Cyber cover is not a substitute for payment controls
Cyber insurance, PCI DSS and chargebacks solve different problems. Insurance may fund breach response and some cyber losses. PCI charges are usually contract costs. Chargebacks are often a normal trading loss.
Think of these as three separate tills. One holds security incident costs. One holds card contract costs. One holds refunds and disputed sales.
Cyber cover cannot replace payment controls, clear delivery evidence or cash held back for disputes.
The policy limit is only the outer wall
A £250,000 policy limit can look reassuring. But a PCI-related extension may have a much smaller sub-limit. A sub-limit is a lower cap for one type of claim.
The excess is the amount you pay before the insurer pays. It changes by insurer, turnover, controls and chosen cover. Compare it with the cash your business can lose without strain.
A large headline limit can hide a small usable amount.
Check the excess, PCI sub-limit and waiting period before choosing a policy. Only choose cover when those figures fit your real cash position.
Fraud labels do not decide cover
Calling an event “fraud” does not decide whether insurance pays. The policy wording decides this. Your merchant agreement also decides what the acquirer can charge.
A stolen-card order and a hacked PSP account may both involve fraud. Yet they can lead to very different insurance outcomes. The first may be a chargeback. The second may trigger cybercrime cover.
The most frequent mistake is treating every payment loss as a cyber claim. Insurers often view normal disputed sales as a trading risk. Keep fraud controls and insurance decisions separate.
Quick comparison of the likely payer
The table below separates costs often mixed together after an online card dispute. It shows why one policy rarely pays every bill.
| Loss after an incident | Typical direct cost | Usual payer | Insurance position |
| Breach response and forensic investigation | Hours to weeks of specialist work | Merchant, then insurer if covered | Often insured, subject to excess and wording |
| PCI assessment or contractual charge | Varies by contract and incident | Merchant | Only if a specific extension applies |
| Reversed card sale | Full transaction value | Merchant | Usually excluded as a trading loss |
| Chargeback or dispute fee | Often £10 to £25 per dispute | Merchant | Usually excluded unless stated otherwise |
| Acquirer reserve | Cash withheld for weeks or months | Merchant | Commonly excluded |
| Website outage after ransomware | Lost gross profit after a waiting period | Merchant, then insurer if covered | May be covered if policy triggers and terms are met |
PCI charges are contractual costs
PCI DSS is a card-security standard set by payment card schemes. Your acquirer or PSP may require it through your payment contract. A PCI charge is not automatically a UK legal fine.
Some cyber policies cover PCI assessments through a named extension. Others exclude contract penalties completely. Read the definition of “PCI DSS assessment” and its sub-limit.
Do not buy cyber cover only for possible PCI charges. First ask your acquirer what your contract permits and requires.
Reserves can hurt more than a fee
An acquirer reserve is money held back from settlements. It protects the acquirer if later refunds or disputes arise. It can harm working cash even where losses remain low.
Ten disputed £120 orders can reverse £1,200 of revenue. They can also add roughly £100 to £250 in chargeback fees. Staff time comes on top.
Insurance will commonly treat that loss as an ordinary trading loss.
A suspected card-data compromise may cause £6,000 of forensic and breach-response costs. It may also lead to PCI charges notified by the acquirer. Contract and policy wording still apply.
If an acquirer holds 10% of £40,000 weekly settlements, £4,000 becomes unavailable. That hold may last weeks or months. Track it apart from fraud losses.
For most small shops, a reserve can damage cash flow sooner than a cyber policy can help.
Hosted checkout reduces scope, not responsibility
A hosted checkout can reduce exposure to card data. The customer enters card details on the PSP’s page. Your website does not directly collect those details.
This reduces your PCI DSS scope. Scope means the systems that PCI DSS checks. It does not remove all duties under your card contract.
Hosted checkout reduces risk, but it does not remove it.
The website can still affect payments
Your website can still send buyers to a false payment page. A hacked plug-in can change a checkout button. Criminals may also steal administrator logins.
Use multi-factor authentication for PSP and shop accounts. It asks for a password and a second proof. A FIDO2 security key is one physical second proof.
A FIDO2 USB key can protect PSP dashboard access. It helps protect access where staff approve refunds, exports or payment-setting changes. It is strongest against fake login pages.
These measures work well in theory, but shared staff logins defeat them. Give each person their own account. Remove access when someone leaves.
A hosted PSP cannot stop disputes
A hosted PSP cannot prove that goods arrived. It cannot fix unclear refund terms. It also cannot stop a buyer forgetting your trading name.
Use a clear card descriptor. This is the name shown on the customer’s bank statement. It should match your shop name and support contact details.
Choose hosted checkout if you do not need to handle card data. Avoid assuming that it protects you from delivery disputes or refund claims.
