Hiscox vs Bateman/Travelers: the incident-led comparison
Hiscox and Bateman Group-arranged Travelers both describe incident-response, recovery and liability features. Bateman, an FCA-authorised broker, advertises cover of up to £10 million with specialist breach advisers and optional social-engineering cover; Hiscox publishes no limit on its page.[7][8] Compare each quotation, schedule, endorsements and full policy wording before choosing.

Hiscox UK
- Incident-response support: Hiscox reports cover for cybercrime investigation, data recovery, system restoration and reputation management.[7] The supplied information does not confirm an around-the-clock activation route, response-time commitment, named forensic or legal panel, freedom to appoint advisers, or prior-consent rules.[7]
- First- and third-party losses: Vendor-reported features include data recovery, system restoration, affected-party notification, hacker-extortion payments, third-party damages and settlements, legal defence, and some regulatory or privacy investigations.[7] Exact limits, excesses and business-interruption terms are not supplied.[7]
- Fraud and social engineering: The page mentions cybercrime investigation and hacker extortion, but does not confirm cover for business email compromise, funds-transfer fraud or social-engineering losses.[7]
Bateman Group-arranged Travelers
- Incident-response support: Bateman reports access to specialist advisers, including Pinsent Masons breach coaches, plus a nominated contact, in-house support and claims handling.[8] Its published material does not confirm activation times, adviser availability, provider-consent rules or the consequences of appointing an unapproved firm.[8]
- First- and third-party losses: Bateman reports first-party cover for notification, public relations, data restoration, extortion, system damage, business interruption and certain incidents involving IT or outsourced suppliers.[8] Advertised third-party features include privacy and security liability, media liability, regulatory proceedings and payment-card expenses.[8] Bateman says cover is available up to £10 million across breach response, cyber-crime, business loss and cyber liability, and includes fines and penalties where insurable by law.[8] Sublimits, waiting periods and exclusions are not published.[8]
- Fraud and social engineering: Bateman advertises computer, funds-transfer and telecommunications fraud, with social-engineering cover described as optional.[8] The NCSC warns that business email compromise may be excluded and that only certain policies cover computer-enabled fraud, so the wording and sublimits must be checked.[1][8]
Price, contract and fit
- Hiscox: Pricing is quote-only and reportedly depends on annual revenue, industry, data held and network security. No specimen premium, excess, tax or payment schedule is supplied.[7] Hiscox says businesses using, sending or storing electronic data may benefit, but binding acceptance criteria are unavailable.[7]
- Bateman/Travelers: Pricing is enquiry-only. Bateman says most packages can be paid monthly, but does not provide premiums, instalment charges, excesses, tax or minimum premiums.[8] Eligibility rules for size, turnover, sector, domicile, controls and claims history are not supplied.[8]
- Contract terms: Bateman says its cover is written on a retroactive basis and that Advanced Persistent Threat cover may be extended to an earlier date; ask for the default retroactive date and extension conditions.[8] Request renewal and cancellation terms from both providers.[7][8]
Test the incident-response service before buying
Cyber insurance may reduce disruption, provide financial protection and assist with legal or regulatory action, but it does not prevent attacks or immediately correct security weaknesses.[1] Insurer services may include IT forensics, legal advice, public-relations support, security consultancy and referral to an internal or external Cyber Incident Response organisation.[1]
Ask each insurer or broker:
- Which telephone number or online route activates the response?
- When is it staffed, and are response times promised?
- Which forensic, legal, communications and recovery firms are approved?
- Is prior approval required for advisers, restoration work, notifications, ransom negotiations or other expenditure?
- How is an urgent incident escalated?
- Which response decisions remain the policyholder’s responsibility?
The Hiscox and Bateman pages do not supply policy-specific hotline terms, service standards, provider panels or consent clauses.[7][8] Do not assume costs incurred through an organisation’s usual IT or legal provider will be reimbursed. Obtain the activation and approval rules in writing, then record the contact route and authorised internal callers in the incident-response plan.
Scrutinise the wording that could decide a claim
A brochure’s use of terms such as fraud or extortion does not establish how the policy defines those events. Compare the insuring clauses, definitions, exclusions, conditions and endorsements against realistic incidents.[1][7][8]
Treat business email compromise as a separate risk
The NCSC warns that some policies exclude business email compromise and that only certain policies cover computer-enabled fraud, so ask for written confirmation of whether money lost this way is covered.[1]
Bateman advertises computer and funds-transfer fraud but describes social-engineering cover as optional.[8] Its page does not supply the definitions, exclusions or sublimits needed to establish whether these categories cover a particular payment-diversion loss.[8] The Hiscox page does not confirm cover for these categories.[7] Give each provider the same payment-diversion scenario and ask it to identify the applicable clause, exclusions and sublimit.
