Is the possibility of a data breach or ransomware attack keeping owners of B&Bs and small hotels awake at night? For many small hospitality businesses the core worries are simple: lost bookings, GDPR fines, payment fraud and reputational damage, and uncertainty about whether standard business insurance covers those threats.
This guide explains, in clear UK terms, what cyber insurance for B&Bs and small hotels usually covers, how cover should vary by business size, how GDPR and breach reporting affect liabilities, how to choose sensible sums insured and excesses, and practical incident-response steps if a ransomware event or breach occurs.
Key takeaways: what to know in one minute
- B&Bs and small hotels face real cyber risks from booking systems, card terminals and guest data; a cyber policy can pay for notification, legal costs and business interruption.
- Cover needs depend on size and systems: micro B&Bs often require simpler cover; small hotels typically need broader business interruption and third-party liabilities.
- GDPR affects response and costs: reporting to the ICO within 72 hours and notifying data subjects may be required, insurance can cover investigation and fines (only where allowed by law and policy wording). See the ICO guidance: ICO.
- Policy limits and excess matter: choose limits that reflect booking income and likely remediation costs; low premiums with inadequate limits can leave a business exposed.
- Have an incident plan: insurers often require basic controls and a documented response plan; an immediate checklist reduces downtime and supports any claim.
Why B&Bs and small hotels need cyber insurance
B&Bs and small hotels often hold a mix of personal and payment data: guest names, addresses, email addresses, payment card details, booking histories and sometimes ID scans for identity checks. These data elements make such businesses attractive to opportunistic criminals and phishing campaigns.
Loss of access to a booking system or property management system (PMS) can cause immediate revenue loss and cancellations. Ransomware that encrypts reservations or accounting files may stop check-ins for days. Guest-facing reputational harm follows data loss or leaked reviews. Traditional property or liability insurance rarely covers the specific costs associated with cyber incidents, such as forensic investigation, regulatory notification, credit-monitoring for affected guests, public relations and the cost of hiring external IT specialists.
Regulators and guidance bodies that should be consulted include the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC): NCSC and ICO. Their advice often forms the benchmark insurers use when assessing security posture and claims.
Common incident types affecting hospitality
- Payment card fraud from skimming or compromised card terminals.
- Phishing attacks targeting staff with access to booking systems.
- Ransomware or file-encrypting malware affecting PMS, reservation files or accounting.
- Data breaches exposing guest contact details or passport scans.
- Website or booking engine compromise leading to fraudulent bookings.

Choosing cover by business size: micro B&Bs vs small hotels
Cover selection should reflect systems, revenue, staff and customer base. Micro B&Bs (1–5 rooms, owner-operated, basic online booking) have different exposures from small hotels (10–50 rooms, multi-staff, integrated PMS, payment terminals and third-party booking channels).
Micro B&Bs: typical profile and needs
- Often run by the proprietor with minimal IT support.
- Use third-party booking platforms (Airbnb, Booking.com) and possibly a simple website with online payments.
- Lower turnover but limited cash reserves to absorb interruption costs.
Insurance priorities for micro B&Bs can include: coverage for data-breach notification costs, cyber extortion (ransom), legal expenses and a modest business interruption sum that reflects average nightly revenue.
Small hotels: typical profile and needs
- Multiple staff, integrated property management systems and direct online booking engines.
- Higher transaction volumes and more complex IT (PMS, Wi‑Fi networks, point-of-sale terminals).
- Greater third-party exposure (payments processors, OTA partners) and regulatory scrutiny.
Small hotels typically need broader cover: larger business interruption limits, contingent business interruption (cover for supplier outages, OTA downtime), cyber liability for guest claims and more extensive forensic and PR budgets.
Side-by-side comparison
| Feature |
Micro B&B |
Small hotel |
| Typical staff/IT |
Owner-operated, minimal IT |
Multi-staff, PMS and POS |
| Key exposures |
Guest contact/payment data, booking outages |
Wider data sets, larger interruption losses, third-party dependencies |
| Recommended policy focus |
Notification costs, small business interruption, ransomware |
Higher BI limits, cyber liability, contingent BI, PR and forensic response |
Typical cyber policy coverages for B&Bs and small hotels
While policy wordings differ by insurer, many UK cyber insurance policies for hospitality include the following sections. Each heading summarises what is commonly covered and practical considerations for B&Bs and small hotels.
First-party cover: what the business itself can claim
-
Business interruption (BI): compensates lost revenue and continuing costs where a cyber incident prevents trading. For hospitality, BI should reflect average nightly takings and seasonal peaks. Many policies apply an indemnity period (e.g. 30, 60 or 90 days), longer periods cost more but suit hotels with seasonal peak losses.
