¿Te preocupa how a cyber incident could hit an IT reseller or value‑added reseller (VAR), financially, legally and operationally? Many small UK resellers sell, configure or manage systems for clients but do not understand how liability flows after a breach. This guide explains IT resellers & VARs cyber liability in clear, UK‑specific terms and gives practical steps to prepare, evidence controls and manage claims.
Key takeaways: what to know in one minute
- IT resellers and VARs face third‑party liability when client data or systems are compromised because of services, software or managed services they supply. Liability can be contractual, regulatory (GDPR) or common law.
- Typical policy areas to check: third‑party liability, first‑party loss (business interruption), cyber extortion (ransomware), and professional indemnity overlap. Not all policies treat these the same.
- Supply‑chain risk matters: many claims arise from a downstream client being harmed by a reseller's configuration, update or integration. Insurers will ask about patching, vendor testing and contractual limits.
- Premiums depend on tangible factors: revenue, size of customer base, evidence of controls (MFA, EDR, backups), past incidents and contractual risk transfer. Providing strong evidence reduces friction.
- On breach, follow insurer and ICO steps: notify the insurer rapidly, preserve evidence, and assess ICO notification obligations under GDPR. Delays can prejudice a claim.
Why IT resellers & VARs need cyber liability cover
IT resellers and VARs often sit between software/hardware vendors and end clients. That positioning creates specific exposures: configuration errors, insecure integrations, negligent managed services, supply of vulnerable third‑party code and account takeovers from administered systems. Even where the reseller is not the root cause, contractual indemnities and client reliance can create financial and reputational loss.
From a UK regulatory perspective, GDPR and the ICO mean a data breach that affects personal data can trigger fines, remedial costs and compensation claims. The National Cyber Security Centre (NCSC) publishes mitigations that insurers commonly reference; insurers also check FCA guidance where financial services clients are involved. Relevant official guidance includes the ICO's breach reporting rules (ICO breach reporting) and the NCSC's mitigations (NCSC 10 steps).
Insurers and buyers treat resellers differently from pure software vendors. Policies often exclude deliberate wrongdoing, criminal acts by the insured and cascade losses from widely used vulnerable components unless managed carefully. Therefore, a cyber liability policy acts as a financial safety net and a competitive credential for tendering to clients with compliance needs.

Key policy features for IT resellers & VARs
A careful reading of policy wordings is essential. The following checklist explains policy features that commonly matter to resellers and how they differ in practice.
| Policy feature |
What it covers |
Why resellers must check |
| Third‑party liability |
Claims from clients for loss, including privacy breaches and system downtime. |
Clients may expect indemnities; covers legal costs and compensatory payments. |
| First‑party loss |
Business interruption, forensic costs, notification and PR expenses. |
Pays incident response costs the reseller incurs to restore service to clients. |
| Cyber extortion (ransomware) |
Ransom payments, negotiator fees, and recovery costs. |
Resellers often manage backups for clients; clarity on ransom cover is important. |
| Professional indemnity overlap |
Errors and omissions arising from advice or services supplied. |
Some cyber policies exclude professional negligence, check before relying on cyber cover alone. |
| Contractual liability and defence costs |
Costs to defend claims arising from contract breaches or indemnities. |
Contracts with large clients may require higher limits or specific wording. |
Key practical checks for resellers: confirm whether the policy covers breaches in hosted environments, clarify retroactive cover dates, check sub‑limits for regulatory fines or PCI DSS claims, and note any exclusions for unpatched vulnerabilities or failure to follow vendor guidelines.
Assessing supply‑chain risk: liability for VARs and resellers
Supply‑chain risk is central for VARs. A typical scenario: a reseller installs or integrates a product that later allows attackers to pivot into multiple clients. Claims may assert negligent configuration, inadequate testing, or failure to warn clients of known vulnerabilities.
Risk assessment steps a reseller can apply before bidding or signing contracts:
- Map where client data flows and which services are managed or supported.
- Identify single points of failure and whether clients rely on the reseller for updates, backups and emergency support.
- Check vendor patch cadences and whether the reseller is contractually required to apply patches on behalf of clients.
- Include contractual risk transfer where appropriate, but recognise that indemnities are only as valuable as the indemnifier’s solvency.
Insurers will ask about these matters during underwriting. For example, underwriters commonly request evidence of supplier due diligence, change control processes, and incident response playbooks. If the reseller has many customers on a shared managed platform, insurers may treat that as aggregation risk and either limit cover or increase premiums.
Calculating premiums: what affects VARs' cyber cover
Premiums for cyber liability for a small UK reseller typically range widely because insurers price on risk factors rather than industry averages. The main premium drivers are:
- Revenue and employee numbers, larger turnover and more staff often increase premiums. Insurers use revenue bands to scale limits.
- Client profile and concentration, serving regulated sectors (financial services, healthcare) or a single large client can increase price. High exposure clients may require bespoke terms.
- Technology stack and managed responsibilities, offering managed services, remote access, or administration rights elevates risk compared with simple hardware resale.
- Evidence of controls and certifications, MFA, endpoint detection & response (EDR), tested backup and recovery, documented patching processes and staff training can reduce underwriting friction and cost. Certs such as Cyber Essentials or ISO 27001 may help but are not guarantees.
- Claims history, prior incidents typically increase premiums and can affect insurability.
- Contractual obligations, contracts requiring high limits or indemnities may push up premium or necessitate higher retentions.
Indicative pricing examples (current at time of writing) are not definitive: many UK micro resellers with limited managed services might see annual premiums from £600–£2,500 for modest limits, while resellers providing extensive managed services to regulated clients may pay several thousand pounds or require higher retentions. Precise quotes depend on the underwriting submission.
