< Back to all clusters
[BUSINESS] · Australia, Ireland, Kenya, United States, United Kingdom · 7 sources

Small businesses face growing cyber‑insurance and backup challenges

Cyber insurers are increasingly demanding proof of immutable, air‑gapped backups from small and mid‑size firms. An immutable backup cannot be altered or deleted for a set period, a safeguard that many businesses lack despite ticking the box on insurance forms. Common weak points include network‑attached storage that can be wiped by ransomware, reliance on Microsoft 365 retention features that a compromised admin can delete, and cloud backup services where immutability is not enabled by default.

A 2025/26 UK cyber‑security survey found 43 % of businesses and 46 % of small firms experienced a breach in the past year. As a result, cyber spending now sits alongside rent and payroll, covering secure email, backup testing, fraud training and external provider fees. About 55 % of small firms hold some cyber‑insurance, yet only 15 % have a dedicated cyber policy, and insurers often raise premiums or limit coverage when backup and control questions are answered poorly.

Research from Australia’s auDA shows that 38 % of small businesses believe they are too small to be targeted, while 92 % store personal or sensitive data. Confidence is low: just 26 % feel they can protect that data and only around half know how to report a breach. Similar patterns appear in Kenya, where the national computer‑incident response team recorded 3.37 billion cyber‑threat events in Q1 2026, illustrating how automated attacks scan for vulnerable, poorly defended organisations.

For managed service providers, the market now ranks insurers such as Chubb, AXA XL, Beazley, AIG, The Hartford and Hiscox based on coverage depth and claims support. Experts advise buyers to assess insurers on claims‑team size, settlement authority, integration of threat intelligence and the ability to turn claim data into proactive risk improvements.