-
Cyber extortion / ransomware payments and negotiation costs: pays for ransom demands (where legal and permitted), the costs of specialist negotiators and, sometimes, negotiated payments. Insurers may require evidence of an attempted negotiation and will often expect firms to use approved responders.
-
Forensic investigation costs: covers IT forensics to determine cause, scope and remedial actions. Detailed logs and backups are valuable here; insurers will often request evidence of backups when validating a claim.
-
Data recovery and restoration: pays for restoring lost data and systems; note that “clean room” restoration from backup can incur significant hourly costs for specialists.
-
Notification and credit monitoring: covers costs of notifying affected guests and paying for credit-monitoring services or identity-protection where personal data is exposed.
Third-party cover: liabilities to guests, suppliers or regulators
-
Privacy liability: covers legal defence and compensation claims by guests whose personal data was exposed. Policy wording often ties indemnity to specific types of data and excludes deliberate acts.
-
Regulatory defence and fines: policies sometimes cover defence costs and regulatory fines, but availability depends on law and insurer wording. For example, coverage for fines under GDPR may be restricted or excluded in some markets; any reference in the policy to fines should be read carefully with legal advice. ICO guidance: ICO.
-
Network security liability: covers claims if an infected system passes malware to a guest or supplier causing loss to others (for example, enabling card fraud).
Ancillary cover: response and reputation
-
Public relations and reputational management: funds for PR agencies to manage communications and limit reputational harm.
-
Legal and regulatory advice: specialist lawyers to advise on notification obligations and regulatory processes.
-
Telephone helpline and crisis support: some policies provide hotlines for immediate action and media advice.
How GDPR and data breach rules affect B&Bs and hotels
GDPR applies to most businesses handling personal data in the UK. The ICO expects prompt action where personal data breaches occur. Key practical obligations for B&Bs and small hotels are:
-
If a breach is likely to result in a risk to individuals’ rights and freedoms, the ICO must be notified without undue delay and, where feasible, within 72 hours of becoming aware. If notification is later, the organisation must explain the delay. See ICO guidance: Guide to Data Protection.
-
Where the breach is likely to result in a high risk to individuals (for example when passport scans or payment card data are exposed), affected guests may also require direct notification.
-
Insurance can cover the costs of investigations and notifications; whether it covers monetary penalties depends on policy wording and legal permissibility. The ICO has historically discouraged policies that appear to incentivise complacency; insurers and insureds should confirm cover specifics and consult legal advice where necessary.
Practical GDPR steps for hospitality businesses
- Record the breach and the facts, its effects and remedial actions in a central incident log.
- Notify the ICO when required and keep evidence of decisions and timing.
- Communicate clearly with affected guests using concise, factual language and offer remedies such as credit-monitoring if appropriate.
- Retain logs, access records and backup snapshots, these are vital for forensic work and insurer validation.
Setting policy limits and excess for B&Bs and small hotels
Choosing sums insured and excesses requires balancing premium cost with potential exposure. A few principles help frame the decision.
How to size business interruption cover
-
Calculate average daily takings during peak season and off-peak. Insurers often expect a realistic gross income figure and may ask for historic accounting records or VAT returns.
-
Consider maximum reasonable downtime for a severe incident. For instance, if a PMS is encrypted and external specialists estimate 7–14 days to restore, the indemnity period should at least cover that window plus time to rebuild reputational trust.
-
For hotels with seasonal peaks, a longer indemnity period may be appropriate; micro B&Bs might choose shorter periods to control cost.
Choosing limits for privacy and liability
-
Privacy liability limits should reflect guest volumes and sensitivity of data held. A small hotel holding passport scans and payment details will need higher limits than a micro B&B that processes payment via a third-party OTA where card data is not stored.
-
Consider contingent limits for third-party claims (e.g., OTA failures leading to cancellations) and include legal defence costs within limits where possible.
Excesses and premium decisions
-
Higher excesses reduce premiums but increase out-of-pocket costs when an incident occurs. For micro businesses with very tight cashflow, a lower excess avoids catastrophic immediate costs.
-
Some insurers impose time-based excesses (e.g., first 24–48 hours of BI not covered). Read wording carefully.
Indicative example (current at time of writing)
- Micro B&B: BI limit £25,000, privacy liability £250,000, forensic & notification costs £25,000, excess £500–£1,000.
- Small hotel: BI limit £100,000–£500,000 depending on turnover, privacy liability £1m+, forensic & PR costs £100,000+, excess £1,000–£5,000.
These figures are indicative; actual sums depend on turnover, operating margins and risk appetite. Consult an insurance broker or legal adviser for precise calculations.
Incident response and ransomware steps for small hotels
A structured response reduces confusion, assists regulatory compliance and supports insurer claims. Below is a concise, practical sequence that aligns with typical insurer expectations and NCSC guidance: NCSC incident management.
