Could a cloud outage or ransomware attack halt trading for days?
Could it breach client contracts and expose the business to costly third-party claims?
Many small UK firms assume standard cyber cover protects them from supplier failures.
Policy wordings, aggregation exposure and sublimits often leave gaps that appear only after an incident.
Key variables that decide endorsement outcomes
The most important variable is whether cover is named or blanket for cloud providers.
Named-provider cover lets insurers quantify aggregation risk and set appropriate limits.
Underwriting controls are the second variable.
Brokers and underwriters expect proof of MFA, backup tests, patching cadence and SOC/ISO reports.
Sublimit structure and subrogation terms are the third variable.
A low supplier sublimit can leave most losses unpaid despite a wide main limit.
Check policies early to avoid last-minute problems.
Named vs blanket provider cover
Named-provider cover limits insurer aggregation exposure for major platforms like AWS, Azure and GCP.
Insurers often accept named cover with lower uplifts than blanket cover.
A citable fact: insurers commonly require naming of large cloud platforms to assess systemic risk.
This lets the insurer set a clear sublimit and pricing.
Negotiate to name only the vendors material to the SME’s operation.
Broad, undefined language increases premium and the chance of declinature.
Required underwriting controls
Insurers rely on documented controls more than promises.
Give SOC 2 or ISO 27001 certificates, MFA screenshots, backup test logs and patch reports.
The error most frequent at renewal is sending only vendor marketing links rather than evidence.
Underwriters reject marketing claims and ask for concrete logs.
Keep a single evidence pack for renewal with dated screenshots.
This speeds underwriting and helps avoid surprise declinature.
Gather vendor evidence at least 30 days before renewal.
Sublimits, retentions and subrogation
A supplier outage sublimit may sit separately from the policy limit.
This can reduce recoverable amounts for a single incident.
Sublimits for vendor outage often range from £50,000 to several million pounds.
This depends on insurer appetite and vendor controls.
Insurers sometimes insist on subrogation rights against the vendor.
Seek a waiver where the vendor accepts contractual liability and holds adequate insurance.
- Insurers price vendor endorsements on aggregation exposure, vendor criticality and the quality of documented controls.
- Translate these factors into numbers to help procurement and finance budget.
- A well controlled SME (SOC 2/ISO, enforced MFA, quarterly DR tests) can expect vendor endorsements to add 5–15% to base cyber premium.
- They may also raise supplier-related deductibles by about £5k–£25k.
- For mid-risk firms that rely on a single platform for core operations, uplifts often sit between 15–35%.
- Retentions can rise to £25k–£100k.
- High-aggregation profiles can see uplifts of 35–60%.
- To budget, run a simple scenario.
- If base annual premium is £10,000, a 20% uplift equals £2,000 extra.
- If a supplier sublimit of £250,000 applies, compare that to probable business interruption exposure.
- Consider buying higher limits or ask the vendor to contribute insurance.
When a policy change matters for the SME buyer
This section explains which SME situations need explicit vendor endorsements.
Each paragraph stands alone for quick reading.
If the SME relies on cloud services for revenue, an endorsement is essential.
Without it, supplier failures may be excluded or capped.
If the SME has strict SLA indemnities to customers, insurers must confirm they will pay those contractual liabilities.
Get this in the wording.
If the SME operates in regulated sectors, ensure endorsements address regulatory notification costs and fines coverage where lawful.
Check ICO and NIS obligations.
Focus on the cover that matches your contracts.
SaaS product with embedded customer data
SaaS providers hosting customer data create both first-party and third-party exposures.
Policy wording must cover both types of loss.
A common omission is that policies cover the SaaS company’s system but not downstream customer liabilities.
This gap appears when the vendor fails.
Add contractual liability endorsements.
Insurer evidence usually includes data residency details, data flow maps and retention schedules.
Show these when customer data is central to the service.
Cloud vendor used for backups and DR
If the vendor holds backups or provides disaster recovery, insurers want proof of successful restoration tests and encryption standards.
Show test dates and results.
This works well in theory, but in practice many firms cannot find dated restore reports.
Keep those documents ready to present to insurers.
A simple clause in the endorsement can tie cover to tested backup evidence.
This avoids vague promises in an SLA.
When the vendor integrates with customer systems, a failure can cascade across clients.
Underwriters treat these cases as aggregation risks.
Expect tighter limits, higher uplifts or requirement to name the platform.
Decide whether to accept a higher premium or seek stronger vendor controls.
An anonymous case: a mid-size reseller saw a single API failure cause five clients to miss payroll.
The reseller had no vendor endorsement and recoveries were limited by a low sublimit.
Errors and warnings when seeking vendor endorsements
Do not assume standard cyber policies cover supplier outages.
Read the wording and ask for explicit endorsement language.
