Are customers' card payments a constant worry? Many small retailers and microbusinesses lack confidence about whether a cyber policy will respond if a physical till is tampered with or an online order turns out to be a card‑not‑present (CNP) fraud. This guide clarifies Retail POS & card‑not‑present fraud cover in plain British English, with practical examples, likely exclusions, claim steps and realistic ways to reduce premium costs.
Key takeaways: what to know in one minute
- Retail POS & card‑not‑present fraud cover protects different losses: in‑store POS compromise (skimming, malware, terminal tamper) is treated differently to CNP fraud (unauthorised online card use).
- Policies often include response and liability elements: forensics, legal costs, card re‑issuance, chargebacks and sometimes customer notification costs are typical elements.
- Sublimits and exclusions are common: fraud/chargeback sublimits, social engineering exclusions and inadequate PCI compliance frequently limit recovery.
- Insurers grade risk by controls: use of EMV/3DS, PCI DSS compliance and Payment Service Provider (PSP) contracts materially affect underwriting and premium.
- Claims need clear evidence: transaction logs, terminal logs, CCTV, PSP correspondence and bank chargeback records accelerate settlement.
Understanding retail POS and card-not-present fraud cover
Retail POS & card‑not‑present fraud cover is the part of a cyber or combined policy that addresses losses from payment‑related compromises. For UK SMEs, two distinct scenarios recur:
- In‑store POS compromise: a physical terminal is tampered with (skimmer), infected with POS malware, or a rogue employee manipulates transactions. Losses include direct theft, chargebacks, forensic costs and reputation management.
- Card‑not‑present (CNP) fraud: online or telephone payments processed without the card physically present; fraudsters use stolen card details to make purchases. Losses include chargebacks, lost goods, card re‑issuance costs and investigation expenses.
Although grouped under 'payment fraud', these scenarios have different causes, evidence requirements and policy wordings. Retailers reliant on terminal operators or third‑party PSPs should map responsibilities: banks/PSPs may accept liability for unauthorised transactions in some cases, but insurers expect the policyholder to show reasonable security measures.
Legal and regulatory context matters. For breach reporting and data protection issues, refer to the ICO breach guidance. For security advice and mitigations, the NCSC publishes business‑oriented guidance. PCI DSS remains the industry standard for card security: see pcisecuritystandards.org.
What typical cyber policies include for POS breaches
A typical UK SME cyber policy that includes retail POS and CNP exposure will combine the following coverage elements. Wording varies by insurer; the list below shows common inclusions and illustrative limits that can appear as indicative figures in 2026 policies.
- First‑party incident response: forensic IT investigation, containment and remediation costs. Many policies pay until a stated sublimit (e.g. £25,000–£100,000) depending on turnover and risk.
- Third‑party liability and regulatory defence: legal costs and fines or regulatory action (GDPR fines are often excluded, but legal defence costs may be insured). Policies often clarify interaction with ICO reporting requirements.
- Chargeback and bank dispute costs: reimbursements for chargebacks where the merchant is held liable. Insurers may apply a fraud/chargeback sublimit (common ranges: £10,000–£50,000 for small SMEs) and may exclude losses resulting from poor card acceptance practices.
- Card re‑issuance and customer notification costs: costs to notify affected cardholders and to re‑issue cards where the merchant is contractually required to pay.
- Business interruption and loss of income: cover for revenue lost while systems are restored; many policies require proof of causation and apply indemnity periods.
- Cyber extortion (if related to POS malware or system compromise): ransom and negotiation costs, but payments may be restricted by sanctions checks.
Examples and realistic scenarios
- A high street cafe finds a card terminal infected with skimming hardware. Forensic investigation costs £8,200, 120 disputed transactions total £6,400 in chargebacks and the insurer reimburses for the investigation and chargebacks subject to the policy sublimit and excess.
- An online retailer suffers CNP fraud after a credential stuffing attack. The PSP refunds affected cardholders but charges the merchant for chargebacks; the cyber policy may cover the chargeback costs if the policy wording includes CNP fraud cover and the merchant can show they had reasonable authentication controls.
