Cyber insurance is usually wise for pubs and restaurants that take cards or use online bookings. Get a hospitality-specific quote and check exclusions for third-party integrations and incident response times.
Exception: if the business takes no cards and has no connected systems, this advice may not apply. In that case, there is little breach or downtime risk.
Why pubs and restaurants need cyber insurance now
In the context of hospitality risk, digital systems are central to trading. According to the UK Government Cyber Security Breaches Survey 2023, 39% of small businesses reported a cyber breach. This risk hits pubs and restaurants through EPOS, bookings and delivery integrations.
Pubs and restaurants trade on narrow margins and daily peaks. A single incident can cost tens of thousands in lost takings. Insurance shifts the immediate cash burden and pays for a professional response.
Keep the insurer's hotline number by the till.
What cyber policies cover for hospitality businesses
In the context of cover, cyber policies for hospitality commonly include these elements. Read each policy wording and confirm limits and sub-limits.
- Forensic investigation to find the cause and scope of an incident.
- Breach coach and legal costs for data breach notification and regulator advice.
- Business interruption for lost takings linked to EPOS, bookings and delivery downtime.
- Payment fraud and card manipulation cover for EPOS malware or skimming.
- Ransomware response including negotiation, recovery and possible ransom payment.
- Reputational and PR costs to manage customer communications and mitigation.
Before
Patch *EPOS*. Use *MFA*. Back up the till so an offsite copy exists.
During
Isolate systems. Call the insurer's hotline. Capture logs and receipts.
After
Forensics, *BI* estimates, PR and regulator reporting.
Common cyber threats to POS and bookings systems
In the context of EPOS risk, attackers seek card data, credentials and payment routing. EPOS machines with outdated software attract malware and remote access tools. Attackers also pivot via staff devices that share the network.
Delivery and booking platforms add supply-chain risk. Many integrations use API keys and webhooks. Insurers often exclude vendor-caused failures or require vendor security controls.
A typical claim is instructive: an independent city pub suffered POS malware. Card data was exposed and three days of trading were lost. The business claimed for forensics, card replacement costs and BI. The total paid was about £28,000.

How cover handles ransomware, data breaches and GDPR fines
In the context of ransomware and breach cover, policies vary by insurer and wording. Ransomware cover usually pays for negotiation, forensics and restoration work. Some policies also pay ransom subject to legal and underwriting approval.
Insurers often appoint specialist negotiators and forensics teams. Data breach cover pays notification costs, credit monitoring and legal defence. The ICO expects notification of some breaches within 72 hours.
If the insurer requires immediate reporting, a delay can invalidate cover. GDPR fines are rarely fully insured. Some policies offer defence costs and civil penalties cover where allowed.
Policy limits and exclusions vary, so read the wording closely.
Insurers commonly require immediate reporting of incidents. Keep the insurer's 24/7 hotline number by the till and on staff rotas.
If your *EPOS* supplier is contractually responsible for security, the insurer may exclude losses caused directly by that supplier. Check vendor SLAs before buying cover.
Reputational damage costs and a quick comms checklist. Reputational response can be a material cost for hospitality businesses. It should be budgeted separately or insured via a PR sub-limit.
Typical small pub or restaurant PR costs start around £1,000. Costs often reach £8,000 for wider reach. Larger incidents can run to £10,000 to £25,000 when agencies or paid adverts are needed.
Practical steps to prepare are simple. Use this checklist before an incident:
- Prepare a 48-hour holding statement.
- Create a dedicated status page or social post template.
- Identify a named spokesperson.
- Collect customer contact data for notifications.
- Agree PR spend authorisation with your insurer.
Check the policy sub-limit for reputational costs. If the limit looks small, increase it or pre-agree a named PR supplier.
Keep the insurer's hotline number by the till.
Cyber insurance for hospitality pubs and restaurants limits
In the context of limits, think realistically about peak trading. Business interruption for a Saturday evening must be modelled separately from average weekly takings. Sub-limits for notification or PR can quickly be exhausted.
Typical market ranges for UK SMEs run from £300 to £2,000 per year. Prices depend on turnover, card volumes and chosen limits. According to Sophos State of Ransomware 2023, 46% of organisations reported ransomware.
| Criterion |
Standalone cyber policy |
Combined commercial policy |
Add-on to liability/property |
| Coverage breadth |
Broad cyber-specific wording and response services |
Good cover but subject to combined wording limits |
Limited, often excludes ransomware or *BI* |
| Typical cost for small SME |
£400–£1,500 per year |
£300–£1,200 per year |
£150–£600 per year |
| Best if |
You rely on *EPOS* and take cards directly |
You want one policy for multiple risks |
You need minimal token cover on a budget |
| When to choose |
If *EPOS*, bookings and delivery integration risks are material |
If you prefer convenience and wider business cover |
If you accept significant exclusions for lower cost |
Choose a standalone cyber policy when EPOS and payment fraud are central. Combined policies suit those who want one policy for many risks. Add-ons cost less but often leave gaps.