Evidence and 3-D Secure beat routine claims
3-D Secure can shift fraud liability for eligible authenticated payments. It is a bank check during checkout. A buyer may confirm the payment through their banking app.
It is not a blanket chargeback guarantee. Scheme rules, issuer choices and dispute reasons can still create exceptions. Delivery and refund disputes can still succeed.
For ordinary card disputes, good order evidence usually matters more than cyber insurance.
Keep a dispute-ready order file
Build the order file before a claim arrives. Keep the checkout record and authentication result. Keep AVS and CVV results where available.
Keep customer messages, refund emails and dispatch scans. Keep proof of delivery too. State delivery dates and returns rules clearly.
A common case involves a £350 order with tracked delivery. The merchant sends only the invoice. The dispute is lost because delivery proof was not supplied.
Insurance buying questions that matter
Ask whether the policy covers forensic work, legal help and customer notices. Ask whether business interruption needs a full website outage. Ask how long the waiting period lasts.
Ask whether PCI contractual charges have their own sub-limit. Ask whether social engineering and funds transfer fraud are included. Get answers in writing from the insurer or broker.
For a sole trader with £80,000 annual online sales through a hosted PSP, a dispute reserve and basic controls may matter more than a large policy limit. For a firm with £1 million to £5 million in sales, staff access, customer-data exports and one vital website, cyber cover with tested business-interruption terms becomes more proportionate.
For card disputes, enable 3-D Secure where your PSP supports it. Use hosted payment pages instead of collecting card details by email or phone. Make your card descriptor easy to recognise.
Set alerts for repeat buyers and unusually high orders. Watch for several failed payment attempts. Review each reason code quickly.
A representment is your evidence-based reply to a chargeback. It works best when evidence answers the stated allegation. Sending an invoice again rarely proves delivery.
Choose prevention and a reserve first when disputes are routine. Add cyber cover when a breach, account takeover or website outage could threaten the business.
What people ask
Does cyber insurance cover PCI DSS fines?
Cyber insurance may cover PCI assessments only when the policy says so. Its conditions must also be met. These are often acquirer contract costs, not automatic UK legal fines.
Does cyber insurance cover chargebacks?
Cyber insurance usually does not repay normal chargebacks, reversed sales or £10 to £25 dispute fees. It may cover a separate cybercrime or social-engineering loss. The wording must clearly include that event.
Is PCI DSS mandatory for a small online shop?
PCI DSS is usually required by card-payment contracts, even for a sole trader. The required checks change with the checkout design. They also change if your systems can affect payment data.
Does 3-D Secure stop all card fraud chargebacks?
No, 3-D Secure may shift liability only for eligible payments. Issuer decisions and scheme rules can create exceptions. Some reason codes still allow disputes.
Can cyber insurance pay an ICO GDPR fine?
Some policies cover regulatory defence costs. They may address some insurable penalties where law allows. The ICO, the policy wording and event facts decide the outcome.
Is cyber cover cheaper than PCI costs?
An annual premium may range from £300 to £1,500 for many small firms. Price depends on turnover, data, controls and claims history. Compare policy wording rather than assuming a premium replaces compliance.
Do I need chargeback insurance as well?
Usually not as a first purchase when disputes arise from delivery, returns or unclear descriptors. Improve evidence and refund handling first. Consider specialist cover for high-value fraud exposure.
What should I ask my acquirer after a breach?
Ask if a reserve, forensic review, PCI assessment or deadline applies. Request the relevant contract clause in writing. Do this within 24 to 48 hours where possible.
Which to choose according to your situation
Choose hosted PSP checkout, MFA, evidence controls and a dispute reserve first if you are a sole trader or micro business. This suits modest order values. It also suits sites that never handle card data directly.
This is the stronger choice when most risk comes from normal chargebacks. It will not pay for a serious breach. It also cannot replace a cyber policy after ransomware.
This comparison matters less if your business does not take card payments online. It also matters less if you do not process customer data. For a live dispute, breach, PCI assessment or cover refusal, check your merchant agreement and policy wording with the provider or a qualified adviser.
Set the cyber policy limit against the largest likely cyber event. Do not set it against annual premium alone. Think of the limit as a fire bucket, not a refund budget.
A retailer with £500,000 turnover through one site may need cyber cover. It may need funds for forensic work, breach response, legal help and ransomware outage. Check PCI charges have their own sub-limit.
Compare the excess with cash available after an incident. A £1,000 excess may be manageable. A long uninsured waiting period may matter more than the headline limit.
Higher limits and extensions suit firms with staff access to customer exports or refunds. They also suit firms reliant on one website or one PSP. Choose that cover if a breach could stop trading for days.
The best first spend for most smaller shops is payment control and a cash reserve, then cyber cover for a credible major incident.
Related sources
These articles can help you explore the topic in more depth: