Do sole traders need cyber insurance?
It isn't compulsory, but it's worth considering if you hold customer data, take payments online or depend on email and cloud accounts to trade. The UK government's Cyber Security Breaches Survey 2025/26 found that 42% of micro businesses suffered a breach or attack in the previous 12 months, and phishing was the most common type. Cyber insurance typically pays for incident response, data recovery, business interruption and liability to affected customers, which public liability and home insurance don't cover. See what insurance does a sole trader need.
- 43% of UK businesses and 42% of micro businesses reported a breach or attack in the last year (CSBS 2025/26).
- Phishing is the most common attack, reported by 38% of businesses.
- Under UK GDPR, reportable personal-data breaches must go to the ICO within 72 hours, and cyber policies often include breach-response help.
- Public liability, professional indemnity and home insurance usually exclude or limit cyber losses.
- Basic controls (multi-factor authentication, backups, updates) both reduce risk and are often required by insurers.
What Cyber Insurance Covers
• Data and system restoration: recovering files and rebuilding accounts.
• Business interruption: lost income while you're locked out.
• Cyber liability: claims from customers whose data was exposed.
• Cyber crime: some policies cover funds lost to invoice fraud or social engineering, often with a sub-limit.
A spoofed email changing your bank details on an invoice can divert a client's payment. Check whether the policy covers social engineering fraud, and at what limit.
Which Sole Traders Need It Most
Cost, Tax and Prevention
Illustrative Case: The Bookkeeper's Inbox
Scenario: A sole-trader bookkeeper clicks a phishing link, and her email account is taken over. The attacker emails three clients with altered bank details and accesses folders containing clients' payroll data.
Resolution & Judicial Outcome: Her cyber policy's incident-response team secures the account, helps her assess whether the breach must be reported to the ICO within 72 hours, notifies affected clients and pays forensic costs. Losses from the diverted payments are paid up to the policy's social-engineering sub-limit. Her professional indemnity policy excluded cyber events.
What You Should Do: Step-by-Step Action Plan
Critical Mistakes to Avoid
- Assuming professional indemnity covers data breaches.
- Reusing passwords across business accounts.
- Changing payment details on an emailed request without a phone check.
- Missing the 72-hour ICO reporting window for reportable breaches.