For UK small business owners, banking and insurance are no longer background administration. They are central to cashflow, fraud resilience, borrowing capacity and the ability to recover when something goes wrong. The most important developments in 2026 are practical rather than flashy: higher protection for eligible business deposits, a more competitive but selective lending market, established reimbursement rules for certain payment scams, and a sharper focus on cyber resilience and insurance adequacy.
The key message is simple: do not assume that a familiar bank account, annual insurance renewal or existing cyber policy still fits your business. Review where cash is held, how payments are authorised, what borrowing is available, and exactly what would happen if a major supplier, employee device or cloud system failed. Here is what SMEHype readers should prioritise now.
1. Business cash deposits have more protection — but check the banking licence
Since 1 December 2025, Financial Services Compensation Scheme protection for deposits held with a UK-authorised bank, building society or credit union has risen to £120,000 per eligible person or company, per authorised firm. This is relevant to incorporated businesses as well as individuals. If an eligible institution fails, the limit applies to the total held under that banking licence, not to every brand or account in a banking group. The FSCS also makes clear that accounts held with brands sharing a licence are combined when compensation is calculated. Read the FSCS guidance on the £120,000 limit.
For a small company with a payroll reserve, VAT funds and a working-capital buffer, this increase is useful. But it is not a reason to stop managing concentration risk. A business keeping £250,000 with two accounts that ultimately sit under the same authorised firm could still have only £120,000 of FSCS protection. The protection is also not a substitute for due diligence on whether money is held as a deposit at all. E-money accounts and payment institutions can safeguard customer funds, but that is different from FSCS deposit protection.
What to do this month
- Map every cash holding: current accounts, notice accounts, savings accounts, payment platforms and foreign-currency balances.
- Check the authorised firm: do not rely on the trading brand. Use the FSCS protection checker and your provider’s regulatory disclosures.
- Set a cash policy: decide the maximum operational balance to retain with one banking licence and when excess funds should be moved.
- Separate operating and reserve cash: this improves both resilience and day-to-day visibility of how much cash is genuinely available.
This is especially important for firms with lumpy cashflows. A construction business awaiting a milestone payment, an agency holding client funds, or a retailer accumulating cash ahead of seasonal stock purchases should know in advance where a temporary surplus will sit and what protection applies.
2. SME borrowing is available, but lenders are becoming more discerning
The lending picture is mixed. The Bank of England reported that annual SME borrowing growth reached 3.9% in May 2026, while the effective interest rate on new SME loans was 6.18%. Its July Financial Stability Report also said that credit availability had slightly decreased for small and medium-sized businesses in the second quarter, even as lenders continued to compete for stronger borrowers. See the Bank’s May 2026 money and credit data and its July 2026 Financial Stability Report.
In practical terms, this means a viable SME should not assume that the first renewal offer is the best one, but neither should it expect funding to be effortless. Lenders are likely to focus on debt-service capacity, recurring revenue, customer concentration, sector exposure, quality of management information and the purpose of the borrowing. A business seeking finance for a clearly costed equipment purchase, contracted order book or proven working-capital cycle will generally present a stronger case than one trying to cover an unexplained cash shortfall.
There are signs that the challenger-bank ecosystem may continue to widen choices for established businesses. In February, the PRA and FCA named Allica Bank, ClearBank, Monument Bank, Nottingham Building Society, OakNorth Bank and Zopa Bank as the first cohort in their joint Scale-up Unit. The initiative is intended to give growing financial firms more tailored regulatory support as they expand. It is not a lending guarantee, but it may support greater product choice and capacity over time. Read the regulators’ Scale-up Unit announcement.
How to make your next finance application stronger
Prepare before the need becomes urgent. Keep monthly management accounts current, reconcile debtor and creditor ledgers, and maintain a rolling 13-week cashflow forecast. Explain the funding need in one sentence: for example, “£80,000 revolving facility to bridge a 45-day gap between supplier payment and contracted customer receipts.” Then show the evidence behind it.
Compare total cost, not merely the stated rate. Arrangement fees, personal guarantees, security requirements, repayment profile, early-settlement terms and covenants can matter more than a marginal difference in interest. For asset finance, compare whether ownership, maintenance obligations and tax treatment suit the business. For invoice finance, investigate customer-notification rules, concentration limits and the service level around collections.
