Could a single supplier breach wipe out months of revenue, trigger regulator fines or leave customers exposed?
Many UK SMEs assume supplier incidents are picked up by standard cyber cover.
But exclusions, sub‑limits and vendor‑specific clauses often create costly gaps at renewal or during a claim.
What this cover pays and what to do now
Most policies split the response into costs you incur directly (first‑party) and liability you face to others (third‑party).
Read the policy schedule to confirm which of the two applies in your case.
First‑party cover pays the expenses your business incurs to revive operations after a supplier incident.
Examples include forensic investigations, breach notification, credit monitoring for affected individuals, crisis PR and contingency hiring.
Contingent business interruption (CBI) covers lost income when a supplier outage stops you trading.
Typical SME policies may limit CBI to a sub‑limit or a fixed sum.
Smaller products often set sums between £100,000 and £500,000.
Some larger market programmes offer £1m or more.
Insurers use simple scenarios to price CBI sub‑limits and waiting periods; a common example is the business impact of one supplier failing for four days. Present that scenario to insurers for pricing and assessment.
Third‑party liability meets claims brought by customers, partners or regulators alleging your negligence caused loss after a supplier incident.
Defence costs may be covered even when damages are not.
Check the exact policy wording to see where defence costs apply.
Before you call a broker or insurer, gather these items: supplier contracts, data protection impact assessments (DPIAs), recent penetration test reports, incident notification logs and a list of critical services.
Be prepared to present the four‑day supplier‑failure scenario so insurers can assess CBI needs and waiting periods.
Quick checklist
- Confirm whether your current cyber policy lists contingent business interruption.
- Check CBI sub‑limits and waiting periods.
- Ensure supplier contracts include a 24‑hour notification clause and an insurance warranty.
Useful resources
Legal and regulatory years to note
- Insurance Act 2015 (disclosure duties)
- Data Protection Act 2018 (implements UK GDPR)
- Computer Misuse Act 1990 (criminal conduct in incidents)
If the business depends on one or more cloud services, the risk concentrates and losses escalate fast.
Identify critical suppliers and map what happens if each fails.
Typical losses for cloud‑reliant SMEs
Cloud outages cause lost sales, failed fulfilment and extra staffing costs.
A four‑day outage at a payment processor can cause direct lost revenue in the tens of thousands for a small retailer.
What to check in policy wording
Confirm the policy covers outages caused by subsuppliers and cloud hosts, not only your own systems.
Look for wording that includes "contingent" or "dependent" interruption to capture supplier failures.
Practical contract steps
Put an incident notification clause requiring the supplier to alert within 24 hours and to provide logs on request.
Record ISO 27001 or SOC 2 evidence from each cloud supplier and keep it on file.
If a single supplier provides a critical function, the business faces concentration risk.
Measure how long the business can survive without that vendor and plan accordingly.
How limits should reflect concentration
Where one supplier provides a critical function, insurers may ask for higher limits or apply stricter sub‑limits.
Increase coverage if the supplier is a single point of failure.
Negotiating contract protections
Request that suppliers provide a copy of their cyber policy wording and an insurance warranty.
Avoid contractual language that requires you to waive insurer subrogation rights or that absolves the supplier of liability.
Where appropriate, require the supplier either to obtain a waiver of subrogation from their insurer in favour of your business or to accept contractual liability.
Do not agree to mutual waivers that prevent insurer recovery.
Discuss the precise wording with your broker or legal adviser.
Include an insurance warranty specifying minimum limits and evidence frequency.
Example clause for contracts
Insurance warranty: The supplier shall maintain cyber liability insurance of at least £[250,000] per claim and shall provide a copy of the insurer's policy wording and proof of payment of premium on request.

The most frequent mistake is assuming the supplier’s insurer will pay your losses without checking that supplier's policy wording.
That error costs firms time and often money.
Late notification and missing records
Insurers expect prompt notice and mitigation.
If the insured delays reporting or cannot show DPIAs, patch logs or supplier due‑diligence, the claim may be reduced or denied.
Systemic exclusions and aggregation
Many policies exclude "systemic events" or cap total insurer exposure where many clients are affected at once.
That wording can turn a large cloud outage into a partial loss for policyholders.
Subrogation and indemnity complications
If a contract waives the supplier’s liability, insurers may find it harder to subrogate.
Always check how indemnities and waivers affect recoveries and discuss this with the broker.
If the reader needs immediate help preparing for a renewal or a specific incident, speak to a specialist cyber broker and gather your supplier contracts, DPIAs and incident logs before the call.
Insurers review evidence early in the claims process and cannot backfill missing documents later.
Practical preparation and how to submit a claim
A clear, evidence‑first approach speeds up claim handling and improves outcomes.
Gather relevant documents and follow the insurer's notification process in the policy.
Preserve logs, capture event timestamps and engage your incident response provider.
Notify the insurer within the policy time limit and keep a written record of every supplier communication.
Documents insurers expect
Insurers often require the supplier contract, DPIA, proof of due diligence, forensics report, and financial records proving losses.
