
Are EPOS or card terminal breaches a real insurance problem for a small business? Many owners know EPOS systems can be attacked, but fewer understand how insurers treat losses that start at the payment terminal. This guide explains, in clear non-technical terms, what EPOS & card terminal cyber insurance covers, where common policy gaps lie, how regulators affect claims and the realistic steps an SME in England should follow after a breach.
Key takeaways: what to know in 1 minute
- EPOS & card terminal cyber insurance protects specific costs such as forensic investigation, notification, fines (where insurable) and business interruption resulting from a breach of payment terminals.
- Not all policies automatically cover physical tampering, skimming or third-party processor failures; wording and endorsements matter.
- Common mistakes include vague asset lists, missing technical evidence and non-compliance with insurer security conditions. These often void cover.
- GDPR and PCI DSS affect both the need to notify and the scope of cover; insurers may reduce or exclude cover for regulatory fines if contractual or wilful breaches are found.
- For claims in England, preserving logs, contacting the insurer promptly and following a documented incident plan are critical.
Why EPOS and card terminal cyber insurance matters
EPOS and card terminals sit at the intersection of physical hardware, networked software and regulated payment schemes. For many UK SMEs, retailers, hospitality, service providers, a compromised terminal can cause immediate loss of takings, liability to card companies and reputational damage. EPOS & card terminal cyber insurance matters because it can pay for the direct costs of responding to an incident and cover consequential losses that standard property or business interruption policies may not.
Key reasons it matters for SMEs in England:
- Payment processing is tightly regulated and integrated with card schemes and acquirers. Incidents can trigger chargebacks and contractual penalties.
- GDPR imposes notification obligations and possible fines where personal data is involved. Insurers often consider GDPR when assessing claims.
- Small businesses typically lack in-house incident response, so insurer-funded forensics and crisis management can materially reduce recovery time.
This cover is not automatic in every cyber policy; many insurers define covered assets narrowly and attach sublimits for payment-related losses. Reading the policy wording matters more with EPOS exposures than with some other cyber risks.
Common myths about EPOS payment breach cover
Myth: a standard cyber policy will always cover a tampered card terminal
A common assumption is that "cyber equals EPOS covered". In reality, coverage depends on policy definitions. Some policies explicitly cover breaches of payment systems; others limit cover to "unauthorised access to electronic systems" and exclude physical tampering or card-skimming unless specifically endorsed.
Myth: the insurer will pay merchant fines and chargebacks automatically
Insurers may cover chargebacks and costs to investigate fraudulent transactions, but many policies include sublimits or exclusions for fines imposed by card schemes or contractual penalties from payment service providers (PSPs). Also, if the SME failed to follow mandatory scheme rules (for example, outdated EMV or lack of tamper-evident seals), an insurer may decline that element of the claim.
Myth: rented or PSP-owned terminals are always covered
Cover depends on who bears legal responsibility. If the terminal is owned by a PSP and the PSP’s contract accepts liability, the SME’s insurer may decline to pay. Conversely, if the SME is contractually liable for losses, insurer cover may still apply, but evidence of contractual liability will be needed.
Myth: PCI DSS compliance guarantees insurance cover
PCI DSS compliance reduces risk and helps insurability, but it does not guarantee cover. Insurers often ask for recent evidence of compliance as a condition of cover or to influence premium, but non-compliance can be a reason for refusal or pro-rata reductions in settlement.
Policy mistakes UK SMEs make with card terminal cover
Mistake: not disclosing the EPOS environment at application
Failing to clearly list terminals, payment gateways, and PSP arrangements at proposal stage can lead to declinature. Insurers underwrite based on stated exposures; undisclosed third-party processor dependencies or remote access arrangements are frequent problem areas.
Mistake: relying on ambiguous policy wording
Words like "systems", "servers" or "payment infrastructure" are interpreted narrowly by courts and insurers. Without specific references to EPOS, card terminals or payment processing, a claim may fail. SMEs should request clear definitions and endorsements that explicitly include card terminals and EPOS software.
