A historic cyber incident can become a costly problem at renewal time, especially for an SME with limited IT resources and a new insurer asking awkward questions. The real issue is not just whether a breach happened, but whether it was known, when it was notified, and whether any gap in cover leaves the business exposed.
Retroactive cover can sometimes help with historic cyber breaches, but only if the incident is not excluded, the claim is first made within the policy period, and the retroactive date reaches back far enough. Prior acts cover is similar, but the details vary by insurer. For SMEs, the key is checking dates, continuity, known incidents, and exclusions before buying.
Can a past breach still be covered?
A past breach can sometimes still be covered under a claims-made policy, but the dates must line up. That means the claim has to land inside the policy period, and the policy has to reach back to the right retroactive date. If either one is wrong, the door usually closes.
Retroactive cover/prior acts for SMEs with historic breaches sounds neat on paper. In practice, it works more like a locked filing cabinet with two keys. One key is the date of the incident. The other is the date the claim gets made. Both matter.
A simple way to think about it: the incident is the accident, but the policy is the umbrella you open later. If the umbrella was not open at the right time, the rain still gets you wet.
Gold answer for SME owners
The safest answer is this: buy retroactive cover only when you can prove the old breach was not known, not reported, and not excluded. If the facts are messy, the insurer may still refuse the claim even with a long retroactive date.
For many SMEs, that means the value sits in continuity. If cover has run without gaps, and the wording is broad, a later claim may still be possible. If there was a break in cover, the gap often becomes the weak point.
A claim under a claims-made policy is about when the claim appears, not only when the problem began. That is the part many owners miss, and it leads to nasty surprises later.
When a historic breach may still be claimable
A historic breach may still be claimable when the company only discovers it later and had no reason to know before inception. That can happen with old stolen emails, dormant ransomware traces, or a supplier-linked data leak found months later.
The breach also needs to sit inside the policy's backdated scope. If the retroactive date reaches before the incident, and no exclusion bites, the claim may survive underwriting scrutiny.
A claims-made policy is judged by the claim date first, then the retroactive date. If the claim is first made after expiry, it usually falls outside cover.
When it is usually excluded already
A known breach is usually the end of the story. If the business had notice before buying, even a generous retroactive date will not rescue it.
The other common blocker is delay. If a firm sits on a breach for weeks and only tells the insurer after the window has closed, the insurer may refuse notification costs, forensic work, or the full claim.
Unreported loss, half-known facts, and vague recollection make poor claim material. The insurer will ask what the business knew, when it knew it, and who knew it.
Choose this if: the breach is old, the facts are clear, and no one knew about it before the policy started.
A useful rule of thumb for SMEs is that retroactive coverage is far more likely to respond to a historic cyber breach that was genuinely unknown at policy inception than to one that was already on the radar. If the business had a known incident, a suspicious login pattern, a supplier warning, or even a half-finished internal investigation before inception, underwriters may treat it as a known incident and refuse cover even where the policy includes backdated cover.
By contrast, a breach discovered only later through logs, customer complaints or a forensic review may still fit, provided the claims-made policy was in force, the notification window is met and there is no excluded loss.
Compare cover options before you buy
The best choice depends on what the old event looks like and how the policy wording is written. Retroactive cover, prior acts cover, and full prior acts coverage often sound similar. They are not always the same thing.
For UK SMEs, the question is not which label sounds broader. The question is which wording actually protects a real historic breach without falling apart at claim time.
| Option |
What it usually means |
Best for |
Main risk |
Typical pricing impact |
| Retroactive cover |
Cover for events that happened after a set date, if the claim is made during the policy period. |
SMEs with a known incident date and no long gap in cover. |
Known circumstances and late notice can still block it. |
Often adds 5% to 20% in wider wording, depending on the insurer and sector. |
| Prior acts cover |
Cover for earlier acts or omissions, usually with wording tied to when the act happened. |
Businesses moving insurer and worried about older unseen issues. |
The wording may still ask for no prior knowledge. |
Can sit near standard pricing, but some insurers charge more for long backdating. |
| Full prior acts coverage |
A broader promise to cover earlier acts, sometimes with no fixed start date, subject to the wording. |
SMEs with long insurance history and clean disclosure. |
The insurer may still exclude known breaches and undisclosed facts. |
Often the highest premium of the three, especially where controls are weak. |
Comparison table: what each option does
Retroactive cover is usually about how far back the policy reaches. Prior acts cover is usually about whether earlier acts themselves count. Full prior acts coverage is often the broadest label, but each insurer uses it differently.
