Are POS terminals or cardholder payment systems compromised and then denied by insurers? For many small UK firms the distinction between a POS glitch, a card-skimming attack or a cloud payment-gateway failure is unclear, and that uncertainty can cost thousands. This piece cuts straight to what most UK micro and small businesses need to know about POS & card payments: are PCI breaches covered?
Discover how common cyber policies treat PCI DSS failures, what costs insurers typically meet after a breach affecting cardholder data, and practical steps that can be followed immediately after a POS incident. The analysis is UK-specific, cites ICO and NCSC guidance, and focuses on realistic outcomes for SMEs and sole traders.
Quick essentials for POS & card payments: are PCI breaches covered?
- Most policies can respond to cardholder data incidents, but coverage is conditional. Coverage often depends on whether the business met stated security obligations (eg, PCI DSS) at the time of the breach.
- Regulatory fines for PCI non‑compliance are often excluded or sub‑limited. Insurers typically exclude penalties imposed by payment schemes, though GDPR fines can be handled differently (see below).
- Insurers commonly cover forensic costs, notification and card reissue fees if the policy includes breach response. These are frequently subject to sub‑limits and excesses.
- Third‑party service failures (payment gateway) may be treated differently from onsite POS compromises. Policies often rely on contractual terms with the acquirer for recovery.
- Immediate evidence and compliance records matter. Logs, PCI Attestation of Compliance (AOC) and merchant‑acquirer correspondence materially affect claim outcomes.
Does SME cyber insurance cover POS PCI breaches?
Explanation: Coverage depends on policy wording, the nature of the incident and whether the insured met pre‑contractual security warranties. Many standard SME cyber insurance policies include first‑party breach response (forensic investigation, breach coach, notification costs) and third‑party liability (claims by cardholders or businesses). However, coverage is subject to conditions, exclusions and sub‑limits.
Context and expert implications:
- Insurers often require adherence to recognised standards (eg, PCI DSS or equivalent) as a condition of cover. If an SME failed to follow mandatory controls included in the policy schedule, the insurer may decline or reduce indemnity.
- Coverage may be split: forensic and notification costs are commonly covered under a breach response element; fines or penalties imposed by card schemes (eg, Visa, Mastercard) are often excluded.
- Claims involving cardholder financial loss (fraudulent card transactions) can prompt recovery actions by the merchant acquirer; insurers may require the insured to cooperate with the acquirer and submit evidence demonstrating that compromise did not result from gross negligence.
Practical consequences for SMEs:
- SMEs should not assume automatic cover for all PCI‑related losses. Where a policy explicitly names PCI DSS breaches in an exclusion or warranty, that clause will control.
- Maintaining and retaining PCI evidence (AOC, QSA reports where applicable, patching records, POS inventory) materially strengthens a claim.
Common errors:
- Failing to notify the insurer within the policy time limits.
- Not preserving logs or removing compromised hardware before forensic capture, which can break the chain of evidence.
- Assuming the acquiring bank will reimburse all card re‑issuance costs automatically.
Should microbusinesses buy cover for cardholder data breaches?
Explanation: Microbusinesses often face a low probability but high impact risk from cardholder data breaches. Buying breach response elements and modest third‑party liability cover can be cost‑effective for card‑taking businesses.
Context and expert implications:
- For a sole trader or a 1–5 person retailer, the largest legacy costs after a POS compromise are forensic investigation, card reissuance, breach notification and reputational remediation, items that many cyber policies explicitly include.
- The cost of a tailored small business cyber product that includes breach response is often a fraction of the operational cost of a prolonged incident.
Actionable advice:
- Check whether the policy includes breach response, PCI forensic investigator (PFI) costs, forensic access to logs, customer notification, and public relations. If these items are absent, consider an endorsement or a specialist SME cyber policy.
- For microbusinesses with low IT capability, simpler policies with a clear breach response hotline and included forensic support are usually more valuable than policies with large liability limits but no immediate incident assistance.
When it matters:
- If the business processes card payments via a physical POS terminal or an in‑store modem, the risk of local compromise (skimming, tampering) is material and justifies cover.
- If card processing is fully outsourced to a reputable gateway with clear contractual indemnities, the insurer’s exposure may be lower but the business still needs cover for residual risks.
PCI DSS breach exclusions: what insurers typically refuse
Explanation: Insurers frequently list exclusions relating to wilful non‑compliance, criminal acts by the insured, contractual fines and punitive damages. For PCI DSS incidents, several specific exclusions recur.
Typical exclusions and why they matter:
- Penalties imposed by payment brands (Visa, Mastercard) and acquirers. These are often excluded as they are considered contractual penalties rather than insurable loss. Many policies state: fines or penalties imposed by any regulatory or private scheme are excluded.