3. APP scam reimbursement is a major safeguard for micro-businesses — not for every SME
Authorised push payment, or APP, fraud occurs when a criminal manipulates someone into making a bank transfer themselves. Common business examples include a spoofed email changing a supplier’s bank details, an impersonation call apparently from the bank, or a fake invoice that looks like it came from a regular contractor.
The Payment Systems Regulator’s mandatory reimbursement regime has applied to eligible Faster Payments and CHAPS APP scams since 7 October 2024. It covers individuals, charities and microenterprises; it does not automatically cover all SMEs. A microenterprise generally has fewer than 10 employees and annual turnover or balance-sheet total not exceeding €2 million. The current maximum reimbursement level is £85,000, firms normally aim to reimburse within five business days, and a final outcome must generally be reached within 35 business days. There can be an excess of up to £100, although it cannot be applied to vulnerable customers. Check the PSR’s APP fraud reimbursement protections.
The latest PSR dashboard, covering claims closed from 1 April 2025 to 31 March 2026, is a reminder that these rules are now an operational reality, not a future proposal. Yet reimbursement should be treated as a last line of defence. It does not apply to every payment type, every loss or every business. It also does not turn a commercial dispute into fraud: paying a genuine supplier for poor or undelivered work is not necessarily an APP scam. Review the PSR’s current APP scam data and scope notes.
Build a payment-control system that does not rely on one person
- Require a call-back to a trusted, independently sourced telephone number for every change to supplier bank details.
- Use dual approval for high-value or first-time payments, with separate staff initiating and authorising where possible.
- Create payment limits by role and use bank alerts for new beneficiaries, unusual payees and large transfers.
- Keep a supplier master file and prohibit changes made solely from an emailed request.
- Train staff to treat urgency, confidentiality and requests to bypass normal controls as warning signs.
If fraud is suspected, contact the bank immediately using a known number, preserve emails and payment records, report the incident, and notify any affected insurer or broker in line with policy conditions. Speed can affect the chance of freezing or recovering funds.
4. Insurance rules are being simplified, but smaller commercial customers retain important protections
In late 2025, the FCA finalised changes designed to simplify insurance rules, including clearer distinctions between smaller commercial customers and larger commercial customers. The regulator’s stated intention is to retain appropriate protection for smaller businesses while reducing unnecessary regulatory burden for larger commercial buyers. The FCA’s insurance rulebook was updated in this area from December 2025, and it continues to review definitions during 2026. Read FCA policy statement PS25/21 and see the current ICOBS client categorisation rules.
For most small firms, the immediate point is not to become an insurance-law expert. It is to recognise that size, group structure and the type of policy can affect the protections and disclosures that apply. Ask your broker to confirm whether your firm is treated as a commercial customer or a larger commercial customer for the policy being arranged, and ask what this means in practice.
SMEs also retain a useful right when dealing with brokers: commercial customers can ask for information about the commission the broker earns. The FCA’s SME guidance makes this explicit. If you are uncertain whether a recommendation is driven by cover quality, insurer appetite or remuneration, request the information before committing. Read the FCA’s guidance for SMEs using insurance brokers.
5. Underinsurance remains the most avoidable insurance problem
The biggest insurance development for many SMEs is not a new product or rule; it is the growing recognition that existing cover may be inadequate. The Association of British Insurers launched an SME insurance guide in January 2026 after research indicated widespread gaps in protection and infrequent policy reviews. Its findings included low take-up of business interruption, commercial contents and cyber cover among businesses facing the relevant exposures. Read the ABI’s SME insurance guide announcement.
Underinsurance is often created by business growth. A manufacturer adds machinery but leaves the declared replacement value unchanged. A consultant starts handling client data but does not revisit professional indemnity or cyber cover. A retailer moves to a larger unit, holds more stock and assumes the old business-interruption limit will stretch far enough. A trades business buys more vehicles or hires staff without checking motor, employers’ liability and tool cover.
Questions to ask at renewal
- Would declared building, contents, stock and equipment values cover a full replacement at today’s prices?
- Is the business-interruption indemnity period long enough to rebuild, replace equipment, regain customers and restore revenue?
