A missed cyber insurance renewal can leave an uninsured gap. Any known suspicious email, failed login, lost device, or customer complaint may need declaring.
Ask for retro cover only when the gap is clean
A clean gap may justify requesting retrospective cover.
A seven-day gap may be worth testing
A lapse of between 3 and 7 days may be worth raising with the existing insurer or broker. This applies where systems stayed stable and no cyber incident is known.
The business should ask what the insurer is offering. It may be reinstatement, a new policy with prior acts cover, or a policy starting today.
Known alerts can change the answer
A phishing email, antivirus warning, lost laptop, unusual Microsoft 365 login, or customer complaint can be a circumstance. A circumstance is a fact that could later lead to a claim.
It is like seeing smoke before finding a fire.
For a lapse of 7 days, request retrospective terms if there are no known incidents. For a lapse of 30 days or more, compare the proposed retroactive date, excess, and exclusions before paying extra. For several months, expect the insurer to ask for more evidence. It may not accept past exposure.
A practical decision starts with four questions. First, how long was the cyber insurance lapse? A few days differs greatly from several months of uninsured trading.
Second, did the business process payments, personal data, customer systems, or remote access during the gap? Higher activity can raise the value of retrospective cyber cover.
Third, is there any known alert, complaint, or suspected unauthorised access that must be disclosed? Fourth, check customer contracts, tenders, and lender requirements for continuous insurance or a stated retroactive date.
If the gap was short, activity was limited, and no circumstances are known, requesting terms may be fair. If exposure was high, seek written terms urgently.
Compare those terms with a fresh-start policy.
Claims-made dates decide what the policy pays
Claims-made dates decide whether a policy responds to a claim.
Prior acts do not mean known losses
Prior acts cover may include acts before the new policy began. It normally starts from a stated retroactive date.
It does not cover a breach already suspected, investigated, or discussed with an IT supplier. Known events need clear disclosure before any replacement cover is arranged.
Three common lapse outcomes
A seven-day lapse may be manageable if ransomware entered during the gap but was found later. The insurer must have accepted prior acts cover.
Cover still depends on the full policy wording. This includes security conditions and the excess.
| Situation | What may help | What can block cover |
| Attack during a 7-day gap, found later | Written prior acts terms from an earlier date | No accepted retroactive date or failed security condition |
| Suspicious login known before replacement | Prompt disclosure and incident response support | Known circumstances or prior known acts exclusion |
| Customer claim after cover restarts | Timely notification under the policy | The underlying act happened before the retroactive date |
The act date can matter as much as the claim date. The next step is giving the broker the full timeline.
Tell the broker before seeking backdated terms
Disclose the facts before requesting backdated terms.
Build a clear evidence pack
Give the broker the expired schedule, exact expiry date, intended new start date, and old retroactive date. Add a plain timeline of every alert.
Include alerts even if the business thinks they were harmless. A dated record gives the insurer a clearer basis for its decision.
Compare cost beyond the premium
Extra premium is only one trade-off. An insurer may offer a lower price with a £1,000 to £5,000 excess.
It may also set a ransomware sub-limit. It may require stricter rules for backups and MFA.
A practical route after a missed renewal
1. Check dates
Check expiry, lapse, and proposed start dates.
2. Check alerts
Review logs, staff reports, and customer messages.
3. Disclose facts
Give the broker a dated timeline.
4. Compare terms
Compare dates, exclusions, excesses, and sub-limits.
📦
Available on Amazon
An encrypted external drive can hold policy schedules, backup reports, and incident logs. Keep it away from the main workstation. Keep it encrypted and test access for authorised staff.
- Stores dated policy documents that prove the lapse timeline.
- Keeps exported security logs away from a possibly affected computer.
- Supports secure evidence handover to an IT provider or broker.
Search on Amazon →
For SME cyber insurance, an underwriter will look beyond lapse dates. It will ask whether the business meets current security conditions.
Evidence may include multi-factor authentication for email, remote access, and administrator accounts. It may also include endpoint detection and response on supported devices.
Tested, separate backups and patching records can also matter. A named incident-response contact may help too.
A short management record can be useful. It should show who reviews cyber risks and how staff report suspicious activity.
It should also state when backups were last restored.
These controls do not create cover by themselves. They can affect premium, exclusions, and whether the insurer offers acceptable terms.
After a missed cyber insurance renewal, prepare a dated underwriting pack. Do not rely on an informal summary.
The pack should contain the previous schedule and wording. Include expiry and proposed inception dates, plus any prior retroactive date.
Include a signed statement of known circumstances if requested. Add a timeline of alerts, supplier tickets, customer complaints, and incident reports.
Add current evidence of MFA, EDR, backup testing, patching, and business-continuity arrangements. Confirm material changes in turnover, data held, remote working, or IT suppliers.
Keep copies of logs and correspondence.
A clear pack helps the insurer assess backdated cyber insurance, prior acts cover, or policy reinstatement. It does not remove the duty to disclose material facts.
Avoid the errors that make a lapse worse
Avoid mistakes that worsen the lapse.
The most frequent error is waiting until cover is arranged before mentioning a possible breach. That can undermine the duty of fair presentation.
It may leave the business disputing cover at the worst possible time.
Choose a fresh start when needed
A fresh policy may be sensible if the insurer will not backdate cover. It may also suit a lapse lasting many months.
It may be the only route where the business already knows of an incident. It can still protect future ransomware, business interruption, cyber liability, and response costs.
That protection remains subject to the policy terms.
Retrospective cover is not the main route if the original policy is still live. It may not suit a business that never needed protection for past acts. A known incident may need notification under an earlier policy. A live breach may need incident response, legal advice, and ICO assessment. This article cannot replace advice from a broker, insurer, or solicitor on a possible claim.
Common questions
Can cyber insurance be backdated after it lapses?
Cyber insurance can sometimes include an earlier retroactive date. The insurer must expressly agree to this in writing.
It will usually exclude incidents or circumstances known before the replacement policy began.
What happens if my cyber insurance renewal is late?
A late renewal can create an uninsured gap between the old expiry and new inception dates. Do not assume continuity unless the insurer confirms reinstatement in writing.
Check every relevant date in the written terms.
Does prior acts cover include a known breach?
Prior acts cover does not usually include a breach, alert, or circumstance known before the policy starts. A known circumstances exclusion can apply even if the claim arrives months later.
Disclose the event before seeking replacement cover.
Should I tell my broker about a suspicious email?
Tell the broker about a suspicious email if it may show fraud, unauthorised access, or a future claim. The Insurance Act 2015 requires fair presentation of material circumstances for commercial insurance.
Keep the original email and any related logs.
How much excess might apply to retrospective cover?
Cyber policy excesses often range between £1,000 and £5,000 for smaller UK businesses. The amount depends on the insurer and the risk.
Check for separate excesses on ransomware, forensic costs, or business interruption.
Is a 72-hour data breach report always required?
A 72-hour report to the ICO is required only when a personal data breach risks people's rights and freedoms. Record every breach assessment, even where notification is not required.
The 72-hour period usually starts when the organisation becomes aware of the breach.
The essentials:- Retrospective cover is worth requesting only if the insurer accepts an earlier date and no known circumstance blocks cover.
- The four key dates are the act, discovery, notification, and claim dates.
- A full disclosure timeline is more useful than a quick quote based on assumptions.
- Compare excesses, sub-limits, and exclusions alongside any extra premium.
Learn more
Here are some additional resources on this subject: