Discovered historic data exposure or received a late claim? For many UK SMEs the key question is when the incident happened and when the business found it.
Insurers usually accept claims only if the incident date sits on or after the policy date. Proving the timeline matters to get cover.
Is retroactive cover necessary after a historic data breach? Sometimes, if the cyber policy is claims‑made and the breach occurred before the retroactive date, retroactive cover (or a prior‑acts endorsement) will be required to claim.
Check the policy’s date, ICO notification windows under UK GDPR and precise insurer wording. Keep reading for a step‑by‑step checklist, model wording and negotiation tips for SMEs.
Which variables decide whether retroactive cover is needed
A claim is usually accepted only if the incident date falls on or after the policy’s retroactive date. The insurer must verify the timeline to accept the claim.
Insurers use three core dates: the incident date, the discovery date and the claim or notification date. The decisive comparison is incident date versus retroactive date, not discovery date alone.
Insurers will demand a dated forensic report or contemporaneous logs that point to the incident date. If forensics place the intrusion before the retroactive date, the insurer typically declines.
A frequent fatal mistake is relying on a discovery note written weeks later rather than preserved logs. That weak evidence usually fails underwriting checks.
Look for the words claims‑made, retroactive date, prior acts exclusion and extended reporting period in your policy. Occurrence wording behaves differently and can cover older incidents when a claim comes later.
Occurrence wording is rare in UK SME cyber products, where most policies are claims‑made. Do not assume occurrence cover unless it is explicit.
Practical rule: if the incident date is earlier than the policy’s retroactive date, the policy will not respond. The only exceptions are a prior‑acts endorsement or a different applicable policy.
Do not buy retroactive cover when an occurrence policy already covers the incident date. Also avoid buying if the retroactive date already predates the breach.
Do not buy retroactive cover when there is no third‑party or regulatory exposure. Also avoid buying when likely recoverable loss is far smaller than the premium cost.
Buying cover without evidence or insurer pre‑screen rarely improves outcomes. Brokers can help clarify whether the endorsement will actually help. If unsure, ask the broker and share the insurer checklist and forensic evidence before buying any endorsement.
A clear next step is to get a forensic triage and a broker pre‑screen, which shows whether an endorsement might lead to a real payout and will save money and time.
Who needs retroactive cover after a historic breach
Businesses that discover a breach but whose active policy has a later retroactive date usually need prior‑acts wording to claim. The gap between incident date and retro date creates the need.
If an earlier occurrence‑based policy covers the incident date, the SME may not need any endorsement. Check policy wording and dates carefully.
Where regulatory exposure exists, prior‑acts cover becomes more important. Defence and response costs can be large when the ICO shows interest.
When a retroactive endorsement is essential
If personal data were accessed and the intrusion predated the policy’s retroactive date, the insurer will likely decline without prior‑acts cover. This is common when records include special category data.
Special category data includes health and financial details. The chance of regulator interest rises with sensitive data.
The ICO expects notification within 72 hours of becoming aware when a breach risks rights and freedoms. That duty is separate from insurer timelines, but it affects regulator action.
When retroactive cover is optional
If no third‑party loss and no regulator risk exist, the cost of cover can outweigh likely recoveries. Low exposure cases often work better with documentation and monitoring.
If the incident produced no third‑party complaints and estimated exposure is small, it may be sensible to document the breach and watch for claims. Small internal disruption alone usually does not justify the premium.
A common SME case
A small practice found stolen client files dating back 18 months. The active policy had a 12‑month retroactive date and the insurer rejected the claim.
The business paid for a forensic report, but the delay and missing logs prevented recovery under any policy. The absence of contemporaneous evidence made a claim impossible.
Real‑world outcomes show timing and evidence quality decide results. A marketing agency with a 20‑month intrusion faced £18k in costs after the insurer declined the claim.
Another case: a medium legal practice had strong forensics and bought a prior‑acts endorsement for a one‑off premium. The uplift equalled about 40% and the firm recovered defence costs.
A GP surgery that notified the ICO within 72 hours still got a narrower settlement. The prior‑acts endorsement carried a separate sub‑limit and a higher excess.
These outcomes show the roles of timing, evidence and endorsement structure. Good forensics and clear disclosure improve the chance of insurer response.
Lack of logs or restrictive sub‑limits commonly leave SMEs exposed.
How retroactive dates and prior acts shape SME claims
Claims‑made wording means insurers only consider incidents dated on or after the retroactive date. The incident must also be notified during the policy period.
Retroactive dates for SMEs commonly range from 12 to 36 months. Some underwriters will consider longer prior acts for added premium.
If a business cannot show the incident occurred after that retroactive date, coverage will usually fail. Evidence is the key determinant.
Claims‑made versus occurrence explained
In a claims‑made policy the trigger is a claim notified during the policy period and the incident must fall on or after the retroactive date. The insurer checks both dates.
In an occurrence policy the trigger is the incident happening during the policy period. The claim can come much later and still trigger cover.
Most SME cyber products sold in England are claims‑made. Do not assume occurrence cover without explicit wording.
Typical retroactive periods and limits
Market practice for SMEs commonly sets retroactive cover at 12–36 months. Larger or specialist accounts may buy 60–120 months retro cover.
Insurers can add sub‑limits for prior acts or exclude particular causes. Exclusions often cover known incidents or social engineering where controls were weak.
Always check whether a prior‑acts endorsement creates a separate sub‑limit. A sub‑limit can reduce the practical value of the endorsement.
Legal and regulatory context to remember
The Data Protection Act 2018 and UK GDPR let the ICO investigate historic breaches and impose fines where applicable. Fines can reach £17.5 million or 4% of global turnover.
Regulatory exposure can push SMEs toward buying prior‑acts cover even if customer claims seem small. The risk of an ICO probe matters.
For ICO guidance on reporting, see ICO breach reporting.

Notification windows versus retroactive dates interact in complex ways in the UK and cross‑border incidents. The ICO expects notification within 72 hours of becoming aware of a qualifying breach, but that statutory notification deadline is separate from an insurer's retroactive date test. Insurers ordinarily compare the incident date with the retroactive date, not the regulator notification date.
In practice this creates three tense scenarios. First, an SME discovers a historic intrusion and notifies the ICO within 72 hours; the ICO may treat the matter as a recent report even though the incident predates the policy's retro date, yet insurers may still decline unless a prior‑acts endorsement is bought.
Second, cross‑border incidents raise conflicting timing rules. US state breach laws can require notification within specific windows for affected individuals, and differing discovery and notification dates across jurisdictions can complicate underwriting assessments. Insurers will check each regulator's filing date.
Third, some underwriters give credit where immediate regulatory notification pairs with forensic proof that the effects continued into the policy period. That combination can sway an underwriter.
For multinational incidents, list every regulator notified, the dates and the legal basis for notification. Insurers will treat the interplay of discovery, notification and incident timing as part of their risk evaluation.
Exact evidence insurers will demand for historic claims
Insurers routinely ask for a dated forensic report, a clear incident timeline, preserved logs and hashes, and copies of third‑party complaints or regulator letters. The single most common reason for denial is inadequate contemporaneous evidence.
Prepare documentation before approaching an underwriter. A tidy evidence pack speeds the decision and improves chances.
Forensic report and technical proof
A usable forensic report shows attack indicators, an estimated incident date, the method of compromise and the scope of data accessed. The report should be signed, dated and include a clear methodology.
Insurers prefer recognised firms such as NCC Group, Mandiant or CrowdStrike for credibility. A report from such firms weighs heavily in underwriting.
Timeline and documents to gather now
Create a timeline with discovery, containment and notification dates. Attach emails, helpdesk tickets and invoices related to the incident.
Preserve original logs and record MD5 or SHA hashes for key files to show they remain unaltered. Also keep communications with customers or suppliers linked to the incident.
Communications with the ICO and others
Document whether the ICO was notified and the dates of any correspondence. Keep copies of letters and any regulator recommendations.
The ICO’s 72‑hour reporting expectation is a regulatory rule, not an insurance trigger. Delayed reporting can still affect insurer trust and settlement.
Practical decision matrix
A simple matrix uses four inputs to choose an action: incident date, discovery date, available retroactive date and evidence quality. The right choice depends on exposure, probability of third‑party claims and likely ICO interest.
Work through the matrix before paying a premium. That prevents wasted spend on endorsements that likely fail.
Columns to use: incident date, discovery date, existing policy retroactive date, evidence quality, ICO risk and estimated exposure in pounds. These items guide the decision.
If incident_date ≥ retro_date and evidence is good then submit the claim. If incident_date < retro_date and evidence is weak then prioritise forensic work.
Action table
| Situation |
Evidence |
Regulatory risk |
Recommended action |
| Incident ≥ retroactive date |
Good contemporaneous forensic report |
Low–medium |
Notify insurer and submit claim |
| Incident < retroactive date |
Strong evidence, high ICO risk |
High |
Seek insurer pre‑screen; consider prior‑acts endorsement |
| Incident < retroactive date |
Weak or no evidence |
Low–medium |
Commission forensic work; do not buy endorsement until evidence exists |
Decision flow
1. Incident date vs retro date
- Incident ≥ retro date → Notify insurer
- Incident < retro date → go to step 2
2. Evidence quality
- Good forensic report → seek pre‑screen
- Poor evidence → instruct forensics
3. Regulatory risk
- High ICO risk → consider endorsement
- Low risk → weigh cost vs benefit
Consider the financial trade‑off carefully.
Typical UK costs and pricing drivers for retroactive cover
For UK SMEs a prior‑acts endorsement commonly costs an uplift to the annual premium or a single premium. Typical uplifts range from about 20% to 150% of the annual cyber premium.
Flat fee alternatives often range from £250 to £5,000 for lower exposures. Fees rise sharply where ICO risk or large volumes of personal data exist.
Underwriters price on records affected, regulatory exposure, prior claims and time since incident. These factors decide the premium and excess levels.
What moves the price most
Primary drivers are volume and sensitivity of records and the presence of special category data. Ongoing regulator interest and time since the incident also push prices up.
Poor or absent forensic evidence increases premium and excesses. Insurers charge more because uncertainty raises their risk.
Prior claims history and whether the business operates in a higher risk sector also move the price. Finance and health sectors usually face higher costs.
Opinion and practical recommendation
Buying retroactive cover makes sense when the estimated regulatory or third‑party exposure exceeds the endorsement cost. This only holds if the SME can supply credible evidence of the incident timeline.
If evidence is weak, paying for cover before securing forensics often wastes money. Obtain a costed quote and an underwriter pre‑screen based on the evidence pack before committing.
When retroactive cover will not protect certain losses
A retroactive endorsement rarely protects against deliberate criminal acts by directors. It also rarely covers known prior acts declared on proposal forms.
Many policies exclude fines or penal sanctions or treat regulatory investigations differently from civil claims. Even where defence costs are covered, the policy may not pay a fine.
Some policies exclude social engineering losses or restrict cover where basic controls were missing. Buying retroactive cover does not guarantee payment.
The insured must still meet policy terms and proof requirements.
Common exclusions to watch for
Look for known prior acts, deliberate criminal acts, failure to patch and social engineering exclusions in the endorsement wording. These exclusions can negate the value of the endorsement.
Insurers may add conditions such as requiring a forensic investigation within a set period. They may also limit the retroactive cover to defence costs only.
If the policy contains such exclusions, the endorsement may offer little practical value. Negotiate the wording where possible.
Interaction with fines and regulatory
Many UK cyber policies exclude fines or penal sanctions. Policies often pay legal costs and regulatory response fees but not the fine itself.
Check wording carefully and get legal advice if ICO fines are likely. Legal input clarifies whether the policy will respond to regulatory penalties.
Clause wording matters more than the headline phrase 'prior acts'. For example, 'ought reasonably to have been known' shifts disputes into disclosure and constructive knowledge.
A 'prior‑acts endorsement' that requires contemporaneous evidence lets an insurer reject where only partial logs exist. Sub‑limits such as 'Prior acts sub‑limit £XX,XXX' create separate caps for historic incidents.
Practical implication: negotiate removal or softening of 'ought reasonably to have been known' language. Also aim to have prior‑acts cover expressed as part of the main limit rather than a separate sub‑limit.
Insist on defining acceptable forms of evidence such as forensic reports, hashed logs and email headers. That reduces later disputes and clarifies expectations.
Errors SMEs frequently make when seeking prior acts cover
The most frequent error is assuming buying retroactive cover automatically delivers a payout. Underwriters still assess incident date, evidence and exclusions.
Another common mistake is delaying insurer notification until after buying cover. Insurers expect timely reporting and may refuse late, unsupported claims.
Failing to preserve logs and contemporaneous notes is a practical error that most often causes denials. Preserve data and avoid altering systems.
Specific practical mistakes
SMEs often overwrite log files, fail to collect email headers showing phishing timestamps, or do not keep invoices and appointment notes. These gaps appear in underwriting checks.
When gaps appear, the insurer may allege non‑disclosure or material misstatement. That can lead to claim denial and future premium rises.
How to avoid the common errors
Preserve evidence and instruct a reputable forensic firm quickly. Notify the insurer that there is a potential historic breach while gathering documentation.
Do not alter systems or delete files; document every action taken. If uncertain, get legal advice before engaging the insurer or publishing any statement.