Cyber insurance for wholesale & B2B suppliers covers a supplier's cyber loss and losses caused to customers. It should include contingent business interruption and contractual liability cover. Check policy wordings, sub‑limits, reinstatements and incident‑response services. Map critical suppliers, gather evidence and brief a broker to compare cover and pricing.
Cyber insurance for wholesale & B2B suppliers key risks
In the context of suppliers, contingent business interruption (CBI) means losses caused when a critical vendor fails. Many standard policies exclude supplier failure unless an endorsement is present. Suppliers must confirm triggers, waiting periods and territorial limits in the policy wording.
According to the NCSC Annual Review 2023, the centre responded to more than 1,200 cyber incidents during the period covered by the review, and the Hiscox Cyber Readiness Report 2023 found about 46% of UK firms faced a cyber breach in the prior year. The ICO reported fines and enforcement actions totalling over £250m.
-
Supplier-specific risk scenarios and modelling show typical triggers and losses. These scenarios help underwriters and buyers agree triggers and waiting periods.
-
EDI or messaging provider ransomware stops order intake for days. CBI should respond to non‑physical interruption in that scenario.
-
Managed Service Provider credential compromise lets an attacker move laterally across customer environments. That can cause simultaneous outages for several buyers.
-
Cloud provider or SaaS API outage degrades service or corrupts data. There may be no physical damage but still large business loss.
-
Third‑party software supply‑chain compromise via a malicious package can cause data exfiltration and regulatory exposure.
-
OT or ICS disruption at a contract manufacturer can halt production and cause product shortfall.
-
Compromise of a logistics or courier partner can break fulfilment SLAs and trigger penalties.
For each scenario, model at least three severities. Use short outage (1–3 days), medium outage (4–10 days) and long outage (over 10 days). Show how waiting periods, territorial restrictions and CBI sub‑limits change recoveries.
Practical tip: ask brokers to run a simple loss‑modelling spreadsheet for your top three supplier dependencies. The spreadsheet should show revenue at risk per day, contractual penalties and legal costs. That produces defensible limit recommendations for negotiations.
The factors that decide cover
Underwriting for suppliers focuses on four variables: dependency on critical IT systems; the volume of customer data processed; contractual indemnities to clients; and the supplier's third‑party connections.
Each factor changes the limit recommended and the pricing band. Pricing benchmarks for typical UK wholesale or B2B suppliers fall into ranges. For low dependency businesses, the market range is £350 to £1,200 annual premium for a £500k limit.
For higher‑dependency suppliers, premiums commonly range from £2,500 to £8,000 for similar limits. Prices remain subject to security controls and contract profile.
Map your top 10 suppliers and note each supplier's service, single point of failure and contractual SLA within three days.
Operational scenarios and recommended cover
The difference between first‑party and third‑party exposure is central. First‑party costs the supplier directly. Third‑party costs arise when customers claim lost profit or penalties from the supplier. Insurers price and word the two risks differently.
Scenario A: critical supplier outage causing customer losses
A warehouse supplier lost order management for four days after ransomware. Contingent BI and supplier failure wording paid a portion of client losses. The insurer reduced recovery by the policy waiting period. The insurer also applied a sub‑limit for CBI.
The supplier had to rely on a reinstatement clause to regain full limit for a second event.
Scenario B: supplier system breach exposing client data
A B2B software provider leaked customer records through a misconfigured API. The claim involved breach notification costs, legal defence and regulatory investigation. The insurer covered notification and legal costs under the data breach section. Contractual liability was limited and required a specific endorsement.
This guidance does not apply if the business is a sole trader with negligible digital dependency. It also does not apply if the business already holds a bespoke corporate cyber programme. In those cases, a tailored legal placement is needed.
Real claims that illustrate what policies pay
Case 1 supplier compromise
An anonymised wholesaler had a supplier's EDI provider hit by ransomware. The wholesaler lost ordering capability for five days. The policy paid for loss of gross profit under CBI after a 48‑hour waiting period. The insurer invoked a territorial restriction that reduced recoverable days.
Case 2 cyber extortion and recovery
A parts distributor received an extortion demand after data theft. Incident response costs and ransom negotiation were paid. The insurer's appointed forensic team handled the recovery, shortening the outage from ten to three days.
Case 3 contractual liability dispute
A B2B packer missed delivery SLAs and faced a client indemnity claim. The supplier's cyber policy had a contractual liability extension and covered defence costs. The settlement eroded the limit and showed the need for higher third‑party limits.
Take a short pause and review supplier risk details.
Choosing cover for wholesale and B2B suppliers
In the context of placement, wording, sub‑limits and capacity layers determine practical protection. Suppliers must balance first‑party loss, third‑party liability and CBI exposure. A broker should be asked to show full wordings, not only the summary schedule.
| Criterion |
Excess layer |
Reinstatement |
When to choose |
| Purpose |
Adds capacity above a primary limit |
Restores the primary limit after a claim |
Choose excess when rare, large losses are your risk |
| Cost pattern |
Lower annual cost for high limits |
Higher cost but better for repeat losses |
Choose reinstatement for frequent claim exposure |
| Claims handling |
Layer pays after primary exhausted |
Primary is replenished for a later event |
Use reinstatement when repeat incidents threaten operations |
Choose excess layers when a single catastrophic loss is plausible. Choose reinstatements when the supplier expects multiple incidents in a policy year. A broker can model scenarios and show the net cost per year.
Stop and mark the top ten suppliers now.
