Tradesman Insurance

Do Tradesmen Need Cyber Insurance?

Fact Checked

Most tradesmen do not need a standalone cyber policy, but almost all of them carry the one exposure that costs real money: somebody intercepting an invoice and taking the payment. Cyber cover exists to pay the recovery costs when that happens.

Cyber marketing tends to borrow corporate horror stories, which is why trades ignore it. The honest position is smaller and more specific, and it sits well outside what a tradesman insurance package normally covers.

This guide uses the government’s own breach survey rather than insurer marketing. It sets out what actually goes wrong for trade businesses, what the law makes you do afterwards, and when buying cover is the wrong answer.

Key Takeaway

Invoice fraud, not a headline-grabbing hack, is the cyber risk most likely to actually cost you money, so double-check bank details by phone before you change them on an invoice. Your existing tradesman policy is unlikely to respond to a cyber loss unless it’s specifically extended. A standalone policy is worth it if you hold customer data or take payments online, less so if you don’t.

Ask about cyber cover when you next renew your tradesman policy.

What cyber risk does a trade business actually carry?

Your risk is not a hacker breaking into a server. It is your email account, your phone and the customer details sitting in a job management app.

The data a tradesman holds without thinking about it

Names, addresses, phone numbers, door codes, alarm codes, survey photographs of the inside of people’s homes and a bank sort code on every invoice. All of it counts as personal data under UK GDPR.

A gas engineer running a service round holds a list of vulnerable customers, their addresses and when they are out. That is a more attractive dataset than most people realise.

The systems that create the exposure

Cloud accounting, quoting software, a shared inbox, WhatsApp job threads and card payment readers all sit between you and money. Each one is a way in.

Phishing was the most prevalent attack type in the government’s latest survey at 38% of businesses. It works because it targets the person, not the software.

Why trades get targeted rather than overlooked

Small businesses are picked precisely because they run lean, use personal email accounts and have no IT department to check anything. The attack does not need to be clever to work.

A one-van handyman business and a fifty-van contractor face the same phishing email. Only one of them has someone whose job it is to spot it.


How common are breaches, and what do they actually cost?

Roughly four in ten small UK businesses identify a breach or attack each year, and the median cost of the most disruptive one is £0. Both halves of that sentence matter.

What the government survey found

The Cyber Security Breaches Survey 2025/26, published on 30 April 2026, found 43% of all UK businesses identified a breach or attack in the previous 12 months. For small businesses the figure was 46%.

Micro businesses, meaning most trade outfits, sat at 42%. Phishing accounted for 38% of businesses affected, far ahead of anything else.

The £0 median nobody quotes

The same survey puts the median cost of the most disruptive breach at £0, with an interquartile range of £0 to £200. Most incidents are a nuisance rather than a bill.

The tail is where the damage sits. For micro and small businesses the 95th percentile is around £4,000, so one incident in twenty lands somewhere between annoying and ruinous.

Measure Micro businesses Small businesses
Identified a breach or attack in 12 months 42% 46%
Hold some form of cyber cover 45% 55%
Median cost of the most disruptive breach £0 £0
95th percentile cost Around £4,000 Around £4,000

Source: Cyber Security Breaches Survey 2025/26, DSIT and the Home Office, published 30 April 2026.


What is invoice fraud and why does it hit trades hardest?

Invoice or mandate fraud is where a criminal intercepts or spoofs your invoice and changes the bank details, so your customer pays them instead of you. It is the single most common way a trade business loses real money online.

How the fraud runs

The criminal gets into an email account, watches the thread until an invoice is due, then sends a near-identical message saying the bank details have changed. The customer pays, and the money is gone within hours.

It works on both sides. Your account can be the compromised one, or the customer’s can be, and the payment still ends up in the wrong place.

Who carries the loss

The customer has paid somebody, but not you, so they usually still owe the money. The argument that follows is commercial, slow and often ends in a discount you did not want to give.

For a painter and decorator chasing a £6,000 final account on a house refurbishment, that dispute can outlast the job by months.

What cover responds

Cyber policies increasingly include a social engineering or funds transfer fraud section, usually with its own lower sub-limit and a callback verification condition. Read the sub-limit before you assume the loss is covered.

The cheap defence costs nothing. Print your bank details on every invoice, state in writing that they will never change, and ask customers to phone a known number before paying anything different.


What must you do if customer data leaks?

If a breach risks people’s rights and freedoms you have to report it to the Information Commissioner’s Office within 72 hours of becoming aware. That clock starts at awareness, not at the point you finish investigating.

The 72-hour notification duty

The ICO expects a report within 72 hours where the breach poses a risk to individuals. If you miss the deadline you must explain the delay when you do report.

Where the risk to individuals is high, you also have to tell the affected customers directly and without undue delay. A lost phone full of client addresses can trigger both duties.

What a notifiable breach looks like for a trade

A stolen tablet with the customer database on it, an emailed quote list sent to the wrong address, or a ransomware attack that encrypts your job records all qualify. Losing a paper diary can count too.

An electrician holding EICR reports for a housing association is handling data about hundreds of tenants, not just their own customers.

Where insurance helps and where it cannot

Cyber cover pays for the forensic investigation, the legal advice on whether to notify, the notification itself and the calls that follow. That response cost is usually larger than the technical fix.

It cannot pay an ICO fine, because UK public policy does not allow regulatory penalties to be insured. Anyone promising otherwise is selling something they cannot deliver.


