Cloud vendor outages happen with increasing frequency, and the central question is straightforward: should an SME rely on a provider’s SLA credits or on cyber insurance to cover loss when a cloud vendor fails? This guide compares what SLAs and cyber insurance typically cover, explains where gaps and exclusions commonly appear, and outlines immediate, practical steps SMEs can take to reduce financial and regulatory exposure after a third‑party outage. The emphasis is UK‑specific: references to the ICO, NCSC and relevant legal context are included to help non‑technical decision‑makers take clear, evidence‑based steps.
Key takeaways
- SLAs are contractual remedies, often limited to service credits; they usually do not restore full business loss.
- Cyber insurance can cover business interruption and some third‑party failures, but policies often contain exclusions and conditions linked to vendor contracts and controls.
- GDPR fines and regulatory costs may not be covered by SLA credits; insurance cover for fines depends on policy wording and legal context.
- A combined approach, negotiate stronger SLAs, adopt technical controls and maintain appropriate insurance, usually offers the best resilience for SMEs.
- Immediate actions after an outage: document timings, preserve evidence, notify insurer and vendor promptly, and follow internal playbook.
Should SMEs rely on cloud SLAs or insurance?
An SLA (service level agreement) is a contract between the cloud provider and the SME. It sets expectations for uptime, response times and usually offers service credits if the vendor fails. Service credits are typically expressed as a percentage of monthly fees or as prorated refunds. Those credits compensate the subscription cost, not the wider financial impact of downtime, such as lost sales, staff idle time or reputational harm.
Cyber insurance, by contrast, is designed to indemnify a business for specified financial losses arising from certain cyber events. Policies commonly include business interruption, incident response costs and, sometimes, third‑party liabilities. However, cover usually depends on triggers, defined exclusions and pre‑conditions (for example, minimum security controls). Policies may also limit cover for losses caused by a third party rather than directly by an insured security breach. For UK SMEs, the practical choice is rarely binary: SLAs provide contractual leverage and limited financial redress, while insurance may provide broader indemnity, subject to policy terms.
Cloud vendor outages: which covers your downtime costs?
Cloud outages create a spectrum of losses: immediate lost revenue, mitigation costs (temp hosting, extra staff), regulatory expenses and longer‑term reputational damage. Mapping those losses to SLA remedies and insurance cover clarifies expectations.
| Type of loss |
Typical SLA remedy |
Typical cyber insurance position |
| Subscription/service fees |
Service credits or refund of fees for downtime period |
Usually not covered (insurance indemnifies business losses, not vendor fees) |
| Lost sales / revenue |
Rarely covered by SLA credits |
May be covered under business interruption if outage is an insured event and policy wording permits third‑party failure |
| Extra mitigation costs (temporary hosting, engineering) |
Not usually covered |
Often covered as reasonable and necessary mitigation costs if policy trigger satisfied |
| GDPR regulatory action / fines |
Not covered by SLA |
Coverage varies; some policies exclude regulatory fines or limit defence costs. Legal analysis required. |
| Loss of client data / breach |
Depends on contract; vendor liability caps may apply |
Typically covered as data breach, subject to policy exclusions and notification rules |
Examples from the UK market show that SLAs are often silent on consequential losses: a provider might accept responsibility for service availability but cap liability to the value of fees paid in the period. Cyber insurers may pay for lost revenue, but only where the policy defines an outage or operational interruption as an insured peril and where exclusions (e.g. failure of a third‑party provider, software bugs, or unencrypted data) do not apply.
Cyber insurance vs provider SLAs for GDPR fines?
GDPR fines are an enforcement tool exercised by the Information Commissioner's Office (ICO). The ICO focuses on data protection failures, including inadequate risk assessment of processors and inadequate technical controls. An SLA cannot discharge regulatory responsibility: contractual clauses with a vendor do not eliminate a controller's obligations under the Data Protection Act 2018.
Insurance positions on GDPR fines vary. Some cyber policies provide cover for regulatory defence costs but exclude monetary fines imposed by data protection authorities, as insuring fines can be restricted on public policy grounds in certain jurisdictions. UK insurers typically clarify whether fines are insured; many offer cover for defence costs and regulatory investigations but exclude the fine itself. For up‑to‑date UK guidance, see the ICO site: ICO and the NCSC guidance on resilience: NCSC.
Hidden exclusions in policies that void cloud outage claims
Several common pitfalls in cyber policies cause third‑party outage claims to be denied or reduced. These are often buried in wording and require careful review:
- Provider exclusion clauses: some policies exclude loss caused by the failure of a named third party or where the failure is the result of the vendor’s acts/omissions. If a policy excludes outages attributable to outsourced cloud platforms, a claim will fail.
- Contractual subrogation and assignment: insurers may seek to subrogate against the cloud vendor after payment. Poor contract terms with the vendor (e.g. broad liability caps) may reduce the insurer’s recovery prospects and affect settlement decisions.
