UK online retailers taking card payments need a policy that covers card-not-present fraud, chargebacks and breach response costs. For most SMEs a payment-fraud enhanced policy is best. High-volume merchants should choose a broker-managed programme with PCI extension.
Best cyber insurance for online retailers with card payments
| Criteria |
Standard SME policy |
Payment‑fraud enhanced policy |
Broker‑managed PCI extension |
| Typical payment‑fraud sub‑limit |
£10,000 total. Per‑incident cap £2,500. |
£50,000 total. Per‑incident cap £10,000. |
£100,000 total. Per‑incident cap £25,000. |
| PCI/GDPR defence costs |
Up to £100,000. Fines often excluded. |
Up to £250,000. Fines capped or excluded. |
Up to £500,000 defence costs. Fine cover negotiable. |
| Typical premium band for turnover |
£300–£800 pa for turnover < £250k |
£800–£2,500 pa for turnover £250k–£1m |
£2,500–£6,000 pa for turnover £1m–£5m |
| Policy wording example |
"Cover for unauthorised access and resulting data loss." |
"Extension: payment transaction fraud caused by credential compromise." |
"Broker arranges specific merchant liability terms with PSP endorsements." |
| When to choose |
Low volume card sales and limited chargeback history. |
Medium volume merchants taking CNP payments frequently. |
High volume merchants or those with strict PSP contracts. |
Choose the option that matches transaction volume and contract risk. For most small online shops a payment-fraud enhanced policy balances cost and protection.
Standard SME cyber policy
A standard SME cyber policy covers breach response, business interruption and basic liability. It normally has a low payment‑fraud sub‑limit. Many insurers set a per‑incident cap. Merchants who rely only on a standard policy often find chargebacks hit that cap quickly.
Advantages include lower premiums and broad general cover. Limitations include small sub‑limits for card fraud. Policies may exclude statutory fines. Insurers usually expect basic security such as MFA and up‑to‑date patching.
This choice suits very small shops with low card volumes. It suits merchants with little chargeback history.
Take a moment to review.
Payment‑fraud enhanced policy
A payment‑fraud enhanced policy adds a dedicated payment fraud extension. That extension raises sub‑limits for CNP fraud and chargebacks. It usually gives a higher per‑incident cap and fraud investigation costs.
This option fits merchants with frequent online card sales. The downside is a higher premium and stricter underwriting checks. Insurers will ask about PSP terms, transaction screening and refund controls.

Broker‑managed programme with PCI extension
A broker‑managed programme negotiates bespoke terms for high transaction merchants. It can include negotiated cover for PCI liabilities and tailored PSP wording. Often brokers secure higher limits and better claims support.
This option suits merchants with complex PSP contracts or large turnover. The downside is higher cost and sometimes a broker fee. It also needs more documentation at inception.
Consider merchant needs.
Which UK online retailers need cover
Retailers who store card data or take card payments online need cover. Shops that use CNP transactions face greater fraud risk. Businesses with recurring payments or subscriptions need stronger protection.
Merchants operating on marketplace platforms may not need the same cover; they must confirm who holds liability in each case.
Not all PSPs are equal when insurers assess risk or respond to claims. Some providers offer dispute handling, chargeback help or optional chargeback protection products. Those services have strict eligibility rules and do not move regulatory or contractual liability away from the merchant.
Underwriters will ask for the merchant‑service agreement and any evidence of PSP chargeback protection. They may reduce the insurer’s payment‑fraud exposure where the PSP covers losses. Alternatively, they may add endorsements excluding amounts recoverable from the PSP.
Merchants should obtain written confirmation from their PSP on chargeback liability and include that confirmation in the insurance submission. They should be ready to show compliance with the PSP’s dispute procedures during a claim to avoid cover disputes.
Review the next steps.
Which card‑payment risks to insure
In the context of card payments the main risks are card‑not‑present fraud, chargebacks and contractual liability with PSPs. Insurers treat each risk differently.
