How to Claim on the Free Cyber Essentials Insurance Policy
Published 25 June 2026
Step 1 – Find your policy documents
After certification, IASME emails policy documents directly. Save them alongside your certificate. The schedule contains the policy number and the 24/7 incident helpline number – you will need both to open a claim.
Step 2 – Call the helpline first, not your IT supplier
The most common mistake is asking your MSP to "have a look" before notifying the insurer. Doing so can compromise evidence and breach the policy's notification clause. Call the helpline first – they will instruct your IT supplier on what to preserve.
Step 3 – Preserve evidence
- Do not wipe or reimage affected devices until told to
- Do not delete suspicious emails – move to a quarantine folder
- Capture screenshots of any ransom notes or attacker messages
- Note the time you discovered the incident and what you did next
Step 4 – Cooperate with the appointed response team
The insurer typically appoints a forensic and legal team within hours. They lead the response – containment, investigation, regulator notification and recovery. Their costs come out of the £25,000 limit, which is why early notification matters.
Step 5 – Notify the ICO if personal data is affected
Under UK GDPR, notifiable personal data breaches must be reported to the ICO within 72 hours. The appointed legal team will advise, but the duty sits with you as data controller.
What can void cover
- Late notification (after the policy's notification window)
- Unauthorised remediation that destroys evidence
- Paying an extortion demand without insurer consent
- Letting your Cyber Essentials certificate lapse
If £25,000 is not enough
The free cover is a baseline. If a meaningful claim exceeds the limit, you bear the rest. See our comparison of free vs standalone cyber insurance to decide whether to top up.