That wording gap matters. The British Insurance Brokers' Association regularly warns firms to read the wording, not just the brochure name, because wording is what decides a claim.
The cheapest quote is often the one with the shortest backdating, the strictest exclusions, or both. That is why the premium alone tells only half the story.
Which option fits which SME
Retroactive cover suits a company that knows the incident date and wants a clean backstop. Prior acts cover suits a buyer worried about earlier mistakes during a switch between insurers.
Full prior acts coverage suits a business with a long, quiet history and strong controls. It looks generous, but it still depends on disclosure and the insurer's exact wording.
A case like this comes up often: a London retailer changes insurer after a supplier email leak. The new policy looks broader, yet the insurer later asks when the firm first suspected the leak. That one answer can decide the claim.
When continuity makes the difference
Continuity means the cover runs without a gap from one policy to the next. If the firm renews on time, backdating may stay alive. If the firm lets cover lapse, the old period can become uninsured.
That is why renewal dates matter as much as breach dates. A gap of even a few days can become awkward if the first claim notice lands in the wrong window.
Choose this if: the business is switching insurer and wants the broadest possible read on old acts.
For SMEs, the practical difference between retroactive cover, prior acts cover and full prior acts coverage is worth spelling out in plain English. Retroactive cover usually focuses on how far back the retroactive date reaches; prior acts cover is often used when the insurer agrees to pick up earlier acts within a claims-made policy; full prior acts coverage is the broadest label, but it still depends on the wording at policy inception.
A sensible buying check is to confirm the retroactive date, ask whether continuity of cover has been preserved, verify whether any coverage gap exists, and check whether the policy quietly narrows protection through conditions, exclusions or a strict notification window.
Known breach, undiscovered breach or future claim
These three cases look similar at first glance. They are not the same. The insurer will treat them differently, and the answer often changes the moment the company admits it had prior warning.
The practical test is simple. Ask whether the company knew, should have known, or had no real reason to suspect the problem before buying the policy.
Already known before buying
A known breach is usually the hardest case to insure. If a director saw the warning signs, got a solicitor's letter, or told the IT provider to investigate, the insurer may call that a known circumstance.
That is where many claims fail. The error most firms make is to think an old incident becomes insurable again after a fresh policy is bought. It does not work like that if the facts were already on the table.
The Information Commissioner's Office treats breach handling seriously under the UK GDPR and the Data Protection Act 2018, and insurers do too. If a firm knew and kept quiet, the risk of refusal rises fast. ICO breach guidance
Hidden at the time of inception
An undiscovered breach is the better case. The firm had no meaningful clue, and the issue only surfaced later through logs, customer complaints, or a forensic review.
This is where retroactive cover can help. It is the insurance version of finding water damage after the storm, not during it.
The catch is evidence. If the insurer sees signs that the breach was already visible, the claim can still fail on knowledge wording or late notice.
A future claim from an old event
A future claim from an old event is common in cyber. The attack may have happened months ago, but the claim arrives only when a customer complains or a regulator asks questions.
That delay can still fit a claims-made policy, but only if the claim is first made inside the policy term. Claims-made wording is the gatekeeper here.
Choose this if: the breach was genuinely hidden when the policy started and the first claim arrives later.
Checks before renewal or switching insurer
This is the part that saves money and trouble. A few minutes spent checking dates can stop a denied claim months later. That is the real value in retroactive wording.
The biggest mistake is treating renewal like a price-only exercise. For cyber, the cheapest policy can be the most expensive one when an old breach comes back.
Check your retroactive date
The retroactive date should sit on or before the earliest possible breach. If it starts too late, older events fall outside cover.
Ask for the date in writing. Do not rely on a sales summary. The policy wording decides the fight, not the quote page.
Confirm continuous cover gaps
A gap between policies can break the chain. If the firm changed insurer and left a month uncovered, the historic claim may have nowhere to land.
The Association of British Insurers often stresses continuity for claims-made classes because the trigger is the claim, not just the event. That logic matters even more when the event is old. ABI cyber insurance guidance
Review the knowledge date wording
The knowledge date tells the insurer when the firm first knew, or ought to have known, about the problem. If that date sits before inception, coverage can vanish.
This wording is a quiet killer. It looks harmless in the schedule. Then it becomes the reason the claim is declined.
Ask about prior acts wording
Ask whether the policy uses prior acts cover, full prior acts coverage, or a strict backdating date. Those phrases are not interchangeable.
The Financial Conduct Authority expects firms to give fair, clear information at sale. That matters because unclear wording around old incidents creates avoidable disputes later. FCA insurance guidance
If the broker cannot explain the retroactive date, the knowledge wording, and the continuity position in plain English, the quote is not ready.
