Could a single breach or DDoS shut the checkout and wipe out weeks of sales? Shop owners face lost revenue, forensic bills, ransom demands, ICO exposure and customer claims. A clear, quantified approach helps replace lost gross profit and brief a broker fast.
Liability vs Losses: Choosing limits for Online Shops. For UK online shops, balance first‑party cover to replace lost online revenue for a 3–12 month recovery. Then choose third‑party liability limits to cover legal defence, ICO exposure and customer claims. A practical starting range is £250k–£2m depending on annual online revenue, payment volume and contractual exposure.
Liability vs First‑Party losses: what they cover
Choose first‑party cover to replace revenue for a chosen period. The aim is to cover lost gross profit and fixed recovery costs. Choose third‑party cover to meet customer or partner claims and regulatory exposure after a breach.
What first‑party cover replaces
First‑party cover pays for direct business losses and recovery costs. For example business interruption, ransom negotiation, forensic costs, data restoration and notification. Online shops lose revenue when checkout or fulfilment fails. First‑party cover can pay faster for simple interruption and forensic invoices.
Payment timing depends on prompt detection, clear incident records and insurer approval. Ransom payments and complex multi‑jurisdiction breaches often need insurer pre‑approval. Pre‑approval can delay payment in some cases.
Measure first‑party need with monthly online revenue, average order value and gross margin. Use the rule: first‑party = (monthly online revenue × gross margin × chosen months) + fixed recovery costs. Multiply monthly gross profit by 3, 6 or 12 months and add fixed recovery costs like forensics and PR.
Check sublimits for ransom, notification and PR to ensure adequate cover.
Short pause to digest the figures.
What third‑party pays and how to estimate exposure
Third‑party cover protects against claims by customers or partners. It includes legal defence costs, settlements and sometimes regulatory investigations. Some policies exclude ICO fines, so always check the wording.
Estimate third‑party exposure by counting affected customers or records and an estimated cost per claim. Multiply records at risk by likely remediation cost per customer. Then add realistic defence costs and a regulator buffer.
Example quantified comparison
Example: monthly revenue £50k, margin 30% and six months indemnity gives a first‑party need of £90,000. The calculation is £50,000 × 0.30 × 6 = £90,000. Add recovery costs on top of that.
The same shop with 10,000 customer records at risk and an average remediation cost of £200 suggests third‑party exposure near £2,000,000. That figure excludes defence and regulatory costs.
Which UK online shops need higher limits and why
Shops with high monthly revenue, many customers or heavy contract terms need higher limits. Shops that process many card payments or run marketplaces face higher third‑party and PCI risk. This section maps common profiles to cover needs.
Low‑volume direct shops
Shops under £10k monthly sales face smaller revenue risk but still face breach costs. Recommended first‑party indemnity is 3 months of gross profit plus recovery costs. Typical third‑party limit band is £250k–£500k for legal defence and small claims.
Mid‑size growing shops
Shops with £10k–£50k monthly sales need wider cover for fulfilment and brand repair. Choose 6 months indemnity as a default and third‑party limits of £500k–£1m. Include notification and PR sublimits in calculations.
Shops over £50k monthly sales need 6–12 months indemnity and higher liability limits. Recommended third‑party limits start at £1m and rise to £2m or more for contractually liable marketplaces. Verify vendor and gateway contract clauses.
Step‑by‑step calculator method to choose limits
Follow five clear steps to produce numbers to brief a broker. Each step uses measurable inputs and gives a single first‑party figure and a recommended third‑party band.
Gather monthly online revenue, average order value, average orders per day and gross margin. Add monthly hosting, subscription and fulfilment fixed costs. These numbers must be recent and verifiable.
Step 2: choose an indemnity period
Pick 3, 6, 9 or 12 months for recovery based on tech stack and supply chain. Complex platforms need 6–12 months. Simple shops often manage with 3 months.
Step 3: calculate first‑party sum
First‑party sum = monthly online revenue × months × gross margin. Add estimated recovery costs: forensic, PR, notification, developer overtime and expedited shipping. Round up by 10–20% as a buffer.
Step 4: calculate third‑party band
Estimate customer claims from affected records and likely claim cost per customer. Add legal defence estimate and regulator buffer. Choose a band that covers settlement plus defence costs.
Step 5: cross‑check policy sublimits
Request the insurer's schedule of sublimits and aggregate limits. If ransom or notification sublimits fall below calculated need, increase headline limits or negotiate sublimit lift. Do not accept low sublimits for critical costs.