- Failure to maintain controls: claims can be denied if minimum cybersecurity requirements (MFA, patching, backups, EDR) are not met. Insurers commonly require documented controls at the time of loss.
- Notification and cooperation clauses: late notification or failure to preserve evidence (logs, timestamps) can lead to denial. Policies require prompt notice and cooperation during investigation.
- War/terrorism or software bug exclusions: some outages caused by geopolitical events or zero‑day vulnerabilities may fall into exclusions.
Careful review of policy wording is essential. When considering cover, the insurer’s stance on third‑party failure should be tested with example scenarios during procurement.
When is cyber insurance worth it after third‑party failure?
Cyber insurance becomes financially worthwhile depending on three broad factors: likely quantum of loss, contract protection from the vendor, and the SME’s capacity to absorb shortfalls.
If an SME’s revenue or operations are highly dependent on a single cloud provider, the expected value of probable losses from a vendor outage may exceed the cost of insurance. Similarly, if the vendor’s SLA caps liability at a negligible amount relative to potential lost profits, insurance can bridge that gap. Conversely, for microbusinesses with minimal cloud dependency and low revenue impact, investing in stronger contractual terms and contingency plans may be a higher‑value first step than purchasing extensive cover.
Insurance can also provide non‑financial benefits: access to incident response teams, legal defence for regulatory matters, and crisis PR support. Those services may materially reduce recovery time and reputational harm even where pure indemnity payments are limited. The FCA and industry guidance encourage boards to treat cyber resilience as a mix of technical, contractual and insurance controls; insurers often expect evidence that the business has reasonable mitigation measures in place before underwriting.
Choosing between SLA credits and actual business interruption cover
Decision makers should weigh SLA credits against insurance cover across six dimensions:
- Quantum of recovery: SLA credits rarely reflect full loss; insurance can be structured to indemnify gross profit or declared turnover.
- Speed of payment: SLA credits are automatic and quick but small; insurance claims take longer but can be larger.
- Scope of cover: SLAs cover availability metrics; insurance covers a broader set of costs if the event matches policy triggers.
- Legal complexity: SLA recovery requires contractual claims against the vendor and possibly litigation; insurance avoids direct litigation with the vendor but may involve subrogation.
- Cost: SLA negotiation is often low or no cost beyond procurement effort; insurance is a recurring premium expense and may carry excesses/deductibles.
- Regulatory and reputation risk: Insurance can include regulators' defence and PR support; SLAs do not.
A pragmatic strategy is to negotiate stronger SLAs for critical services (shorter RTO/RPO, lower liability caps, dedicated support) while maintaining an insurance programme that addresses residual risk. A contractual clause reducing vendor liability in return for lower fees may be tempting, but that increases the insurer’s subrogation difficulty and potentially the SME’s uncovered exposure.
Practical SLA clauses and contract checklist (examples)
The following clauses are illustrative and not legal advice. These examples help SMEs negotiate clearer remedies and preserve subrogation rights:
- Service credit formula: "Service credits shall equal X% of monthly fees for each hour of downtime, capped at Y% of monthly fees." (Negotiate for practical, measurable definitions of "downtime" and start/stop criteria.)
- Notification obligations: "Provider shall notify customer and provide real‑time incident logs within 60 minutes of detecting a service disruption affecting customer tenancy." (Essential for evidence preservation.)
- Liability cap carve‑outs: "Provider’s liability cap shall not apply to losses arising from willful misconduct, gross negligence, or breach of confidentiality and data protection obligations." (Limited carve‑outs support claims for consequential loss.)
- Subrogation waiver: "Provider and customer waive mutual rights of subrogation to the extent permitted by law." (Helps avoid insurer recovery complications but insurers may require subrogation rights.)
- Audit and data portability: "Provider shall permit emergency data export and provide read‑only snapshots for continuity within X hours of outage." (Reduces recovery time.)
Coordinating insurer, vendor and SME during an outage: a playbook
A clear incident playbook reduces disputes and speeds recovery. Key steps:
- Immediate evidence capture: time‑stamped screenshots, logs, ticket IDs and communications with the vendor. Preserve all records in a separate, secure location.
- Notify insurer early: give preliminary notice even if investigation is ongoing; deny late notification risk. Provide policy number, summary of impact and expected financial exposure.
- Engage vendor support: request incident timeline, root cause analysis and remediation ETA in writing. Request formal incident reference and any service credits due.
- Mitigate and document costs: procure temporary capacity, route payments to alternative channels, hire incident responders. Keep invoices and decision memos.
- Legal and regulatory check: assess whether the outage triggers a mandatory ICO notification under GDPR or other sectoral reporting obligations. Seek legal advice where appropriate.
- Post‑incident review and subrogation: share findings with insurer; if insurer pursues recovery, provide contractual documents and evidence.