Mistake: not meeting insurer security conditions
Policies often include warranty-style conditions (e.g. patching schedules, anti-malware, segmentation) which, if breached, can void cover. Common failures include outdated terminal firmware, shared networks between till and back-office without segmentation, and lack of logging.
Mistake: accepting low limits or high sublimits for payment losses
Insurers may cap payment-related losses with a sublimit far below overall policy limits. Accepting a low sublimit without understanding realistic exposure can leave a business self-insured for the majority of costs.
Mistake: poor evidence collection and chain of custody
Insurers expect forensic evidence: transaction logs, terminal logs, network logs, CCTV and receipts. SMEs often overwrite logs, reboot terminals or fail to maintain chain of custody, weakening claims.
How EPOS & card terminal cyber insurance is typically structured
Most UK SME cyber policies that cover EPOS incidents include some combination of the following sections:
- Forensic and incident response costs
- Business interruption and loss of income caused by a covered incident
- Liability to third parties for data breaches (including customers' card data)
- Regulatory defence costs and fines (often with specific exclusions or caps)
- Card scheme chargebacks and remediation costs
Sublimits, excesses and specific endorsements will often apply to payments-related losses. Always check the schedule and wording for a "payment systems" or "merchant services" clause.
| Cover element |
Typical inclusion |
Common limit / note |
| Forensic investigation |
Often included to determine scope |
£25,000–£100,000 typical |
| Business interruption (payment outage) |
Covers lost income during remediation |
Subject to indemnity period and sublimits |
| Card scheme chargebacks |
May be covered if resulting from covered breach |
Often capped or excluded |
| Regulatory fines and defence |
Defence costs common; fines often limited |
Fines: often excluded or subject to UK law clause |
Ransomware risks to EPOS and card terminals
Ransomware targeting EPOS environments can cause immediate business interruption and customer-data exposure. Attackers increasingly encrypt or disrupt POS networks to force a quick ransom payment. Key considerations for SMEs:
- Ransom payment cover: Some cyber policies include ransom payments and negotiation costs. Insurers may require use of approved negotiators and MDR providers.
- Segmentation and backups: Insurers review network design; poor segmentation between EPOS and back-office increases risk and may affect claim outcomes.
- Recovery costs: Restoring terminals, re-keying devices and re-certifying with acquirers can be costly and may fall under remediation or business interruption cover.
Practical note: If a ransomware incident affects card terminals, the claim will be assessed for whether the cause is an insured cyber event (e.g. unauthorised access) versus excluded causes (e.g. wilful non-compliance with maintenance warranties).
How GDPR and PCI DSS affect your cover
GDPR
- Notification obligations: Under the UK GDPR, personal data breaches that risk individuals’ rights must be reported to the ICO within 72 hours. Insurer response often depends on prompt notification and cooperation.
- Fines and penalties: Insurers often distinguish between defence costs (legal advice, representation) and fines. In the UK, many policies cover defence costs but exclude or limit fines. Whether a fine is insurable can depend on statute and policy wording.
- Evidence matters: Demonstrating documented policies, data minimisation and prompt action increases the likelihood of insurer support.
PCI DSS
- Compliance as a condition: PCI DSS is not an optional technicality. Insurers commonly ask for recent evidence of compliance or remediation plans.
- Contractual consequences: Non-compliance can trigger acquirer penalties and may shift liability. Insurers may decline aspects of a claim if non-compliance contributed materially to an incident.
- Practical implications: Keep PCI evidence (reports on compliance, scans, recent penetration tests) organised and available when negotiating cover or submitting claims.
Refer to the ICO guidance for breach notification: ICO and the NCSC resources on endpoint security: NCSC.