- Isolate affected systems: disconnect infected machines from the network to prevent spread, but do not power off devices needed for forensic evidence unless instructed by an investigator.
- Preserve evidence: retain logs, screenshots and backups; avoid re-imaging or deleting files before forensic capture.
- Activate incident contacts: call the internal incident lead, nominated technical responder and insurance incident hotline if available.
Short-term containment (first 24–72 hours)
- Engage forensic specialists (many policies provide an approved panel). They will determine infection vector, scope and advise on recovery sequencing.
- Inform the ICO if personal data breach thresholds are met, and prepare guest notifications if required.
- Implement temporary workarounds to continue critical operations (manual check-ins, phone bookings) while systems are restored.
Recovery and review (days to weeks)
- Restore from clean backups once systems are validated as malware-free.
- Perform root-cause analysis and implement mitigations to prevent recurrence: patching, credential resets, segmentation, improved logging.
- Document the incident and outcomes to support claims, compliance and future audits.
Staff checklist for ransomware response
- Do not pay any ransom without legal and insurer guidance; some payments may be unlawful depending on sanctions or specifics.
- Notify the insurer promptly and follow their claim-notification requirements (record times, persons contacted and actions taken).
- Communicate with staff and guests using clear, factual messages; avoid speculation.
Visual process: incident response flow for B&Bs and small hotels
Incident response timeline for B&Bs and small hotels
🔔 **Detect** → 🛑 **Isolate** → 🧾 **Preserve evidence**
📞 **Call insurer/forensic** → 🧯 **Contain** → 📢 **Notify ICO/guests if needed**
🔁 **Restore from backups** → ✅ **Test systems** → 📊 **Review & harden
Estimated timeline: Immediate (0–2 hrs) → Short (24–72 hrs) → Recovery (days–weeks)
Advantages, risks and common errors
✅ Benefits and when insurance makes sense
- Protects cashflow: covers losses while systems are restored, avoiding insolvency risks after a severe incident.
- Access to specialists: many policies include access to forensic teams, negotiators and PR consultants that would be costly otherwise.
- Regulatory support: covers the cost of investigations and notifications that GDPR requires.
Insurance is particularly valuable when the business stores sensitive guest data, manages direct payments or runs its own booking engine or PMS.
⚠️ Errors to avoid and residual risks
- Assuming standard business insurance covers cyber: traditional property or liability policies often exclude cyber-specific losses.
- Under-insuring BI: choosing low BI limits to save premium can mean out-of-pocket losses far exceed insurance payouts.
- Ignoring policy conditions: many insurers require minimum cyber controls (patching, anti-malware, backups); failure to maintain these can invalidate claims.
- Relying on OTA or payment provider cover: third-party platforms reduce some risk but do not eliminate exposure, especially for data held locally.
Questions frequently asked by B&Bs and small hotels
Frequently asked questions
Yes. Using a platform reduces some exposure (platforms often handle payment processing) but the B&B still holds guest contact details and may run a website or card terminal that creates separate risks.
Will cyber insurance cover ICO fines for breaches?
Policies vary. Some include regulatory defence costs and limited fines cover where permitted by law, but many exclude fines or cap them. Check policy wording and consult a legal adviser.
How quickly must a breach be reported to the ICO?
The ICO expects notification without undue delay and, if feasible, within 72 hours of becoming aware that a notifiable breach occurred. Keep records of timing and decision rationale.
What basic cybersecurity steps reduce premiums and claims risk?
Simple, effective measures include: regular patching, anti-malware on endpoints, strong unique passwords with MFA where possible, routine backups stored offline, and staff training on phishing.
How are ransom payments handled by insurers?
Insurers will have specific procedures and may require use of approved negotiators. Some insurers cover ransom payments where legal, others do not. Always follow insurer reporting requirements.
Should a small hotel buy a standalone cyber policy or add an extension to liability insurance?
Stand-alone cyber policies commonly provide broader first-party cover useful for hospitality. Extensions to general liability may be cheaper but often provide narrower cover. Compare wordings and limits.
Can the insurer refuse a claim if controls were weak?
Yes. Insurers frequently require minimum controls and accurate disclosure at proposal. Failure to maintain stated controls or to disclose relevant facts can lead to declined claims.
Your next step:
- Calculate a simple profile: list third-party systems, payment flows, average daily takings and types of personal data held.
- Check existing policies for explicit cyber exclusions and gather historic trading figures for BI calculations.
- Prepare a short incident checklist (contacts, backups location, insurer details) and store it offline and with key staff.
Written by Peter White, business risk researcher. For regulatory guidance consult the ICO and NCSC links embedded above. For tailored financial or legal advice, consult a regulated insurance broker or legal professional.