Updated in July 2026

Insurance for holiday lets and B&Bs should be considered. It covers guest data breaches, ransomware and booking‑system outages. Check forensic, notification and business interruption limits before deciding.
Cyber insurance for holiday lets & B&Bs
A short answer helps decide quickly: policies vary but the crucial items are forensic costs, guest notification and business interruption limits. Owners who store guest IDs, take card payments or use a Property Management System must confirm those items. UK data-protection law requires action. UK insurance law affects what to disclose to insurers.
Why it matters
Guest data breaches cause clear costs. Forensic work, legal advice and notification fees mount fast. Under UK GDPR, notify the ICO within 72 hours of becoming aware of a breach if it risks individuals. Many platform protections do not pay these costs for hosts.
Test your incident plan within the next thirty days.
Cover essentials
A practical policy covers first‑party forensic costs, incident response and privacy notification. It also covers reputational PR, cyber extortion and business interruption. Sub‑limits often apply to forensic and PR expenses. Check those sub‑limits rather than cover names alone. Network and information-systems rules may affect some service suppliers and supply-chain risk.
How marketplace cover compares
Platform host protections focus on property damage and guest injury. They do not usually cover cyber forensics or GDPR fines. Owners must not assume an OTA or AirCover will fund ransomware recovery. They must not assume an OTA will pay lost bookings during a PMS outage.
Platform protections give some comfort but leave gaps. Those gaps hit holiday lets and B&Bs in peak season. The difference is visible in forensic, ICO and business interruption cover. Compare the lines below before relying on any OTA.
OTA host protections often include limited property damage cover and dispute support. They rarely cover incident response, ICO defence costs or prolonged business interruption. Hosts must read Airbnb and Booking.com terms for precise limits.
What commercial cyber policies add
Commercial policies fund forensic investigation, legal defence and ICO notification costs. They also give crisis PR and cover ransomware negotiation under agreed terms. Many policies include business interruption for lost bookings caused by a cyber incident.
| Coverage item |
Airbnb / Marketplace cover |
Booking.com / OTA cover |
Commercial cyber policy |
| Forensic IT investigation |
Usually none |
Usually none |
Included (check sub‑limits) |
| ICO notification & legal defence |
Not covered |
Not covered |
Included (subject to limits) |
| Business interruption (OTA/PMS outage) |
No |
Limited or none |
May be included with day‑zero waiting period |
| PCI fines and card‑processor fees |
Not applicable |
Not applicable |
Often excluded unless bought as extension |
| Crisis PR and guest notification |
Not provided |
Not provided |
Usually included up to a sub‑limit |
1
Scope your tech stack
List PMS, channel managers, payment processors and data types.
2
Check platform terms
Identify what OTAs exclude: forensics, ICO and BI cover.
3
Get three quotes
Compare limits, sub‑limits and incident response times.
4
Test your incident plan
Run a tabletop exercise and confirm backup restores.
When combining cyber with public liability (PI) and business interruption (BI), check how policies interact. Avoid gaps and double cover. There are three common architectures: a single combined policy that includes cyber and liability extensions; separate cyber and PI policies with clear primary or secondary wording; or a modular approach where BI for physical damage sits on a material damage policy and cyber BI sits on the cyber policy.
For multi‑property managers pay attention to aggregate limits versus per‑property sub‑limits. An aggregate limit can be used up by one large ransomware event. Per‑property limits can protect peak‑week revenues.
Also check how deductibles apply. Some insurers apply a single retention across combined claims which can cost more if one incident triggers both cyber and PI elements. Ask for policy clauses that define “event”. Clarify whether cyber BI covers third‑party vendor outages and confirm whether crisis PR and ICO defence costs sit inside first‑party cyber limits or as separate expenses.
Test your incident plan within the next thirty days.
Single-property hosts and small B&Bs
Small hosts must prioritise simple, clear protection that pays fast. A compact policy with reasonable forensic and notification limits suits most single properties. Price sensitivity is common. Cheap policies often hide low sub‑limits that force out‑of‑pocket costs.
Typical needs for a single property
Hosts need cover for guest data breaches, ransomware and chargeback fraud from card‑not‑present transactions. The policy should include incident response and PR for reputational damage. Business interruption cover must account for peak booking days.
