A quiet shop, workshop or venue can still face a cyber claim after the shutters come down. Online bookings, card records, supplier emails and staff logins may remain live, which means a ransomware attack or data breach can land when trading is at its slowest and cash flow is tightest.
Cyber insurance for businesses during dormant periods can still protect a business while it is dormant, but only if the policy is set up properly. It depends on how the period of restoration, waiting period and business interruption cover are defined. It is worth checking whether fixed costs, online sales and notification duties are included while the premises are closed.
Will cyber cover still work when you close?
Cyber cover can still respond during a closed season, because the risk often stays alive even when the front door is shut. The real test is whether the policy covers the systems, data and income streams that remain active in the background.
The key point is simple: a shut building is not the same as a shut business.
If bookings still come in, emails still run, card payments still clear or staff still use remote access, the exposure usually continues. That means a claim may still arise under first-party cover, third-party liability or business interruption, depending on the wording.
Closed doors, live systems
A seasonal business often keeps a few systems running while trading slows. Those systems can be enough to trigger a loss if they fail or get attacked.
A hotel may stop taking walk-in guests, but still use online bookings and customer data. A seaside café may close for winter, but keep card terminals, payroll access and supplier accounts live. A retail pop-up may sit empty, but still have shared cloud storage and remote admin access.
That is why cyber insurance does not only matter when tills are ringing. It matters when systems still talk to each other behind the scenes.
A business can still suffer insured cyber loss if the claim starts from live digital activity, not from physical trading.
Loss can arise during dormancy in three common ways. First, a hacker gets into email and redirects bookings or invoices. Second, ransomware locks a booking system or shared drive. Third, a breach exposes customer data while the site is closed and response work still costs money.
Insurers usually start with the same four questions. Are the systems still used, who can log in, what data sits online and how fast can the firm recover if access is lost?
During a dormant period, the main question is not whether the front door is shut, but whether the digital engine is still running. In many seasonal businesses, online bookings continue to arrive, payment links stay live, supplier portals remain active and staff may still need remote access to check schedules or refunds. If a ransomware attack freezes those systems, the claim can still arise even when the premises are empty. The policy wording matters because some insurers will treat the loss as ordinary business interruption cover, while others may limit cover if the business has materially changed how it trades.
A hotel closed for winter may still lose deposit income through its booking platform, and a garden centre may still handle customer data for spring orders. In both cases, the cyber cover needs to match the reality of digital dependence rather than the physical opening hours.
Which seasonal businesses need this cover?
Any business with digital dependence can need cyber cover, even if it trades hard for only part of the year. The strongest need appears where cash flow, bookings or client data keep moving during the quiet period.
Tourism, hospitality and leisure
Hotels, guesthouses, holiday parks, tour operators and attractions often keep booking engines live all year. That means a hacker can still steal deposits, block access to reservation systems or expose guest details when the premises look closed.
Retail and events businesses
Seasonal retail, market traders, Christmas sellers and event firms often rely on online orders, supplier portals and payment links. Those systems stay attractive to criminals even if the physical site is dark.
If the business still takes bookings, takes payments or stores customer data, cyber risk usually remains live.
This matters most when the business still has fixed costs. Payroll, rent, software fees and supplier contracts can keep running even if revenue falls to near zero for 3 to 7 weeks or longer.
How insurers assess a dormant business
Insurers do not only ask whether the business is open. They ask what stays switched on, how fast issues get spotted and whether the firm can prove basic controls still work.
Waiting period and restoration time
The waiting period is the short delay before cover starts paying. The period of restoration is the time the policy allows for getting systems back and losses measured. They are not the same thing, and they rarely match a seasonal closure date.
The legal deadline to report a personal data breach to the ICO is generally 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to people’s rights or freedoms.
That rule comes from the UK GDPR and the Data Protection Act 2018, and it still applies when the site is closed: ICO breach reporting guidance.
Backup and access controls
A seasonal firm that turns things off for months can create its own problem. If backups sit unplugged, admin access is shared too widely or passwords are left unchanged, an insurer may ask awkward questions after a claim.
Insurers usually want logs, invoices, booking records, email alerts and proof of restoration work. They also like to see that the firm kept basic checks going during the slow season.
What cover gaps matter most?
The biggest gaps sit in wording, not in the sales brochure. A policy can promise cyber protection and still leave seasonal owners exposed on the details.
Fixed costs and payroll
Not every cyber policy pays fixed costs the same way. Some cover net profit only. Some add specified working costs. Some cap payroll cover or exclude wages entirely during a shutdown.
Online sales and reservations
Online orders and bookings deserve a close read. Some wording treats them as part of turnover. Some need an extra trigger. Some apply a sublimit that is far lower than the main business interruption limit.
Policy exclusions to watch
Policy exclusions often mention lack of maintenance, failure to apply updates, unsupported software and known vulnerabilities. They can also bite when the business changes activity or leaves systems idle for too long.
My experience with seasonal SMEs is blunt on this point: the cheapest policy is often the one with the narrowest claim wording, especially around income loss during quiet months. A better approach is to match the limit, waiting period and restoration period to the slowest part of the year, not the busiest. That usually means reading the exclusions line by line and telling the insurer when trading patterns change.
Hidden trade-offs in price
Cheaper premiums can hide a shorter indemnity period, higher excess or lower sublimit for income loss. A slightly higher premium may buy the one thing that matters most: enough time to get the business moving again.
