You may treat Stripe, PayPal, Square, or another payment gateway as proof that payment cyber losses sit elsewhere. That assumption can leave a UK SME paying for fraud, lost sales, customer messages, or recovery help. Your provider may have strong security. Its contract may still limit what it repays.
Third-party processors: should you insure when using payment gateways? Yes. A payment gateway does not remove your cyber risk. The provider may protect its platform, but your business can still face fraud, card-data exposure, lost sales, and recovery costs. The right cover depends on your contract, controls, and reliance on the gateway. Map what the merchant, gateway, acquirer, bank, and insurer may each pay.
A gateway reduces card scope, not your cyber risk
A payment gateway can reduce the card data reaching your systems. It does not pass every cyber, fraud, or UK GDPR duty to the provider.
The most common mistake is assuming tokenisation removes all exposure. Tokenisation replaces a card number with a unique reference. It is like getting a cloakroom ticket instead of handing over your coat. It helps protect card data. A criminal who steals your gateway login may still issue refunds or alter payment settings.
They may also view customer details.
What still belongs to the merchant?
Your business remains responsible for people and systems under its control. This usually includes staff access, website plug-ins, API keys, webhooks, passwords, customer messages, and payment integration accuracy.
A provider agreement often limits compensation to service credits. A service credit is a small discount on a future bill. It is not payment for a lost trading day, damaged reputation, or staff overtime.
Hosted payments reduce card-data risk, not all business risk.
A sensible starting view: Hosted payments reduce card-data risk. They do not protect your email accounts, gateway credentials, customer database, website code, or income during every supplier outage.
Who pays after a gateway incident?
The merchant often pays the first bill after a payment incident. This can happen even when another party caused the original fault.
A merchant acquirer is the financial firm that lets a business accept card payments. Visa and Mastercard rules usually pass through the acquirer. They do not usually pass straight from the card scheme to the merchant. This route can lead to fees, reserves, or PCI DSS assessments. That can happen even when the merchant never stored a full card number.
Financial Conduct Authority rules under the Payment Services Regulations 2017 govern parts of payment services. They do not make an FCA-regulated PSP liable for all lost profit or contract costs.
Cost map for common payment incidents
| Incident | Likely immediate cost | Who may carry it first | Cover to check |
| Gateway platform breach | Customer queries, legal review, notices | PSP and merchant | Cyber response and privacy liability |
| Stolen API key | Fraudulent refunds or altered payouts | Merchant | Cyber crime and social engineering |
| Card testing | Fees, failed-payment traffic, disputes | Merchant and acquirer | Fraud cover, subject to wording |
| Chargebacks | Refunded sale, fee and stock loss | Merchant | Usually not standard cyber cover |
| PSP outage | Lost online revenue | Merchant | Contingent business interruption |
| Card-data exposure | Forensics, notices, PCI costs | Depends on contract and cause | Cyber liability and PCI extensions |
Chargeback alerts, 3-D Secure, and fraud scoring can reduce disputes. They are useful controls. They do not usually repay every fake order, fraudulent refund, or business interruption loss.
Cyber insurance may pay for forensic work, breach notices, and some third-party claims. Crime or fidelity insurance is a different policy type. It may cover theft by employees or some dishonest acts. Each policy has its own trigger, exclusions, and excess.
The party with the best security may not absorb the merchant's loss.
The party with the best security is not always the party that absorbs the merchant's loss. Contract wording and insurance wording decide that question.
Your access, data and downtime set the risk
Your real exposure comes from your access, your data, and your trading downtime without the PSP.
Secure dashboards and API keys
An API key is a digital pass that lets software speak to your PSP account. Treat it like a warehouse master key. It is not an ordinary password for a shared spreadsheet.
Use multi-factor authentication, or MFA, on all PSP administrator accounts. MFA asks for a second proof, such as an app code. A stolen password then becomes less useful. Limit refund and payout rights. Remove former staff quickly and keep logs of setting changes.
The Payment Card Industry Security Standards Council publishes PCI DSS rules and guidance at PCI SSC. Compliance shows good practice. It does not guarantee claim payment or prevent every breach.
Plan for the payment service to fail
Test the plan instead of just writing it down. Ask whether staff can explain an outage to customers. Ask whether they can record unpaid orders safely. They must not take card details by email or in a spreadsheet.
A payment gateway can reduce card-data risk but cannot remove all cyber insurance needs. Cover remains relevant when stolen access, a compromised plug-in, or supplier downtime can stop sales. This changes for firms with no remote payments and no meaningful loss from an outage. For most online UK SMEs, check fraud, breach response, and supplier-outage cover as separate items.
Where payment risk remains after outsourcing
Merchant controls
Staff access, website, API keys, customer messages
PSP controls
Gateway platform, token vault, processing systems
Insurance question
Which costs remain if either side fails?
Check fraud, breach response, and supplier-outage wording separately. One policy called cyber insurance does not guarantee all three.
Ransomware and malware can cause a payment incident without breaching the gateway. An infected ecommerce plug-in may alter checkout scripts. It may steal a token or API credential. It may stop your order system from sending successful-payment confirmations.
A software supply-chain attack can have a similar effect. It may affect a shopping-cart extension, tag manager, or integration provider. It can hit many merchants at once.
Your own website can still become the weak point.
