POS / EPOS Retail Cyber Insurance covers losses tied to point-of-sale terminals and payment processing. Retailers should check whether a policy names compromised terminals explicitly. They should also check cover for card-skimming, tampered hardware and processor breaches.
What POS / EPOS Retail Cyber Insurance covers
In the context of EPOS incidents, cover typically pays for forensics, notification, defence costs and business interruption tied to payment outages. Policies vary, but these elements are common.
- Forensic investigation to confirm scope and cause.
- Customer notification and credit monitoring costs when cardholder data is exposed.
- Legal and PR costs to manage regulatory or litigation exposure.
- Business interruption loss when sales fall because card payments fail.
- Card replacement, reimbursement or fraud loss sublimits for affected payments.
Quick underwriting trigger: insurers expect a terminal inventory, patch history and supplier SLAs before offering full cover.
If terminals are physically tampered with, insurers often want CCTV, reported theft or tamper reports and a chain of evidence to consider a claim.
Forensics
Establish compromise and create a remediation plan
Customer costs
Notification and card replacement where required
Business interruption
Sales loss from payment outages or till downtime
How insurers typically word EPOS / payment cover
When reviewing policy wording, look for explicit sections that name "payment card compromise", "cardholder re-issuance/chargeback costs" or "payment processing losses". A typical retail endorsement separates first-party response costs from payment-related liabilities. First-party items are forensics, notification and remediation.
Insurers often set a specific sublimit for card replacement and chargebacks. Common SME endorsement ranges are circa £10,000–£50,000. Larger retailers can negotiate £100k plus in some cases.
Insurers note whether contractual liabilities to acquirers or processors are excluded unless an "acquirer liability" extension is purchased. Many wordings include insurer recovery or subrogation rights against terminal vendors or suppliers. A supplier warranty can affect recovery prospects.
Check definitions carefully. Confirm what counts as "compromise", the trigger for BI linked to "payment outage" and any retroactive date or known-loss exclusions. Request sample policy clauses from brokers to confirm actual scope before purchase.
Common exclusions for POS / EPOS Retail Cyber Insurance
The principal difference between cover and no cover is the cause and the controls in place. Many policies exclude losses where lack of basic controls is proven. Read the policy wording before you assume cover.
- Card-skimming or hardware tampering may be excluded or limited when PCI DSS evidence is absent.
- Contractual liabilities that the merchant agreed with an acquirer or processor are often outside cyber cover unless specifically included.
- Fines and regulatory penalties under GDPR may be excluded or limited, especially when the merchant failed to follow required controls.
- Physical theft or damage not caused by a cyber action is typically excluded under cyber policies. Those losses sit in property or theft policies.
Insurers commonly apply sublimits to payment costs. A cyber policy might pay full forensics and PR but cap card replacement costs at £25,000. Ask for sublimits in writing.
Practical policy comparisons: typical exclusions and sample limits for payment items
In practice there are three common policy approaches for retailers:
- Standard SME cyber policy — usually covers forensics, notification and general BI. It often excludes card chargebacks or caps them at a low sublimit. Typical caps are £5k–£25k.
- Retail EPOS endorsement — explicitly names card compromise and payment outage. It has clearer BI wording tied to till downtime. Common sublimits sit in the £10k–£50k band. PCI evidence is usually required.
- Full payment extensions / acquirer indemnity add-on — more expensive and may cover contractual liabilities to acquirers. Cover is negotiable and often subject to excesses and strict controls.
Typical exclusions to watch for across all types include losses caused by pre-existing or unremediated vulnerabilities. Policies also exclude intentional dishonest acts by employees. Physical theft not caused by a cyber act is excluded.
When comparing quotes, request an itemised schedule showing payment-related sublimits, applicable excesses, and precise definitions of "compromise" and "payment outage".
How GDPR and PCI DSS affect POS / EPOS Retail Cyber Insurance
GDPR governs personal data processing and affects notification costs and fines. Insurers often separate response costs from regulatory fines and penalties.
- Notification and response costs are usually insurable. Policies name these costs explicitly.
- Fines and penalties may be uninsured by default. A minority of insurers offer limited cover when the insured can show they followed required controls.
- PCI DSS compliance is frequently asked for at underwriting. Insurers ask for a PCI attestation of compliance or evidence of compensating controls.
According to the UK Government's DCMS Cyber Security Breaches Survey 2023, 39% of businesses reported a cyber attack in the previous 12 months. Insurers use this prevalence to price retail EPOS risk.
Ransomware, payment fraud and interruption cover
Ransomware cover and payment fraud protections exist, but with caveats. Not all policies treat ransomware the same.
- Forensic, containment and recovery costs are commonly covered.
- Ransom payments may be covered but require insurer approval and often face sublimits. Some insurers exclude payments made without prior consent.
- Payment fraud caused by social engineering or staff error can be excluded when control failures are shown.
- Business interruption for lost takings caused by payment outages must tie to insured perils. Claimants must prove losses with till and EPOS records.
Insurers will check time to detection. Claims where compromise remained undetected for weeks face more scrutiny. Such claims often get lower recoveries.
Practical checklist for buying POS / EPOS Retail Cyber Insurance
In the context of quotations, insurers expect a clear set of evidence. Gather these items before requesting quotes to get accurate premiums.
- Terminal inventory with serial numbers and locations.
- Patch and software update records for terminals and back-office systems.
- Evidence of network segmentation between EPOS and back-office or guest Wi-Fi.
- PCI DSS Attestation of Compliance or a remediation plan with dates.
- Supplier contracts and SLAs with acquirers and terminal vendors.
-
Recent vulnerability scans or penetration test summaries where available.
-
Run a short internal exercise: confirm how long staff would take to notice a payment outage, and record the answer.
| Criterion |
Standard SME cyber policy |
Retail EPOS endorsed policy |
When to choose |
| Card compromise cover |
Often limited or excluded |
Specified, with sublimits and evidence conditions |
Choose endorsed policy if you use on-site terminals |
| Business interruption |
Generic BI wording |
BI linked to payment outage definitions |
Choose endorsed policy for till downtime cover |
| Underwriting evidence |
Minimum IT controls |
Detailed terminal logs and PCI evidence required |
Choose endorsed policy if you can supply evidence |
Choose a retail EPOS endorsed policy where payment flow is on-site and you can provide PCI evidence. For fully hosted payments, a standard SME policy may suffice.
Exception: if payments are fully outsourced and no cardholder data touches your systems, EPOS cyber endorsements may not apply. Confirm scope with your insurer.
Simple premium estimation matrix for EPOS risk
- Low risk: single-site micro shop, under five terminals, up-to-date patches and PCI evidence. Indicative premium range £350–£700 pa.
- Medium risk: multiple sites, six to fifteen terminals, partial PCI evidence. Indicative premium range £700–£1,600 pa.
- High risk: sixteen to fifty terminals, no PCI evidence and a history of incidents. Indicative premium range £1,600–£5,000 pa.
Premiums vary by insurer, turnover, claim history and controls. The ranges reflect typical quoted bands for small UK retailers.
Ask brokers for comparative quotes and the assumptions behind any published range.
Step-by-step technical hardening checklist to present at quotation
Before you submit evidence to underwriters, implement and document a short hardening programme. Present a repeatable sequence that shows dates and owners.
- Build a terminal inventory with serial numbers and map each to a VLAN isolated from back-office and guest Wi-Fi. Restrict routing between VLANs.
- Apply vendor-approved patches and record the update cycle. Disable unused interfaces and change default credentials.
- Enforce TLS and certificate validation for payment traffic or use P2PE or HSM solutions where available.
- Configure host-based logging and forward logs to a centralised SIEM or archive. Retain till and EPOS logs for 90 days minimum.
- Deploy endpoint protection on any PCs with EPOS-management access. Restrict admin rights via MFA and role-based access.
- Use tamper-evident seals, routine physical checks and CCTV covering terminal areas. Record inspection logs.
- Produce a concise remediation plan showing when outstanding issues will close. Presenting timestamps improves underwriting confidence and may reduce sublimits or premiums.
