Using online bookings and card payments usually raises cyber exposure and premiums. Choose a hosted gateway, tokenisation, MFA and clear contracts to cut loadings.
Quick comparison table
The table shows how booking and payment setups change cover and premiums.
How to read the table
Each row links a setup with typical cover and premium impact. Show the listed evidence to your broker at renewal.
What to show your broker
Brokers ask for PCI attestations, token details and provider terms. Keep screenshots and scanned pages to prove controls and show them to your broker at renewal.
The table below shows how common booking and payment setups change the cover you need and how insurers typically price them.
| Payment / booking setup |
Cover typically needed |
Typical premium impact |
Evidence broker/underwriter asks for |
| Hosted gateway (Stripe Checkout, PayPal hosted) |
First‑party forensic costs, data breach, BI, limited transfer‑fraud extension |
Low to medium |
PCI attestation, hosted‑page evidence, tokenisation details |
| Direct integration (stores or passes PANs) |
Full cyber cover, higher limits for card data liability, transfer‑fraud extension |
High (often 30–100% loading) |
PCI scope docs, vulnerability scans, patching and logging evidence |
| Marketplace/booking platform (Checkatrade, Rated People) |
Third‑party liability, indemnity clarity, BI from platform failure |
Medium to high (depends on T&Cs) |
Platform T&Cs, indemnity clauses, SLA and liability split |
| Bank transfers / APP payments handled manually |
Transfer‑fraud (APP) cover, controls on authorisation, reconciliation |
Medium (depends on controls) |
Bank authorisation policies, two‑step approval evidence, staff training logs |
Estimated cost: Typical UK SME cyber premiums range from £200 to £2,500+ per year. Actual cost depends on transaction volume, provider type and security controls.
A simple cover versus premium framework helps tradespeople choose the right policy. It avoids guessing at renewal.
- Insurers and brokers commonly price three tiers:
-
Basic: first‑party forensic and breach response only, small BI and transfer‑fraud sub‑limits. Typical sole trader premiums £200–£450 with low online turnover.
-
Standard: adds social‑engineering and authorised‑push payment extensions, higher BI limits and PR/defence costs. Expect a moderate loading of +20–60% on basic.
-
Premium: comprehensive cyber with large transfer‑fraud limits, full BI cover and regulatory fines cover. Premium can add +50–150% depending on volume and controls.
Check the numeric sub‑limit before relying on cover.
Hosted gateway vs direct integration: when to pick which
Choosing a hosted gateway usually lowers underwriting concern because card data leaves your systems. Insurers favour hosted pages that hold card details.
Hosted gateways: clear advantages
Hosted gateways reduce your PCI scope by moving PANs off your systems. Merchants still keep residual duties such as completing the correct PCI SAQ type and securing admin interfaces. Underwriters therefore may still request the provider's PCI attestation, the SAQ type and evidence of transaction monitoring; keep those attestation documents and hosted checkout setup screenshots for renewal. Expect premium reductions, not a guaranteed waiver.
Direct integration
Direct integration that stores or processes PANs expands PCI scope and raises claim severity potential. Underwriters typically apply higher premiums and more conditions.
Expect quarterly vulnerability scans, patching evidence and a dedicated incident response plan. Expect endorsements or higher excesses when card data touches your servers.
How payment provider choice alters your premium
Underwriters change premium loadings and sub‑limits based on provider type, controls and contractual liability. Use tokenisation, hosted pages and chargeback protections to lower exposure.
Use hosted pages, tokenisation and clear contracts to lower insurer concern and shrink premium loadings for most small trades. However, underwriters still ask for PCI attestations, logs and proof of MFA; show those documents at renewal and brokers can often negotiate lower loadings or secure higher transfer‑fraud sub‑limits for your business.
Tokenisation
Tokenisation replaces card numbers with tokens and lowers theft risk from systems. Insurers treat tokenisation as a material control when assessing exposure.
Request the provider's technical statement and pass it to the broker.
