Do worries about lost takings from a payment outage or a ransomware lock-out keep decision-makers awake? Does it feel unclear whether a single policy can cover both cyber attacks and the shop-floor losses that follow?
This guide explains, in plain UK business terms, the practical options for combined cyber and business interruption (BI) cover aimed at retail SMEs. It sets out when combined cover is useful, how common retail incidents play out financially, what policies typically pay for, where wording traps appear, and the focused questions to ask insurers when comparing quotes.
Key takeaways: what to know in 60 seconds
- Combined cover links cyber incidents and business interruption in one policy, useful where digital failure quickly halts sales (e.g. POS, e‑commerce).
- Retail-specific scenarios such as ransomware, POS outages and supplier cyber-disruption often cause both direct cyber costs and measurable BI losses.
- Costs vary widely: premiums depend on turnover, POS/E‑commerce exposure, controls, indemnity period and sublimits, expect indicative UK premiums from a few hundred to several thousand pounds a year.
- Watch for exclusions and small-print traps: card scheme fines, certain frauds, pre-existing vulnerabilities and supply‑chain caps are common gaps.
- Use a checklist when comparing: indemnity period, definition of incident, waiting period, civil authority cover, dependent business interruption, sublimits, and claims examples.
Who needs combined cyber and business interruption (BI) cover?
For retail SMEs the decision depends on how closely trading depends on digital systems. Combined cover often suits businesses that meet one or more of the following:
- Brick-and-mortar retailers where tills, card terminals or stock systems are networked and a systems outage stops sales.
- E‑commerce or click-and-collect retailers whose main revenue flows through a website or payment gateway.
- Businesses using third-party tills, EPOS providers or cloud point-of-sale platforms where supplier outages can halt trading.
- Retailers handling regulated personal data (loyalty programmes, CRM) where a breach may also trigger legal and notification costs under GDPR.
Combined cover is less useful where trading is largely cash-based, manual fallback processes exist and digital downtime would be brief or easily mitigated.
Real retail incidents: ransomware, POS outages, supply-chain delays
Retail claims often combine a technical incident and a measurable revenue impact. The three scenarios below show typical paths and cost categories.
Ransomware: locked systems and lost takings
Scenario: A ransomware infection encrypts EPOS and back-office servers overnight. The shop cannot process card payments; online orders fail.
Common costs that combined cover may respond to:
- Incident response and forensic costs (to identify and remove malware).
- Ransom demand payments (where permitted and subject to policy wording).
- Revenue loss during the indemnity period (lost gross profit, not just transactions).
- Extra costs to restore systems or to hire temporary manual payment terminals.
- Legal and notification costs if customer data is affected (GDPR).
Indicative example: a 10‑site retail chain with £2m annual turnover may claim £50k–£200k for a multi‑day outage depending on gross margin and length of downtime (indicative figures).
POS outages: hardware, network or payment‑processor failure
Scenario: A nationwide card‑processor outage prevents authorisation for hours on a Saturday peak. The retailer can accept cash only; average card share is 80%.
Key considerations:
- Does the policy define interruption as inability to use systems or inability to trade at all?
- Does the policy require a proportion of receipts to fall below a threshold before BI cover triggers?
- Is there cover for the civil authority closure if a network outage forces temporary shop closures?
Supply‑chain delays: third‑party IT and dependent BI
Scenario: The cloud EPOS vendor suffers a cyber incident, affecting many customers. Retailers face stock replenishment delays and inability to reconcile sales.
Modern policies increasingly include dependent business interruption (DBI) or supplier failure cover, but limits and waiting periods often differ from primary BI. Retailers should check whether suppliers are named or whether cover is triggered by a supplier’s failure generally.

Policy costs, excesses and hidden trade‑offs explained
Premiums and policy structure change materially with a few levers. The most influential are turnover, indemnity period, historic claims, cybersecurity controls, and the chosen limits and sublimits.
- Indemnity period: longer periods (e.g. 12 months vs 3 months) raise premiums significantly. Retailers with seasonal peaks may need longer indemnity periods to capture recovery.
- Sublimits: many policies set sublimits for cyber BI, dependent BI, cardholder data breach costs and ransomware payments. Sublimits reduce premium but cap recovery.
- Waiting period/excess: policies commonly have a waiting period (e.g. 24–72 hours) before BI payments start. Shorter waiting periods cost more.