Real claim examples and lessons for UK retail cyber
Case A: card skimming from a tampered terminal. A small chain found the tampered terminal during a shift change. Detection took three days.
Forensics cost £4,200. Cardholder reimbursement and chargebacks cost £9,800. Business interruption loss was £2,400.
The insurer paid £13,900 after a £2,500 excess. A £10,000 sublimit on card costs applied, but in this case it did not reduce the card-related component. Lesson: keep serial numbers, CCTV and report tamper incidents to the acquirer immediately.
Case B: malware on back-office PC affecting EPOS. An installer connected an unmanaged laptop and malware spread. Detection took fourteen days.
Forensics cost £12,500. Notification and remediation cost £8,000. Regulatory engagement and legal costs were £6,700.
The insurer disputed cover for lack of segmentation and limited payment losses to £5,000. Lesson: network segmentation and documented patching are decisive.
These examples show total claim costs can range from under £10k to over £30k. Fast detection and strong supplier contracts improve outcomes.
Underwriting requirements for EPOS and till-based retailers
Cyber insurance for EPOS & till-based retailers is more likely to be available on favourable terms when retailers can demonstrate strong controls around card payments, tills and connected systems. Insurers increasingly assess how well a business prevents unauthorised access to payment data and limits the impact of a breach.
PCI DSS compliance and payment data controls
Retailers that process card payments should maintain the appropriate level of PCI DSS compliance. Underwriters may ask whether cardholder data is stored, transmitted or accessible through the EPOS environment, and what steps are taken to minimise this exposure. Using tokenisation, segregated payment networks and approved payment service providers can help reduce risk.
Software patching and payment-terminal security
EPOS software, back-office systems, routers and payment terminals should be kept on supported versions and patched promptly. Insurers may also expect unique administrator credentials, multi-factor authentication for remote access, anti-malware protection and restricted access to till management functions. Terminals should be physically secured and regularly checked for tampering, unauthorised replacement or suspicious peripherals.
Evidence insurers may request after an incident
Following a cyber incident, insurers may request evidence that reasonable safeguards were in place before the event. This can include PCI DSS documentation, patching records, endpoint security logs, access-control reports, supplier contracts, incident-response plans and payment-terminal inspection records. Keeping this information organised can support a smoother claim and help demonstrate that the retailer met the conditions of its cyber cover.
Frequently asked questions
Is POS / EPOS Retail Cyber Insurance mandatory in the UK?
No. There is no legal obligation to buy cyber insurance for EPOS systems. Some acquirers or landlords may require cover in contracts. Many insurers will ask for evidence of controls when you apply.
What is POS / EPOS Retail Cyber Insurance?
POS / EPOS Retail Cyber Insurance covers losses linked to payment terminals and card data compromise. It pays for forensic work, notification costs and limited card-related losses. It suits retailers using on-site terminals or handling card data locally.
How much does cyber insurance cost for a small retailer?
Costs depend on turnover, terminal count and controls. Typical SME premiums range from £350 to £5,000. Better controls and PCI evidence usually reduce premiums by twenty to forty percent.
What evidence will insurers ask for at underwriting?
Insurers typically request a terminal inventory, patch logs, network segmentation proof, PCI DSS attestation or remediation plan, and supplier SLAs. Lack of these items raises premium or leads to exclusions.
Will cyber insurance pay GDPR fines?
Some policies exclude regulatory fines. A minority offer limited cover when the insured can show compliance steps. Insurers expect prompt notification and clear evidence of controls.
How long does a typical EPOS cyber claim take to settle?
Forensics and immediate response costs are often authorised within a few days for small, clear incidents. Approval times vary by insurer and complexity.
Final settlement for larger claims takes thirty to one hundred and twenty days. The range depends on investigations and third-party recoveries.
Conclusion
POS / EPOS Retail Cyber Insurance helps UK SMEs manage costs from terminal compromise, skimming and payment outages. Check wording for card-related sublimits and PCI DSS requirements before buying. Gather terminal inventories, patch logs and supplier contracts to improve quotes and claims outcomes.
PCI Security Standards Council
UK Finance payment crime data