MFA, logging and scans reduce loadings
Multi‑factor authentication on admin and accounting accounts cuts credential takeover chance and social‑engineering success. Keep logs for at least 90 days and show vulnerability scans at renewal.
Present these artefacts to contest loadings and secure better sub‑limits.
1
Choose hosted gateway
Remove card data from your systems
2
Document controls
PCI attestation, MFA, logs, backups
3
Show evidence at renewal
Get lower loadings and higher sub‑limits
Policy clauses tradespeople must check before renewal
The clauses that most change cover are social‑engineering wording, payment sub‑limits, BI triggers and notification terms. Ignoring these clauses often causes denied or reduced claims.
Social engineering and transfer‑fraud
Many SME policies either exclude social‑engineering losses or put them behind small monetary sub‑limits. Ask for the exact endorsement reference and the numeric sub‑limit to avoid surprises.
A common error is to assume standard cyber cover includes authorised‑push payments. That assumption often fails at claim time.
Business interruption and incident
Business interruption triggers vary by wording and endorsement. Some policies exclude contingent third‑party outages while others include contingent BI endorsements.
If a third‑party platform is a material risk, secure a contingent‑BI endorsement or contractual SLAs that insurers accept as dependency evidence.
Confirm whether response costs, PR and legal defence sit inside the main sum insured or behind sub‑limits. If response fees sit outside main cover, effective protection can be much lower than expected.
Typical premium ranges by trade and transaction volume
Underwriting bands depend on turnover, online payment volume and controls. Use these ranges as a starting point when comparing quotes.
Sample premium bands and assumptions
Low online volume (payments under £5,000/year) for a sole trader often receives quotes around £200–£500 per year when basic cyber hygiene is shown. Medium volume (£5,000–£50,000/year) commonly sits at £400–£1,000. High volume or marketplace dependence (over £50,000/year) can push premiums to £800–£2,500+.
Factors that push premiums higher
Premiums rise if card data is stored, PCI controls are absent, backups are untested or no incident response provider is listed. Expect higher excesses and specific endorsements for direct integration.
Examples by trade (UK market, illustrative):
-
An electrician taking under £5k online per year and using a hosted gateway commonly sees premiums of about £200–£450 with basic controls in place.
-
A plumber with medium online turnover (£5k–£50k) and direct payment links or marketplace exposure typically sees £400–£1,000 depending on tokenisation and MFA.
-
Small builders who take large online deposits or process over £50k annually often fall into the £800–£2,500+ band when payments are integrated.
Marketplace dependence, frequent chargebacks or holding card details push insurers to add higher excesses and endorsement loadings of 20–75%.
Checklist to reduce insurer risk scores and premiums
This checklist lists actions underwriters expect to see at renewal and that reduce perceived exposure when shown to a broker.
Provider and technical checklist
- Use a hosted PCI‑DSS gateway with tokenisation and obtain the provider's attestation or SOC report.
- Enable MFA on all admin, booking and accounting accounts and keep logs for at least 90 days.
- Keep encrypted backups and run restore tests at least twice a year.
Operational and contractual checklist
- Keep written booking‑platform contracts that state who is liable for payment disputes and data breaches.
- Maintain a short incident response plan naming a forensic provider and their hourly rates.
- Train staff on refund and transfer authorisation and keep a signed attendance log.
Exact questions and model wording to get from underwriters
Asking precise questions and getting written answers prevents ambiguity at claim time. Request endorsement numbers and scanned policy pages so the cover is verifiable.
Four essential written confirmations to request
- "Please confirm the exact endorsement reference and monetary sub‑limit that applies to authorised‑push payment/transfer fraud."
- "Please confirm whether social‑engineering losses are excluded, and if covered state the sum insured, excess and any conditions such as MFA."
- "Please confirm the retroactive/prior‑acts date and whether incident response costs are included in the main sum insured."
- "Please list which documented controls (PCI SAQ type, hosted gateway, tokenisation, MFA) will reduce premium loadings or increase sub‑limits."
Template email to broker
Subject: Confirmation of cyber endorsement details
Dear [Broker name],
Please confirm in writing the following for policy [policy number]:
1) Endorsement reference and monetary sub‑limit for authorised‑push payment/transfer fraud.