Many insurers place payment‑fraud on a sub‑limit or exclude it without an extension. They also scrutinise PSP terms that shift liabilities to the merchant.
Ensure your policy lists payment‑fraud sub‑limits and per‑incident caps in writing before purchase.
If the payment service provider (Stripe, PayPal) contract shifts chargeback responsibility to the merchant, some insurers may reduce cover.
When a CNP fraud event happens a worked example helps. Imagine a fraudster uses stolen card details to place ten online orders totalling £12,500. If the policy has a payment‑fraud sub‑limit of £10,000 and a per‑incident cap of £2,500 the insurer would pay only £2,500 for the first incident. The insurer would then refuse the remainder, leaving the merchant to absorb £10,000 plus chargeback fees and acquirer penalties. Chargeback fees typically range £10–£25 per dispute.
Insurers expect contemporaneous evidence such as transaction logs showing IP anomalies, AVS/3DS results, PSP dispute paperwork and customer contact attempts. Forensic reports speed payment and avoid disputes over whether a chargeback was fraudulent or merchant error.
Check your documentation now.
How policy size and structure affect premium
Premiums depend on turnover, transaction volume and past incidents. Higher turnover and more card transactions raise premiums. Underwriting also looks at PSP terms and security controls.
Sample premium ranges under current market conditions are:
- Turnover < £250k: £300–£800 pa.
- Turnover £250k–£1m: £800–£2,500 pa.
- Turnover £1m–£5m: £2,500–£6,000 pa.
These ranges reflect typical insurer pricing; exact quotes depend on refunds, chargeback rates and fraud controls.
Consider the premium ranges above.
First‑party versus third‑party cover
The principal difference between first‑party and third‑party cover is who suffers the loss. First‑party covers the merchant’s direct losses. Third‑party covers claims by customers or partners.
A merchant needs both cover types. First‑party pays for breach response and lost sales. Third‑party pays defence costs and settlements for customer data breaches.
Many standard SME policies mix both types.
Note the cover-gap risk.
Hidden costs, excesses and contractual liabilities
Watch for per‑claim excesses on payment fraud and high deductibles for business interruption. Some policies have aggregate limits that apply across loss types. These hidden caps reduce real cover.
Read PSP contracts carefully. Some providers give chargeback assistance. Others transfer liability to the merchant. Insurers will test those contracts and may restrict cover.
Statutory regulatory exposure can be much larger than defence cost sums. Under GDPR the maximum administrative penalty can reach €20 million or 4% of global turnover. The ICO rarely uses the absolute maximum, but fines of several hundred thousand to low‑millions have occurred.
Compare that with a policy that only covers £100,000 of defence costs and excludes fines. A retailer facing a £300,000 regulatory penalty would meet the first £100,000 via the policy if defence is covered. The retailer would likely be left liable for the remaining fine and associated costs.
For underwriting, ask insurers for exact wording on fines, penalties and regulatory costs. Quantify worst‑case exposures by modelling a plausible fine. For example use 1%–2% of UK turnover for a mid‑sized shop.
Prepare your worst‑case numbers.
Practical checklist choosing the best policy
- Evidence of PCI compliance level and recent vulnerability scans.
- Transaction volumes and chargeback history for the last 12 months.
- Copies of PSP contracts and refund policies.
- Details of security controls such as MFA, endpoint protection and logging.
- Desired limits and payment‑fraud sub‑limits, plus per‑incident caps.
- Claims service expectations and contact details for incident response.
Claims walkthrough step by step
- Notify insurer immediately by phone and in writing. Keep copies.
- Preserve logs, transaction records and fraud evidence. Do not alter data.
- Follow insurer incident response instructions and use appointed vendors.
- Document all costs and time spent for the claim.
- Work with the PSP to dispute chargebacks where appropriate.
- Submit final costs and agree settlement with insurer promptly.