Choose this if: the business is renewing, switching insurer, or trying to protect a past event before signing.
Before buying SME cyber insurance, it helps to run a simple checklist against any historic cyber breach exposure. First, confirm the policy inception date and whether the retroactive date reaches back far enough to capture the oldest possible incident. Second, check that there has been continuity of cover with no lapse between renewals, because a coverage gap can break the chain. Third, ask the broker whether any excluded loss wording, known incident wording or prior-knowledge clause could remove the claim.
Make sure the policy allows time for cyber incident notification, because even a valid claim can fail if the insurer is told too late.
Exclusions that kill old-breach claims
Exclusions do the real damage. Many policyholders focus on the date. The insurer often focuses on the wording that stops cover even when the date looks fine.
That is why a historic breach can still fail after a careful backdate. The policy may reach far enough back, but the exclusion list closes the trapdoor.
Known circumstances exclusions
A known circumstances exclusion blocks cover when the firm knew about the issue before the policy started. It is common, and it is often decisive.
A warning sign can be small. A suspicious login, a missing laptop, or a supplier email bounce can be enough if the firm should have escalated it earlier.
Minimum controls and security conditions
Some policies require basic controls, such as multi-factor authentication, patched systems, or backups. If the business failed to keep those controls, the insurer may refuse the claim.
The National Cyber Security Centre has long said that small firms should keep core protections simple and current, because weak basics make attacks easier and recovery slower. NCSC small business guidance
Late notification and delay
Late notification can ruin an otherwise good claim. If the policy says notice must be given within a set time, missing that window may cut off cover.
The practical lesson is blunt. Tell the insurer as soon as the issue looks real, not after the firm has spent days debating whether it counts.
Deliberate non-disclosure risks
Deliberate non-disclosure can void the policy or narrow the claim. Under the Insurance Act 2015, fair presentation and proper disclosure matter, especially on renewal and when the business switches insurer.
That means a director should not hide the awkward email chain or the half-investigated incident. If the underwriter later finds it, the whole claim position weakens.
Choose this if: the firm has clean controls, clear notice, and no hidden history that needs to be disclosed.
The hidden cost of retroactivity
Retroactive wording can look cheap when the quote lands. The extra cost sits elsewhere, especially in underwriting time, documentation, and tougher questions.
This is where many guides go soft. They talk about premium only. They skip the hidden cost of proving an old event was not already in sight.
The extra premium for broader backdating is often modest on paper, but the real cost can be more disclosure work and a narrower insurer appetite.
The extra premium usually pays for more risk taken by the insurer. Older acts are harder to price because records are thin and memories fade.
For a small business, that means one thing. A cheaper policy may only be cheap because it is taking less historic risk.
Where the price jumps fast
Price jumps are common where the firm handles personal data, payment data, or third-party access. London-based firms in regulated sectors often pay more because the knock-on loss can be wider.
The UK Government's cyber security breach survey has repeatedly shown that breaches remain common among smaller firms, which helps explain why insurers treat weak controls with care. UK cyber breaches survey 2024
When paying more is still worth it
Paying more can make sense if the business has a real, unresolved historic issue and strong records. In that case, the policy may protect a risk that would otherwise sit entirely on the balance sheet.
The opposite is also true. If the breach is already known, the extra premium buys little or nothing.
Choose this if: the business needs backdated protection and can prove the old event was not known earlier.
Can prior acts protect against GDPR fines?
Sometimes, but not safely enough to assume it. Civil and regulatory exposure can be covered in parts, but fines are tricky and the wording matters a lot.
The UK GDPR and Data Protection Act 2018 sit at the centre of this issue. The Information Commissioner's Office can investigate, and insurers often separate defence costs from any penalty itself.
What may be covered
A policy may cover legal defence, forensic work, notification costs, and third-party claims linked to a data breach. Those are often the practical bills that hit first.
That can be valuable for an SME. A forensic investigator alone can cost more than the annual premium in a bad case.
What may not be covered
Many policies will not pay a fine if law or public policy stops them. Even where a policy mentions regulatory cover, the exact wording can still limit what is paid.
The Crown Prosecution Service and criminal law issues can complicate matters too, especially where computer misuse is alleged under the Computer Misuse Act 1990. That is not the same as a civil data claim.
Why wording beats headlines
The headline may say cyber liability. The real answer may be narrower. A policy can help with defence, yet still leave the penalty itself outside cover.
That is why a broker should show the exact wording on regulatory cover, not just a marketing summary. Without that, the buyer is guessing.