2) Whether social‑engineering losses are excluded or included (state sum insured, excess and conditions).
3) Retroactive/prior‑acts date and inclusion/exclusion of incident response costs.
4) Which controls you require to reduce premium loadings (eg. PCI SAQ, hosted gateway, MFA).
Please attach the scanned policy pages or endorsement wording.
Regards,
[Your name]
What insurers often omit or misstate
Insurers and brokers sometimes use phrases that sound protective but shift risk onto the tradesperson. The crucial detail is the endorsement wording and numeric sub‑limits, not the marketing lines.
The error most frequent at claim time is relying on verbal assurances rather than signed endorsements. Get the exact clause and the money figure in writing.
A common case:
- A sole trader used a marketplace to take bookings and assumed the platform indemnified payment losses.
- After a transfer‑fraud incident the platform pointed to limited T&Cs and the insurer applied a low transfer‑fraud sub‑limit.
- The insurer’s wording required documented MFA and provider proofs, which the trader could not provide.
The evidence points to one practical rule: get the exact clause and the money figure in writing. The claim will hinge on that number, not on general policy descriptions.
This recommendation works well, but only when the tradesperson can produce the required evidence quickly. If those documents are missing, pause online payments or switch to a hosted gateway until controls are in place.
Legal and regulatory note: Tradespeople should note the Data Protection Act 2018 and UK GDPR set notification duties for personal data breaches, and the Payment Services Regulations 2017 govern some payment services. Also note PCI DSS 4.0 was published and may change merchant duties.
If you want broker wording to present at renewal, ask for written endorsement numbers and scanned pages before the renewal payment is taken; do not rely on verbal promises when buying cover.
If ready to act, request written endorsements and provider evidence from your broker today.
Two anonymised examples illustrate how policy wording and controls determine outcomes. Case A:
- A sole‑trader decorator authorised a bank transfer of £7,800 to a fraudster after a convincing invoice change request.
- The insurer’s transfer‑fraud endorsement had a £5,000 sub‑limit and required MFA on the accounting email as a condition.
- Because MFA was not demonstrably enabled the insurer paid only the £5,000 sub‑limit and declined the balance, leaving the trader short about £2,800.
Lesson: numeric sub‑limits and control conditions such as MFA logs are decisive.
Case B:
- A small electrical firm suffered a ransomware attack that knocked out its booking portal hosted by a third‑party marketplace.
- The firm claimed BI losses for two weeks, but the policy’s BI wording required an insured‑owned system outage or a named contingent‑service endorsement.
- The BI claim was refused, though response and forensic costs were paid.
Lesson: ensure BI wording explicitly covers third‑party platform failure or obtain contractual SLAs that support a contingent‑BI claim.
Final recommendations and next steps
Tradespeople using online booking and payments should obtain written policy pages and any endorsements that mention payment fraud or social‑engineering. Next, gather the provider's PCI attestation, enable MFA and keep logs and backup test records.
Suggested immediate actions: switch to a hosted gateway if not already using one, enable MFA across admin accounts, run a backup restore test and email your broker the template above requesting endorsement references. These four steps reduce insurer concern and usually lower premiums.
Frequently asked questions about cyber cover and premiums
How much does cyber insurance cost for a tradesperson?
Typical cost varies by controls and payment volume. Sole traders with little online payments often see premiums of £200 to £600 per year. Small teams with medium turnover commonly pay £400–£1,000, and heavy marketplace use may cost £800–£2,500+.
Do insurers cover ICO fines after a breach?
Insurers sometimes cover legal defence and fines, but policies vary. The Data Protection Act 2018 and UK GDPR allow the ICO to fine, and cover may have caps. Get written confirmation on fines and defence costs and any monetary caps.
What is a common reason a cyber claim is declined?
A common reason is failing to notify material changes or meet policy conditions. Switching to a direct integration that stores card PANs or lacking MFA often voids cover or limits payout. Always get endorsement numbers and scanned policy pages to avoid disputes at claim time.