Example costs and bands
Annual premiums for single small properties often range from £200 to £750 depending on controls and turnover. For a single holiday let with £80k turnover expect £500–£1,200 per year if limits increase. Expect a standard excess of £500–£2,000 depending on insurer.
Practical underwriter checklist
Owners should document bookings per year, payment processors used and any stored passport scans or contact details. Evidence of backups, Multi‑Factor Authentication and staff training reduces risk. A Cyber Essentials certificate can help lower premium bands.
A simple way to make pricing clearer is to express premium as a percentage of short‑let turnover. Underwriters often use a rate band of 0.25%–2.0% of annual turnover for holiday businesses. Low‑risk profiles with MFA, up‑to‑date patching and Cyber Essentials might attract 0.25%–0.6%. Moderate profiles might fall in 0.6%–1.2% and higher‑risk examples 1.2%–2.0%.
Applied to an £80,000 turnover holiday let, that gives a notional premium range of £200 to £1,600. Selecting higher forensic or BI limits typically moves the rate toward the upper end. Adding PMS outage cover or increasing indemnity periods raises the premium. Demonstrable controls such as MFA, encrypted payment processing and documented backups commonly reduce renewal rates.
Test your incident plan within the next thirty days.
Property managers and multi-property portfolios
Property managers run aggregated risk across many listings and need policies built for scale. Multi‑property cover should offer aggregate limits or per‑property sub‑limits that match peak revenue days. Brokers often provide multi‑property discounts and central policy wording for managed portfolios.
What portfolio policies change
Policies for portfolios add higher business interruption limits and broader supply‑chain cover. They may include vendor breach clauses for channel managers and PMS providers. Underwriting will ask for aggregated revenue, peak season exposure and IT architecture details.
Sample portfolio pricing
A small portfolio with three to ten properties commonly sees premiums from £1,500 to £5,000 per year. Larger managers with 10+ properties or over £1m turnover may expect £5,000–£15,000 or more per year. These are ranges. Controls and claims history change pricing.
Claims handling and consolidation
Multi‑property claims can scale quickly and require central incident coordination and a named claims handler. The insurer should provide a single incident response team that can work across properties. The error most frequent at this point is assuming a single small sub‑limit will cover multiple simultaneous incidents.
Test your incident plan within the next thirty days.
Common mistakes and policy warnings
Owners and managers commonly assume platform or home insurance covers cyber losses. Home or landlord policies rarely include sufficient cyber cover for short‑let businesses. The most damaging surprise is a low forensic sub‑limit when costs exceed it.
Exclusions to watch
Watch for explicit exclusions for credential‑stuffing, unpatched systems and failure to follow insurer‑required controls. PCI fines are commonly excluded unless bought as an extension. Policies sometimes exclude losses from software the owner failed to update.
Claims disputes and legal timings
Under the Insurance Act 2015 the insured must disclose material facts when buying or renewing a policy. Keep records and show them to the broker and insurer. Under UK GDPR and the Data Protection Act 2018 the ICO must be informed within 72 hours if a breach risks individuals. Insurers expect timely engagement.
Practical warning
This works well in theory. In practice small hosts often delay contacting insurers and forensic teams to avoid disruption. Delay increases overall costs and complicates legal defence. The earlier the insurer and a forensic firm join, the faster containment and restoration.
Policies often use named clauses and sub‑limits that make a material difference in hospitality claims. Typical wording to watch includes social engineering or funds transfer fraud, contingent or dependent business interruption, retroactive date exclusions and time‑element waiting periods. Insurer schedules commonly set forensic investigation and crisis PR on separate sub‑limits, for example £10k–£50k for forensic IT and £5k–£25k for PR.
Regulatory fines are frequently excluded in UK wordings. What is usually covered is ICO defence costs and privacy notification expenses, not the fine itself. Hosts should check clause titles such as "Cyber Crime (Social Engineering) Exclusion/Extension", "Dependent Third Party Outage" and "Forensic Costs Sublimit".
Test your incident plan within the next thirty days.
On discovery isolate affected systems, preserve logs and contact your insurer and an incident responder immediately. The insurer often funds the response. The owner still must meet GDPR timing and keep records. Prepare simple templates to speed notification and guest communications.