These steps align with guidance from the NCSC and ICO on incident management: NCSC incident guidance and ICO resources.
Quick outage action flow ➜ preserve evidence → notify insurer → deploy mitigations
📌 Capture timestamps & logs
📤 Notify vendor + request incident ref
📞 Notify insurer (preliminary notice)
🔁 Failover or temporary hosting
🧾 Keep invoices & decisions
🔍 Post‑incident review & evidence handover
Cost–benefit: negotiating better SLAs vs buying more cover
A simple numerical approach helps. Estimate the potential weekly loss from an outage affecting core operations (lost orders, staff downtime, refunds). Compare this with: (a) expected service credits under current SLA; (b) additional insurance premium to increase limits or add coverage for third‑party outages.
Example: if a retailer estimates £10,000 lost revenue per day during an outage, and the SLA offers credits equal to one day’s fees (~£100), there is a clear shortfall. A policy that covers business interruption up to £50,000 with an annual premium of £2,500 may be cost‑effective. Conversely, if an SME’s exposure is modest and negotiating a tighter SLA (faster RTO, better support) costs only management time, renegotiation may be preferable. This calculation is indicative; insurers and brokers can provide scenario quotes and probability estimates but any purchasing decision should rely on regulated advice.
Real‑world case examples (UK context, illustrative)
-
A UK accounting firm lost client access during a major SaaS outage. The SaaS SLA offered a credit equal to one month’s subscription; the firm’s lost billing revenue exceeded the credit by several thousand pounds. The firm’s cyber policy covered business interruption after an established waiting period and paid mitigation costs, excluding the regulatory fine for delayed client reporting which the ICO later applied. The insurer covered incident response costs but challenged recovery against the SaaS vendor due to a liability cap.
-
An e‑commerce SME experienced a multi‑hour payment gateway outage. The gateway’s SLA provided service credits only. The SME’s insurer declined a business interruption claim because the policy excluded outages caused by a third‑party payment processor named in schedule. This emphasises the importance of testing policy wording against likely vendor failure scenarios.
Common mistakes SMEs make
- Assuming SLA credits equal business loss: many businesses accept small credits without modelling true exposure.
- Not documenting controls required by insurer: missing MFA, backups or patch evidence can void claims.
- Delaying insurer notification: late notice risks denial.
- Accepting vendor liability caps without carve‑outs: limits often restrict recovery and reduce insurer subrogation value.
- Treating insurance as a substitute for technical resilience: insurance is risk transfer, not prevention.
FAQ
Can a service credit from a cloud provider replace insurance?
Service credits cover subscription costs and are not a substitute for indemnity against lost profits, mitigation costs or regulatory defence. Credits rarely match full business loss.
Will cyber insurance pay GDPR fines from a vendor outage?
Coverage for fines varies by policy; many UK policies cover defence costs but exclude monetary fines. Legal interpretation and policy wording determine outcomes; consult a regulated adviser.
What evidence is needed to support an insurance claim after a cloud outage?
Time‑stamped logs, vendor incident reports, communications, invoices for mitigation costs, and proof of required security controls are commonly required.
Can an insurer sue the cloud provider after paying a claim?
Yes. Insurers often subrogate against third parties. Contractual waivers or vendor liability caps can affect subrogation recoveries.
How fast do insurers pay business interruption claims?
Claims timelines vary; insurers typically investigate and may pay after validating evidence. Payments can take weeks to months, unlike immediate SLA credits.
Should SMEs list cloud providers on their insurance proposal?
Yes. Full disclosure of material third parties and software vendors helps ensure accurate covers and avoids surprise exclusions.
Is it cheaper to negotiate a better SLA than to buy insurance?
Negotiation has low direct cost but may not remove residual financial exposure. A combined strategy is often optimal depending on quantified risk.
How does the ICO view third‑party outages?
The ICO focuses on the controller’s responsibility to ensure processors provide adequate safeguards. Contracts and technical controls matter; see the ICO guidance at ICO.
Action plan: three steps under 10 minutes each
1. Capture evidence now
Open a secure document and record exact outage start time, error messages, vendor ticket numbers and affected services. Save screenshots and email timestamps.
2. Notify insurer and vendor preliminarily
Send a short, factual notice to the insurer (policy number, summary) and request incident reference from the vendor in writing.
3. Activate contingency measures
Redirect customers to status pages, trigger failover if available, and route new orders to alternative channels. Keep receipts for any emergency costs.
Conclusion
Mapping cloud vendor SLAs against cyber insurance highlights complementary roles: SLAs provide contractually defined, quick but limited remedies; insurance can provide broader financial protection but relies on careful wording and compliance with policy conditions. For UK SMEs, the most resilient approach combines sensible contractual negotiation, documented technical controls and appropriate insurance cover calibrated to quantified exposure. Consultation with regulated insurance and legal advisers is recommended when structuring cover or negotiating vendor contracts.