- Identify critical suppliers.
- Quantify client exposure.
- Check policy triggers.
- Request full wordings.
-
Negotiate endorsements.
-
a) Contingent BI or dependent vendor trigger example: “The insurer will indemnify the insured for loss of gross profit incurred as a result of interruption to the business caused by interruption of or damage to the property of a dependent supplier. The clause covers interruption that results from a malicious cyber act or failure of technology services and is subject to the waiting period specified herein.”
-
b) Dependent party definition example: “ 'Dependent party' means any external supplier, third‑party service provider or manufacture named in the insured’s supplier dependency register. The failure of such a party would reasonably be expected to cause interruption to the insured’s business.”
-
c) Contractual liability extension example: “This policy shall cover sums which the insured becomes legally liable to pay under any contract or agreement to indemnify a third party for loss arising from a cyber event. Cover applies provided such liability would have attached to the insured irrespective of such contract and subject to any specific contractual liability sub‑limit.”
-
d) Forensic and ransom sub‑limit example: “Forensic investigation, incident response, notification and ransom payments shall be subject to a combined sub‑limit of £[X]. This applies unless otherwise agreed.”
Practical reading tip: ensure the dependent party definition is broad enough to capture MSPs and cloud providers. Confirm whether the CBI trigger requires physical damage or expressly covers non‑physical cyber events. Check whether contractual liability is primary or subject to a narrow endorsement and a separate sub‑limit.
Broker and placement checklist for suppliers
A broker should receive the following documents before quoting. Provide contracts that contain indemnities and a supplier‑dependency register. Also provide recent penetration test summaries and a list of third‑party vendors. Give details of previous incidents and any cyber hygiene certifications.
Ask brokers to deliver the full policy wordings and to highlight these items. They must mark CBI triggers, territorial limits and retroactive dates. They must also mark contractual liability extensions and sub‑limits for ransomware, forensic costs and notification.
Practical broker and wholesale placement guide
- One‑page executive summary with business description, top 10 clients and single points of failure.
- Supplier‑dependency register.
- Copies of sample contracts with indemnities and SLA remedies.
- Recent pen‑test and vulnerability scan executive summaries.
- Summary of cyber controls such as MFA, EDR, backups and an incident response plan.
- Three‑year incident and claims history with timelines.
Underwriting criteria brokers should expect to answer for a supplier include the single largest customer concentration. They should also cover average order processing downtime tolerance. They must confirm vendor segregation, segregated credentials and backup testing cadence. They must say whether the supplier delegates critical functions to MSPs.
Placement process: prepare a data room and set realistic timelines. Expect two to four weeks for MGAs and four to eight weeks or more for Lloyd's capacity. Instruct brokers to split primary and excess submissions to markets that underwrite dependent‑vendor risk. Negotiate clear deliverables including full policy wordings in clean copy and a mark‑up showing any bespoke endorsements. Ask for a quotation matrix comparing limits, waiting periods and sub‑limits.
Pause and check your supplier list and contracts.
Errors suppliers make when buying cyber cover
Common mistakes erode protection and cause surprise rejects at claim time. One mistake is assuming CBI automatically covers supplier outages. Another mistake is buying by premium alone and not checking reinstatement or retroactive dates. A third mistake is failing to evidence security controls when asked by underwriters.
An example error: a supplier believed a standard policy covered client replacement costs. The insurer denied the claim due to an exclusion for contractual penalties. The supplier then faced a large settlement out of pocket.
Questions suppliers ask about cyber insurance
What does cyber insurance cover?
Cyber insurance covers first‑party costs like incident response, data recovery and business interruption. It also covers third‑party costs such as client claims, defence costs and regulatory fines when the policy wording allows. Wording details decide the practical cover.
How much does cyber insurance cost in the UK?
Cost depends on exposure and controls. Typical annual premiums for SMEs range from £350 to £8,000. Higher risk suppliers pay above that range when contractual liability and CBI are large.
Do suppliers need cyber insurance?
Suppliers with digital operations or client data should carry cyber insurance. It transfers financial risk from outages, data breach response and contractual claims. Small micro businesses with minimal digital dependency may not need it.
Does cyber insurance cover supply chain attacks?
Policies may cover supply chain attacks if CBI and dependent vendor wording are present. Many policies exclude supplier failure by default. Suppliers must seek explicit CBI endorsements to secure cover for supply chain attacks.
How do I get cyber insurance for wholesale suppliers?
Prepare a supplier dependency register and evidence of security controls. Brief a broker with contracts and incident history. Ask the broker for full wordings, pricing for reinstatement and any recommended endorsements.
Cyber insurance for wholesale & B2B suppliers?
Yes. Cover must match supplier exposure. Insurers look for data volumes, contract indemnities and critical vendor connections. Negotiate limits and endorsements before signing.
Does cyber insurance handle GDPR fines?
Some policies cover regulatory defence costs and fines where permitted by law. UK GDPR fines may not be fully insurable. Review the wording and ask the broker for clarity on regulatory exclusions.
Conclusion
Suppliers should buy cyber insurance that covers both first‑party losses and losses caused to customers. The placement must include clear CBI triggers, contractual liability endorsements and suitable limits or reinstatement. Prepare documentation, map supplier dependency and get full wordings from brokers before accepting a quote.
For technical guidance and legal interpretation, consult a broker experienced in wholesale and B2B placements. For regulatory detail, see the ICO guidance on data breaches and NCSC advice for businesses.