Claim process flow for EPOS incidents
📌 Step-by-step quick view
🔎 **Step 1** → preserve devices and logs
📞 **Step 2** → notify insurer and PSP/acquirer
🛠️ **Step 3** → engage forensic team (insurer or approved)
💬 **Step 4** → assess card-scheme and GDPR obligations
🔁 **Step 5** → remediate, restore terminals and re-certify
How to prepare a claim: practical steps for SMEs in England
- Do not reboot or factory-reset affected terminals.
- Isolate devices from the network while keeping them powered if safe to do so.
- Save transaction logs, receipts, CCTV around the time of the incident and any emails from customers or PSPs.
Notify relevant parties
- Contact the insurer on the policy’s incident number without undue delay; follow the insurer’s initial instructions.
- Notify the acquirer or PSP as required by contract. Card schemes (Visa, Mastercard) often have mandatory reporting windows.
- Consider informing the police where criminal activity is suspected.
Engage forensic and legal support
- Insurers often provide or approve forensic teams. Independent forensic reports strengthen a claim.
- Legal advice can be necessary for regulatory and contractual exposure, particularly re: GDPR notification.
Keep clear records of loss
- Maintain a simple ledger of lost takings, refunded transactions and mitigation costs (e.g. hiring temporary terminals).
- Evidence of lost revenue (till reports, bank statements) helps quantify business interruption claims.
Advantages, risks and common mistakes
✅ Benefits / when EPOS & card terminal cover is appropriate
- Businesses reliant on card income where an outage would cause material loss.
- Companies that hold or process cardholder data on-site (even short-term caches).
- Retailers required to demonstrate risk transfer to partners or compliance teams.
⚠️ Risks / errors that reduce the value of cover
- Assuming broad cover without checking policy definitions and sublimits.
- Poor operational hygiene: unpatched firmware, shared networks, weak physical security.
- Weak contractual clarity with PSPs about responsibility and liability.
Checklist: what insurers commonly ask for at proposal and claim time
- Asset register of EPOS terminals and software versions
- Network diagram showing segmentation between EPOS and corporate networks
- Evidence of PCI DSS compliance or recent scan reports
- Patch and firmware update records for terminals
- Incident response plan and contact details for PSP/acquirer
- Copies of merchant agreements with PSPs/acquirers
Frequently asked questions
How does the claims process work for an EPOS breach in England?
The SME should report to the insurer immediately, preserve evidence, notify the acquirer/PSP and engage a forensic investigator. The insurer will assess cause, scope and coverage before approving remediation costs and any outages.
Will my policy cover chargebacks from card issuers?
It depends. Many policies cover chargebacks only when they arise from a covered cyber event and within stated sublimits; wording and exclusions are decisive.
Are GDPR fines covered after a card terminal breach?
Some policies cover defence costs but exclude statutory fines, or apply conditions. Coverage often depends on policy terms and whether the insured followed legal obligations at the time.
Do insurers cover physical skimming and tampering of terminals?
Not always. Physical tampering may be excluded unless specifically included. Evidence of tamper-evident seals and maintenance records helps support a claim.
What if the terminal is owned by the PSP or rented?
Liability follows contract. If the merchant contract places responsibility on the SME, the SME’s insurer may be asked to cover losses; if the PSP is liable, the PSP’s insurance may respond instead.
How long does it take to settle a claim involving EPOS systems?
Timescales vary: forensic analysis and card-scheme issues can delay settlement. Prompt notification and complete evidence shorten the process, but some complex claims take months.
Can failure to maintain PCI compliance void my cover?
Yes. Breaches of insurer-mandated security warranties, including PCI failings, can lead to refusal or proportionate reduction of settlement.
Your next steps:
- Review the current policy wording to identify explicit references to EPOS, card terminals and payment-processing sublimits.
- Compile the EPOS evidence checklist (asset list, recent patches, PCI scans and merchant agreements) and store it with the insurer contact details.
- If uncertain, consult a regulated insurance broker or legal adviser to review wording and recommend endorsements; document any agreed actions.