For UK e-commerce SMEs, standalone cyber insurance usually gives broader limits and specialist incident help.
It can also provide stronger cover for outages and data breaches.
Is bundled cover enough for an online shop?
A good extension may pay for basic incident response, data recovery, customer notification costs and third-party claims after a data breach.
Some policies offer limits between £25,000 and £100,000. This can suit a low-volume retailer with no saved card data.
Choose bundled cover if: your online revenue is low, you can absorb two or three days without orders, and the wording covers your main cyber risks.
A bundled cyber extension is an added part of a commercial package. It usually has its own limit, excess and listed insured events.
A cyber endorsement may be broad or narrow. The label alone is not enough.
Silent cyber is different. It is possible cyber-related cover within property, liability or crime wording.
That wording was not built as cyber insurance.
For example, a contents policy might pay for physical damage from a cyber-triggered event. It may not pay for forensic work, customer notices or lost online sales.
For UK e-commerce cyber cover, ask the insurer to list each cyber-related section. Ask which losses are covered, excluded or have a separate sub-limit.
Choose bundled cover if: you have low online exposure and the written cover meets your likely loss.
A direct comparison of limits, cost and response
The table shows common UK SME policy patterns. It is not a quote or guaranteed policy terms.
Annual premiums can range between £200 and £800 for lower-risk small firms. Higher turnover, claims, PCI exposure and larger limits can cost much more.
| Check before buying | [Bundled cyber](https://dealergen.uk/bundled-cyber-professional-indemnity-uk-smes/) extension | Standalone cyber policy |
| Typical annual premium range | Often £50 to £300 added to a package | Often £200 to £800 for lower-risk SMEs |
| Main cyber limit | Often £25,000 to £100,000 | Often £250,000 to £1 million or more |
| Excess and waiting period | Often £250 to £1,000; interruption may wait 12 to 24 hours | Often £250 to £1,000; options may start after 8 to 24 hours |
| 24/7 incident response | May be limited or outsourced | Commonly includes a breach coach, forensics and legal support |
| Supplier or platform outage | Often excluded unless stated | May include dependent [business interruption](https://dealergen.uk/restoring-data-may-end-before-business-interruption-does/), subject to wording |
The practical test: if one day without online orders costs more than the cyber extension limit, view the bundle as a starting point. It is not your final protection.
Bundled cyber: useful baseline, narrow triggers
Pros for a smaller retailer
A package policy is easier to renew alongside stock, employers' liability and business contents insurance.
It may avoid duplicate excesses. It can give a new e-commerce firm a sensible first layer of cyber liability insurance.
This can keep early insurance costs low.
Limits that can catch you out
A bundled policy can look stronger on paper than it works in practice.
It may pay for a data breach but exclude non-damage business interruption. Lost sales from a cloud or SaaS failure may then be uninsured.
The most common mistake is trusting the headline limit. Sub-limits and exclusions often decide the real claim payment.
Choose bundled cover if: your shop can trade through a short outage and holds little customer data.
Standalone cyber: wider response for online loss
Ransomware is harmful software that locks files or systems. It demands money to unlock them.
A dedicated policy may cover cyber extortion, restoration and lost income. Payment is never automatic.
Insurers will check sanctions, security controls and the facts of the attack.
Supplier outages need named wording
Dependent business interruption can pay lost income after a cyber event at an outside supplier.
The supplier must be named or meet the policy definition. Check Shopify, WooCommerce hosting, Stripe, PayPal, Amazon, cloud storage and warehouse software.
Think of supplier cover like a chain of shops. Your policy must include the link that has broken.
How an e-commerce cyber claim usually unfolds
1. Contain
Call the 24/7 response line
2. Investigate
Forensics find the entry point
3. Restore
Recover systems and orders
4. Notify
Legal advice on affected people
Test each option against incidents that can stop a real online retailer.
A criminal may take over a Meta or Google advertising account and spend your marketing budget.
Cover may depend on a social engineering, crime or fraudulent-transfer section. It may not sit within data breach insurance.
A changed payment link can redirect customer payments. Invoice payment fraud cover may have a separate, low sub-limit.