Check outsourced services, extortion and developing threats
Confirm how an outage or compromise at a cloud service, outsourced IT provider or other supplier would trigger cover. Bateman mentions incidents involving unspecified IT or outsourced suppliers, but does not publish the operative definitions or dependency limits.[8] The NCSC also recommends checking whether the policy addresses attack types not contemplated when cover began.[1]
Both vendors mention extortion-related protection; ask each for the insurer-consent requirements, sanctions conditions and sublimits that apply to ransom payments.[7][8] Bateman lists fines and penalties “if insurable by law”, so whether a particular regulatory fine would be paid depends on the law as well as the wording; ask a solicitor if this matters to you.[8] Also request the war and state-backed-attack clauses, territorial scope and minimum security conditions.[1]
Make every security declaration provable
Applications may require details of technical, procedural and human controls, with input from internal teams and outsourced providers.[1] The NCSC cautions that an insurer may not have to pay if security measures claimed during the application were not in place.[1] Keep dated evidence supporting each answer and correct inaccuracies before inception or renewal.
Check existing insurance before buying standalone cover
Existing property or business-interruption policies may provide some cyber protection or expressly exclude cyber incidents. The NCSC recommends checking the documents and asking the insurer or broker to confirm the position.[1]
Read the schedule, endorsements and full wording together, checking:
- the insuring clauses and definitions;
- cyber exclusions and business-interruption triggers;
- provisions for restoring data and systems; and
- sublimits, excesses, waiting periods and endorsements.
Also disclose any Cyber Essentials or Cyber Essentials Plus certification when requesting quotations. The NCSC says certification may qualify an organisation for insurer discounts, although it provides no discount amount.[1] Some organisations obtaining Cyber Essentials receive cyber-liability insurance through the IASME Consortium, but the NCSC warns that this will not suit every organisation.[1]
Set a limit from interruption and recovery scenarios
Choose a limit by estimating the cost of serious incidents rather than accepting a package limit or unsupported rule of thumb. The NCSC recommends identifying critical assets, unacceptable scenarios, operational dependencies and the financial effects of interruption, response and recovery.[1]
For each material scenario, record:
- Critical system or data: what must remain available or confidential.
- Business process: the operations or revenue activity it supports.
- Dependencies: relevant internal teams and external cloud, IT, payment or communications providers.
- Incident: the outage, compromise or misuse being assessed.
- Tolerance: the point at which disruption becomes unacceptable.
- Recovery: the work needed to investigate, contain and restore operations.
- Estimated loss: forensic, legal, notification, public-relations, restoration, additional operating and interruption costs, plus possible third-party claims.
Useful scenarios include:
- Core systems becoming unavailable and disrupting critical processes.
- Customer data being compromised, creating response costs and potential third-party liabilities.
- A fraudulent payment following account takeover or business email compromise.
The NCSC recommends considering first-party recovery, third-party compensation claims and liability arising from personal-data loss.[1] For each scenario, compare the estimated exposure with the proposed aggregate limit, relevant sublimits, excess and waiting period.
Bateman’s advertised maximum is £10 million; Hiscox does not publish a limit, and neither publishes sublimits, excesses or waiting periods.[7][8] An advertised maximum is not a recommendation, so set the limit from your own scenarios. Separate or appropriately designed cloud backups may reduce ransomware impact, but insurance does not replace security and resilience measures.[1]
Complete a like-for-like quotation comparison
Use the documented scenarios to complete each proposal, drawing on contractual or legal, IT or security, and process or HR expertise. Where technical expertise is unavailable internally, the NCSC suggests an NCSC-assured cyber-security consultancy; smaller organisations may seek broker guidance.[1]
Request the following from both providers:
- the quotation and premium breakdown;
- the policy schedule and full wording;
- every endorsement and exclusion;
- aggregate limits, sublimits, excesses and waiting periods;
- incident-notification and provider-consent rules;
- minimum security conditions and underwriting assumptions;
- territorial and retroactive cover;
- renewal and cancellation terms; and
- the incident-response contact route and any service commitments.
Choose according to how the written terms match the organisation’s incident scenarios and required response model. Neither provider page offers independent claims or response-time data, so rely on the wording rather than marketing claims.[7][8]
If a claim or sale is disputed
Complain to the insurer or broker first. The Financial Ombudsman Service operates an independent dispute-resolution scheme as an alternative to the civil courts, deciding on what is fair and reasonable in the circumstances.[4]
- Who can use it: Eligible complainants include micro-enterprises, small businesses and smaller charities and trusts, with size assessed when the complaint is referred to the firm.[5]
- Insurance link: Eligibility covers a person for whose benefit an insurance contract was taken out with or through the firm, so brokers as well as insurers can be the subject of a complaint.[5]
- Timing: The ombudsman can usually consider a complaint once the firm has issued its final response or eight weeks have passed, and it must generally be referred within six months of the final response.[5]
Larger businesses outside these categories may need to rely on the policy’s dispute clause or legal action; speak to a solicitor in that case.
References
- Cyber insurance guidance | National Cyber Security Centre (ncsc.gov.uk)
- FCA and Financial Ombudsman Service MoU – July 2025 (fca.org.uk)
- FCA Handbook – DISP 2 Jurisdiction of the Financial Ombudsman Service (fca.org.uk)
- What is cyber insurance? | Hiscox UK (hiscox.co.uk)
- Cyber Insurance | The Bateman Group (bateman-group.co.uk)