company's D&O insurer that remained unresolved at the time of writing.
These are not outlier scenarios. Insurance brokers with specialist cyber practices report that partial or disputed settlements are becoming increasingly common as claims volumes rise and insurers scrutinise policy terms more rigorously.
The Regulatory Context Directors Cannot Ignore
The UK government's Cyber Security and Resilience Bill, expected to progress through Parliament in 2025, proposes to extend mandatory incident reporting obligations and impose new duties on directors of organisations operating critical infrastructure or handling significant volumes of personal data. Even for businesses that fall outside those definitions today, the direction of regulatory travel is unambiguous: personal accountability at board level is increasing, not diminishing.
The Financial Conduct Authority has already signalled that regulated firms must treat cyber resilience as a board-level governance matter, equivalent in seriousness to financial controls. For directors of FCA-regulated businesses, the bar is already high — and the penalties for falling short are applied personally, not merely institutionally.
A Practical Checklist for Boards
The following steps represent a minimum standard of diligence for any UK board seeking to close the compliance gap:
-
Commission a policy gap analysis. Engage a specialist cyber insurance broker — not a generalist — to map your current coverage against your actual risk profile. Pay particular attention to sub-limits, exclusions, and the interaction between your cyber policy and your D&O cover.
-
Confirm regulatory fine coverage. Ask your broker explicitly whether regulatory fines and investigation costs are covered, under what circumstances, and up to what limit. If the answer is ambiguous, treat it as a gap.
-
Audit your notification procedures. Ensure your incident response plan includes a tested, timed process for ICO notification within 72 hours. Insurers increasingly require evidence of a documented response plan as a condition of cover.
-
Review third-party and supply chain clauses. Understand exactly how your policy treats breaches originating outside your own systems. If sub-limits apply, consider whether they reflect your genuine exposure.
-
Align D&O and cyber cover. Work with your legal advisers to confirm that personal liability arising from cyber-related negligence is addressed either within your cyber policy or through a specific endorsement to your D&O policy.
-
Document board-level cyber governance. Regulators and courts look for evidence that boards have actively engaged with cyber risk. Board minutes should reflect regular, substantive discussion of cyber posture — not merely a quarterly IT update.
The Cost of Inaction
Directors who treat cyber insurance as an administrative formality are, in effect, making a financial bet against themselves. The average cost of a UK data breach reached £3.4 million in 2024, according to IBM's annual Cost of a Data Breach Report. For smaller businesses, even a fraction of that figure can be existential. For directors personally, the reputational and legal consequences of a poorly managed incident can follow them from one boardroom to the next.
The good news is that the gap is closable. The policies exist, the specialist brokers are available, and the regulatory guidance is clearer than it has ever been. What is required is the willingness to treat cyber insurance as a strategic governance matter — and to give it the same rigour applied to any other material risk on the board's agenda.
The time to discover what your policy actually covers is before the incident, not during it.