How insurers assess card-not-present payment fraud risk
Insurers underwrite payment fraud risk using a mix of quantitative and qualitative factors. Key underwriting considerations include:
- Transaction mix and volumes: high CNP transaction rates or large average order values increase exposure.
- Payment controls in place: adoption of 3D Secure (3DS), tokenisation, EMV for in‑store and strong password/2FA for merchant accounts reduce rating.
- PSP agreements and liability split: whether the merchant or PSP bears chargeback liability.
- PCI DSS status and evidence of remediation: many insurers ask for PCI status or completion of a vulnerability scan.
- History of prior incidents: frequency and severity of previous fraud or breaches.
- Physical controls for POS: CCTV, tamper‑evident seals on tills, staff access controls.
Underwriting typically requests a short questionnaire covering these elements and may apply endorsements or limitations. Insurers will often require risk improvements as a condition of cover or to avoid higher premiums.
Exclusions and limits for retail POS fraud cover
Understanding typical exclusions prevents unexpected claim denials. Key exclusions and limits to check:
- Social engineering / authorised push payment (APP) exclusions: many policies exclude loss caused by deception that convinces staff to authorise payments, unless a specific extension is purchased.
- Intentional or criminal acts by directors: acts by senior personnel may be excluded.
- Failure to maintain basic security: inadequate patching, no MFA, or knowingly failing PCI obligations can be grounds for refusal.
- Sublimits for fraud/chargebacks: policies may cap payment fraud reimbursements at a lower figure than the overall policy limit.
- Card scheme fines or interchange fees: not always covered.
- Reluctance to cover offline or legacy terminals: older POS models with known vulnerabilities may be excluded.
Typical policy wording traps to watch
- “Loss resulting from the transfer of funds as a result of social engineering” – this often excludes scenarios where an employee is tricked into sending refunds or providing credentials.
- “Direct financial loss due to unauthorised use of payment card details” – could be interpreted narrowly; clarify whether this includes chargebacks for goods/services and the cost of investigation.
- Retroactive date clauses and prior acts: ensure there is no retroactive exclusion for known compromises.
Evidence and claims process after a POS fraud incident
Claims for retail POS and CNP fraud depend heavily on documentary and technical evidence. Prompt action and organised records increase the chance of a positive outcome.
- Contact the acquiring bank or PSP immediately to suspend affected terminals or merchant accounts.
- Preserve logs: terminal logs, POS application logs, transaction records and timestamps. Do not overwrite or power‑cycle devices if instructed by the insurer or forensic team.
- Gather CCTV footage, till receipts, batch reports and staff shift rotas for the period in question.
- Record communications with customers, banks and PSPs about chargebacks or disputed transactions.
- Report relevant personal data breaches to the ICO when required: see ICO guidance.
What insurers commonly ask for in a claim
- Detailed chronology of the incident and remedial actions taken.
- Bank statements and chargeback documentation showing disputed transactions.
- Copies of the merchant‑PSP contract and terminal provider agreements.
- Evidence of security controls (PCI attestation, 3DS logs, EMV usage stats) and proof of any vulnerabilities addressed.
How long claims take and common delays
Claims involving POS compromises often take longer because of forensic investigations and chargeback processing cycles. Typical delays arise from:
- Slow bank/PSP response to chargeback investigations.
- Missing or overwritten logs from POS terminals.
- Disputes over whether the loss is due to merchant negligence or a covered criminal act.
A clear, well‑documented claim with early insurer contact usually speeds resolution.
Buying tips: reduce premiums for POS and card-not-present cover
Insurers reward demonstrable controls. Actions that frequently reduce premiums or improve terms:
- Implement 3DS and tokenisation for online payments; adopt EMV chip and contactless for in‑store.
- Maintain up‑to‑date PCI DSS attestation or an external vulnerability scan report.
- Use reputable PSPs with robust dispute handling and liability protections in writing.
- Apply network segmentation: keep POS systems separate from guest Wi‑Fi and back‑office networks.