Deliverable to broker
Provide one page with inputs, chosen months and current controls—include exact monthly revenue, AOV, orders/day, margin, backup cadence, MFA status and PCI compliance—so brokers can get comparable quotes quickly and speed quote turnaround.
Recommended limits by revenue and order volume
Use the table below to pick a starting band and then tailor it with the calculator. The table maps monthly revenue bands to suggested first‑party indemnity months and third‑party limits.
| Monthly online revenue |
Avg orders/day |
Suggested indemnity (months) |
First‑party limit example |
Suggested third‑party limit |
| Under £10k |
Under 50 |
3 |
£9k–£30k |
£250k–£500k |
| £10k–£50k |
50–300 |
6 |
£18k–£90k |
£500k–£1m |
| £50k–£200k |
300–1,200 |
6–12 |
£90k–£720k |
£1m–£2m |
| Over £200k |
1,200+ |
9–12 |
Bespoke (£500k+) |
£2m+ |
How to pick within a band
Pick the higher band when order velocity or fulfilment complexity is high. High AOV or many international shipments increase recovery time. Use the calculator to get a precise first‑party figure.
Comparative table: cover lines
Insurers often advertise a headline limit but apply sublimits that bite. The table below shows common cover lines, typical sublimits and what to watch for.
| Cover line |
Typical headline |
Common sublimits |
Red flags |
| Ransom / extortion |
Included in first‑party |
£50k–£250k |
Payment excluded or separate approval needed |
| Notification & credit monitoring |
Part of first‑party |
£10k–£100k |
Per‑claim limits or per‑year caps |
| Regulatory defence & fines |
Part of third‑party |
Fines often excluded |
Fines excluded without clear limit for defence costs |
| PR / reputation |
Optional add‑on |
£2k–£50k |
Low cap compared to potential brand damage |
Real UK incident cost examples for online shops
The following anonymised examples show typical cost breakdowns for different events. They help translate limits into likely payouts.
Case: ransomware hit for a 10‑person shop
Shop lost access to order management for five days, blocking fulfilment. Recovery costs: forensic £25k, negotiations £10k, developer overtime £15k, lost gross profit £75k. Total first‑party cost ≈ £125k. Third‑party exposure was minimal.
Case: data breach and legal claims for a small shop
Customer payment data leaked through a misconfigured store plug‑in. Notification and credit monitoring £18k, legal defence £40k, settlement costs £60k. Total third‑party and related first‑party costs ≈ £118k.
Case: payment fraud and chargebacks for a shop
Fraudulent transactions rose after credential stuffing attack. Chargebacks £32k, fraud remediation £8k, PR and customer refunds £12k. Total ≈ £52k. Potential regulatory interest depends on PCI posture.
How premiums change with limits and controls
Insurers price limits against controls and claim history. Demonstrable controls reduce premium and allow higher limits. This section gives practical control‑to‑premium guidance.
Controls that reduce premium most
Multi‑factor authentication, tested backups and PCI DSS compliance matter most. Insurers ask for evidence like backup test logs, MFA rollout proof and recent pen test reports. Present these at quote stage to obtain better bands.
Typical premium trade‑offs
Doubling limits often increases premium by 20–100% depending on controls. Adding MFA and tested backups can cut premium by a noticeable percent. Discuss excess level adjustments with a broker.
Practical nuance on controls and evidence
The error most frequent at quote stage is assuming controls are equal across insurers. Different insurers accept different evidence for the same control. Many guides say having controls is enough. What many do not mention is that insurers score and weight each control differently.
The evidence shows insurers care about tested backups and MFA most. The National Cyber Security Centre has published small business guidance that highlights MFA and backups as priority controls. See NCSC guidance.
First‑party cover is practical for most online shops when limits tie to revenue and chosen recovery months. It works well only if sublimits do not cap important costs. Pair a calculated first‑party number with a third‑party band that reflects contractual and regulatory risk.
Practical letter and email templates for notification
Include ready‑to‑use templates to notify customers and vendors after discovery. Use them to speed legal and PR action and to meet regulator deadlines.
Customer notification email template
Use this short template to inform affected customers quickly.
Subject: Important information about your data held by [Shop Name]
Dear [Customer name],
We recently discovered an incident that may have affected your personal information held by [Shop Name]. We have contained the incident and started an investigation. We will update you with recommended next steps within [X days]. For questions call [phone] or email [address].