Many buyers rely only on a supplier SLA.
The insurer may require policy wording that matches contractual indemnities.
Another common error is failing to document controls.
Without dated evidence, insurers may price endorsements out of reach or decline them.
Get insurer confirmation in writing before you sign contracts.
Beware silent cyber and ambiguity
Policies can be silent on cloud vendor risk and leave interpretation to the claims stage.
Clarify cover before renewal.
A citable rule: Insurance Act 2015 requires fair presentation of risk at inception and renewal.
Give honest, complete vendor evidence.
Ask the broker to obtain explicit insurer confirmation in writing for any SLA-linked indemnity before signing agreements with vendors.
Aggregation and systemic exposure
Insurers worry about one cloud outage affecting many insureds simultaneously.
This concern pushes prices up for blanket endorsements.
To control this, insurers prefer named-vendor limits and may apply aggregate caps per event across insured portfolios.
If the SME’s vendor is a major cloud platform, consider risk sharing.
Negotiate vendor insurance obligations and evidence to present to the insurer.

Practical endorsement text and clause redlines to use now
Below are ready-to-paste examples that the SME can send to a broker, insurer or vendor legal team.
Edit amounts and names as needed.
Policy endorsement template
Endorsement: Vendor Named Cover
It is agreed that notwithstanding any provision to the contrary, this Policy shall respond to loss arising from interruption of or interference with the Insured’s business caused by outage or security failure of the Named Cloud Vendor(s) listed below, where such outage or failure directly causes a Business Interruption loss to the Insured.
Named Cloud Vendors: [AWS, Microsoft Azure, Google Cloud Platform, Other]
Vendor Outage Sublimit: £[amount] any one loss or series of losses arising from the same event.
Ransomware/Extortion: This Policy shall cover ransomware extortion and incident response costs where the extortion arises from a security failure of a Named Cloud Vendor.
Subrogation: The Insurer waives rights of subrogation against the Named Cloud Vendor where the Insured holds a contractual indemnity from the vendor in respect of the same loss.
Evidence Condition: Coverage subject to provision of evidence as declared to the Insurer, including SOC 2/ISO certificates, MFA screenshots, and backup/restore test reports.
Contract redline to insert in SLA
Supplier shall maintain cyber insurance with limits and vendor coverage equivalent to those required by the Customer. Supplier will name the Customer as an interested party and provide a copy of the insurance policy and certificate on request.
Supplier shall indemnify Customer for direct financial losses caused by Supplier outage up to £[cap], and Supplier agrees that such losses shall be covered by Supplier’s cyber insurance where applicable.
Supplier will notify Customer of cyber incidents affecting Customer data within 24 hours and preserve relevant logs for forensic review for at least 90 days.
Negotiation pointers for legal and procurement teams
- Ask the broker to get insurer agreement to the exact policy text before signing the SLA. Keep the text identical in both documents.
- Aim for named vendor cover with a clear sublimit and waiver of subrogation tied to vendor contractual indemnity.
- Require vendor to provide dated evidence: SOC 2 report, ISO 27001 certificate, MFA screenshots, backup restore logs and incident response contact details.
Sample evidence to collect now: dated SOC 2/ISO reports (last 12 months), screenshots proving MFA is enforced, backup restore test logs showing successful restore within the vendor RTO, and the vendor’s incident response plan with named contacts.
Comparative table of insurer approaches
| Insurer |
Illustrative sublimit |
Named vs blanket |
Typical uplift |
Evidence required |
| Hiscox (example) |
£100k–£1m |
Prefers named |
5–25% |
SOC 2, backups, MFA screenshots |
| Beazley (example) |
£250k–£5m |
Named or segmented blanket |
10–40% |
ISO27001, incident plan, vendor list |
| AIG/Allianz/Chubb (market examples) |
£50k–£5m |
Named preferred |
Varies widely |
Detailed vendor evidence, appetite review |
Note: the above figures are illustrative ranges to start negotiation. Obtain firm quotes through brokers such as Marsh, Aon or Willis Towers Watson.
Simple decision flow
How to decide on a vendor endorsement
1. Identify vendor criticality
Revenue impact, data held, customer SLAs
2. Gather evidence
SOC2, MFA screenshots, backup logs
3. Ask broker for named endorsement
Get sublimit, uplift and waiver details
4. Insert SLA redlines
Align contract and policy text
How GDPR, NIS and regulatory costs fit the endorsement
Regulatory notification and fine exposures can be triggered by vendor incidents.
Confirm whether the policy covers regulatory costs where permitted by law.
A citable source is that the ICO and NCSC publish guidance on reporting breaches.
Insurers often expect notification costs to be covered separately from fines.
See NCSC for incident guidance.
