A policy may help when a breach disrupts online payments or exposes customer data. However, a ยฃ5,000 card-not-present transaction later reversed through a chargeback may be treated differently.
Processors, marketplaces and firms using PSPs can face losses outside standard cover. The real risk is assuming every payment loss has the same insurance answer.
Choosing the best cyber insurance for payment processors and card-not-present risk is not about finding a policy labelled โCNP coverโ. Most policies cover incident response and business interruption. They may exclude chargebacks and direct fraudulent transactions.
Compare cyber, crime and technology E&O cover. Also check contractual liability, sub-limits and exclusions in the policy wording.
Does cyber insurance cover CNP fraud?
Standard cyber cover can handle a security incident. It does not automatically pay for CNP fraud or chargebacks.
Does a policy pay fraudulent cards?
Cyber liability may pay for forensic work, legal advice, customer notices, data recovery and privacy claims. These costs can follow exposure of payment card data.
The ICO can investigate a breach under the UK GDPR and Data Protection Act 2018. That is why these costs matter, even when no money leaves an account.
A data breach can cost money before any fraud claim arrives.
Are chargebacks an insured loss?
Not necessarily. Chargebacks are often treated as card-scheme, contractual or trading losses rather than insured cyber losses.
Ask one precise question: โDoes this policy cover our own fraudulent transaction loss, chargeback liability, PCI assessment, and merchant contractual liability?โ A vague answer is not cover. Request the clause, sub-limit and exclusion in writing.
Preparing for ransomware, phishing and card-data breaches
Ransomware, phishing and card-data breaches can create several losses at once. They can stop authorisation or settlement services. They can also trigger forensic costs, customer notices, merchant claims and fraud attempts against support staff.
Your incident plan should name staff who can isolate systems. It should also cover insurer contact, bank or PSP notices, log preservation and customer messages.
Include a playbook for phishing-led account takeover. Check merchant bank-detail changes, refunds and payout instructions quickly.
Fast action can limit both loss and confusion.
Cyber liability policies normally require prompt notice and reasonable co-operation. Delays can increase business interruption. They can also make recovery under processor cyber insurance harder.
Which policies protect processor losses?
Processors usually need cyber liability, crime insurance and technology E&O. One policy rarely covers every payment loss.
When is crime cover essential?
Crime or fidelity insurance may cover employee dishonesty, social engineering fraud and funds transfer fraud. Cover depends on the exact policy definition.
A fraudulent instruction looks genuine but sends money to a criminal account. Think of a convincing fake email that changes a supplier's bank details.
The most common error is treating a fake payment instruction as a cyber loss. Insurers may instead place it under crime cover.
When does technology E&O matter?
๐ก
You may be interested in
A USB security key adds a physical second check for payment dashboards or settlement accounts. It supports multi-factor authentication. Insurers often ask about this control during underwriting.
- It reduces the chance that a stolen password opens a payment administration account.
- It helps protect users who can amend merchant bank details or refunds.
- It gives practical evidence of multi-factor authentication during a proposal.
View options on Amazon โ
Technology E&O can address claims that your payment service failed. It may matter where an outage, software error or service fault harms a merchant.
Check whether the wording covers contractual duties. A policy may exclude liability accepted only through a contract.
Compare cover, exclusions and contract gaps
Compare each loss event, sub-limit, excess and exclusion in one quotation summary. Do not compare premiums first.
| Market route | Best initial fit | Must confirm | Typical gap to test |
| CFC or Beazley cyber route | Breach, ransomware, incident response | Fraud and PCI sub-limits | Chargebacks and direct card fraud |
| Hiscox cyber and PI route | SME cyber and service claims | Technology E&O scope | Client-money and settlement loss |
| Lloyd's specialist placement | Higher-risk PSPs and marketplaces | Manuscript wording and retentions | Contractual liability assumed by agreement |
Which exclusions matter most?
First-party fraud, pure commercial loss, sanctions and cyber war exclusions need direct attention. PCI assessments, card-scheme penalties and supplier failure may also be excluded or capped.
Some policies cover these losses only after a defined cyber event. Read that definition before relying on it.
