Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Cyber Insurance Explained

Directors and Officers Insurance: What D&O Cover Means for SMBs

By the Assured Cyber Protection team · Updated 2026 · Reviewed
Directors and Officers Insurance: What D&O Cover Means for SMBs

Directors and officers insurance protects the people running a company, personally, when someone claims they got a management decision wrong. It is not cover for the business itself in the way public liability or cyber insurance is. It sits behind the individual director or officer, paying to defend them and to settle claims that a wrongful act in their role caused a loss. Small and medium businesses often assume D&O is a big-company product, but the risk to a director’s own house and savings is arguably sharper in a small firm, where there is no in-house legal team and the same handful of people make every call.

This guide explains what directors and officers insurance covers, how the three layers of a policy work, the claims that actually hit SME directors, and why a cyber incident increasingly ends up as a D&O question too.

What directors and officers insurance actually covers

D&O insurance is a form of management liability cover. It responds when a director, officer or senior manager faces a claim for a “wrongful act” committed in that capacity: a breach of duty, negligence, a misleading statement, an error or omission, or a failure to comply with a regulation. Crucially, the claim is against the individual, and it is their personal assets that are exposed if there is no policy behind them.

What it pays for, in practice, is threefold: the legal costs of defending the director (often the largest and earliest expense), any damages or settlement awarded, and the day-to-day costs of responding to an investigation, such as attending interviews with a regulator or an insolvency practitioner. Because a defence can run for months before anyone decides whether the director did anything wrong, that funding of legal costs is the part directors value most.

It does not cover everything. Deliberate fraud or dishonesty, once proven, is excluded. Bodily injury and property damage belong to other policies. Fines and penalties are often uninsurable by law. And a director’s professional advice to clients is professional indemnity territory, not D&O. Knowing where the edges are matters, which is why we keep a separate explainer on indemnity insurance and how the products differ.

The three layers: Side A, B and C

A standard D&O policy is built in three parts, usually labelled Side A, Side B and Side C. They cover different situations, and understanding which is which tells you who the policy is really protecting.

  • Side A protects individual directors directly when the company cannot or will not indemnify them. This is the layer that matters most in the worst case: the company has become insolvent, or the law forbids it from covering the director, or it simply refuses. Side A stands between a claim and the director’s personal assets.
  • Side B reimburses the company when it has indemnified a director, so the business recovers those costs from the insurer rather than carrying them itself.
  • Side C, sometimes called entity cover, protects the company itself, most commonly for securities claims. For a private SME this layer is often narrower or less relevant than it is for a listed company.

For a small business owner-director, Side A is the part to check first, because it is the one that works precisely when the company can no longer help you.

The claims that hit SME directors

D&O feels abstract until you see what triggers a claim in a smaller company. The common ones are not exotic:

  • Insolvency and creditor actions. When a company fails, creditors, liquidators and insolvency practitioners scrutinise the directors’ conduct, and allegations of wrongful trading or breach of duty follow. This is the single most common route to a D&O claim for SMEs.
  • HMRC and regulatory disputes. Tax investigations and regulatory enquiries can name directors personally.
  • Health and safety breaches. A serious incident can lead to proceedings against the individuals responsible for the failure, not only the company.
  • Employment claims. Allegations of discrimination, wrongful dismissal or harassment are frequently brought against directors as well as the business.

In each case the director faces legal costs long before any finding of fault. That is the exposure D&O is designed to fund.

Where a cyber breach becomes a director’s problem

For a cyber-aware business, this is the connection worth understanding. A data breach or ransomware attack is a first-party and third-party loss that cyber insurance handles. But the same incident can generate a separate line of claims aimed at the directors personally: that they failed to oversee cyber risk properly, ignored known vulnerabilities, or misrepresented the company’s security posture to customers, investors or a regulator. Those are management-liability allegations, and they land on the D&O policy, not the cyber policy.

The two covers are complementary, not interchangeable. Cyber insurance pays to recover systems, notify the ICO, manage the incident and defend third-party data claims against the company. D&O responds if the fallout turns into an action against the directors for how they governed the risk. A business that has thought carefully about a breach should hold both, and understand which policy answers which claim. Our guide to what cyber insurance covers and excludes sets out that side of the line.

Do smaller companies really need it?

If a company has directors, and almost every limited company does, then those individuals carry personal liability for their decisions. The question is whether the business, or the directors, are willing to fund a legal defence out of their own resources. For most SMEs the honest answer is no, and D&O is comparatively affordable set against that exposure. It becomes close to essential when a company takes on external investment, has employees, operates in a regulated sector, or faces any real prospect of financial distress. The government’s guidance on directors’ duties under the Companies Act is a useful reminder of just how much personal responsibility the role carries.

Before you buy, read the policy the way you would any liability cover, checking the wrongful-act definition, the exclusions and how the layers are structured. Our walkthrough on how to read an insurance policy applies just as well to a D&O schedule.

Frequently asked questions

What does directors and officers insurance cover? It covers company directors, officers and senior managers personally against claims that a wrongful act in their role, such as a breach of duty, negligence or a misleading statement, caused a loss. It pays their legal defence costs, any damages, and the cost of responding to investigations.

What is the difference between Side A, B and C in a D&O policy? Side A protects individual directors directly when the company cannot indemnify them, for example after insolvency. Side B reimburses the company when it has covered a director. Side C protects the company itself, usually for securities claims.

Do small businesses need directors and officers insurance? If a company has directors, those people carry personal liability for their decisions. Most SMEs cannot fund a legal defence from their own pockets, so D&O is often worthwhile, and close to essential once a firm has employees, external investors or operates in a regulated sector.

Does D&O insurance cover a cyber breach? Not the breach itself, which is a job for cyber insurance. But if a breach leads to claims against directors personally for failing to manage cyber risk, those management-liability allegations fall to the D&O policy. The two covers work alongside each other.

What does directors and officers insurance not cover? Proven fraud or dishonesty, bodily injury and property damage, most fines and penalties, and a director’s professional advice to clients, which belongs to professional indemnity insurance instead.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.