¿Te preocupa how an online ordering platform failure, card fraud or a ransomware attack could close a restaurant for days, and what insurance will actually pay?
This guide explains how cyber insurance for UK restaurants with online ordering systems works, what it commonly covers and excludes, realistic cost ranges for 2026, how GDPR and ICO fines interact with policies, and the precise questions to ask insurers during underwriting. The content is UK-specific and focused on practical decisions for SME owners and directors.
Key takeaways: what to know in 1 minute
- Cyber insurance can pay for incident response, legal costs, customer notification and some business interruption losses, but not all policies are identical and many have sublimits for card fraud and ransomware.
- Typical premiums for small restaurants with online ordering are indicative and vary widely; a microbusiness might see low hundreds per year, while busier multi-terminal sites commonly pay higher premiums depending on turnover, transaction volume and controls.
- GDPR fines and ICO costs are a special area: some policies cover notification and defence costs; cover for fines is limited or excluded, check wording and notify the ICO as required.
- Payment fraud and marketplace/aggregator responsibility matter: policies differ on whether losses caused via third‑party ordering platforms (Deliveroo, Uber Eats, own website payment gateway) are covered.
- Ask about policy limits, sublimits, waiting periods for business interruption and insurer incident response providers, these materially change claim outcomes.
How cyber insurance protects UK restaurants with online ordering systems
Cyber insurance is designed to reduce the financial impact after a cyber incident. For UK restaurants using online ordering systems this typically includes:
- Incident response and forensics: Payment to an approved digital forensics firm to investigate the breach, contain it and produce evidence for insurers and regulators.
- Data breach costs: Legal advice, customer notification letters, credit monitoring for affected customers and call‑centre support.
- Business interruption (BI): Reimbursement for loss of gross profit or additional increased costs of working while systems are down, subject to the policy’s indemnity period and waiting period.
- Cybercrime and funds transfer fraud: Coverage (when included) for social engineering, authorised push payment fraud and some card‑not‑present (CNP) fraud; often subject to specific sublimits and evidential requirements.
- Ransom payments and negotiate‑and‑pay services: Some policies will cover ransom payments and the costs of a professional negotiator, though cover may be limited and subject to legal/regulatory checks.
- Regulatory defence and fines: Legal defence costs for GDPR investigations are commonly included; cover for fines is rare or restricted, see the GDPR section below.
A policy is only as good as its definitions and sublimits. For restaurants relying on third‑party ordering platforms or outsourced POS systems, the policy must be read for clauses about third‑party technology failures and vendor liability.
ICO breach reporting guidance and the NCSC guidance are commonly referenced in insurer breach response conditions. Insurers often require immediate reporting to incident response partners and may deny cover if the insured failed to follow agreed mitigation steps.
- If the restaurant’s own website or payment gateway is compromised, the restaurant is usually the insured party and claims typically flow under the restaurant’s policy.
- If a third‑party marketplace (e.g. an aggregator) suffers a breach, the aggregator may carry primary liability, but restaurants still risk reputational damage, customer notifications and BI losses which a restaurant policy may cover. Policies vary on whether losses caused by upstream providers are included.

Typical costs and pricing for restaurant cyber cover in the UK (indicative 2026)
Pricing depends primarily on turnover, transaction volume, number of terminals, whether card processing is isolated, past claims, and the quality of technical controls (MFA, patching, network segregation). The ranges below are indicative at time of writing and intended for budgeting only.
| Profile |
Typical annual premium (GBP) |
Typical limits offered |
Common sublimits/excesses |
| Sole trader/café, low online volume |
£150–£400 |
£50k–£250k |
£500–£2,000 excess; card fraud sublimit £10k–£25k |
| Independent restaurant, moderate online ordering |
£400–£1,200 |
£100k–£500k |
BI waiting period 24–72 hrs; ransomware sublimit £50k–£150k |
| Multi‑terminal site, high online volume |
£1,200–£5,000+ |
£250k–£2m+ |
Higher BI limits; ransom sublimits vary; tailored excesses |
Notes on pricing drivers:
- Turnover and card transaction volume often weigh more than headcount. A low‑staff, high‑takeaway turnover restaurant paying thousands of card transactions daily will attract higher premiums.
- Technical controls reduce premiums. Insurers ask about network segmentation of POS, MFA on admin accounts, patching cadence and backups.
- Claims history increases cost. Past ransomware or PCI failures often push limits down and excesses up.
- Third‑party exposure: Restaurants using several aggregators may face additional underwriting questions and potential sublimits.