The clause matters more than the policy label.
Can provider outages be covered?
Although provider outages may be covered in some circumstances, card-not-present liability depends on more than whether a card transaction was fraudulent. Merchant agreements, acquirer rules, processor contracts and card-scheme rules can affect chargeback allocation.
For example, 3-D Secure may shift liability for some eligible fraud disputes. The result can depend on transaction type, authentication outcome, merchant category and any exemption used.
It can also depend on whether the transaction met scheme rules. That liability shift may work in theory, but real claim outcomes can be less clear.
A processor should map who absorbs fraud, refunds, retrieval requests, scheme fees and reserve shortfalls. Map every payment flow, not only the main checkout route.
This matters where the processor indemnifies merchants or an acquiring bank. Cyber liability may exclude liabilities accepted solely under contract.
Set limits and controls before you buy
Set limits against a plausible combined event. Do not base them on annual card volume alone.
Give accurate annual and peak monthly payment volume. Include countries served, merchant category codes, chargeback ratio and the largest single merchant.
MCCs classify the goods or services sold. High-risk categories can sharply change an underwriter's view.
A limit should reflect your worst credible payment event.
How should limits be tested?
This framework does not fully apply to a merchant using an external provider. That merchant must not store, transmit or control card data. It must also accept no material payment liability. This does not replace contract reviews with acquirers, PSPs, merchants or card schemes. It also does not replace legal, regulatory or insurance advice.
Payment-services underwriting checklist
A strong payment processor cyber insurance submission should show how the business limits card-data exposure and transaction fraud. Underwriters often ask for the PCI DSS level and scope.
They may ask whether primary account numbers are tokenised. They may also ask what share of eligible transactions use 3-D Secure.
Explain how staff monitor fraud rules outside normal business hours. Cover privileged access, multi-factor authentication and settlement or refund tools.
Use dual approval for merchant bank-detail changes. Include penetration testing, supplier checks and tested backups.
Include annual and peak payment volume, countries served and merchant category codes. Add chargeback ratios, largest merchant concentration and the highest plausible settlement exposure.
This evidence can improve terms and reduce pressure on fraud sub-limits. It also helps insurers assess payment service provider risk.
Your questions answered
Does cyber insurance cover chargebacks in the UK?
Cyber insurance usually does not cover chargebacks unless the wording expressly includes them. Chargebacks are often card-scheme, contractual or trading losses. Check the relevant exclusion and any fraud sub-limit.
Does cyber insurance pay for CNP fraud?
Cyber insurance may pay breach costs but often excludes direct CNP fraud losses. Crime cover may help with defined funds transfer fraud. Fraudulent card purchases and refunds need separate written confirmation.
What insurance does a payment processor need?
Most processors should assess cyber liability, crime insurance and technology E&O together. FCA status, client-money exposure and merchant contracts affect the final mix. Peak settlement value also matters.
Are PCI DSS fines covered by cyber insurance?
PCI DSS assessments may be excluded or subject to a small sub-limit. Confirm whether the policy names scheme assessments and contractual penalties. Check regulatory fines and defence costs separately.
How much cyber insurance do I need in the UK?
A suitable limit reflects your worst credible combined event, not turnover alone. Test between 3 and 10 outage days. Add response costs, fraud exposure and the largest merchant claim.
Does 3-D Secure mean the insurer will pay?
No, 3-D Secure does not guarantee an insurance payment. It can affect liability allocation and underwriting. Exclusions, notice duties and policy definitions still apply.
Can an insurer cover a cloud provider outage?
Cover is possible if contingent business interruption includes that supplier and a covered cyber event occurs. A routine technical outage may not qualify. Maintenance errors or service failures may need technology E&O cover.
The essential points:- Cyber cover handles many breach costs, but it does not automatically insure chargebacks or CNP fraud.
- Map direct fraud, merchant claims, service failures and client-money exposure to separate policy sections.
- Compare exclusions, excesses, sub-limits and contractual liability before comparing premium.
- Give accurate PCI DSS, 3-D Secure, tokenisation and chargeback data for a meaningful quote.
Learn more
Here are some additional resources on this subject: