Retroactive cover can help, but only in some cases. Buy it fast only when evidence shows discovery came after the chosen retro date.
When retroactive cover will help your SME
Insurers ask whether the loss was known or discoverable before the retro date. If evidence shows discovery before that date, underwriters usually decline cover.
A report to the ICO or a public announcement often fixes discovery date for insurers. The Data Protection Act 2018 and UK GDPR require reporting within 72 hours of becoming aware.
Keep a clear timeline and record every action.
What insurers check
Insurers check when the firm first knew about the breach and what steps it took next.
The quality and provenance of forensic evidence matter. Key items include immutable logs, forensic hashes and UTC timestamps.
Also obtain an independent, signed report from an external forensic firm.
An incident timeline should include board minutes, staff emails and backup records. Signed discovery statements add weight.
Prior disclosures to other insurers, brokers or regulators can be fatal for retro cover. Earlier notification will often preclude a retroactive endorsement.
Keep logs and records in one safe place.
How evidence quality affects acceptance
High-quality, verifiable evidence raises the chances that underwriters accept a retrospective effective date. For example, UTC timestamps and forensic hashes give clear time anchors.
The common error is thinking a short briefing to a broker is enough. A few facts rarely match the proof insurers need.
When retro cover won’t protect you
Retroactive cover does not protect losses known, reported, or reasonably discoverable before the retro date. Insurers exclude such losses in most cases.
If the endorsement has a low sub-limit, waiting period, or criminal-act exclusions, its value can fall close to zero. Check all clauses carefully.
Do not buy retro cover when the loss is already declared to an insurer or regulator. That wastes premium and time.
Careful wording review saves money later.
Wording to watch for
Watch phrases like "facts or circumstances known to the Insured prior to the Retroactive Date." Such words broaden the insurer’s right to decline cover.
Also watch exclusions for ransom, extortion and data exfiltration. These clauses often appear in the fine print and can strip cover.
When retroactive cover typically helps small firms
Retroactive cover helps mainly when recoverable loss is larger than the endorsement cost. Proof must show discovery came after the chosen retro date.
This often fits SMEs with material remediation, notification and business interruption exposure. The firm must show solid evidence and act quickly.
If the business holds much personal data or depends on IT for revenue, retro cover can cut out-of-pocket costs when accepted. The decision rests on exposure size and proof quality.
Who benefits most from buying retroactivity?
SMEs with clear forensic evidence and medium or high exposure benefit most. They should document incident timelines and appoint a forensic firm promptly.
Firms with little data, low business interruption risk or weak evidence rarely gain from buying retro cover. They often lose the premium.
Which incident types commonly qualify?
Qualifying incidents include unauthorised access found late and stealthy data exfiltration discovered only after log review. Ransomware that left few traces can also qualify.
Incidents that usually do not qualify include long-standing misconfigurations known to staff. Breaches already notified to customers or regulators also fail to qualify.
Cost trade-offs: premiums, excesses and sub‑limits
Ask whether expected benefit is larger than the endorsement cost. A simple rule helps decide quickly.
Use this rule: buy only if Exposure (E) × Probability of Acceptance (P) is greater than three times the premium. Adjust for any sub-limit.
Estimate exposure as remediation plus legal, notification and business interruption costs. Judge acceptance probability on evidence quality.
A numeric rule gives a quick decision tool.
How to calculate expected value
Estimate recoverable exposure (E). Multiply E by probability of insurer acceptance (P). Compare that result to three times the endorsement premium.
Buy when E × P is greater than three times the premium. That keeps expected value positive after you pay the premium.
Example ranges: small exposure £10–50k, medium £50–250k and large £250k+. If E = £40k and P = 0.7, expected value is £28k.
Worked numeric examples
Example 1: E = £40k, P = 0.7, premium £4k, sub‑limit £50k. Expected value £28k. Three times premium £12k. Decision: buy.
Example 2: same E and P but sub‑limit £10k. Effective E caps at £10k. Expected value £7k. Decision: do not buy.
Legal deadline: the ICO requires reporting a notifiable personal data breach within 72 hours of becoming aware, under UK GDPR and the Data Protection Act 2018. Keep a recorded timeline of discovery and actions taken on the day you become aware.
Discover
Record time of discovery and isolate systems
Preserve
Preserve logs and engage forensics within 24h
Assess
Estimate exposure, collect evidence and board notes
Contact
Notify broker, provide checklist and request retro quote
Decide
Use E×P > 3×Premium rule to buy or decline
Comparing retroactive endorsements and occurrence policies
A retroactive endorsement sits on a claims-made policy and moves its retro date backward. An occurrence policy covers events that happened during the policy period regardless of when reported.
For long latency threats where discovery lags months, an occurrence policy can be better. Retro endorsements are narrower and require specific evidence.
Check whether the market offers occurrence wording for cyber, or consider extended discovery or run-off cover when you change insurers.
What is claims‑made vs occurrence?
Claims-made covers claims reported during the policy period and often uses a retro date to exclude earlier acts. Occurrence covers events that happen in the period even if reported later.
Most UK cyber policies are claims-made with a retro date. Retro endorsements move that retro date backwards for specific events, subject to conditions.
When an occurrence policy is better
If a firm fears long latency undetected breaches, an occurrence form avoids retro gaps. However, occurrence policies are rarer for cyber.
Occurrence forms can carry higher premiums than claims-made. If occurrence cover is not available, obtain a clear retro date and a matching discovery period.
| Policy type |
Typical price |
Covers known loss? |
Waiting period/sub‑limit |
When to choose |
| Claims‑made with retro endorsement |
Moderate to high (endorsement adds 10–50% premium) |
Only if accepted; known losses often excluded |
Often waiting periods and sub‑limits apply |
When discovery lag short and evidence strong |
| Occurrence policy |
Higher than claims‑made |
Yes, for events in period |
Usually no waiting periods for past events |
When long latency risk is primary concern |
| Run‑off / discovery extension |
Variable; often one‑off fee |
May cover late claims depending on wording |
Fixed discovery period; caps possible |
When changing insurers or closing business |
A clear success case shows how evidence and timing matter. The anonymised examples show real outcomes and what to do right away.
If urgent help is needed, contact a cyber specialist broker. Arrange an urgent forensic review so the broker gets accurate information.
Anonymous success case
A 20‑staff retailer found unusual data transfers after a routine log review. Forensics showed access began two days earlier, and discovery occurred three days after that access.
The firm appointed a forensic firm within 24 hours and logged board minutes. An insurer issued a retroactive endorsement and covered remediation up to the sub‑limit.
Anonymous denial case
A professional services firm delayed forensics while shopping insurers. Staff emails later showed a partner suspected an issue earlier.
Underwriters denied retroactive cover for prior discoverability. The firm paid remediation and legal costs from reserves.
Do not pursue retroactive cover when the incident and likely losses are already declared to an insurer or regulator. Also avoid it when the insurer’s terms explicitly exclude the event.
What to do now
Preserve evidence and appoint a forensic firm within 24 hours. Record a discovery timeline and board minutes that show when the business became aware.
Ask your cyber specialist broker for a retro quote only after you have key documents ready. Use the E×P > 3×Premium rule and check any sub‑limits before buying.
One‑page insurer checklist
Company: [Company name]
Incident discovery date: [YYYY-MM-DD HH:MM UTC]
Forensic firm engaged: [Name, contact]
Systems affected: [short list]
Data types: [personal, financial, none]
Ransom demanded/paid: [Yes/No, amount if paid]
Board notification time/date: [YYYY-MM-DD HH:MM UTC]
Evidence attached: forensic report, logs, board minutes, backup integrity
Requested retroactive date: [YYYY-MM-DD]
Contact person for insurer: [Name, role, phone, email]
Short email template to broker
Subject: Urgent: Cyber incident discovered [Company] — request for retroactive endorsement quote
Dear [Broker name],
We discovered unauthorised access on [date/time]. Forensics are engaged (Firm: [name]). Affected systems: [brief].
We request an urgent quote for a retroactive endorsement dated [proposed date]. Attached: one‑page checklist and initial forensic notes.
Please confirm required documents and likely premium range.
Signed,
[MD name], [company], [phone]
Frequently asked questions, ask before you buy
Does buying retroactive cover change legal duties?
No. Legal duties to report to the ICO remain unchanged and must be followed within 72 hours. Reporting a breach does not create cover and may affect insurer decisions.
Can an insurer void my whole policy for late disclosure?
Yes. Under the Insurance Act 2015, non‑disclosure or misrepresentation can let insurers avoid cover. Provide full, honest facts and keep a record of what was known and when.
How long does an insurer take to decide on retro cover?
Decision time varies but expect 3–21 working days depending on evidence and complexity. Quick forensic reports shorten the timeframe and improve chances of acceptance.
Are there regulators or guidance to follow during an incident?
Yes. Follow ICO reporting guidance and NCSC advice on incident handling. See ICO breach reporting guidance for steps and timelines.
Will paying ransom before getting a retroactive endorsement affect cover?
Rarely. Insurers scrutinise ransom payments and often exclude pre‑existing payments unless expressly accepted. Declare any payment promptly and get legal advice before paying.
Who in the business should lead communications
The managing director or appointed claims contact should lead communications, supported by the DPO and CISO. Use one contact to avoid mixed statements and keep messages factual.