Choose this if: the main concern is defence costs, notification costs, and third-party claims, not a guaranteed fine payment.
What nobody tells you
The best policy is often the one that answers one awkward question cleanly: what did the business know, and when did it know it? If that answer is messy, even a broad retroactive date can fail. This works well in theory, but in practice the claim often turns on one email, one report, or one quiet warning that nobody escalated.
The claim file decides the outcome
A clean claim file often beats a broad sales promise. Emails, incident notes, vendor tickets, and board minutes can all change the insurer's view.
If the evidence shows the issue was spotted early, the claim weakens. If the evidence shows discovery came later, the claim gets stronger.
Brokers matter, but only up to a point
A good broker can spot bad wording and ask the right questions. A weak one may only compare premiums and miss the old-breach trap.
The majority of guides say ask for broad cover. What they omit is that broad wording without honest disclosure can be worse than a narrower policy with clean terms.
One edge case to watch
If no policy ever covered the period, and the breach was discovered late, the answer may be no cover at all. That can feel harsh, but it is a real outcome.
In that case, the business should still map the loss, tell the right parties, and fix the controls. Insurance may be gone, but the response still matters.
This advice does not fit a brand-new cyber event, a pure price comparison, or a business with no claims-made cover history. In those cases, dates and backdating matter less than the basic policy fit and current controls.
Frequently asked questions
Does retroactive cover pay for a breach i knew
Usually not. Retroactive cover does not rescue a breach that was already known or reasonably suspected before inception. The insurer will look at the knowledge date, prior reports, and any sign that the issue was being investigated. For SMEs, that is the key limit. A historic breach only stays possible when it was genuinely hidden and first claimed inside the policy period.
Is prior acts cover the same as retroactive cover?
No, not always. The two ideas overlap, but insurers use them differently. Retroactive cover usually points to how far back the policy reaches. Prior acts cover usually focuses on whether earlier acts or omissions themselves are covered. Full prior acts coverage can be broader, yet the wording still matters more than the label on the quote.
Can a claims-made policy cover an old cyber
Yes, if the claim is first made during the policy term and the wording reaches back far enough. That is the point many owners miss. The incident date alone does not decide the claim. The claim date, the retroactive date, the continuity of cover, and the exclusions all need to line up.
What if the breach was discovered after the
That can still work. If the breach was genuinely undiscovered when the policy began, and the insurer did not ask about known circumstances that would catch it, the claim may be covered. The firm still needs to notify quickly and keep evidence. Delay can turn a usable claim into a refusal.
What documents should an SME keep before claiming?
Keep a timeline, emails, alert logs, incident notes, and any regulator or customer notices. Those papers show what the company knew and when it knew it. They also help the broker and insurer test the retroactive date, the knowledge wording, and whether the loss sits inside the policy period.
It can be, but only when the business has a real historic risk and no known breach problem. Broader backdating costs more because the insurer takes on older uncertainty. If the issue is already known, the extra premium usually buys little value. The best use is a clean, uncertain, not-yet-known incident.
Which option fits your situation
If the business has a genuine historic breach, prior acts or retroactive cover may be worth paying for, but only when the claim is still alive on the policy dates and the facts were not already known. If the company already knew about the incident, the money is usually better spent on remediation and disclosure discipline. If the business is switching insurer, continuity and wording matter more than the headline price.
Buy the broader wording if...
Choose the broader wording if the firm has an old, undiscovered issue and wants the best chance of backdated support. That suits SMEs with good records, clean disclosure, and no gap in cover.
It also suits companies handling personal data, supplier access, or payment details, where the investigation bill can land fast. In those cases, the extra premium may buy real breathing room.
Avoid it if...
Avoid it if the breach is already known, under investigation, or likely to appear in a future disclosure question. The policy may not survive contact with those facts.
Avoid it too if the insurer will only offer a weak backdate and heavy exclusions. That is not protection. It is a false sense of security.
The safest real-world choice
For most UK SMEs, the safest choice is a policy with a clear retroactive date, no gap in cover, and plain wording on known circumstances. That gives the best mix of value and certainty.
If no option fits cleanly, the honest answer is that no policy should be bought on hope alone. In that case, the firm should fix the controls, document the incident, and get the facts straight before asking for cover.
Will prior acts cover pay UK GDPR fines?
Not reliably. Some policies may help with defence costs, forensic work, and notification expenses, but fines are often excluded or limited by law. The wording needs checking line by line. An SME should never assume a policy that covers cyber liability will automatically pay every regulatory outcome.