Practical steps to reduce premiums and claim risk
In the context of controls, insurers give better pricing when basic controls exist. Implement these controls and document them. Small changes that are shown will help at renewal.
- Keep EPOS and booking software patched and supported.
- Use multi-factor authentication for admin and remote access.
- Enforce separate networks for POS and guest Wi-Fi.
- Maintain offline, immutable backups and test restores weekly.
- Train staff on social engineering and payment fraud checks.
Small, documented changes to controls will reduce risk and improve an insurer's view. Reductions in premium or excess are not guaranteed. Improvements usually show at renewal once underwriters reassess risk.
Keep the insurer's hotline number by the till.
Downloadable templates and quick-start resources. These tools speed insurance and incident response for busy operators. Offer simple, editable files that staff and the insurer can use on day one.
- One-page risk assessment for EPOS and integrations.
- A PCI and GDPR checklist tailored to hospitality.
- A short incident-log template to capture timestamps and contacts.
- Two communications templates: a 48-hour holding statement and a full customer notice.
Operators who provide these items to staff and the insurer’s forensics team will speed triage and evidence capture.
The factors to decide
In the context of buying cover, the main variables are turnover, card volume, number of integrations and appetite for downtime. Also consider contractual requirements with platforms and landlords.
Ask three simple questions before you quote:
- How much daily takings would you lose in a 48-hour outage?
- What payment flows rely on third parties?
- How quickly can you restore systems?
When you have simple EPOS and few integrations
If the business uses a single EPOS, an off-the-shelf standalone policy with a modest limit usually suffices. Choose a low excess and confirm BI wording covers lost bookings and takeaway revenue. Keep vendor contracts and receipts to speed claims.
When you use multiple delivery and booking integrations
If multiple delivery apps and booking platforms are core to income, buy cover that explicitly includes third-party integrations. Check for exclusions that name vendors or exclude supplier failures. Consider higher limits for PR and reputational costs.
Errors to avoid when buying cover
In the context of common mistakes, do not assume property or public liability will cover a cyber incident. Many buyers make this mistake and then find key costs excluded. Do not buy solely on price without reading exclusions for EPOS, payment processors and social engineering.
Underinsuring BI is common. Model weekend takings and ensure your indemnity period matches recovery time, not average weekly revenue.
Keep the insurer's hotline number by the till.
Frequently asked questions
What does cyber insurance cover?
Cyber insurance covers forensic work, breach coaching, legal defence and customer notification costs. It pays for PR and regulator liaison in many policies. For hospitality, confirm EPOS, payment fraud and booking platform downtime are covered specifically.
Do pubs and restaurants need cyber insurance?
Most do. Pubs and restaurants accept cards and use online booking or delivery systems. Those systems carry data breach and downtime risk. If the business has no card payments and no connected systems, insurance may not be necessary.
How much does cyber insurance cost for small business?
Costs vary by turnover, card volumes and controls. Typical UK SME premiums range from £300 to £2,000 annually. Higher limits, ransomware cover and low excesses increase cost. Prepare evidence of controls to get the best price.
Does cyber insurance cover ransomware?
Yes, many policies cover ransomware response, negotiation and recovery costs. Some will pay a ransom where legal and under insurer approval. Policies differ on ransom limits and excluded payouts. Always follow insurer notification rules when attacked.
Will it cover payment card fraud?
Insurers cover EPOS malware and card data theft when wording includes payment fraud. Coverage may exclude losses caused by third-party payment processors. Check your policy for named exclusions and vendor security conditions.
How do I make a cyber insurance claim?
Call the insurer's 24/7 incident hotline immediately. Preserve logs, receipts and images of affected systems. Follow the insurer's instructions and engage the appointed forensics team. Timely reporting usually speeds payments and avoids coverage disputes.
Is cyber insurance required by law?
No law forces businesses to buy cyber insurance. However, contracts or lenders may demand it. The ICO requires appropriate security and breach notification. Insurance does not remove regulatory duties.
Cyber insurance for hospitality pubs and restaurants
This cover should explicitly list EPOS, bookings and delivery integrations. Check exclusions for supplier failures and confirm BI wording covers lost bookings and takeaway income. For many hospitality SMEs, tailored cyber cover is cost-effective and practical.
Keep the insurer's hotline number by the till.
Practical claims timeline and what to expect. Immediate steps in a typical claim run like this. Times vary by insurer and complexity, but these expectations help with staffing and cashflow planning.
- 0–4 hours: isolate systems, preserve logs and call the insurer hotline.
- 4–24 hours: insurer triage and appointment of a forensic provider.
- 24–72 hours: forensic scoping, initial BI estimate and first PR holding statement.
- 3–14 days: deeper restoration work and BI quantification.
- 2–8 weeks: regulator liaison, final BI settlement and supplier recovery.
Conclusion
Cyber insurance for hospitality protects trading by funding forensics, BI and response. Check for exclusions relating to third-party integrations and verify BI calculations for peak days. Get a hospitality-specific quote and prepare simple evidence of controls before you buy.
UK Government Cyber Security Breaches Survey 2023
Information Commissioner's Office guidance on data breaches