A customer-data breach can trigger forensic costs, legal advice, customer notices and third-party claims.
A SaaS-provider attack may be covered only if dependent business interruption applies. The provider must also meet the policy definition.
Ransomware insurance and cyber extortion cover can fund specialist response and data recovery costs. Each claim still depends on policy conditions and sanctions rules.
For most established e-commerce SMEs, standalone cover is the better choice when systems drive sales. It costs more, but can combine incident help, lost-income cover and data-breach costs. That protection may fail if your key supplier is outside the definition. Check that wording before you buy, then set limits for a realistic multi-day outage.
Choose standalone cover if: a platform, payment firm or cyber attack could stop your orders for more than one day.
Which cover fits your e-commerce risk score?
Score the risks that stop orders
- More than 50% of turnover comes from online sales.
- You process over 500 online orders each month.
- You store customer account data or rely on card-payment systems.
- One marketplace, payment processor or SaaS supplier handles most orders.
- You cannot restore trading from backups within 24 hours.
- You sell into several countries or face contractual PCI DSS requirements.
Each point shows a route through which a cyber event can halt sales. More routes mean a small bundled limit is less likely to fit.
Questions your broker must answer
Ask for written answers on dependent business interruption and social engineering fraud. Also ask about invoice payment fraud, PCI costs and regulatory investigation expenses.
Ask for the excess for each section. An excess is the amount you pay first on a claim.
The Information Commissioner's Office can investigate UK GDPR breaches. Insurance does not remove your duty to protect data or report a serious breach.
Written answers are easier to check at claim time.
This comparison matters less if you have no real online operations. It also matters less if you hold no personal or payment data. It is not a substitute for policy wording, regulated advice or an insurer's emergency line during a live incident.
Use a simple points score rather than a general feeling about risk.
- Add two points if online sales exceed 50% of turnover.
- Add two points if you process more than 500 orders each month.
- Add two points if you retain customer accounts or payment-related data.
- Add two points if one marketplace, payment firm, host or warehouse platform is essential.
- Add one point for sales into multiple countries.
- Add one point for contractual PCI exposure.
A total of 0 to 2 may justify comparing bundled cyber cover with a modest limit.
A score between 3 and 5 normally warrants a higher-limit standalone cyber policy.
A score of 6 or more calls for business interruption, supplier outage cover and incident response. Base limits on a realistic multi-day outage, not the annual premium.
Choose standalone cover if: your score is 3 or more, or one supplier can halt your trading.
Before renewal, send your broker this score and your key supplier list. Ask them to confirm each item in writing.
Common questions
Is bundled cyber insurance enough for e-commerce?
It can suit a low-risk retailer with limited online revenue and little customer data. Check the limit, supplier-outage wording and sub-limits against a realistic loss.
Does cyber insurance pay for Shopify downtime?
It may pay only if the policy includes dependent business interruption. Shopify must also fall within the supplier definition.
Many policies have a waiting period between 8 and 24 hours.
Are GDPR fines covered by cyber insurance?
Some policies cover certain defence costs and insurable civil penalties. Cover depends on law and the policy wording.
A policy cannot promise to pay UK GDPR fines in every case.
Does a cyber policy cover card payment fraud?
It may cover PCI DSS assessments or fraudulent transfer losses. These often have separate sub-limits.
Confirm social engineering and payment-change fraud cover before relying on the policy.
What security controls do insurers expect?
Most insurers expect multi-factor authentication, patched software, endpoint protection and tested backups. They also expect payment checks.
A missing control can affect terms or a claim if it was material to the loss.
Verdict: favour standalone when sales depend on systems
Choose standalone cyber cover when a cyber incident could stop orders. Choose it when customer data or a key supplier is at risk.
This is the stronger choice for most established England-based e-commerce SMEs. It costs more than a packaged extension.
Choose a bundled extension only when your measured exposure is truly low. The wording must clearly meet that exposure.
If neither policy covers your main supplier, payment fraud risk or recovery period, ask for a tailored extension. You can also seek another insurer rather than accept a known gap.
Choose standalone cover if: your business depends on systems to take, process or fulfil online orders.