Missing any of these items can delay payment or reduce the amount paid.
Typical claim stages and timescales
The insurer acknowledges notice within 24 to 72 hours and may appoint a claims handler or forensic firm.
An initial urgent payment can appear in days.
Full settlement often takes weeks to months depending on complexity.
Include a single folder for the claim pack: contract, supplier evidence, DPIAs, notification logs, forensics and financial loss evidence. This is the pack the claims handler will open first.
Step‑by‑step
A practical purchase and claims flow reduces ambiguity.
Step 1 (procurement):
- Map critical suppliers, quantify 3–6 months gross profit exposure and ask three brokers for quotes against the same scenario.
- Request explicit wording for ‘contingent business interruption’ and any CBI sub‑limit.
Step 2 (contracting): insist the supplier provides an insurance warranty and copies of policy wording, and record notification obligations (for example, supplier to notify within 24 hours).
Step 3 (renewal): compare premiums against CBI sub‑limits, waiting periods (eg 24–72 hours) and excesses before binding.
Step 4 (incident): within the policy time limit, notify the insurer in writing, preserve logs and engage forensics.
- Record a simple claims timeline (timestamp, supplier notice, actions taken).
Step 5 (claims handling): expect an acknowledgement within 24–72 hours, potential interim payments within 7–14 days for urgent costs (forensic investigation costs, breach notification costs), and full settlement in weeks to months.
This labelled flow aligns procurement choices with the claims timeline and reduces surprises when using third‑party vendor insurance or invoking supply chain cover.
Templates, costs and anonymised case studies
Real examples show how cover can work and where it fails.
Use the templates below to improve procurement and claims outcomes.
Case study: SaaS outage causing £180k CBI claim
A London SME lost order processing for four days after a SaaS provider ransomware attack.
The insurer paid forensic costs (£15,000) and lost revenue (£150,000) after the supplier provided logs proving the cause.
The firm had clause evidence and a retained incident responder which sped approval.
Case study: payroll processor data leak and ICO
A small firm faced an ICO investigation after payroll data exposure.
The insurer paid notification and legal defence costs (£40,000) but denied ICO fines where the policy excluded regulatory penalties.
The firm learnt to check ICO fine coverage before renewal.
Ready‑to‑use templates
- Supplier due‑diligence checklist: record ISO certificates, penetration test dates and remediation evidence.
- Contract clause pack: notification clause, insurance warranty and evidence provision clause.
- Claim evidence checklist: contract, DPIA, logs, forensics report, invoices for remediation and financial loss detail.
Quick decision paragraph
Buying supply chain cover makes sense for most SMEs that rely on external IT, payroll, payment or logistics suppliers.
It works well when policy limits and sub‑limits match the measurable impact of a supplier outage.
It is less helpful if concentration risk, systemic exclusions or missing contract evidence remain unaddressed.
Review contracts and evidence first and then set limits accordingly.
Opinion: Buy specific contingent business interruption and a clear supplier proof folder if the business relies on third‑party cloud or payment services; increase sub‑limits for single‑vendor exposure and insist on a 24‑hour notification clause from suppliers.
This does not apply to businesses that operate entirely offline or where losses are already coverable under another valid policy such as product liability. In those cases a specialist broker or legal advice is still recommended.
If uncertain before renewal, prepare your supplier evidence pack and ask a specialist cyber broker to compare at least three market quotations against the same scenario and limits.
Frequently asked questions
What triggers a vendor claim?
A vendor claim triggers when your business suffers loss because a supplier was breached or unavailable.
The insured must show causation: documentation that links the supplier incident directly to your loss.
Do GDPR or ICO fines get covered?
Some policies cover regulatory defence costs but exclude fines.
Confirm whether the policy includes ICO fines and check the exact wording before assuming cover.
When will insurers deny a supply chain claim?
Insurers commonly deny claims for late notification, missing DPIAs or when systemic exclusions apply.
The most common denial reason is failure to meet the policy’s mitigation or evidence conditions.
How large should my limit be?
Match the limit to the business impact of the supplier failing: a basic rule is cover for 3–6 months of lost gross profit for critical services.
Discuss exact figures with a broker and test the policy with a loss scenario.
What evidence do insurers ask for in practice?
Insurers expect the supplier contract, proof of supplier due‑diligence, forensics report, notification logs and financial records proving loss.
Missing any of these items can delay a claim.
Can I force a supplier to share their insurer's policy wording?
Yes, contract language can require the supplier to provide policy wording and claims history.
Insist on this in procurement and record responses annually.
Infographic: Claim flow for a supplier breach
Supplier incident detected
(timestamp logs, notification)
→
Preserve evidence
(logs, screenshots, emails)
→
Notify insurer
(within 24–72 hours)
→
Appoint forensics/claims handler
(interim payments possible)
Will the supplier's insurer pay my loss?
Not automatically; your loss is your claim and depends on your policy wording and evidence.
The insurer may subrogate against the supplier later, but you should not rely on that as your primary recovery route.