SME cyber risk misread leaves UK brokers facing an uphill sale
Markel research finds 39% of uninsured small businesses think they face low risk, despite evidence to the contrary
SME cyber risk misread leaves UK brokers facing an uphill sale
CYBER
By Mark Rosanes
06 Oct 2026

Nearly four in ten UK SMEs without cyber insurance believe they face a low risk of attack. The same survey found that 29% of all uninsured SMEs in the sample had already experienced a cyber incident.

The figures come from Cracking the Cyber-Market Code, a research report commissioned and published by Markel UK. The insurer surveyed 1,500 UK small businesses and 16 insurance brokers, including members and the chair of the British Insurance Brokers' Association (BIBA) Cyber Committee. The research identifies a persistent disconnect between how SMEs perceive digital risk and the disruption a cyber incident can actually cause.

"Attackers don't check headcount before they send a phishing email," said Mark Lowther, head of technology and cyber underwriting at Markel UK. "A supplier payment redirect or a locked-out booking system can stop a five-person firm as easily as a five-hundred-person one."

The UK government's Cyber Security Breaches Survey 2025/2026, published in April 2026, found that 43% of UK businesses experienced a cyber breach or attack in the last 12 months. Yet 44% of the SMEs in Markel's sample had no cyber insurance at all.

A wording problem with liability consequences

Beyond the perception gap, the report surfaces a more structural obstacle in the cyber sales journey. All 16 brokers surveyed, a small but deliberately specialist sample that included senior members of the BIBA Cyber Committee, reported confusion when comparing cover and limitations across different providers. When one insurer uses "social engineering" and another uses "eCrime" to describe similar risks, brokers must interpret language before they can give a client a meaningful comparison.

That interpretation burden carries professional liability consequences. A broker who misreads an inclusion or exclusion based on ambiguous wording faces errors and omissions exposure. If a client later finds their claim falls outside what they were advised was covered, the cost is borne by more than just the client.

The report also identifies a technical differentiator that brokers are increasingly pressing for. The split between Any One Claim (AOC) and aggregate limit structures has become a live issue in client conversations. Under an AOC policy, the limit applies separately to each covered incident. Under an aggregate structure, multiple incidents draw from the same pool. A ransomware attack followed by an invoice fraud incident in the same year could see the first claim erode or exhaust the limit before the second arrives. The report states that composite insurers still commonly use aggregate structures, and identifies this as a competitive differentiator for standalone cyber products.

Markel sells standalone cyber insurance and has a commercial interest in that distinction.

The confidence gap in the sales conversation

A second layer of friction sits within the broker-client relationship itself. Every broker interviewed said they sometimes felt under-equipped to handle the more technical questions that informed clients raise. One respondent said: "I'm advising my clients why they need something but I'm not technical enough to know what all the answers are."

The research found that 84% of brokers said clients care most about the right level of cover at the right price. A significant 69% said ease of use is now a critical buying factor. Clients who encounter jargon-heavy wordings or complex proposal forms tend to disengage before a policy is bound.

"There's too much jargon and not enough clarity," said another broker respondent. "It makes clients switch off."

The picture is not uniformly negative. Among SMEs who had made a cyber claim, 71% said the experience exceeded their expectations. The cover works when clients use it, but the purchasing journey too often prevents them from reaching that point.

The research also found that SME buying behaviour has shifted. Businesses are less likely to search for "cyber insurance" and more likely to search for answers to specific problems, such as what to do if client data is stolen. That shift points to how brokers frame the initial conversation, and to the kind of plain-language materials that help clients understand what they are buying before cost becomes the only question.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.