A typical claim timeline is 3–7 days for initial response. Full remediation can take 30–180 days depending on the breach.
Set realistic timelines.
What no one tells merchants about premiums and cover
Insurers often expect merchants to show active fraud controls. That expectation can reduce premium. If controls are weak insurers add conditions and increase excesses.
Many policies exclude statutory fines. For example ICO fines may be excluded or capped, though GDPR permits high fines.
According to UK Finance, card‑not‑present fraud makes up around 60% of reported card fraud, and the Hiscox Cyber Readiness Report found about 47% of UK firms suffered a cyber incident in the prior year. These figures explain why insurers focus on payment fraud controls.
Consider these statistics.
Cyber insurance for online retailers: the wider risks beyond card fraud
For many UK eCommerce businesses, card fraud is only one part of the cyber risk picture. Cyber insurance for online retailers is designed to respond to a much broader range of incidents that can disrupt trading, expose customer data and trigger costly recovery work.
Ransomware and extortion attacks
A ransomware attack can lock you out of your systems, halt order processing and delay fulfilment. The right policy may help with incident response, forensic investigation, data recovery and, where appropriate, specialist negotiation support. For online retailers, the main issue is often not just the ransom itself, but the lost sales and operational disruption that follow.
Data breaches and response costs
If customer information, payment details or login credentials are compromised, you may need to notify affected individuals, report to the ICO and manage reputational fallout. Cyber insurance for online retailers can help cover breach response costs such as legal advice, PR support, customer notifications and credit monitoring, depending on the policy wording.
Business interruption and third-party liability
A cyber incident can bring your website, warehouse systems or checkout process to a standstill. Business interruption cover may help replace lost income while you recover. Some policies also include third-party liability, which can be vital if a breach affects suppliers, delivery partners or customers and leads to claims against your business.
Together, these protections make cyber cover a practical risk management tool, not just a fraud policy.
FAQ
What does cyber insurance cover for online shops?
Cyber insurance covers breach response costs, forensic investigations and business interruption losses. It covers legal defence costs for data breaches and usually some third‑party liability. Many policies include cyber extortion and media liability. Payment‑fraud cover varies so merchants must check sub‑limits and per‑incident caps.
Does cyber insurance cover card chargebacks?
Sometimes, if a payment‑fraud extension is bought. Standard policies may cap chargeback cover at low amounts. Many insurers require documented evidence of fraud and steps taken to prevent it. Chargebacks due to merchant error are often excluded.
Do shops need cyber insurance if they use Stripe or PayPal?
Yes. Using Stripe or PayPal does not remove the merchant’s exposure. PSPs set contract terms that affect liability. Insurers review those contracts. Merchants must confirm who is liable for refunds and chargebacks under each PSP agreement.
How much does cyber insurance cost in the UK?
Premiums depend on turnover, transaction volume and claim history. Typical ranges are £300–£6,000 per year for SMEs. Enhanced payment‑fraud extensions add cost. Exact quotes require underwriting and PSP contract review.
How does cyber insurance help with PCI and GDPR fines?
Defence and investigation costs for PCI and GDPR incidents are often covered. Direct statutory fines are frequently excluded or capped. Merchants should confirm whether fines are insured and the cap levels. Legal advice costs for regulatory enquiries are usually included up to policy limits.
What is the best cyber insurance for online retailers?
The best policy depends on transaction volume and PSP contracts. For most SMEs a payment‑fraud enhanced policy gives the best balance. High‑volume merchants benefit from broker‑managed programmes with PCI extensions to negotiate higher limits.
What must a merchant prepare to make a claim?
Merchants should keep transaction logs, chargeback notices and PSP communications. They must keep breach timelines and remediation records. Evidence of security controls such as MFA and vulnerability scans speeds underwriting and claim handling.
For regulatory guidance see ICO guidance on data breaches. For payment trends see UK Finance reports.