Worried a compromised payment gateway or a malicious plugin could stop sales overnight? Owners of UK e‑commerce SMEs face realistic risks. These include payment fraud, customer data breaches and ransomware. They may also face costly chargeback cascades. Many lack specialist IT or clear cost expectations.
Where an online shop operates in England, cyber insurance helps cover payment fraud. It also covers data breaches, ransomware and business interruption. Policies typically pay for forensic, PR and regulatory costs.
Expect details on typical cover and likely premiums for UK micro and small retailers. The article gives essential underwriting controls and a simple incident-response checklist. Owners should check controls and gather documents before requesting quotes.
E‑commerce SMEs: deciding factors
The main decision point is simple. If the shop takes payments, stores customer data or lists on marketplaces, cover is worth a serious look.
Turnover and payment volume
Insurers focus on annual turnover and monthly payment transactions when pricing and setting limits.
Which CMS, apps or plugins the shop uses strongly affects underwriting.
A hosted Shopify store with no server access looks different to a self-hosted WooCommerce site using third-party payment plugins.
Security controls that matter
Underwriters ask about MFA, backups, patching cadence, and PCI evidence.
Documented backups and two-factor authentication can reduce premiums. They also lower the chance and severity of claims. Controls commonly improve an applicant's negotiating position at quotation time. Exclusions appear in the policy wording and do not disappear automatically with controls. Owners should show evidence of controls to the broker. The broker must check that evidence against policy exclusions and endorsements.
Keep this plan pinned where the team can see it.
Self‑hosted CMS, plugin‑reliant and marketplace/PSP‑reliant
Shops that run their own CMS or rely on plugins face specific exposures, while those that sell mainly through marketplaces or use PSPs face other exposures.
Plugins increase the attack surface for self-hosted sites. Marketplace accounts and PSP logins attract account takeover and social-engineering attacks.
Both models can lead to card‑skimming, unauthorised payouts, disrupted sales and regulatory or contractual consequences.
- Plugins extend functionality but often increase the attack surface.
- An outdated payment plugin can let attackers inject card‑stealing scripts at checkout.
- Using Stripe, PayPal, Worldpay or marketplace platforms reduces the need to hold card data.
- This does not remove risk.
- Social engineering that steals login credentials can still cause unauthorised payouts, listing changes or account loss.
Typical incident and cost profile
- For self‑hosted shops, the usual immediate costs are forensic analysis and customer notification.
- A forensic engagement can range from £2,500 to £20,000 depending on scale and complexity.
- For marketplace‑reliant shops, a lost account can stop sales immediately.
- This may trigger contractual penalties from the marketplace.
- Chargeback cascades from fraudulent transactions can also create large losses quickly.
Chargebacks and contractual liabilities
Many insurance policies restrict cover for card‑not‑present (CNP) fraud, so check policy wording on CNP and chargeback limits. Chargeback cascades can rapidly amplify losses.
Controls to prioritise
- Apply security updates promptly and remove unused plugins.
- Use strong, unique admin passwords.
- Limit admin access and enable multi-factor authentication for all site accounts and platform and PSP logins.
- Maintain an incident response plan that anticipates forensic costs and customer notification obligations.
- Regularly monitor account activity and marketplace listings for unauthorised changes.
Planned restore tests: keep an encrypted offline backup copy.
Carry out a full restore test at least twice a year to prove recoverability.
| Cover element |
Common policy position |
Relevance to online shops |
| Forensic & incident response |
Usually covered, often first expense |
Critical to online shops |
Common errors and warnings for online shops
Many owners assume a standard business policy covers cyber losses. That is a frequent mistake.
The error most frequent at this point is believing public liability or contents insurance will protect against data breaches. Owners also expect it to cover payment fraud.
Mistake: not checking marketplace
Marketplaces sometimes require sellers to hold specific insurance or accept contractual penalties. Not reading those terms can mean unexpected liabilities if the marketplace holds the seller responsible.
Mistake: treating backups as sufficient
Backups help recovery but do not stop reputational or regulatory fallout. This works well in theory, but in practice backups must be tested and isolated to satisfy underwriters.
Practical warning on prior incidents
Not disclosing previous incidents can void a claim or lead to policy cancellation. Always declare past breaches or ransomware attempts when applying for cover.
This guidance does not apply to businesses with no online sales presence. It also does not apply when a marketplace contract demands bespoke insurance that overrides standard SME cyber policies.
As shown in the infographic below, the incident flow for an online shop follows clear stages. Those stages are contain, notify, restore and learn.
Keep this plan to hand during a breach.
Incident flow for online shops
24–72 hour focus
Contain
Isolate systems, preserve logs
Notify
Call insurer, PSP, marketplace
Restore
Use tested backups, validate orders
Learn
Patch, change passwords, update policy
E‑commerce operators must factor UK GDPR obligations into both insurance and incident planning. Under UK GDPR, the ICO expects data controllers to notify a personal data breach to the regulator. They must do this within 72 hours of becoming aware if the breach is likely to risk individuals' rights and freedoms. They should inform affected customers without undue delay when the breach is likely to result in high risk.
Marketplaces, PSPs and gateway providers can be controllers or processors depending on contract and function. A marketplace that controls listing data or order processing may be a controller. A PSP that handles card payments typically acts as a processor. That distinction affects who leads notification and defence.
Failing to meet notification duties can increase regulatory costs and complicate claims. Fines for serious GDPR breaches in the UK can reach up to £17.5m or 4% of global annual turnover.
Document processor agreements and keep records of processing activities. Run a DPIA when adding new payment integrations or when starting large-scale customer profiling.
What insurers and brokers will ask
A broker or underwriter will want clear numbers and proof of controls before offering terms. Prepare structured answers and evidence to speed quoting and avoid surprises.
Typical questions on payment handling
Expect questions about monthly transaction volumes, PSPs and whether card data is stored. Provide screenshots or statements from Stripe, PayPal or Worldpay when possible.
Questions on security controls
Underwriters ask about MFA, patching, backups and penetration tests. Proof of Cyber Essentials or an internal security checklist helps negotiations.
Keep your evidence together in one secure place.
The recommendation is simple: shops benefit from cover if they meet basic controls. The value varies by profile and by risk.
This works well for most shops, but only when controls are in place and declared; otherwise sublimits or exclusions often apply.
Owners should prioritise quick wins like MFA and tested backups, then seek tailored quotes from a broker who understands e‑commerce risks.
Cost example: a small WooCommerce shop with £250k annual turnover quoted in 2026 might expect premiums near £650 per year.
This assumes a £1,000 excess and that MFA and tested backups are in place.
Documents to prepare for a quote
Have turnover statements, PSP contracts, plugin inventories and evidence of controls ready. Also include any letters from the ICO or prior incident reports if they exist.
As a practical guide, consider these illustrative quote scenarios from 2024 market norms:
- A micro hosted shop using Stripe and with £50k turnover often sees premiums around £150–£350 per year.
- A typical excess is £500–£1,000 and common policy limits run £50–£100k.
- A small self-hosted WooCommerce store with £250k turnover and multiple plugins typically quotes in the £600–£1,200 per year band.
- A £1,000 excess is common.
- Card-not-present sublimits often sit at £20k–£50k.
- A multi-channel retailer at about £1m turnover can expect quotes from about £2,000 to £5,000 or more.
- These policies often have higher excesses and larger aggregate limits.
Prior breaches, high monthly transaction volumes or failure to evidence controls commonly push premiums up by 50–200%. They may also trigger lower card-not-present caps. Always check sample endorsements and any explicit sublimits for chargebacks when comparing offers.
Quick incident plan for an online shop
Keep a concise 24–72 hour script to preserve evidence and restart sales quickly.
24–48 hour checklist
- Contain: take affected systems offline if instructed and preserve logs.
- Notify: call the insurer or broker and activate a forensic consultant.
- Repair: restore from a trusted backup and validate payment flows.
Post‑incident actions
- Compile claim documentation: forensics, sales loss evidence and communications.
- Update plugins, rotate credentials and force MFA resets for all admin accounts.
Example incident
One common case: a small online retailer used a third‑party payment plugin that was later compromised. The forensic bill reached £15,400 and downtime cost the shop £8,200 in lost orders. The insurer paid forensic and legal costs but denied most chargeback claims due to a CNP exclusion.
Pre-quote checklist for brokers:
- Annual turnover and monthly online revenue
- PSP names and whether card data stored
- List of CMS, themes and plugins with versions
- Evidence of MFA and backup restore test date
- Incident history and ICO correspondence
For a tailored quote, bring the checklist above to an experienced broker or a BIBA member. Brokers can often give a firm indication within three business days when documents are ready.
A practical, timed incident playbook for online shops reduces friction when seconds count.
0–4 hours: isolate affected systems and take checkout to maintenance mode. Preserve logs and create disk images and database snapshots. Capture payment gateway and API logs.
Notify your insurer or broker and your PSP immediately. Tell the web host to preserve forensic evidence.
4–24 hours: engage a forensic firm as recommended by the insurer. Change API keys and admin credentials. Rotate PSP and merchant credentials. Temporarily suspend affected listings on marketplaces. Tell fulfilment and shipping partners to pause suspect orders.
24–72 hours: assess the scope of the breach. Prepare an ICO notification if required. Draft and send a concise customer message describing what happened and what data is affected. Recommend actions such as changing passwords, monitoring cards and contacting the bank. Arrange PR and communications support if reputational risk is high.
Post-incident: reconcile chargebacks and sales-loss evidence for claim submission. Run a full restore test from encrypted backups. Patch or remove vulnerable plugins. Update marketplace and PSP contracts and internal runbooks with lessons learned.
A short customer notification example:
"We are contacting you because we have discovered unauthorised access affecting order and payment details dated [date]. We recommend customers monitor their accounts and contact their bank if they see unauthorised transactions. If help is needed contact [email/phone]."
Frequently asked questions
Do SMEs need cyber insurance?
If the shop takes payments, stores customer data or sells on marketplaces, yes. Cover helps pay for immediate forensic work, legal advice and notification costs that can otherwise bankrupt a small shop.
How much does cyber insurance cost?
Expect £150–£5,000+ per year depending on risk and controls. Micro shops with hosted PSPs often see £150–£400 pa; shops with higher transaction volumes or prior incidents reach four figures.
What does cyber insurance typically cover?
Forensic costs, legal defence, notification, ransomware and business interruption are common. Read policy wordings for limits on card‑not‑present fraud, marketplace liabilities and whether fines are insured.
Does cyber insurance cover ransomware payments?
Many policies pay ransom negotiation fees and extortion costs subject to sublimits. Many cyber policies require immediate insurer notification. They also require that ransom negotiation, forensic analysis and other specialist services are coordinated with approved vendors. Insurers often expect prior consent before authorising a ransom payment. Exact requirements and approvals differ by insurer and must be checked in the policy wording.
How to choose the right insurer or broker?
Pick a broker with e‑commerce experience and compare endorsements, retroactive dates and sublimits. Ask specifically about CNP fraud, marketplace exclusions, defence of regulatory actions and aggregate limits.
What to do next
First step: gather the documents listed in the pre-quote checklist. Run a short internal review of MFA, backups and plugins.
Owners should ask a broker about policy wordings on card‑not‑present fraud and marketplace liability before signing. Contact a broker who understands online retail and prepare to provide turnover, PSP statements and screenshots of security controls.
Relevant guidance from the National Cyber Security Centre and the Information Commissioner supports the controls recommended here. See the NCSC small business guidance for practical steps: NCSC small business guide.
Will an insurer pay for chargebacks?
Sometimes, but CNP and marketplace chargebacks may be limited. Sublimits and exclusions for chargebacks are common. Document payment flows to reduce disputes at claim time.