Contain the incident by isolating infected devices and stopping remote access. Preserve evidence by saving logs and recording dates and times for a timeline. Contact the insurer’s 24/7 incident line and a cyber forensics team.
ICO notification template
To: Information Commissioner's Office
Date: [date]
Controller: [business name]
Description: On [date] we became aware of a personal data breach affecting [number] individuals. Categories: [names, passport numbers, emails]. Likely consequences: [identity theft, fraud]. Measures taken: [containment, forensics, notification]. Contact: [name, email, phone].
Guest notification example
Dear [Guest name],
We detected unauthorised access to our booking system on [date]. Your name and booking details were involved. We have contained the issue and started an investigation. Please check your bank statements and change any passwords used with us. Contact [email] or [phone] for help.
Real claims and anonymised cases
Real claims show forensic and business interruption costs frequently exceed £30,000 per incident for holiday lets. One anonymised example involved ransomware that encrypted a PMS and paused bookings during a bank holiday week. The combined forensic and lost bookings costs totalled £33,700 after excess.
Case: ransomware on a PMS
Situation: A manager in Cornwall faced ransomware that encrypted the PMS and booking logs. Forensic costs of £18,500 followed. Booking losses for six days in peak season added £12,000. PR and notification costs were £3,200.
Outcome: The commercial cyber policy covered £33,700 after excess. The OTA provided no forensic or BI help. Lesson: Business interruption limits must reflect peak season turnover.
Case: channel manager data leak
Situation: A B&B in Yorkshire had guest emails and passport scans exposed after a channel manager API misconfiguration. ICO assistance and legal defence costs were £22,000. Guest notifications and goodwill payments were £6,500.
Outcome: The insurer paid for legal defence and notification costs. PCI fines were not covered and were pursued against the vendor. Lesson: Check vendor indemnities and pursue supplier responsibility.
Test your incident plan within the next thirty days.
What to do next
Owners should gather basic underwriting information: annual turnover from short‑lets, number of properties and the names of any PMS or payment processors used. Use that data to request at least three quotes and compare limits and sub‑limits carefully. A broker experienced in hospitality can speed the process and help negotiate multi‑property terms.
A sensible approach works well, but only if the owner prepares clear information and tests incident plans. Buyers should prioritise fast incident response and realistic business interruption cover that reflects peak weeks. The practical recommendation is to get quotes and arrange a tabletop exercise within 30 days to verify contacts and restore procedures.
For a quick next step, contact a broker that specialises in hospitality insurance and request a multi‑property quote that lists forensic, notification and business interruption limits in writing.
Do not apply this advice if the property never processes online payments and never stores guest personal data. Also, if bookings are taken only by phone or in person and an existing commercial policy explicitly lists cyber, PI and business interruption for short lets, further cover may not be necessary.
For guidance on reporting breaches to the UK regulator see ICO guidance on reporting a breach. For practical steps to protect small businesses see the NCSC 10 Steps guidance: NCSC 10 Steps.
Frequently asked questions
Platform protections do not replace a commercial policy. Platforms focus on property damage and guest disputes. They rarely fund forensic investigations, ICO fines or business interruption caused by PMS outages.
How much should forensic and notification limits be?
Aim for at least £25,000–£50,000 combined for forensic and notification for a small B&B. This band typically covers a basic forensic investigation and guest notification. Increase limits for higher turnover or if passport scans are stored.
Will home or landlord insurance cover short‑let businesses?
Home or landlord policies rarely provide adequate cyber cover for short lets. Those policies often exclude business activities and lack forensic, PR and GDPR defence cover. Check policy wordings and seek a commercial extension.
What if a channel manager or PMS caused the breach?
Vendor responsibility depends on contracts. The insurer may cover immediate costs and then subrogate against the vendor. Keep vendor logs and contract clauses to support recovery actions. Pursuing vendor liability can take months.
How soon must the ICO be notified when guest data is breached?
Notify the ICO within 72 hours of becoming aware if the breach risks individuals. Record the reasons if notification is delayed. Insurer engagement does not remove this legal duty.
Can I get a multi‑property discount for several properties?
Yes, many insurers offer multi‑property discounts for several properties; brokers can negotiate consolidated wording and per‑property sub‑limits to reflect peak revenue and manage aggregate exposure.