Data point: the ICO recorded over 40,000 breach reports in one year.
This shows that incident response planning is vital for SMEs.
Give dated evidence of incident readiness to insurers.
Interaction with fines and penalties
Policies differ on cover for regulatory fines and penalties.
Some UK policies exclude fines, unless the endorsement explicitly permits them where lawful.
Ensure the endorsement language states whether the insurer will pay defence costs, notification costs and regulatory penalties.
Also confirm if this is permitted under UK law.
Legal teams should review endorsements against the Data Protection Act 2018 and the UK GDPR to confirm permitted coverage.
Cross-border data and transfer issues
If vendor servers sit outside the EEA, insurers will want to know about data transfer arrangements.
They ask for legal bases such as SCCs or adequacy decisions.
Some insurers restrict cover where transfers breach data protection rules.
Give documentation of transfer mechanisms and vendor compliance.
Ask the broker whether the insurer applies territorial exclusions for data stored in specific jurisdictions.
Underwriting and enforceability of endorsements vary by jurisdiction and should shape both policy wording and contract clauses.
In the UK, insurers commonly accept coverage for notification and defence costs.
They may exclude monetary fines unless the endorsement specifically permits them where lawful.
Insurers will scrutinise alignment with the Data Protection Act 2018 and UK GDPR.
In the EU, underwriters often apply strict territorial or transfer exclusions where SCCs or adequacy decisions are not in place.
An insurer may decline cover for losses caused by transfers that breach EU data rules.
In the US market, state laws and the treatment of civil penalties differ.
Some carriers are more willing to offer broader contractual liability coverage.
They may impose different sublimits or higher retentions.
Endorsements should declare territorial scope and reference the legal basis for transfers, such as SCCs or adequacy.
They should state whether regulatory fines, notification costs and defence fees are insured in each jurisdiction where data is processed or stored.
Checklist: steps a cloud vendor can take
-
Obtain SOC 2 Type II or ISO 27001 and share the latest report with customers and brokers.
-
Enforce MFA and keep dated screenshots proving policy enforcement for critical accounts.
-
Run quarterly backup restore tests and keep logs showing successful restores within RTO.
-
Keep a one-page incident response summary showing escalation contacts and test dates.
-
Agree contractual indemnities and provide evidence of supplier insurance with named interested parties.
-
Share a vendor security pack for client brokers to attach to renewals.
Exceptions: This guidance does not apply when an SME sits under a bespoke group insurance programme that centrally covers supplier risk, when the cloud provider is the SME itself, or when a sole trader uses a free consumer cloud service with minimal dependency.
To check whether a proposed endorsement covers a specific SLA clause, present the exact policy wording and vendor evidence to a broker.
Ask the broker for a written position from the insurer.
This avoids unwelcome surprises at claim stage.
A vendor-facing, step-by-step qualification roadmap speeds underwriting and reduces uplift.
- Day 0–30: identify critical services and assign a security lead.
- Collect the latest SOC 2 Type II or ISO 27001 report and assemble a one-page vendor security summary.
- Day 31–60: enable and document MFA for all admin and cloud consoles.
- Capture screenshots with timestamps.
- Complete a full backup restore test with dated logs and show RTO and RPO achieved.
- Run an authenticated vulnerability scan with a remediation plan showing patch windows (eg critical patches within 7 days, high within 30).
- Day 61–90: implement endpoint detection on management workstations and publish an incident response contact list.
- Provide evidence of encryption at rest and in transit.
- Present this evidence pack to your customers’ brokers at least 60 days before renewal.
- Meeting these milestones typically moves a submission from a mid/high uplift band to a low uplift band.
- It can also reduce insurer requests for higher sublimits or added retentions.
The action plan
Start with three actions.
Assemble vendor evidence, ask the broker for a named-vendor endorsement draft, and insert matching SLA redlines.
Each step reduces the chance of uncovered loss and speeds underwriting.
Collect SOC 2 or ISO reports, MFA screenshots, backup restore logs and an incident response summary within 14 days.
Present that pack to the broker at least 30 days before renewal.
Ask the insurer to provide the exact policy endorsement in writing before signing contracts.
This ensures the SLA and policy align and claims do not fail on wording differences.
Frequently asked questions
What specifically should a cloud vendor ask for?
The endorsement should name the vendor, specify the supplier outage sublimit, confirm ransomware and incident response cover, and include any subrogation waivers. Insurers must agree to the exact wording in writing for it to be reliable.
Provide the endorsement text to the broker and ask for insurer confirmation in the renewal terms. Keep the wording identical in both the policy and the SLA.
How much does a vendor endorsement typically add
Typical uplifts vary by control quality: well‑controlled firms can expect 5–15%, mid-risk firms 15–35%, and high-aggregation profiles 35–60%.