- Have turnover, payroll, headcount, premises, products, territories or contractual obligations changed?
- Do client contracts require specific professional indemnity, cyber, public liability or product liability limits?
- Are exclusions for cyber events, unattended tools, theft, flood, subcontractors or contractual liability understood?
Do not simply ask, “What is the cheapest renewal?” Ask, “What is the realistic worst-case event this policy is intended to fund, and what remains uninsured?” Document the answers. This will improve the renewal conversation and help if a claim is later scrutinised.
6. Cyber insurance is becoming a resilience tool, not a replacement for security
Cyber risk now joins property damage, liability and interruption as a core business-continuity issue. The government’s 2025/26 Cyber Security Breaches Survey found that 47% of businesses reported having some form of cyber insurance. Among small businesses, 55% reported some cyber cover, although many policies were part of a broader package rather than standalone cyber insurance. Crucially, 22% of businesses did not know whether they had cyber insurance at all. Read the government’s 2025/26 cyber breaches survey.
That uncertainty is dangerous. General business insurance may provide limited cyber-related cover, but it may also contain exclusions that leave an SME exposed to ransomware, data restoration costs, digital business interruption, fraud, incident response, legal advice or regulatory issues. The National Cyber Security Centre recommends checking existing policy documentation and discussing coverage with the insurer or broker rather than assuming protection exists. It also stresses that insurance does not prevent an attack. Read NCSC cyber insurance guidance.
The direction of travel is clear. The government launched a cyber-resilience campaign for businesses in February 2026 and is continuing work on a Cyber Security and Resilience Bill. Meanwhile, proposed ransomware measures would require businesses outside a targeted public-sector and critical-infrastructure payment ban to notify the government of an intention to pay a ransom if the policy is implemented. These proposals are not yet a general legal obligation for ordinary SMEs, but they are a reason to establish an incident plan now. See the government’s 2026 cyber campaign and read the ransomware policy response.
Match cyber cover to your real exposure
Request a clear schedule from your broker covering incident-response providers, ransomware and extortion conditions, data restoration, business interruption, social engineering or funds-transfer fraud, third-party liability, notification costs and exclusions. Ask whether insurer consent is required before appointing IT forensic specialists, lawyers or public-relations advisers. In a fast-moving incident, knowing whom to call first matters as much as the headline policy limit.
At the same time, strengthen the basics insurers and customers increasingly expect: multi-factor authentication, prompt software patching, tested backups separated from the main network, restricted administrator access, staff phishing awareness and a rehearsed recovery process. The NCSC provides free tools and guidance specifically for organisations with up to 250 employees. Use the NCSC’s small and medium-sized organisation guidance.
7. If an insurer or broker gets it wrong, use the complaints route promptly
Small businesses can complain to the Financial Ombudsman Service about business protection insurance issues, including declined claims, delays, inadequate settlements and alleged mis-selling. The usual first step is to make a formal complaint to the insurer or broker. If it does not issue a final response within eight weeks, or if its final response is unsatisfactory, an eligible business can take the case to the Ombudsman. Read the Ombudsman’s business protection insurance guidance.
Eligibility is size-sensitive. The Ombudsman can generally consider complaints from micro-enterprises and, for relevant events after 1 April 2019, small businesses with annual turnover below £6.5 million that meet the relevant employee or balance-sheet criteria. Preserve the proposal form, schedule, policy wording, renewal communications, claim timeline, invoices, photographs and emails from the start. A well-organised file is useful whether the claim is resolved directly or escalated.
Conclusion: turn developments into a quarterly resilience routine
The best response to 2026’s banking and insurance changes is disciplined housekeeping. Each quarter, reconcile cash holdings against FSCS protection, test payment controls, refresh the cashflow forecast, compare borrowing options before renewal, and review insurance values and exclusions after any business change. Then run one cyber tabletop exercise: who calls the bank, insurer, IT provider, customers and advisers if systems or funds are compromised?
Take action before an incident forces the issue. A short conversation with your accountant, broker, bank relationship manager and IT support provider can expose gaps that are inexpensive to close today but potentially business-threatening tomorrow.





















