No. Landlord cover rarely pays a tenant's data loss or lost revenue after a cyber incident. Tenants need their own cyber policy and clear lease clauses.
Comparativa rápida. landlord vs tenant cover
The table below shows typical covers, common exclusions and the action a tenant should take when agreeing a lease.
| Cover area |
policy (typical) |
Tenant policy (typical) |
Who to ask / what to demand |
| Building fabric & common areas |
Usually covers fire, flood and physical damage. |
Not relevant unless the tenant changes the structure or fits out. |
Ask for the landlord policy schedule and the insurer name. Check rebuild sums. |
| Business interruption (tenant revenue loss) |
Often excludes tenant revenue loss and first-party BI for tenants. |
Covers tenant BI tied to their systems and sales if the tenant buys it. |
Ask for BI limits, indemnity period and examples of covered triggers. |
| Cyber incidents & data breach |
Commonly excluded from landlord policies. |
Covers first-party cyber, ransomware, response costs and regulatory defence. |
Obtain full wording that shows cyber exclusions. Buy tenant cyber cover. |
| Shared systems (BMS, managed Wi‑Fi) |
May insure physical damage only. Cyber gaps are common. |
Tenant policies can include contingent BI and dependent supplier cover. |
Require a lease clause naming who is responsible and proof of MSP insurance. |
| Third‑party liability (personal injury, data affected third parties) |
Covers landlord liability for common areas. |
Covers tenant liability for customer data breaches if the tenant buys it. |
Confirm the scope of tenant liability and limits in the policy schedule. |
Act now to avoid costly insurance gaps for tenants.
Rely on landlord cover only? when it makes sense and limits
Relying only on landlord cover fits businesses with no digital systems and no client data. Landlord insurance protects the building and third-party injury in common areas.
Most SMEs handle client data or sell online. The landlord policy will not cover their revenue loss.
The most common error is assuming a landlord policy covers tenant business interruption and data loss. This error leads to late claims and insurer denials.
When might landlord‑only cover be enough?
A single-tenant lease that places clear responsibility on the tenant may rely on landlord cover for building only. This situation is rare for SMEs with client data.
A business with no online sales and no customer data needs less tenant cyber cover. Still, confirm shared systems do not create exposure.
What limits and checks to accept
Check the landlord policy schedule for sums insured, named perils and any cyber exclusion. Confirm insurer name and policy number with a certificate of insurance.
A practical benchmark: the lease should require the landlord to disclose the insurer and whether cyber exclusions apply to building systems. If the wording is unclear, buy tenant cover.
Buy tenant cyber policy? advantages and honest limits
A tenant cyber policy protects first-party losses that a landlord policy usually ignores. This cover pays for breach response, ransomware and tenant BI.
A tenant policy has limits, excesses and conditions. Buying cover without matching limits to turnover or suppliers creates gaps despite holding a policy.
This works on paper but often fails in practice. Tenants commonly underinsure BI or miss social engineering cover.
Key cover features to buy
Choose features that include forensic costs, legal and PR fees, breach notification and cyber extortion. Add social engineering and funds transfer fraud when relevant.
Benchmark figures: BI for 3–6 months turnover is sensible. Cyber limits commonly range from £50,000 to £250,000 or more depending on size.
Policy conditions that matter
Check conditions such as prompt notification, multi-factor authentication and patching obligations. Failing to meet conditions can void cover.
Ask the insurer to confirm, when possible, cover for incidents caused by third-party MSPs or shared building systems.
A simple numeric mapping helps size tenant cyber and BI.
- As a starting point, consider these rough 2024 benchmarks: micro businesses (turnover <£250k) should consider cyber limits of £50k–£100k and BI for three months' fixed costs.
- Small SMEs (£250k–£1m) typically need £100k–£300k cyber limits and BI for 3–6 months' turnover or fixed costs.
- Mid-sized SMEs (£1m–£10m) often require £250k–£1m+ cyber limits with BI for at least six months and more for high digital dependency.
Premiums vary by sector and exposure. Simple cyber packages for micro businesses commonly cost £300–£1,000 p.a. Small SME packages commonly cost £800–£3,000.
Act now to avoid surprises at claim time.