Seasonal owners should check exactly what the policy pays for when income drops to almost nothing. Some wordings only respond to lost profit, which may be small in the quiet months, while others can extend to fixed costs such as rent, software subscriptions, loan repayments or payroll for essential staff. That distinction is important for a business that must keep paying overheads even when the shop is shut or visitor numbers are low. For example, a coastal café may have no walk-in trade in January but still need to pay rent, card processing fees and booking software charges, while a Christmas retailer may have pre-season marketing costs and customer service staff to fund after a breach.
If online bookings are interrupted, the insured loss may also include deposits or reservation income, but only where the business interruption cover is drafted broadly enough to capture that turnover.
How much does seasonal cover cost?
Seasonal cyber cover usually costs less than broad year-round cover only when the insurer accepts the lower risk. If the business still relies on live systems, the premium may barely move at all.
Three things usually drive price: number of users, volume of customer data and strength of controls. A business with multi-factor authentication, regular backups and limited remote access often looks safer than one with old shared passwords.
Seasonal discounts are not automatic
Some insurers offer reduced cover when trading slows. Others do not. Some will only accept a seasonal adjustment if the insured reports the closure dates and confirms what systems remain live.
Ask whether the policy changes if staff numbers fall, if bookings stop or if remote access is limited. Ask whether the cyber insurance market outlook for 2026 suggests tighter terms for firms with patchy controls or sparse logging. Ask whether the broker has seen claims on similar seasonal businesses recently.
- Ask for the exact waiting period. A 12-hour delay is very different from a 48-hour one.
- Ask for the indemnity period in months. Three months and twelve months are worlds apart.
- Ask whether income cover includes fixed costs. That often decides whether a claim helps or just looks helpful.
- Ask whether dormant-period exclusions apply. The wording can change the answer fast.
What a good seasonal policy review looks like
A good review starts with the business calendar, not the insurance form. The policy should mirror the months when the business is busy, the months when it is quiet and the systems that stay live in between.
Match cover to the real calendar
List the months of peak trading, the months of closure and any overlap in between. Then compare that with the waiting period, indemnity period and the date on which the insurer expects normal trading to resume.
Check the notification duty
Tell the insurer when the business changes shape. That can mean fewer staff, shorter opening hours, a full winter closure or a switch from walk-in trade to online orders.
Keep the controls simple
Use multi-factor authentication, keep backups off the main network, limit admin access and update software before the off-season starts. These are basic controls, but they matter because they show the business still takes cyber risk seriously.
A sensible seasonal review should compare the busiest months with the quietest ones and test the policy against both. In hospitality, the risk may be highest in summer when booking volumes surge, but the financial pain of a cyber event can be worse in winter if the same incident hits a lean cash flow period. In tourism, a hacked reservation system can stop peak-season sales, while in retail a breach in the off-season may still damage supplier relationships and delay stock planning for the next peak.
A useful checklist is to confirm the waiting period, period of restoration, income sublimits, exclusions for dormant periods, notification duties and any change in access controls before closure. That way, the policy is not only priced for the season, but shaped for the operational reality of a seasonal business.
FAQ
Does cyber insurance cover a business during
Yes, often it does. The cover depends on the wording, the systems still in use and the loss type. A closed seasonal business can still face ransomware, phishing or a data breach if emails, bookings, payments or cloud storage stay live. The policy must still treat that loss as insured under business interruption or first-party cover.
What is dormant period cover in cyber insurance?
It is cover that still works when trading slows or stops for a season. The point is simple: the business may be quiet, but the digital risk remains. A booking engine, customer database or remote admin login can still be attacked while the site looks closed.
Does business interruption cover lost bookings in
Sometimes, but not always. Some policies include lost bookings as part of turnover, while others use a narrower formula or a sublimit. The answer depends on the period of restoration, the waiting period and whether the policy treats bookings as insured income.
Can fixed costs be claimed during a cyber
Sometimes they can, if the wording includes them. Rent, payroll, software subscriptions and other fixed costs are often where seasonal firms feel the pain. The policy must spell out whether it covers those costs during the dormant period or only lost net profit.
What should a seasonal SME tell its insurer
It should tell the insurer the closure dates, what systems stay live, who still has access and whether online trading continues. That helps the insurer price the risk properly and reduces the chance of a dispute. A short note before renewal is usually enough to start the conversation.
Does the ICO care if a breach happens while the
Yes. If a personal data breach creates risk to people’s rights or freedoms, the 72-hour reporting duty can still apply. The closure of the premises does not remove the duty under UK GDPR. The risk sits in the data, not in the front door.
Are seasonal businesses more likely to miss
Yes, because the quiet period changes the shape of the risk. The most common misses are lack of maintenance, unsupported software, weak access control and failed disclosure of trading changes. Those points matter more for seasonal firms than for businesses that operate steadily all year.
This advice does not apply in the same way if the business has no meaningful digital exposure, no customer data and no online trading. It also changes if the policy clearly excludes dormant periods or seasonal closure, because the wording then controls the answer.
The plan before renewal
A seasonal business should review cyber cover before the quiet months begin, not after the first problem. The safest approach is to match the policy to the real calendar, real systems and real revenue streams.
Start with the three numbers that matter most: the waiting period, the indemnity period and the sublimit for business interruption. Then check exclusions, confirm notification duties and tell the insurer exactly how the business behaves when trading slows.