Franchises & multi‑site SMEs: critical variables that decide cover and cost
Franchise networks face concentrated risk when systems are centralised. Underwriters focus on aggregation clauses and correlated exposures first. The single most common policy trap is a broad aggregation clause. It lets one incident consume the sum insured for all sites.
The decision path depends on three variables. First, how centralised are systems like POS, CRM or booking engines? Second, the allocation of contract responsibilities between franchisor and franchisee. Third, the desired commercial outcome for claims handling and reputational control.
Controls affect price. Insurers look for network segmentation and MFA on admin accounts. They also seek endpoint detection and response (EDR) and tested backups. If those controls are missing, expect higher premiums or refusal to bind multi‑site exposure.
The legal framework that shapes cover includes the Insurance Act 2015, and is complemented by the Data Protection Act 2018 and the Computer Misuse Act 1990. Regulators influence response obligations; include ICO and NCSC guidance in documentation.
Immediate action: compile a site register. List centralised services, confirm Cyber Essentials for the group and capture 12 months revenue per site. These items enable rapid, comparable tenders to brokers within 48 hours.
A short, clear plan speeds the process.
Allocation of responsibility: franchisee vs franchisor, contract clauses and who pays
Three placement models exist: independent policies per franchisee; a franchisor master policy; or a hybrid with shared and local covers.
Independent policies give franchisees control. They prevent a single incident from using a network limit. They raise administrative costs. They can create gaps if the franchisor requires coverage for brand protection.
A franchisor master policy pools risk. It can be cheaper per site and centralises claims and PR control. It creates moral hazard. Only strict operational controls and underwriting rules reduce that hazard.
A hybrid model is common. The master policy covers brand liability and major BI for central systems. Local policies cover site‑specific incidents and smaller BI losses.
Sample clause. Additional insured and loss payee (copyable):
"The Insurer shall name the Franchisor as an Additional Insured and Loss Payee. Coverage for any claim arising from the Franchisor's proprietary systems or central platforms shall respond on a primary basis. It shall be non‑contributory to the extent of the Insurer's limit for such claim. Nothing in this clause shall increase the Insurer's liability beyond the stated Limits of Liability."
Sample clause. Indemnity and cost allocation (copyable):
"Where a single event gives rise to claims against both Franchisee and Franchisor, the Parties shall notify insurers and appoint a joint claims administrator. Costs shall be allocated pro rata by demonstrated financial loss per Party. This applies unless a contrary written agreement exists. The Franchisor may deduct verified expenses from funds it controls only with prior written consent of the Franchisee."
Sample clause. Waiver of subrogation (copyable):
"Each Party waives rights of recovery against the other for losses covered by insurance. This waiver applies provided the loss is covered by insurance. Such waiver shall not operate to invalidate any insurer's right of subrogation under the Policy unless expressly stated."
Practical examples clarify allocation. Table 1 shows side‑by‑side outcomes under three models for two claim scenarios.
| Scenario |
Master policy (Franchisor) |
Local policy (Franchisee) |
Hybrid |
| Centralised POS breach hitting 40 sites |
Franchisor policy responds. Aggregate limit is used and BI covered centrally. |
Multiple franchisee claims. Potential coverage disputes and higher admin arise. |
Master pays central BI. Franchisees claim local losses under own limits. |
| Single‑site ransomware from local credentials |
Franchisor policy may not respond if incident is isolated. Response depends on wording. |
Local policy generally responds. Quicker indemnity follows for local BI. |
Local policy covers site. Master may cover spillover to central services. |
Red flags to avoid.
- Naming both parties without clarifying whether coverage is primary or excess invites dispute.
- A blanket waiver of subrogation can stop recovery from third parties.
- Silent‑cyber or supply‑chain aggregation exclusions can void cover for centralised failures.
Warning: This allocation model does not apply if an insurer refuses to accept multi‑site exposure until minimum technical controls exist. In such cases, controls must be upgraded before cover will be placed.
Plan the technical upgrades promptly.
Comparing cyber security controls, policy cover limits and aggregation risk for multi‑site networks
Underwriting for networks differs from single sites. Insurers assess correlation risk from shared systems first. Aggregation rules determine whether one incident counts as one claim or many. Define the aggregation trigger early.
Define terms. Aggregate limit is the total the insurer will pay in the policy period. Per‑incident limit caps an individual event. An aggregation clause defines when related losses are a single incident.
A poorly drafted aggregation clause can let one central failure exhaust limits for all sites. That exposes franchisees to uncovered BI and reputational damage.
Indicative premium bands and drivers (UK, England):
- Small multi‑site (3–10 sites, combined revenue £0.5–2m): typical £1,200–£8,000 per year. Drivers include centralised POS, PCI scope and EDR presence.
- Medium (11–50 sites, combined revenue £2–20m): typical £8,000–£50,000 per year. Drivers include aggregate BI exposure and backup architecture.
- Large networks (50+ sites): £50,000+ per year. These often require Lloyd's panels and minimum controls.
Cost drivers include aggregated revenue exposed and centralised cloud providers. PAN/cardholder data handling, control maturity and historical incidents also matter. Underwriters will ask detailed questions.
Underwriting checklist for brokers and underwriters:
- Consolidated site register with revenue by site.
- Inventory of centralised systems and admin accounts.
- Backup strategy, frequency and offsite copies.
- EDR and MFA coverage evidence.
- Incident history for past 5 years.
- Copies of franchise agreements with indemnity clauses.
Technical control differences matter. Centralised POS or CRM demands strict segmentation and per‑site encryption. Isolated sites with limited connectivity carry lower aggregation risk. Compensating controls sometimes suffice, but underwriters prefer hard segmentation.
Actionable control: enforce MFA for all admin accounts. Enable EDR on all workstations. Maintain air‑gapped backups and test restores quarterly. Insurers often mandate these before binding multi‑site limits.
Aggregation risk (single incident)
One central failure can consume the policy limit. All sites may remain uninsured for the period.
Segmented limits (per site)
Per‑site limits contain losses. One site may exhaust its limit without harming others.
How cyber insurance responds: data breaches, ransomware and business interruption
Cyber policies split cover into first‑party and third‑party sections. First‑party covers incident response, forensics, extortion, data recovery and PR. Third‑party covers liability to customers and regulators.
Business interruption for multi‑site networks is tricky. Policies may provide per‑site daily BI limits and an aggregate BI cap. The measurement of loss requires clear wording on the basis of revenue and the indemnity period.
Ransomware cover will include negotiation, extortion payments, and recovery costs. Many UK policies require insurer approval before any ransom payment or engagement of negotiators. Always check consent and subrogation clauses in the draft wording and obtain written confirmation of insurer ransom processes during placement.
Claims process steps are predictable: detection and containment come first, followed by insurer notification, appointment of forensic specialists, regulatory reporting, and then quantification and payment.
Median operational timelines seen in practice:
- containment within 24–72 hours
- forensic report in 7–21 days
- staged recovery in 30–90 days
- full restoration may exceed 90 days for complex central systems
These timelines affect BI calculations and reserve estimates.
Short anonymised case study (numbers and timeline):
- Context: a mid‑sized franchise with 25 sites operating across England. Central booking and POS systems used.
- Incident date: 2024. Ransomware encrypted central database.
- Immediate costs: forensic & IR £120,000; ransom £85,000 (paid); PR & regulatory costs £35,000.
- Business interruption: estimated £420,000 over 6 weeks.
- Insurance response: policy had per‑incident limit £1,000,000 and aggregate limit £1,000,000. The insurer treated event as a single claim and met IR, ransom and BI claims.
- Timeline: detection day 0; containment day 2; forensic report day 9; staged restoration weeks 2–8; business parity week 12.
Lesson learned: the group had insufficient BI per‑incident sub‑limit and no clear apportionment clause in the franchise agreement.
Exception: single‑site businesses with no shared systems rarely face aggregation risk. A multi‑site insurance strategy is unnecessary when no central services or shared cloud exist.
Prepare a small exceptions list for clarity.
Practical underwriting checklist to get comparable quotes fast
Prepare these documents before issuing an RFP to brokers. Each item shortens lead time and improves quote comparability.
-
Consolidated site register. Include address, SIC code, opening date, employees and revenue per site.
-
Inventory of centralised systems. Identify POS, CRM, booking platforms, cloud providers and who has admin rights.
-
Data map. List categories of personal data and whether cardholder data is processed. Indicate retention periods.
-
Controls evidence. MFA screenshots, EDR deployment map, network segmentation diagram, and backup architecture description.
-
Incident history. A summary of incidents in the last 5 years and remediation actions taken.
-
Franchise agreement extracts. Show indemnity wording, additional insured clauses and any waiver language.
-
Certificates. Cyber Essentials or ISO27001 documentation, and the scope of certification.
-
Business continuity facts. RTO/RPO targets, cold/ warm site arrangements, and vendor SLAs.
-
Desired policy specification. Minimum per‑incident and aggregate limits, BI indemnity period and preferred endorsements.
-
Claims contacts. Name of DPO, IT lead, legal counsel, and preferred IR vendor.
Below is a comparison table template brokers will use to present proposals.
| Insurer / Broker |
Premium |
Per‑incident limit |
Aggregate limit |
BI cover (period) |
IR & forensic sub‑limit |
Ransom sub‑limit |
Named insureds & endorsements |
| Insurer A |
£12,500 |
£1,000,000 |
£1,000,000 |
90 days |
£250,000 |
£100,000 |
Franchisor named as Additional Insured |
| Insurer B |
£18,000 |
£2,000,000 |
£2,000,000 |
120 days |
£500,000 |
£250,000 |
Primary cover; subrogation waiver included |
Selection rubric (suggested weights): 30% coverage & limits, 25% claims capability, 20% premium, 15% exclusions, 10% additional services.
Broker selection tips. Use brokers with multi‑site experience. Check references for franchise placements. Prefer brokers who present policy wordings early. Avoid quotes that only provide summary terms without full wording.
Common policy traps and warnings for franchise networks
Aggregation clauses often hide exposure. When the policy defines "one event" broadly, the insurer may treat related incidents as one claim. That can leave the network underinsured for months.
Low forensic and incident response sub‑limits are a frequent error. For a multi‑site incident, early IR often costs six figures. Small sub‑limits create delays and out‑of‑pocket payments.
Naming conventions cause disputes. If the franchisor is merely an additional insured without primary wording, coverage may default to franchisee policies first. Precise language avoids conflict.
Silent cyber and supply‑chain exclusions sometimes attach after placement. Ensure the policy wording addresses coverage triggers tied to central cloud providers and third parties.
Caution: Selecting the cheapest premium without reviewing aggregation wording is a false economy. A low‑cost policy with wide aggregation can cost the group millions in uncovered losses.
Pause and read the aggregation wording carefully.
Frequently asked questions
This FAQ answers common long‑tail questions plainly.
Do franchisees need cyber insurance in UK chains?
Yes. Franchisees need cover when contracts or shared systems expose them. If the franchise agreement shifts liability to the franchisee, a local policy is essential. If the franchisor demands notification or brand protection, ensure the policy names the franchisor with precise wording.
What does cyber insurance cover for SMEs and multi‑site businesses?
Cyber insurance typically covers incident response, forensics, cyber extortion, data recovery, PR, regulatory defence costs and third‑party liability. For multi‑site networks, BI cover, aggregation wording and sub‑limits must be checked closely.
Does cyber insurance cover ransomware attacks?
Policies commonly cover ransomware where extortion sub‑limits exist and insurer approval is obtained. Many UK insurers require documented backups and controls. Payment often needs pre‑approval and may be subject to legal and sanctions checks.
How much does cyber insurance cost for a franchise or multi‑site business?
Indicative ranges exist: small multi‑site £1,200–£8,000 pa; medium £8,000–£50,000 pa; large £50,000+ pa. Final price depends on controls, revenue exposure, BI potential and claims history.
Who is responsible for a cyber incident, franchisor or franchisee?
Responsibility depends on contract clauses and the incident cause. Where central systems fail, franchisors typically bear responsibility if they control the system. Where local negligence causes the breach, franchisees are usually liable.
How to obtain cyber essentials certification for multiple sites?
Centralise the policy and sample sites for evidence. Gather configuration screenshots and patching logs. DSIT and NCSC guidance helps. Expect a 2–4 week process for documentation and assessment per wave.
Can a breach at one location affect the whole franchise network?
Yes. If central systems or credentials are shared, one breach can affect all sites. Insurers treat correlated failures as aggregation risk. One breach can consume the policy limit if aggregation wording applies.
Recommended next steps to secure and insure franchise networks in England
Day 0–2: run the 48‑hour checklist. Compile the consolidated site register and inventory central services. Confirm Cyber Essentials for the group and collect 12 months revenue per site.
Day 3–7: gather controls evidence. Capture MFA screenshots, EDR deployment maps, backup diagrams and incident history. Send the RFP to two experienced brokers with multi‑site placement records.
Week 2: obtain full policy wordings and sample aggregation clauses. Ask brokers to model a central POS outage and show whether it counts as one or many occurrences. Seek written insurer confirmation on ransom and subrogation processes.
Week 3–4: negotiate naming and apportionment clauses with legal counsel. Add primary wording where the franchisor must be an additional insured. Insert a joint claims administrator clause for multi‑party losses.
Months 1–3: implement required controls. Enforce MFA, deploy EDR and establish tested, air‑gapped backups. Reassess segmentation and admin account controls with the IT team.
If the insurer will not bind without upgrades, act immediately. Controls must be in place before multi‑site cover will be placed.
For immediate assistance, prepare the checklist and contact a specialist broker with franchise experience.