Sincerely,
[Shop Name] Data Response Team
Vendor notification brief
Use this to tell payment, marketplace or hosting vendors about an incident.
To: [Vendor contact]
Subject: Incident notification – potential impact on services for [Shop Name]
This notice is to report a security incident discovered on [date]. Current impact: [brief]. Actions taken: [contained, backups activated, forensics engaged]. Please confirm whether this affects your services and any steps you require. Contact: [Name, role, phone].
Policy traps and exclusions to watch closely
Insurers may reject or limit claims for reasons not visible in the headline wording. Avoid choosing limits without reading schedules and endorsements. The following items cause the most problems.
Retroactive dates and prior acts
Some policies exclude incidents before a retroactive date. If the shop lacks historical coverage, the insurer might refuse related claims. Confirm the retroactive date and any prior act exclusions.
Aggregate limits and single event caps
Annual aggregate limits may let one event consume the year’s cover. Check for per‑event limits and reinstatement options. Ask whether a major cyber event could exhaust cover.
Fines and regulatory exclusions
Many policies exclude fines and penalties even when they cover defence costs. The ICO guidance requires reporting within 72 hours when feasible. Defence costs can mount rapidly, so confirm whether fines are covered or excluded.
When a shop relies on third‑party platforms you must confirm whether losses belong to the provider or to the shop. Request the provider’s insurance certificate and check limits, retroactive date and per‑event wording. Consider a contractual clause such as:
"Vendor shall maintain cyber insurance with a minimum limit of £1,000,000 per claim, provide a copy of the insurer's certificate within 10 days of request, notify the Shop within 48 hours of any incident likely to affect services, and indemnify the Shop for losses caused by Vendor negligence or security failures."
Also verify that contingent business interruption triggers are explicit and that subcontractor flow‑downs exist for critical suppliers. Where gaps remain, require the vendor to increase insurance or procure contingent BI cover for the Shop.
One‑page brief to give a broker
This one‑page brief speeds quoting and reduces misunderstandings.
Shop name: [Shop Ltd]
Monthly online revenue: £[amount]
Average order value: £[amount]
Average orders/day: [number]
Gross margin: [percent]
Desired indemnity months: [3/6/9/12]
Controls: MFA [yes/no], backups tested [date], PCI DSS [yes/no]
Key vendors: [Shopify/Stripe/PayPal/Hosting]
Preferred third‑party limit: £[band]
Preferred first‑party limit: £[amount]
If unsure, brief a cyber broker with the one‑page metrics above to get tailored quotes quickly.
A short brief often gets faster, clearer quotes.
What to do next
Set a short plan to decide limits before renewal. Start by running the calculator steps with current monthly revenue and margin. Then gather evidence of controls, pick an indemnity period and prepare the one‑page brief for a broker.
Run the calculator with current numbers. Produce first‑party figures for 3, 6 and 12 months and pick a preferred band. Send the one‑page brief to two brokers and request schedules of sublimits and any exclusions.
Final checks before signing
Confirm ransom, notification and PR sublimits are adequate. Check retroactive date and aggregate limits. Ensure contract clauses with marketplaces and payment gateways do not force unlimited indemnity.
This guidance does not apply when a marketplace or payment provider has contractually assumed and visibly insured the cyber risk for the shop, or when a broker has already produced a bespoke limit calculation based on audited revenue and contract terms.
Frequently asked questions
What first‑party cover should a small online shop buy?
For most small shops buy 3–6 months indemnity and cover for forensic costs. Then add notification and PR sublimits that match expected needs. Use monthly revenue and margin to calculate a precise figure and check sublimits before accepting a quote.
Do cyber policies cover ICO fines?
Many policies exclude fines; some cover defence costs only. Check policy wording carefully for fines and regulatory penalties. If fines are excluded, ensure legal defence cover is sufficient to handle investigations.
How do sublimits affect headline limits?
Sublimits can reduce usable cover for specific costs like ransom or notification. Always request the schedule of sublimits and any per‑claim caps. A high headline limit with low sublimits can leave critical gaps.
How long does a typical e‑commerce recovery take?
Recovery often takes 3–12 months depending on complexity. Simple website issues may clear in days. Complex data recovery, regulatory processes and reputational repairs can stretch to a year.
What counts as a ransom payment under a policy?