What does a cyber policy pay for, and what does it leave out?

A cyber policy is mostly an incident response service with a cheque attached. It pays for getting you working again and dealing with the fallout, not for upgrading your systems.

The sections that do the work

IT forensics, data restoration, business interruption while you cannot invoice, legal and ICO liaison, customer notification and third-party liability make up the core. Many policies bundle a 24-hour response line, which is the part most people actually use.

Funds transfer fraud, cyber extortion and reputational costs are usually add-on sections with separate limits. Ask for the sub-limits in writing rather than the headline figure.

The exclusions worth knowing about

Regulatory fines, physical hardware damage, loss of intellectual property and betterment sit outside almost every wording. Betterment means the insurer restores what you had, not a better system than you had before.

Most policies also carry a minimum standards condition covering patching, backups and multi-factor authentication. Fail those and cover can fall away when you need it.

Cyber cover pays for Cyber cover excludes
IT forensics and removing the attacker Fines and penalties imposed by a regulator
Restoring data and rebuilding systems Physical damage to laptops, phones or hardware
Lost income while you cannot trade Upgrading systems beyond their previous standard
Legal advice and ICO liaison Losses from failing to patch or back up as required
Customer notification and call handling Loss of intellectual property or trade secrets
Third-party claims from a data breach Ordinary bad debt and commercial disputes

Does your existing tradesman policy respond to a cyber loss?

No. Public liability, employers’ liability, tools and contract works are all written around physical injury and physical property, so a data loss falls outside every one of them.

Why liability sections do not reach it

Public liability answers for injury and damage to tangible property. Whether you need public liability is a separate question from whether you need cyber cover, and the answer to one says nothing about the other.

Some wordings borrow the phrase general liability from American policies, which adds to the confusion. UK trade policies do not cover data losses under any of those names.

Where professional indemnity overlaps

Professional indemnity can respond where a client suffers financial loss from your advice, and some wordings include a narrow confidentiality extension. It is not a substitute for cyber response costs.

The distinction matters if you design or specify as well as install. Professional indemnity compared with public liability sets out which claims land where.


How much does cyber cover cost and what reduces the premium?

Cyber sits at the cheap end of business insurance for a one-van trade, and the controls that cut the premium are the same ones that stop the attack.

What published figures suggest

ByteStart puts entry-level cyber premiums for the self-employed at £6 to £15 a month. No trade insurer publishes an official average, so treat any single figure as an illustration rather than a quote.

Insurance Premium Tax of 12% is already inside whatever you are quoted and cannot be reclaimed. Set against that, premiums bought wholly and exclusively for the business are an allowable expense against your profits.

For context on where this sits in a wider trade budget, how much tradesman insurance costs runs from decorators at the bottom of the range to scaffolders at the top.

The controls underwriters actually ask about

Multi-factor authentication on email, offline or separated backups, patched software and a documented process for verifying bank detail changes. Those four questions decide most small cyber quotes.

Cyber Essentials certification is the government-backed baseline and can open public sector work as well as improving terms. It costs less than most tradesmen assume.

Buying it without getting stung

Check the firm on the FCA Register before you buy, and ask whether the cyber section is a genuine standalone policy or a token extension bolted onto a package.

A £25,000 sub-limit with a response line beats a £250,000 headline with no incident team behind it. Ask who answers the phone at 7am on a Saturday.


Which tradesmen genuinely need cyber insurance?

If you invoice by email, hold customer records digitally or take card payments, the case is strong. If you take cash, keep a paper diary and run no software, it is weak.

The clear yes cases

Anyone with employees on email, anyone using cloud job management, anyone holding data for commercial or public sector clients, and anyone whose average invoice runs into four figures.

Working from a home office does not reduce the exposure either, because the risk follows the data rather than the building.

The honest no cases

A part-time sole trader taking cash on the day, with no stored customer list and no email invoicing, is buying cover for a risk they do not run. The money is better spent on liability limits.

Even then, spend an hour turning on multi-factor authentication and setting up a backup. The controls are free and they remove most of the exposure that cover would have paid for.

Frequently Asked Questions (FAQs)

Is cyber insurance a legal requirement for tradesmen?

No. UK GDPR requires you to protect personal data and report serious breaches, but it does not require you to insure against them.

How many small businesses actually get attacked?

The government’s Cyber Security Breaches Survey 2025/26 found 46% of small businesses and 42% of micro businesses identified a breach or attack in the previous 12 months.

If most breaches cost nothing, why buy cover?

Because the median hides the tail. The same survey puts the 95th percentile cost for micro and small businesses at around £4,000, and the disruption usually costs more than the repair.

Does my public liability policy cover a cyber attack?

No. Public liability responds to injury and damage to physical property, so data loss, ransomware and invoice fraud all sit outside it.

Who pays when a customer sends payment to a fraudster?

The customer has not discharged the debt, so they usually still owe you. Recovering it can take months, which is why a funds transfer fraud section is worth checking for.

Do I have to report a lost phone to the ICO?

If it held personal data and the loss poses a risk to those individuals, yes, within 72 hours of becoming aware. Encryption and remote wipe can reduce that risk.

Will cyber insurance pay an ICO fine?

No. Regulatory fines are not insurable in the UK, though the legal and response costs around the investigation usually are.

Does cyber insurance cover a ransom payment?

Some policies include extortion cover where payment is lawful, but many exclude it. The National Cyber Security Centre discourages paying, and restoration from backup is the better answer.