GDPR, fines and data breach cover for restaurants
Restaurants process customer personal data (names, addresses, phone numbers, card details stored by gateways). GDPR obligations mean incidents can attract regulatory action and notification duties.
- Policies commonly cover notification costs, forensic costs and legal defence costs where the restaurant must respond to an ICO investigation. These are often essential cover items.
- Monetary penalties/fines imposed by the ICO (administrative fines) are frequently excluded by insurers or only covered where permitted by law. The ICO’s ability to fine depends on the breach; some smaller incidents attract enforcement notices rather than fines.
- Insurers may cover fines or penalties in some jurisdictions or on specific wording, but this remains rare in the UK market. Where cover for fines exists, it is usually limited and subject to strict conditions.
Practical steps and implications:
- Notify the ICO if required under the UK GDPR guidance. Failure to follow statutory reporting duties can affect claim handling.
- Keep records of mitigation and communications. Insurers will expect evidence that reasonable steps were taken to protect data and to manage the incident.
- Legal defence costs: ensure the policy includes legal representation for regulatory investigations; this can be as valuable as BI cover in some scenarios.
Ransomware, payment fraud and risks in online ordering
Key risk scenarios for restaurants with online ordering systems:
- Ransomware encrypts POS or kitchen systems, stopping order fulfilment and deliveries. This can cause immediate BI losses and reputational harm.
- Card‑not‑present (CNP) fraud on takeaway websites or phone orders, where attackers use stolen card details.
- Social engineering and invoice fraud: staff may be tricked into paying fraudulent invoices or changing account details for payouts to fraudster accounts.
- Supply chain/aggregator compromise: a breach at a marketplace or payment processor may expose customer data or disrupt ordering services.
How policies treat these risks:
- Ransomware: Many policies offer ransomware response and a ransom payment sublimit. Some insurers mandate use of their response provider and pre‑approval for ransom payments.
- Payment fraud: Cover for card fraud is inconsistent. Some policies explicitly exclude losses where the restaurant is liable under card scheme rules; others include limited protection for social engineering‑driven transfers.
- Aggregator failures: Coverage for losses caused by third‑party platforms is variable. Policies often require demonstrations that the restaurant maintained appropriate vendor due diligence.
Evidence needed for claims:
- For ransomware: forensic report showing encryption, timelines, and containment steps.
- For card fraud: transaction logs, payment gateway reports and communications with card acquirers.
- For social engineering: copies of communications and proof of how the payment was made.
Choosing policy limits and business interruption cover for restaurants
Selecting limits requires balancing affordable premium with realistic exposure. Consider these elements:
- Gross profit versus turnover: BI indemnity should reflect the gross profit margin and maximum probable loss period (how long it would take to restore operations or migrate to a backup ordering method).
- Waiting periods and indemnity periods: Typical waiting periods are 24–72 hours. Longer waiting periods reduce premiums but increase risk. Indemnity periods (how long BI cover runs) commonly range from 30 to 365 days; restaurants with long lead times for equipment replacement may need longer periods.
- Sublimits: Many policies apply sublimits for ransomware, card fraud and regulatory fines. Check totals against realistic worst‑case scenarios.
- Reinstatement and aggregation: Check whether the limit is per incident or aggregate for the policy period; some policies are annual aggregate which can limit recovery from multiple events.
A simple approach to an initial limit: estimate weekly gross profit and select an indemnity period that covers expected recovery time (e.g. 4–12 weeks), then multiple weekly gross profit by that period to determine a BI sum insured. This is indicative and not advice.
Example: calculating an indicative BI limit
- Weekly gross profit: £7,500 (turnover £15,000 × gross margin 50%)
- Desired indemnity period: 8 weeks
- Indicative BI limit: £7,500 × 8 = £60,000
Insurers will ask for evidence and may adjust based on mitigation (backup strategy, contingency plans, ability to switch to phone/collection temporarily).
Questions to ask insurers about online ordering cover
When discussing cyber insurance for UK restaurants with online ordering systems, these targeted questions clarify scope and reduce surprises at claim time:
- What is the policy limit and is it per claim or aggregate for the year?
- Are ransomware payments and negotiation costs covered, and are there sublimits or pre‑approval requirements?
- How is business interruption calculated for lost online orders and delivery income specifically? Is gross profit used and what is the waiting period?
- Is there explicit cover for card‑not‑present fraud or losses arising from payment gateway compromise? What sublimits apply?
- Does the policy cover losses caused by third‑party ordering platforms or marketplace outages?