- Enable strong logging and retain logs for at least 90 days; ensure automatic backups.
- Train staff on refund procedures and social engineering indicators; keep clear approval levels for refunds.
Risk reduction checklist that insurers like to see
- Up‑to‑date patching for POS software and terminals.
- MFA for merchant portals and remote access.
- Tamper‑evident seals on devices and CCTV covering terminal points.
- Written PSP/terminal provider SLAs showing liability split.
Comparative table: typical coverage differences for in‑store POS and CNP fraud
| Coverage item |
In‑store POS compromise |
Card‑not‑present (online) fraud |
| Forensic investigation |
Often included (sublimit £25k–£100k) |
Often included (similar sublimit) |
| Chargebacks/merchant liability |
Covered subject to sublimit and excess |
Covered if policy includes CNP extension; may have specific sublimit |
| Social engineering loss |
Frequently excluded |
Frequently excluded unless endorsed |
| Business interruption |
Possible if systems directly affect trading |
Possible if payments stopped and loss is proven |
| Customer notification costs |
Included where personal data exposed |
Included where cardholder data impacted |
| Requirement for PSP/PCI evidence |
High |
High |
Advantages, risks and common mistakes
✅ Benefits and when this cover helps
- Direct reimbursement for chargebacks and investigation costs reduces cashflow strain.
- Access to specialist forensics and legal support speeds recovery and regulatory compliance.
- Insurance can transfer part of the operational risk of payment fraud when contracts and controls are in place.
⚠️ Common mistakes to avoid
- Assuming all payment fraud is covered without checking exclusions and sublimits.
- Failing to preserve evidence: overwriting logs or neglecting CCTV will frustrate a claim.
- Not reading PSP/merchant agreements: liability may sit with the merchant even if a policy exists.
- Ignoring PCI and 3DS: insurers may decline or restrict cover where basic controls are absent.
Process timeline (simple flow)
Step 1 → Step 2 → ✅ Outcome
- Step 1: detect suspicious transactions → notify bank/PSP and suspend terminals
- Step 2: preserve evidence → contact insurer and appoint forensic team
- Outcome: investigation, chargeback resolution, reimbursement subject to terms
Claims process at a glance
1️⃣
Contact bank/PSP
Block terminals/accounts; record reference numbers
2️⃣
Preserve evidence
Logs, CCTV, receipts, staff rotas
3️⃣
Notify insurer
Provide incident chronology and paperwork
4️⃣
Forensic & chargeback response
Insurer appoints or approves experts
5️⃣
Settlement & remediation
Claim paid subject to terms; implement controls
Frequently asked questions
What is covered by retail POS fraud cover?
Cover usually includes forensic costs, chargebacks, customer notification and sometimes business interruption; exact cover depends on the policy wording and any fraud sublimits.
Will insurers pay for chargebacks from online card-not-present fraud?
Insurers may reimburse chargebacks if the policy includes CNP cover and the merchant can show reasonable authentication and controls; sublimits and excesses often apply.
Does PCI DSS compliance guarantee cover?
Compliance helps underwriting and reduces the chance of refusal, but it does not guarantee cover. Insurers will still review circumstances and controls at claim time.
Are social engineering losses covered?
Many policies exclude social engineering or APP losses unless a specific extension is purchased; check wording carefully.
What evidence speeds a POS fraud claim?
Terminal logs, transaction records, batch reports, CCTV, PSP correspondence and bank chargeback documentation are essential.
How long does a POS fraud claim take to settle?
Duration varies: simple forensic-led claims may resolve in weeks, but chargeback cycles and regulator enquiries can extend timelines to months.
Can small retailers lower premiums quickly?
Yes, implementing 3DS, tokenisation, EMV, network segmentation and documented staff training are among the most effective measures.
Next steps
- Review merchant contracts and PSP liability clauses to confirm who bears chargeback risk.
- Document current payment controls (PCI status, 3DS usage, EMV adoption) and store logs centrally for at least 90 days.
- Contact insurers with a precise losses/turnover profile and request explicit wording on fraud sublimits and social engineering exclusions.