How limits and excesses are chosen
Limits should reflect potential third‑party exposures and restoration costs. Typical small‑business cyber limits range from £250,000 to £2m. Excesses (deductibles) reduce premium but shift immediate post‑incident cost to the insured; resellers should choose a level they can afford to pay without jeopardising client recovery.
Practical cyber hygiene controls IT resellers must evidence
Insurers place heavy emphasis on observable controls. Evidence should be clear, auditable and recent. Key controls insurers and clients expect include:
- Multi‑factor authentication (MFA) on all administrative and remote access accounts. Screenshots of settings or a short policy extract help.
- Endpoint detection and response (EDR) deployed and centrally managed with alerts monitored. Logs or vendor portal printouts are useful evidence.
- Tested backups with regular restore drills and air‑gapped or immutable copies. Date‑stamped restore reports or runbooks are persuasive.
- Patch management with documented SLAs for applying critical patches and a change log. Provide recent patch cycles and exception approvals.
- Network segmentation for multi‑tenant platforms to prevent lateral movement. Diagrams and network architecture notes are helpful.
- Access controls and least privilege for service accounts and admin roles. A grants matrix or role definition document suffices.
- Employee cyber awareness training with records of completion and phishing simulation results.
An insurer may decline a claim or apply an exclusion if evidence shows a systemic failure (for example, credentials stored in plaintext or no MFA on admin accounts). Maintaining contemporaneous evidence is therefore important.
Reseller incident flow: who does what
🔍 **Step 1** → Identify and contain the incident
🛠️ **Step 2** → Notify insurer & begin forensic triage
📣 **Step 3** → Assess client impact and regulatory reporting (ICO)
✅ **Step 4** → Restore systems, notify stakeholders and review contractual obligations
Handling a breach: claims, ICO notification for resellers and VARs
When a breach occurs, timing and evidence preservation are critical. The steps below reflect standard insurer expectations and UK regulatory obligations.
- Notify the insurer promptly using the policy's claims contact. Many policies require immediate notice; delays can prejudice cover.
- Preserve evidence, capture system images, logs and communication records without altering timestamps. Use read‑only forensics processes where possible.
- Disconnect affected systems to contain lateral movement, but avoid destroying evidence.
- Engage incident responders approved by the insurer where required. Some policies mandate use of panel firms for forensic work.
ICO notification obligations
A reseller must assess whether the breach is likely to result in a risk to the rights and freedoms of individuals. If so, the ICO expects notification within 72 hours of becoming aware where feasible. Even where the reseller is a processor rather than controller, contractual arrangements and the nature of the data determine who notifies. ICO guidance is available at ICO breach reporting.
Important: notification to the ICO is distinct from notifying the insurer. Both may be required and the timing differs; notify the insurer quickly but ensure regulatory filings are accurate.
Claims process essentials
- Provide a clear timeline of events to the insurer including discovery time, containment measures and affected systems.
- Supply contractual documents showing liability caps or indemnities with clients; insurers use these to quantify potential exposure.
- Document mitigation costs such as forensic fees, notification and PR expenses, legal advice and client remediation.
Insurers will investigate causation and whether any policy exclusion (for example, failure to apply critical patches) applies. Transparent cooperation and early evidence improve the likelihood of a favourable outcome.
Benefits, risks and common mistakes
✅ Benefits / when to apply cyber liability cover
- Access to incident response expertise and funding for recovery costs.
- Financial protection for client claims and regulatory expenses under GDPR.
- Commercial advantage when tendering to clients requiring evidence of risk transfer.
- Confidence to offer managed services or remote administration.
⚠️ Errors to avoid / risks
- Relying on general business insurance that excludes cyber events or professional negligence.
- Accepting client contractual terms without checking whether the insurer will recognise those indemnities.
- Failing to maintain or evidence core controls such as MFA and backups.
- Delaying insurer notification or altering evidence after a suspected breach.
Frequently asked questions
What is cyber liability insurance for IT resellers and VARs?
Cyber liability insurance is a policy that can cover legal liability to third parties, first‑party loss (such as business interruption), and costs related to managing and remediating a cyber incident that affects clients or the reseller's own operations.
Do resellers need both cyber insurance and professional indemnity?
Many resellers benefit from both because cyber policies sometimes exclude professional negligence. Professional indemnity covers advice or design faults; cyber covers forensic, notification and extortion costs. The exact boundary depends on policy wordings.
When should a reseller notify the ICO after a breach?
Notification to the ICO is required where a breach is likely to result in a risk to individuals’ rights and freedoms. The ICO expects notification within 72 hours where feasible. Determining responsibility depends on controller/processor roles and contractual arrangements.
How does a reseller prove they had adequate controls before a claim?
Maintaining contemporaneous evidence, policies, screenshots of configurations, backup test results, training records and patch logs, is the most persuasive proof for underwriters and claims handlers.
Will a single customer breach affect the reseller's whole portfolio cover?
Insurers consider aggregation risk; a flaw affecting multiple clients (for example, a multi‑tenant platform) may lead to higher premiums or limits applied. Aggregation clauses are common and should be reviewed.
Can a reseller transfer liability to a vendor contractually?
Contractual transfer is possible but not absolute. Insurers will still underwrite the reseller's own exposure and the solvency of the party accepting liability matters.
Your next steps:
- Prepare a concise risk pack: include network diagram, MFA screenshots, EDR status, backup test reports and recent patch logs for underwriters.
- Review client contracts to identify high‑risk indemnities and seek legal input on caps and passthrough clauses.
- Put a breach playbook in place: notification contact list (insurer, panel forensics, legal), immediate containment steps and ICO reporting checklist.