Mix: tenant top‑up cover plus lease negotiation
Top-up cover plus clear lease clauses balance cost and protection. Tenants keep control of revenue risk without relying only on landlord policies.
Negotiating lease clauses reduces legal fights after incidents. A mix of contract clarity and tenant insurance gives both prevention and pay-out routes.
Unclear allocation of responsibility for shared systems drives many cross-tenant disputes. Tenants should place this point high in negotiations.
Practical top‑up options
Options include contingent BI, dependent supplier cover and higher cyber limits. Match the top-up to turnover and supplier exposure.
Compare quotes from insurers such as Hiscox, Aviva and Zurich. Work with brokers like Aon or Marsh for wording checks.
Lease points to secure before
Demand a waiver of subrogation, named responsibility for MSPs and landlord obligations for security patches and incident response plans. Attach proof of MSP insurance to the lease.
Require the landlord to notify tenants when shared systems have vulnerabilities. This reduces delay and finger-pointing.
Contingent BI and dependent-supplier cover need careful drafting to trigger payment. Map critical suppliers and shared IT systems such as BMS, managed Wi‑Fi and payment gateways.
Set trigger events clearly, for example a total or partial supplier service interruption for a set number of hours. Also set aggregation rules for multi-tenant claims.
Insurers commonly impose sub-limits and waiting periods for contingent BI. Name the most critical suppliers in the schedule where possible and buy limits to cover the revenue at risk.
Also require MSPs to maintain their own cyber cover with minimum limits and provide SLA-backed restoration times. Cover that excludes third-party failures will leave tenants exposed.
How to choose according to your situation
Choose based on turnover, customer data volume and shared system dependency. A simple decision matrix makes trade-offs clear and repeatable.
A small consultancy with few online sales may accept lower cyber limits. An SME that takes client payments needs higher limits and BI cover.
A broker or insurance adviser can map turnover to recommended limits. This avoids guesswork and the common error of underinsuring.
Decision criteria and thresholds
Use these criteria: monthly revenue at risk, customer personal data held, reliance on shared building systems and critical supplier dependencies.
Thresholds: set BI to cover a minimum of three months' fixed costs and lost margin. For digital revenue consider six months when recovery times are unclear.
Step‑by‑step selection process
- List critical systems and suppliers and mark which are shared.
- Obtain landlord insurance schedule and MSP contracts.
- Get tenant cyber quotes tied to the required BI and features.
Keep records of quotes, policy wordings and lease clauses for claims and audits.
What nobody tells you about shared building risk
An attack on an MSP or an IoT device can hit several tenants at once. Shared systems often mean shared pain but not shared pay-outs.
Many landlord policies exclude cyber in ways insurers interpret narrowly. Tenants see gaps only when they file claims and face denials.
Anonymised case: a managed Wi‑Fi breach exposed customer records across three tenants. One tenant faced regulatory fines after delayed ICO notification.
Hidden costs and cascading losses
Costs include forensic bills, customer notification, regulatory fines and long revenue gaps. These costs quickly exceed building repair bills that insurers pay.
Check whether the landlord insurer has rights to subrogate against tenants. A missing waiver can lead to costly legal action between parties.
What landlords rarely reveal
Landlords may not give MSP contracts or the frequency of security patching unless asked. Tenants should request MSP names and evidence of security testing.
A practical route is to require the landlord to provide annual confirmation of MSP insurance and a short summary of recent security testing.
Estimated cost: for a small SME in England, a basic cyber policy with £50k–£100k limit commonly costs between £300 and £1,200 annually, depending on sector and previous claims.For an SME needing £250k–£1m cover, premiums typically start around £1,000 and rise with risk factors such as payment volumes and customer data held.
Many tenants assume that seeing the landlord's certificate means all losses are covered. In practice, you must read the full wording for exclusions and limits.
Typical exclusions to watch include cover limited to "physical loss or physical damage", express cyber exclusions and failures to maintain systems. Also watch prior known incidents, contractual liability and aggregation wording.
A practical example: if a BMS is taken offline by malware with no physical damage, a property policy that needs physical damage may decline the claim. Tenants then rely on their own BI or contingent BI cover.