- Excess (financial): often a fixed sum or percentage per claim. Retailers should model small claims vs catastrophe scenarios to judge affordability.
Table: quick comparison of typical options and trade-offs
| Feature |
Low‑cost option |
Higher‑cost option |
Trade‑off / impact |
| Indemnity period |
30–60 days |
6–12 months |
Short covers brief outages; long covers recovery and supply-chain issues |
| Waiting period |
48–72 hours |
0–24 hours |
Longer wait reduces claim payments for short outages |
| Dependent BI |
Often excluded or low sublimit |
Included with named suppliers |
Without DBI, third‑party failures may be uncovered |
| Ransom payments |
Frequently limited |
May be broader with higher premium |
Limits may prevent settlement; affects recovery time |
| Card and payment losses |
Often excluded |
Included with specific wording |
Card‑scheme fines often excluded; check wording |
Note: the table is indicative; exact terms depend on insurer wording.
Common exclusions, GDPR gaps and small‑print traps
Retailers commonly discover gaps only at claim time. Frequent pitfalls include:
- Pre‑existing vulnerabilities: incidents that exploit known, unpatched weaknesses reported before inception may be excluded.
- Card‑scheme fines and PCI DSS penalties: many insurers exclude fines imposed by card schemes or limit them severely.
- Social engineering fraud and physical theft of funds: some cyber policies exclude employee deception losses unless a specific extension is bought.
- Inventory spoilage or perishable stock loss: physical stock loss linked to cyber incidents (e.g. refrigeration controls hacked) may be excluded or sublimited.
- Dependent supplier caps: DBI may apply only to named suppliers or have a short indemnity period; cloud vendor outages can therefore leave gaps.
- GDPR fines: while some policies cover notification and remediation costs, regulatory fines are often excluded or limited; under UK law the Information Commissioner's Office (ICO) can levy penalties, insurers may limit support for fines. See ICO guidance: ICO guidance.
Check whether cover for defence costs, regulatory enquiries and fines is explicit, and whether notification costs are included within BI limits or separate.
Business Interruption from Cyber Attacks vs Physical Damage Cover
For UK retail SMEs, Business Interruption from Cyber Attacks vs Physical Damage Cover is not an either/or choice in many cases. The two policies respond to very different events, and understanding the gap is essential when reviewing risk and arranging insurance.
| Aspect |
Cyber business interruption |
Physical damage business interruption |
| Trigger |
Cyber incident, ransomware, system outage, malicious data access |
Insured physical damage such as fire, flood or escape of water |
| Main exclusions |
Poor cyber hygiene, unpatched systems, pre-existing outages, uninsured third-party failures |
No physical damage, wear and tear, gradual deterioration, many non-damage events |
| Claims process |
Evidence of cyber event, IT logs, restoration costs, loss of revenue linked to downtime |
Evidence of insured damage, repair timelines, stock checks, trading interruption |
| Typical example |
EPOS or till systems encrypted, website checkout fails, stock ordering stops |
Shop flood forces closure for repairs, preventing trading |
When a business may need both covers
Many retailers need both because a cyber event can halt trading without any physical damage, while a fire or flood can still trigger traditional interruption losses. Business Interruption from Cyber Attacks vs Physical Damage Cover should therefore be assessed alongside a business’s reliance on online sales, EPOS, cloud systems and outsourced IT providers.
How insurers treat hybrid losses
Hybrid losses can be contentious. If a cyber incident causes a physical event, or a physical incident triggers a cyber outage, insurers may examine which policy responds first, whether both are involved, and whether any exclusions apply. Clear wording, coordinated limits and named dependent business interruption extensions can help reduce disputes.
Which UK SMEs should review both policies?
Retail SMEs with online sales, card payment dependency, stock management systems or third-party hosting should check whether their cyber policy includes BI, and whether their property policy excludes non-damage losses.
How to compare combined policies: questions to ask insurers
A simple checklist of вопросы to use when obtaining quotes helps spot meaningful differences.
- How is an "incident" defined for BI triggers, technical failure, unauthorised access, or both?
- What is the indemnity period and how is gross profit calculated for retail sales?
- Are card‑scheme fines, PCI costs and chargebacks included or excluded?
- Is dependent business interruption included? If yes, are suppliers named or automatically covered?