- Which incident response providers does the insurer require or recommend, and can the restaurant use its own forensics firm?
- Are ICO notification costs and legal defence fees included? Are fines covered?
- What evidence will be required to support claims for ransomware, payment fraud and BI?
- Does the policy include PR and customer notification services, and are call‑centre costs covered?
- What cyber security controls (MFA, network segregation, backups) are required to obtain quoted terms and reduced premiums?
Answers to these questions should be requested in writing and included within the policy documentation or schedule.
Advantages, risks and common mistakes
✅ Benefits and when cyber insurance makes sense
- Provides funded access to incident responders, forensics and legal teams at short notice.
- Can reimburse direct financial losses, notification and remediation costs, and certain BI losses.
- Useful for restaurants that take card payments online and handle customer personal data, especially where fallback operations are limited.
⚠️ Errors to avoid and limitations
- Assuming all card fraud or aggregator failures are covered without checking policy wording.
- Choosing limits based on premium alone rather than realistic BI exposure.
- Failing to meet underwriting questions accurately (e.g. about backups or MFA), misstatements can invalidate claims.
- Overlooking sublimits: a large BI limit is less helpful if ransomware payments and card fraud are carved out or capped.
Incident response playbook (how to act after a cyber incident)
The following numbered steps form the basis of an actionable HowTo and support the provided schema.
- Contain operations: isolate affected devices and networks to stop spread.
- Notify the insurer’s incident response team (if required) and the chosen forensics provider.
- Preserve evidence: keep logs, images and communications intact.
- Assess immediate operational options: manual phone ordering, temporary card machines not connected to affected systems.
- Notify the ICO if personal data breach criteria are met and begin customer notifications if required. See ICO guidance.
- Record costs and downtime for BI claim preparation: staff overtime, delivery refunds, lost bookings.
Visual process: quick claims flow for restaurants
Claims process in 6 steps for restaurants
🔍 Step 1 → Isolate affected systems and preserve logs
📞 Step 2 → Contact insurer's incident responder and forensics
🛠️ Step 3 → Implement recovery plan: backups, manual ordering
📣 Step 4 → Notify customers and ICO if personal data lost
💷 Step 5 → Capture all costs for a BI claim (invoices, payroll)
📑 Step 6 → Submit claim with forensics report and evidence
Practical checklist to improve terms and reduce premiums
- Implement MFA on admin panels and POS management accounts.
- Segment guest Wi‑Fi from POS and kitchen systems.
- Maintain tested, offline backups with regular restore tests.
- Keep software and payment terminals patched to vendor guidance.
- Document vendor agreements with aggregators and payment gateways.
Questions frequently asked about cyber insurance for restaurants
Frequently asked questions
What does cyber insurance for restaurants usually cover?
Policies typically cover incident response, forensics, customer notification, legal defence costs, and business interruption. Specific cover for ransomware and payment fraud varies and is often subject to sublimits.
How much does cyber insurance cost for a small restaurant in the UK?
Indicative costs in 2026 range from approximately £150 to £5,000+ annually depending on turnover, online transaction volume, technical controls and claims history. Exact quotes depend on underwriting answers.
Will insurance pay for ICO fines after a data breach?
Most UK policies exclude regulatory fines or restrict cover. Notification and defence costs are commonly covered, but liabilities for ICO fines are often excluded or limited. Legal advice is recommended for specific policies.
Are losses from aggregator outages covered by restaurant policies?
Coverage depends on the policy wording. Some insurers cover consequential loss from third‑party service failures, others exclude losses arising from providers where contractual liability sits with the aggregator. Ask insurers to confirm.
How should a restaurant prepare evidence for a cyber claim?
Preserve logs, forensic snapshots, payment gateway records, communications with customers and third parties, and detailed financial records showing lost sales and additional costs while systems are down.
Can ransom payments be insured?
Some policies permit ransom payment cover, often with pre‑approval and limits. Many insurers require the use of their approved negotiators and strict legal checks before payment.
Which security measures reduce premiums most effectively?
Segregation of POS networks, MFA on admin accounts, regular backups with tested restores, up‑to‑date patching and documented vendor management commonly improve underwriting terms.
Your next step:
- Compare policy wordings on limits, sublimits and waiting periods and request written confirmations from insurers for online ordering scenarios.
- Implement basic technical controls (MFA, network segregation, offline backups) and document them for underwriting.
- Prepare an incident playbook and record essential logs and evidence to speed claims and reduce downtime.