Cyber insurance for payment-gateway risks should sit alongside cover for your website, endpoints, and key technology suppliers. Keep plug-ins patched and restrict script changes. Watch for unusual checkout behaviour. Keep tested backups and manual-order plans.
Gateway contracts decide your recovery rights
The provider agreement, data processing agreement, and service level agreement may decide your recovery. They can matter more than the gateway's marketing page.
Compare the cap with your highest-value trading period. Do not compare it with an average quiet week. A retailer processing between £20,000 and £80,000 during a busy weekend may get little value from a modest service credit.
The ICO explains UK data duties and breach expectations at the Information Commissioner's Office. Under the Data Protection Act 2018 and UK GDPR, your contract should set notice duties. It should also set evidence-sharing times and customer request handling.
Review the DPA and SLA
A data processing agreement, or DPA, sets rules for a processor handling personal data. The controller is the business that decides why and how that data is used. Check whether the DPA names sub-processors. Check overseas transfers and fast incident-notice duties.
An SLA is the provider's written service promise. Check uptime terms, support hours, planned maintenance, outage notices, and service-credit limits. A stated uptime figure does not promise payment for lost income.
Check limits before buying cover
Look for waiting periods between 6 and 24 hours before business interruption cover starts. Also check whether the policy needs physical damage. That requirement rarely fits a cyber-only outage. Check whether it covers a third-party PSP only after a qualifying cyber attack.
The error most firms make is reading the insurer's summary before the supplier contract. A £50 service credit cannot fund a weekend of missed sales. Nor can it pay staff, customer support, or expert help after a breach. Read both documents together before relying on either one.
Match payment losses to the right policy
Cyber insurance helps when it covers costs after a cyber attack, data breach, or qualifying supplier outage. It is not a catch-all policy for payment losses.
Cyber liability insurance often includes incident response, forensic work, legal advice, notice costs, and third-party claims. First-party losses are your own costs. These may include system repair or lost income. Third-party liability means claims against you by customers or others.
Professional indemnity insurance usually covers mistakes in professional services. It may help a consultant facing a negligence claim. Do not assume it pays after a stolen PSP login or gateway outage.
Check social engineering and PCI costs
Social engineering is fraud that tricks someone into approving an action. A fake email may appear to come from a director. It may ask finance staff to change bank details.
Many policies limit this cover with a low sub-limit. They may require call-back checks. They may exclude losses where an employee made the payment willingly. Check whether fraudulent refunds, invoice fraud, and authorised push payment fraud have different treatment.
PCI DSS assessments, card-scheme fees, and revalidation costs may also be limited or excluded. Read the policy wording before relying on cover for fines. Some regulatory fines may not be insurable under the law.
Use a simple insurance decision test
A business with low transaction volume may need lower limits. This can apply if it stores no payment data and has a workable offline route. A firm relying on one PSP may need more cover. Ask whether a realistic incident could exceed your cash reserves.
Use this short review with your broker and payment provider:
- Transactions: Record average and peak-day card revenue. Also record the largest refund you could approve.
- Dependency: Identify whether one PSP, acquirer, or cloud service can stop all online sales.
- Data: Confirm whether you store card data, tokens, customer contact data, or API keys.
- Controls: Test MFA, role-based access, key rotation, software updates, and payment logs.
- Contract: Compare the liability cap, DPA, SLA, notice period, and audit rights with likely losses.
- Policy: Get written confirmation of supplier outage, fraud, social engineering, PCI, and business interruption terms.
The practical choice is to insure where gateway failure, stolen access, or data exposure could materially harm the business. Then match the policy to the gateway contract and your controls. Buying cover without reading fraud and supplier-failure terms is like fitting an alarm while leaving the back door unlocked.
The policy must match the loss you actually face.
This issue matters less if you take no online or remote payments. It also matters less if you have no payment-provider accounts or integrations. It may not matter if a third-party payment service failure causes no meaningful loss. This guidance cannot replace legal, insurance-broking, or PCI DSS advice after an incident. Seek specialist advice where a contract creates material duties.
Common questions
Does cyber insurance cover third-party payment processors?
It can cover third-party provider failure if the policy includes contingent business interruption. This is not automatic. Check whether the PSP must suffer a cyber attack. Check whether a waiting period between 6 and 24 hours applies.
Does PCI DSS compliance guarantee an insurance claim?
No, PCI DSS compliance does not guarantee claim payment. Insurers may assess the incident cause, exclusions, declared security controls, and PCI-related sub-limits.
Who is liable if a payment gateway is breached?
Liability depends on the cause, merchant agreement, DPA, and each party's UK GDPR role. The gateway may be liable for its platform. The merchant may still face customer messages, regulator contact, and lost revenue.
Are chargebacks covered by cyber insurance?
Usually not as standard cover. Chargebacks follow card-payment dispute rules and are not always cyber losses. Some fraud extensions may help in limited cases. Check the policy wording and acquirer's fee schedule.
Can a gateway outage be insured?
Yes, if business interruption wording covers non-physical cyber events and third-party supplier failure. A policy needing physical damage will not usually pay. A 12-hour waiting period may also prevent payment for a shorter outage.
Do small UK businesses need cyber insurance if they use a gateway?
Many do if a hacked dashboard, phishing email, or provider outage could cause material loss. A hosted checkout reduces card-data exposure. It does not protect your business from every fraud, privacy, or trading-interruption cost.