- What waiting period/excess applies to BI losses? Is it time-based (hours/days) or monetary?
- Are ransomware payments covered, and are there restrictions or approval clauses?
- What sublimits apply to cyber BI, ransomware, legal/regulatory costs and forensic expenses?
- Are voluntary PR or crisis‑management costs covered to protect reputation and recovery of trade?
- Does the policy cover e‑commerce downtime separately (e.g. loss of online sales while website is down)?
- What claims examples can the insurer provide for retail clients (dates, size, outcome)?
When insurers answer, request wording or clause references rather than verbal summaries. Where possible, obtain sample policy wordings for review.
Quick decision flow for retail SMEs
🛒 Step 1 → Assess exposure: POS, e‑commerce, suppliers
⚙️ Step 2 → Map controls: backups, MFA, PCI compliance
📄 Step 3 → Compare wording: indemnity period, DBI, sublimits
✅ Result → Choose combined cover if core trading depends on digital systems and supplier outages cause material revenue loss
Deciding if combined cover suits your retail SME
A pragmatic approach reduces cost and avoids redundant cover:
- Quantify exposure: estimate daily gross profit and the potential days of lost trade for a realistic outage. If a short outage would cause negligible loss, separate cyber cover without BI may suffice.
- Map dependencies: list critical suppliers (payments, EPOS, fulfilment) and ask whether supplier failure would stop revenue. Dependent BI becomes more relevant if multiple suppliers are single points of failure.
- Evaluate controls: insurers favour MFA, tested backups, PCI DSS compliance and patch management. Strong controls can lower premiums and broaden insurer appetite. The NCSC outlines basic cyber hygiene that insurers commonly reference: NCSC tips.
- Balance limits vs sublimits: a large overall limit with low sublimits for BI may not help; prefer clarity on BI sublimits and whether they are part of the overall sum insured.
Advantages, risks and common mistakes
✅ Benefits / when combined cover helps
- Single claims process for technical and BI losses.
- Potentially broader response including forensic, legal and PR costs.
- Easier modelling for events that cause both cyber remediation and lost takings.
⚠️ Errors to avoid / risks
- Buying low premium cover that excludes dependent supplier losses or has short indemnity periods.
- Accepting vague definitions of interruption that restrict claims.
- Assuming regulatory fines or card‑scheme penalties are covered (they frequently are not).
Practical checklist to reduce premium and improve terms
- Maintain and demonstrate MFA, endpoint protection, patching and tested backups.
- Keep PCI DSS evidence and card processing contracts ready.
- List and categorise suppliers by criticality; insist on SLAs with cloud EPOS providers.
- Create a simple manual fallback for tills or card acceptance to reduce actual lost takings and waiting period exposure.
Frequently asked questions
What is combined BI and cyber cover for retail SMEs?
Combined cover is a policy structure that pays for cyber incident costs and the subsequent business interruption losses (lost gross profit) arising from that incident. It links technical response and trading loss assessments.
How long should the indemnity period be for a retail business?
It depends on recovery time and seasonality. Many retailers choose 3–12 months; where supply-chain recovery or stock replacement is complex, longer periods may be needed.
Will insurance pay for card chargebacks after a breach?
Some policies include chargeback cover but others exclude card‑scheme penalties. Confirm whether chargebacks, PCI costs and fines are explicitly covered.
Do insurers cover ransomware payments in the UK?
Some insurers cover ransom payments subject to conditions and approval. Insurers increasingly restrict or require specialist negotiation before payments; wording varies significantly.
Is dependent business interruption usually included?
Not always. DBI may be optional, limited by sublimit or only apply to named suppliers. Ask for clear wording or extensions if supplier risk is material.
Can a small shop reduce premium by improving controls?
Yes. Insurers commonly offer better pricing or broader terms where MFA, backups, patching, and documented incident response plans exist.
Initial steps include isolating affected systems, contacting a cyber response provider, and if personal data is involved, checking ICO requirements on reporting. Insurers often provide breach coaches and forensic partners.
Your next step:
- Calculate a simple daily gross profit figure (turnover × gross margin) and multiply by plausible outage days to estimate BI exposure.
- Request sample policy wordings that include BI, DBI and ransomware clauses; compare indemnity period, waiting period and sublimits.
- Prepare evidence of cyber controls (MFA, backups, PCI compliance) to present to insurers and brokers when seeking quotes.