- Losses resulting from failure to maintain required controls named in the policy schedule or warranty. If a warranty required quarterly vulnerability scans or encrypted POS terminals and these were not in place, insurers may decline.
- Any loss arising from intentional fraudulent acts by the insured or employees. This includes collusion to bypass payment controls.
- Non‑compliance discovered before inception or known vulnerability not disclosed at proposal. Pre‑existing issues must be declared; failure to do so can void cover.
Implications for SMEs:
- Even when a policy pays forensic and notification costs, it may not pay fines levied by payment schemes, this can still leave the merchant with large settlement demands from the acquirer.
- SMEs should review policy exclusions in the context of contractual obligations with the merchant acquirer and payment brands.
POS terminal compromises vs payment gateway failures: which cover?
Explanation: The location and vector of the compromise matter because insurers and acquirers treat them differently. A local POS terminal compromise (skimming, tampering, malware) and a remote payment gateway outage or breach are distinct events.
Comparison table (typical treatment by insurers)
| Event |
Likely insurer response |
Dependency |
| On‑site POS compromise (skimmer/malware) |
Breach response often covered (PFI, notification); fines from schemes often excluded |
Requires evidence of maintenance, patching, PCI compliance steps |
| Payment gateway compromise (third‑party SaaS) |
Insurer may cover business interruption and notification but seeks recovery from gateway/provider |
Dependent on provider contract and insured’s access to provider logs |
| Payment API misconfiguration by merchant |
Often treated as insured fault; cover may be denied if warranty breached |
Evidence of developer/testing and secure configuration required |
Context and implications:
- When the gateway is the root cause, many insurers will expect the insured to pursue contractual recovery from the gateway provider; insurers may pay initial costs but reserve rights to subrogate.
- For on‑site compromises, the merchant’s operational security controls are under scrutiny; failure to demonstrate routine checks, tamper seals or software updates can jeopardise a claim.
Practical checklist to determine policy applicability:
- Was cardholder data stored or transmitted in a manner that contravened PCI DSS requirements stated in the policy?
- Can the business provide recent vulnerability scan results, patching records and AOC or SAQ documentation?
- Was the POS terminal owned/managed by the merchant or by the acquirer? Ownership affects liability and recoverability.
What costs are insurers likely to pay after a PCI breach?
Clear answer: Insurers commonly meet forensic investigation costs, customer notification, PR/credit monitoring (if included), legal defence and certain third‑party liabilities, subject to policy limits and excesses. Fines by payment brands and contractual penalties are frequently excluded.
Breakdown of common cost elements (with typical treatment):
- Forensic investigation (PFI): Frequently covered. Insurers often appoint or approve an external forensic firm to identify the scope and timeline of compromise.
- Notification to cardholders and regulators: Often covered under breach response, including letters or emails and helplines.
- Costs to reissue cards: Usually a merchant/acquirer cost; insurers may reimburse if policy specifically covers card re‑issuance fees.
- Fraudulent transaction losses: Typically borne by card issuers and then recovered from the merchant via the acquirer; insurers rarely cover transaction reversals unless specific fraud cover exists.
- PCI brand fines and acquirer penalties: Commonly excluded or capped by sub‑limits.
- Business interruption: Can be covered if the policy includes cyber BI and the interruption resulted directly from a covered cyber event.
- Legal costs and third‑party liability: Often covered for claims by customers or partners, subject to defence limits.
Indicative figures (current at time of writing):
- PFI investigations for a small retail breach commonly cost from £8,000–£35,000 depending on complexity.
- Notification and PR can range £3,000–£20,000 for small businesses.
- PCI brand fines can be material; reported acquirer chargebacks and settlement demands can exceed £50,000 in severe incidents, hence the importance of exclusion review.
Why these numbers matter:
- Even when insurers cover initial response, gaps in cover for fines or chargebacks can leave the merchant with significant liabilities. Early liaison with the acquirer and insurer is essential.
How does GDPR affect PCI breach claims in England?
Direct answer: GDPR applies where cardholder data qualifies as personal data. GDPR obligations (eg, breach notification to the ICO) sit alongside PCI obligations. GDPR fines and corrective orders are regulatory, and their insurability is limited by law and policy wording.
Key points and practical implications:
- The ICO expects organisations to report data breaches where personal data has been compromised; guidance: ICO breach reporting.
- GDPR fines are regulatory sanctions. Insurers often exclude fines and penalties arising from statutory breaches, or they may cover defence costs only. Policy wording should be examined to see whether defence costs for GDPR investigations are included.
- Distinguish between civil liabilities (eg, claims by customers for misuse of their card data) and regulatory fines. Policies are more likely to cover civil claims than regulatory penalties.
- Cooperation with supervisory authorities, timely notification, and documented remediation steps can reduce the likelihood and quantum of fines, and improve the chance of an insurer paying defence costs.
Caveat on legality: Under UK law insurers cannot contractually insure away criminal fines or certain statutory penalties. Policies that appear to indemnify regulatory fines often have tightly worded exceptions.
Explanation: Follow a structured process to preserve evidence, involve the insurer promptly and keep the acquirer informed. The insurer may appoint a PFI and reserve rights; rapid, documented action strengthens a claim.
- Stop further loss: Remove or isolate the affected POS terminal but avoid altering logs or disk images.
- Notify the insurer and acquirer: Use the policy emergency hotline and the merchant acquirer’s incident contact.
- Preserve evidence: Take photos, note serial numbers, and record exact timestamps of the detection.
Step‑by‑step claim process (detailed)
- Notify the insurer via the emergency contact and confirm the policy number and scope.
- Gather contractual documents: merchant agreement, PCI Attestation of Compliance (AOC) or Self‑Assessment Questionnaire (SAQ), maintenance logs and any third‑party SLA for POS support.
- Allow the appointed PFI to image devices and collect logs. Do not attempt to reinstall or reconfigure compromised devices before imaging.
- Collate customer notification lists, transaction logs, and bank/acquirer correspondence for potential chargebacks.
- Maintain a written incident log of actions and communications with the insurer, acquirer and any law enforcement contacts.
PCI breach response flow for POS incidents
PCI breach response flow for POS incidents
Detected ➜ Isolate ➜ Notify insurer & acquirer
Preserve evidence ➜ PFI investigation ➜ Customer notification
Recovery ➜ Remediation & check PCI controls ➜ Claims & subrogation
Balance strategic: the reality of PCI coverage for POS & card payments, benefits vs challenges
When cover is the best option (benefits of buying relevant cover)
- ✅ Immediate access to forensic expertise that most SMEs cannot afford on short notice.
- ✅ Fast notification support and PR management to reduce reputational harm.
- ✅ Potential cover for business interruption where sales stop due to compromised systems.
What to watch for (red flags)
- ⚠ Policy exclusions for PCI fines and acquirer penalties that shift the biggest costs back to the merchant.
- ⚠ Warranties requiring specific technical controls (eg, chip & PIN, encrypted terminals) that the business cannot evidence.
- ⚠ Low sub‑limits for breach response meaning the insurer’s contribution may be insufficient in a moderate case.
Practical contract checklist before buying cover
- Confirm whether the policy contains a PCI DSS warranty or wording requiring specific compliance steps.
- Check the sub‑limits for PFI, notification and PR, these are often lower than the overall limit.
- Ask whether the insurer will cover claims arising from third‑party payment providers or whether those are excluded.
- Verify the policy’s requirements for log retention and incident reporting timeframes.
DETAILED how-to: make a claim, short tutorial
How to claim on cyber insurance after a PCI breach
- Contact the insurer via the policy emergency line; provide a short statement of the incident and request appointment of a PFI.
- Collate evidence: AOC/SAQ, merchant agreement, transaction data and maintenance records.
- Allow the PFI to perform imaging and analysis; follow their instructions to avoid contaminating evidence.
- Submit a formal written claim with itemised costs and insurer claim forms.
- Keep the acquirer informed and cooperate with their investigations to reduce chargeback exposure.
Lo que otros usuarios preguntan about POS & card payments: are PCI breaches covered?
How is a PCI breach defined for insurance purposes?
A PCI breach usually means unauthorised access to cardholder data or systems that handle it. Insurers define this by policy wording; check the definition in the policy. Definitions control whether an event triggers coverage.
Refusal commonly follows undisclosed pre‑existing vulnerabilities, breach of policy warranties (eg, missing encryption) or deliberate acts by the insured. Lack of evidence also leads to decline.
What happens if the payment gateway is at fault?
If a third‑party gateway is responsible, the insurer may cover initial response but pursue subrogation against the gateway. The merchant should review provider contracts and liability caps.
Which evidence convinces insurers after a POS compromise?
Logs, AOC/SAQ, maintenance and patch records, tamper‑seal photos and transaction timelines. Early forensic imaging is crucial.
What costs do insurers rarely pay after a PCI incident?
Payment‑scheme fines, standard chargebacks resulting from merchant negligence, and punitive damages are commonly excluded or limited.
Conclusion
A clear understanding of policy wording, early preservation of evidence and rapid liaison with both insurer and merchant acquirer substantially improves outcomes after a POS or cardholder data incident. For many UK micro and small businesses, a modest breach response package plus clear contractual protections with payment providers offers the best balance between cost and real protection.
- Create a short incident pack: policy number, insurer emergency phone, acquirer contact and recent PCI evidence (AOC/SAQ), take ten minutes now to assemble and save it.
- Photograph POS devices and note serial numbers; store images in cloud backup for quick access.
- Add the insurer emergency number and the acquirer incident contact to the phone and email favourites list for instant notification.