Could a single billing outage wipe out a month’s MRR and trigger GDPR fines or chargebacks? Yes. A billing outage can stop income and create regulatory work.
Cyber insurance for subscription & membership businesses: If your business sells by subscription, cyber insurance should explicitly cover lost recurring revenue, billing-system failures and third-party payment interruptions. In the UK, look for policies that define “subscription income”, include ransomware and business-interruption cover tied to MRR/ARR, cover PCI-related breaches, and provide incident-response support. Below are practical checks, examples and cover levels for SMEs.
Cyber insurance for subscription & membership businesses
First check whether your policy names subscription income or just "turnover". Insurers pay based on the policy wording. Declare MRR and list payment integrations to avoid claim shortfalls.
What underwriters look for
Underwriters want historic MRR, churn rate and ARPU when pricing cover. They use those numbers to model probable lost revenue and set limits. Proof of controls like Cyber Essentials or ISO 27001 reduces premium bands.
Policy elements that matter
Key items are the definition of insured revenue, indemnity period and contingent cover for suppliers. Check whether regulatory defence, forensic costs and reputational support are included. A short indemnity period often leaves recovery costs uncovered after initial downtime.
Recommended quick check: if the policy defines loss using the word "turnover" only, ask for an endorsement to include recurring subscription revenue and list all payment gateways in the schedule.
Quick comparison table
Provider
MRR cover
Contingent BI
Indemnity options
Ransomware/IR
Hiscox (example)
Available with endorsement
Available
1, 3, 6, 12 months
IR retainer options
Aviva (example)
Often by endorsement
Limited unless named
3, 6, 12 months
Available
Lloyd's Market (example)
Custom wording possible
Yes, with evidence
Bespoke periods
IR plus PR cover
If a provider is not listed by name in the policy schedule, the insurer may treat outage as a supplier problem and decline contingent business interruption without proof of SLA breach.
One quick point about evidence: insurers will expect documentation such as outage notices, timestamps and logs to support a claim.
SaaS with in-house billing and stored cards
This profile describes businesses that host billing, store cards and handle renewals. The underwriting focus will be on your auth system, PCI evidence and incident plan. Prepare MRR reports, churn history and acquisition cost figures for a smooth quote.
Underwriting evidence for in-house
Provide 12 months of MRR and monthly churn as a minimum. Show PCI DSS status and any third-party penetration test results. Include authentication controls such as multi-factor authentication and rate limits.
Pricing and excesses for this profile
Premiums rise with declared MRR and shorter indemnity periods raise excess risk. Insurers calculate loss using your declared MRR and chosen indemnity months. A higher excess reduces premium but increases immediate cash exposure at claim time.
This recommendation works well in theory but insurers still reject claims when gateways or SaaS integrations were not declared. The most common mistake at this point is assuming an insurer will read your platform architecture from public docs. Explicit disclosure of every payment integration avoids later disputes under the Insurance Act 2015.
Choose a limit that covers immediate lost MRR and a churn uplift. Buy incident response with a retainer. The cover only works if payment providers and billing software are declared to the insurer.
This profile covers businesses where Stripe, GoCardless, Chargebee or Zuora manage billing. Underwriters care about vendor SLAs, liability caps and incident history. Document contracts and outage reports to support contingent business interruption claims.
What insurers expect from gateways
List every payment processor and billing SaaS in the schedule to the policy. Insurers often demand evidence of PCI compliance from both the merchant and the gateway. Include provider incident contacts and SLA breach thresholds in your claim folder.
Contingent business interruption details
Contingent BI requires proof the supplier caused the loss and breached SLA. Insurers may ask for timestamps, outage notices and provider logs as evidence. Recovery often depends on the supplier's incident timeline, so record communication.
An anonymised case: A platform lost 10 days of renewals after a major gateway outage. The insurer paid BI after the gateway published a 36-hour outage and the claimant showed logs and re-billing attempts. The payout included funds for retention campaigns but excluded fines where the breach stemmed from customer credential compromise.
Illustrative incident breakdowns show why subscription revenue insurance must account for more than headline lost turnover. For example, a mid-market SaaS with 5,000 active subscribers and MRR of £50,000 that suffers a 10-day billing outage will lose approximately £16,667 of billed revenue. If the outage causes a 5% churn uplift, that is 250 customers lost; at a reacquisition cost of £120 each the reacquisition bill is about £30,000.
Add forensic investigation, PR and manual rebilling costs and short-term retention offers and the total cash impact becomes multiple times the headline lost MRR. Underwriters modelling claims therefore need historic MRR, the underwriting churn rate assumptions and a clear split of one-off incident costs versus ongoing churn to set appropriate indemnity periods and limits.
Underwriters and brokers increasingly expect concrete technical and contractual controls for billing systems and payment integrations before offering payment gateway failure cover or contingent business interruption. Practical evidence includes an architecture diagram showing tokenisation, card-on-file token usage, 3DS flows, webhook signing and replay protection, idempotency keys on billing APIs, retry and backoff logic on failed charges and a documented fallback queue for manual billing.
Contractually, insurers look for SLAs that specify uptime (for example 99.9–99.95%), incident notification windows (for example Initial report within 60 minutes), credits for downtime and liability caps. They also value audit or access clauses and recent PCI DSS Attestation of Compliance, external penetration test reports and proof of encryption-key management.
Presenting these items at quote stage, plus signed contracts listing provider incident contacts and log export procedures, materially reduces disputes at claim time.
Three quick actions help speed a claim.
Common errors that void subscription claims
Not declaring integrations is the single biggest error when underwriting subscription models. Other frequent issues are short indemnity periods and thinking defence costs equal fines. Also avoid assuming standard BI covers long customer recovery phases.
Typical exclusions to watch
Exclusions often list vendor outages, voluntary shutdowns and contractual disputes. Policies commonly exclude fines under UK GDPR but may cover defence costs. Retroactive date exclusions can deny cover for incidents predating the policy.
Steps to avoid a rejected claim
Disclose all payment providers, cloud hosts and auth services to the broker. Keep written evidence of PCI status, DPO reports and incident logs. Retain copies of contracts showing who bears liability for outages.
Contact a broker experienced in subscription models to request a tailored endorsement and a quote that names your payment providers.
Frequently asked questions
Does standard business interruption cover lost subscription income?
Standard BI often uses "turnover" not "subscription income". If the policy does not name recurring revenue, a claim can be lower than expected. Ask for an endorsement that replaces "turnover" with "recurring subscription revenue".
How do insurers calculate lost MRR payments?
Insurers use declared MRR, churn and an indemnity period to calculate loss. They adjust for seasonal variation and mitigation steps such as manual billing. Provide 12 months of monthly MRR to make their model accurate.
Are regulatory fines covered under UK policies?
Most policies exclude regulatory fines but may pay defence costs. Underwriters often provide limited regulatory defence cover for ICO investigations. Keep DPO records and prompt notification processes to reduce fine risk.
What evidence do insurers need for a gateway outage?
Insurers require provider outage notices, timestamps and your re-billing attempts. Screenshots, ticket IDs and email chains form the primary evidence set. Record all customer communications during the outage to show mitigation.
How long do claims typically take to settle?
Initial insurer acknowledgement is usually within 24 to 72 hours of notification. Full settlement follows forensic reports and can take four to twelve weeks. Keep a claims folder to speed up the adjuster’s review.
How large a limit should an SME buy?
Buy a limit covering immediate lost MRR plus churn and incident costs. A common formula is (MRR × indemnity months) + churn uplift + fixed incident costs. Use the calculator below to estimate a starting limit.
Practical benchmarks help translate MRR and churn into an insured limit and indemnity period that reflect customer lifecycle and recovery time.
A simple rule of thumb is to choose indemnity months that mirror how long customers typically take to notice, cancel and be re-acquired: high-churn consumer subscriptions (>5% monthly churn) commonly require 3 months
healthy B2B SaaS with 1–3% monthly churn typically need 6 months
enterprise or contract-based models with annual renewals often require 9–12 months
Use a starting limit formula: (MRR × indemnity months) + (MRR × expected churn uplift) + fixed incident costs (forensics, PR, manual rebilling). For excesses, many SMEs pick one month’s MRR or a percentage of the annual limit to balance premium and cash-flow exposure. When requesting recurring revenue insurance, ask underwriters what underwriting churn rate they will apply and stress-test the quote with a 10–30% churn uplift to see how limits and premiums move.
What to do next
Step 1: pull 12 months of MRR, monthly churn and ARPU and save them as PDF. Step 2: list every payment provider, billing SaaS and cloud host with contract dates. Step 3: ask your broker for a subscription revenue endorsement and an indemnity period test quote.
Simple calculator and example
Inputs: MRR, indemnity_months, churn_uplift_percent, fixed_incident_costs
Formula: limit = (MRR * indemnity_months) + (MRR * churn_uplift_percent) + fixed_incident_costs
Example: MRR=10000, months=6, churn=0.30, fixed=25000
limit = (100006) + (10000 0.30) + 25000 = 60000 + 3000 + 25000 = 88000
Endorsement clause template
Endorsement: The policy is amended to include "recurring subscription revenue" within the definition of insured revenue. This covers loss of subscription income arising from direct or indirect failure, compromise or unavailability of the insured's billing, authorisation or subscription management systems, and named payment processors listed in the schedule.
Member notification email template
Subject: Important update about your subscription
Hello [Member name],
We experienced a billing issue affecting renewals on [date]. We are identifying affected accounts and will ensure you do not lose service. Expect a follow up by [date]. If you have questions contact [support email].
Regards,
[Company]
Incident response checklist for member
Immediately isolate affected systems and preserve logs.
Engage IR retainer or forensic team within 24 hours.
Notify the DPO and prepare ICO notice if personal data likely leads to risk.
Draft member communications and PR lines within 48 hours.
Start customer retention offers and manual billing where possible.
This plan does not apply if the business does not control billing, does not process member data, and the platform provider accepts liability for outages in contract. In that case rely on the provider's insurance and SLAs instead of this checklist.
1
Declare MRR, list gateways and attach PCI evidence.
2
Choose indemnity months that match probable customer recovery.
3
Request an endorsement naming "recurring subscription revenue".
4
Buy IR retainer and PR support to reduce churn risk.
References and legal points
Insurance Act 2015, Data Protection Act 2018 and Payment Services Regulations 2017 set duties affecting disclosure and claims. National Cyber Security Centre and Information Commissioner's Office provide guidance on incident reporting and mitigation. See ICO guidance on personal data breaches: ICO breach guidance and NCSC advice: NCSC .