Use the checklist at lease signing or renewal. It saves time and limits surprises during a claim.
- Obtain the landlord’s current certificate of insurance and the full policy wording.
- Confirm whether landlord policies include cyber or explicitly exclude it.
- Require a waiver of subrogation in the lease in favour of tenants.
- Ask for the MSP/contractor list and proof of their insurance and Cyber Essentials.
- Request a clause assigning responsibility for BMS/IoT patching and incident response SLAs.
- Buy tenant cyber with BI equal to 3–6 months turnover and include ransomware and social engineering.
- Agree notification and co‑operation obligations between landlord and tenants in writing.
Documents to collect and store
Store the landlord policy wording, certificate of insurance, MSP contracts and your tenant policy wording together. Keep them for claims and audits.
A practical habit is to review the landlord COI and MSP evidence annually and when renewal approaches.
Model lease clauses to use or adapt
Below are short model clauses tenants can propose. Insert them into the lease under insurance and services sections.
Text
1. Waiver of Subrogation: Each party waives any right of recovery against the other for loss which is insured and for which the insurer has paid.
-
Shared Systems Responsibility: The landlord shall ensure all named MSPs maintain a cyber insurance policy with a minimum limit of £1,000,000 and shall provide relevant certificates annually.
-
BMS and IoT Security: The landlord shall ensure BMS and IoT devices receive security patches within 14 days of patch release and shall notify tenants of incidents within 24 hours of discovery.
-
Proof of Cover: The landlord provides the current policy schedule and full wording for any building‑level insurance within 14 days of request by the tenant.
How to present clauses to the landlord
Attach the clauses as a proposed lease annex and request insurer confirmation by broker email. Ask for a written response to each clause.
If the landlord resists, prioritise waiver of subrogation and MSP insurance naming over cosmetic language.
Who pays and when
Who pays after a shared building cyber incident?
Landlord insurer
Physical damage, common area repairs and landlord liability to third parties.
Tenant insurer
Tenant data loss, forensic costs, ransomware and business interruption tied to tenant systems.
MSP / Contractor
May carry liability if the breach stems from their failure. Require their insurance and security proof.
Note: If subrogation is allowed, insurers may sue other parties. Insist on a waiver of subrogation to avoid this.
Preserve evidence and notify insurers and the landlord without delay. Early notification helps secure cover and co-operation.
Isolate affected systems, change credentials and preserve logs in read-only form. Do not overwrite possible evidence.
Contact forensic specialists and log all costs and actions. Keep a record of communications with the landlord and MSP.
Reporting and regulatory steps
If personal data is affected, follow ICO guidance on breach notification and keep a record of decisions. Report to the ICO where required.
Notify your insurer within policy timescales and ask for written confirmation of cover for immediate response costs when possible.
Real‑world claims in england
These cases show how landlord cover often falls short and how lease clauses and tenant cover change outcomes.
Case 1: manchester office BMS ransomware
Multiple tenants lost heating and access after the BMS vendor had ransomware. The landlord insurer covered building repairs only.
Tenants with tenant cyber policies recovered BI and extortion costs. Tenants without those policies bore long revenue losses.
Lesson: tenant BI and cyber are decisive when shared systems fail.
Case 2: shared Wi‑Fi exposing client data
A managed Wi‑Fi platform leaked client records for several tenants. One tenant faced regulatory action after delayed notification.
The tenant's failure to notify the ICO in time reduced recovery chances and increased fines. The landlord policy did not pay for regulatory defence.
Lesson: rapid notification and breach response cover are essential.
Case 3: subrogation fight after vendor compromise
A landlord insurer tried to recover costs from tenants after an MSP compromise. The lease had no waiver of subrogation.
Tenants faced legal costs defending themselves. Settlements followed; the disputes took months and were costly.
Lesson: insist on a waiver of subrogation and clear MSP responsibility clauses.
Opinionated recommendation with nuance
A separate tenant cyber policy plus negotiated lease protections gives the best balance of cost and certainty. This is particularly true for most SMEs.
Buy tenant cover that matches turnover and supplier exposure. Negotiate lease clauses that name MSP responsibilities and require MSP insurance.
Act early and document everything in the lease and insurance schedules.