Is the till really just a till? For a small shop using an EPOS system, the answer is no: the till is a gateway to card payments, customer data and supply-chain systems. A problem with an EPOS setup can quickly become a costly data breach, payment disruption or regulatory headache.
This practical analysis explains what cyber insurance typically covers for retailers with EPOS, how GDPR and PCI requirements change insurer expectations, how to choose sensible limits for payment-related disruption, and what small shops can do now to reduce premium surprises and claims refusals.
Retailers with EPOS explained in one minute
- Core idea: Small shops using EPOS face combined risks from payment processing, customer data and third-party integrations; cyber insurance can transfer some financial risk while not replacing basic security controls.
- Typical covers to expect: data breach response, legal costs, regulatory fines (limited), business interruption for payment downtime, forensic costs and optional social engineering cover.
- Why it matters: a single EPOS compromise can stop card payments, damage reputation and trigger ICO involvement under GDPR.
- Quick action: document EPOS provider security, retain supplier contracts, and collect transaction backups—insurers often ask for these after enquiry.
- Bottom line: Cyber insurance is useful for EPOS retailers but depends on wording, limits and documented security controls.
Do small retailers with EPOS need cyber insurance?
Small retailers are not legally required to hold cyber insurance, but many find it useful. The decision often depends on exposure and appetite for risk.
Why it matters
- EPOS systems often store or transmit personal data and payment-related information. A compromise can mean forensic costs, notification expenses and business interruption.
- Regulatory exposure under the UK GDPR or Data Protection Act can create legal and compliance costs; the Information Commissioner's Office (ICO) can investigate breaches affecting customer data.
When insurance can help
- Where the EPOS connects to online inventory, card terminals, or cloud services that the retailer relies upon for revenue continuity.
- Where third-party payment processors are central; policies can cover contractual liabilities or costs to restore services.
Common mistakes
- Assuming a standard business insurance policy covers cyber events. Many property or business insurance policies exclude cyber perils or have limited cover for electronic data.
- Believing insurer cover applies regardless of poor controls. Failure to follow basic security measures (patched EPOS, unique admin passwords, no default logins) can lead to declined claims.
Practical implication
- For most small shops using EPOS, a tailored microbusiness cyber policy or a cyber add-on is often appropriate, provided required security minimums are met and documented.
How EPOS, card terminals and GDPR affect cover
EPOS systems and card terminals intersect with several regulatory and insurer concerns.
PCI DSS and cardholder data
Payment Card Industry Data Security Standard (PCI DSS) applies to how cardholder data is stored, processed and transmitted. While PCI compliance is enforced by card schemes and acquirers rather than the ICO, failure to meet PCI can influence insurer decisions and claims handling.
- Insurers commonly ask whether EPOS and card terminals meet PCI requirements or are 'PCI compliant' via the payment provider.
- If a compromise occurs due to an insecure terminal or direct storage of PAN (primary account number), insurers may limit cover or apply sub-limits for payment card liabilities.
Authoritative source: PCI Security Standards Council.
GDPR, personal data and fines
Personal data stored by EPOS (names, email addresses, loyalty data) is subject to the UK GDPR. The ICO can impose fines or enforcement action; however, many cyber policies do not cover statutory regulatory fines in full.
- Policies vary: some include cover for ICO investigations and defence costs, others exclude or cap regulatory fines. Any regulatory cover is often conditional on the insured having followed reasonable security measures.
- Insurers will typically ask about data retention, data minimisation and whether customer data is encrypted in transit and at rest.
Relevant resource: Information Commissioner's Office.
Card terminals, ownership and liability
Who owns and manages the terminal matters. Three common arrangements:
- Merchant-owned terminals: the shop controls terminals and is directly responsible for their security and updates.
- Rented or rented-and-managed terminals (from acquirer): the provider may accept responsibility for firmware and PCI compliance.
- Integrated EPOS + cloud payments: security responsibility is shared; contracts should clarify scope.
Insurer implications
- Ownership impacts cover and subrogation. If a breached terminal was out of date but managed by the acquirer, liability may sit with the provider; insurers will investigate contracts and maintenance records.
- Clear supplier contracts and evidence of updates reduce the risk of declined claims.
Choosing limits for EPOS-driven tills and payment disruption
Selecting limits requires estimating realistic financial impact from payment downtime, data breach costs and recovery.
Key cover areas to consider
- Data breach response: forensic investigation, customer notifications, credit monitoring and legal fees.
- Business interruption: lost revenue from inability to take card payments or access stock information.
- Crisis management and PR: costs to manage reputational damage.
- Social engineering and funds transfer fraud: cover for human-factor scams leading to theft.
How to approximate limits
- Calculate average daily card takings and stock turnover. Many insurers use days/hours of revenue loss when setting BI (business interruption) limits.
- Typical microbusiness cyber policies offer BI cover of 30–90 days or a monetary limit (for example £25,000–£100,000), depending on premium and risk.
- Data breach response limits are often set between £10,000 and £250,000 depending on policy tier and insurer appetite. For small shops, a common sensible band is £50,000–£150,000.
Example table: policy elements and indicative limits
| Policy feature |
Typical cover |
Why it matters |
Indicative limit |
| Data breach response |
Forensic IT, customer notification, legal fees |
Handles immediate costs after a compromise |
£25,000–£150,000 |
| Business interruption (payments) |
Lost takings while EPOS/payments unavailable |
Covers cashflow while systems restored |
30–90 days or £25,000–£100,000 |
| Social engineering / fraud |
Loss from fraudulent instructions or employee scams |
Covers human-targeted theft not via malware |
£5,000–£50,000 |
| Regulatory defence costs |
Legal defence during ICO investigation |
Helps manage fines and defence costs |
£10,000–£100,000 (often limited) |
Notes on limits
- Limits are indicative and depend on insurer wording, industry and previous claims history. Always check whether regulatory fines are covered or excluded.
- For many very small shops, modest limits aligned to average takings will be cost-effective; for higher-turnover stores, consider higher BI and breach response limits.
Comparing cyber policies for microbusinesses using EPOS
When comparing policies, focus on wording and exclusions rather than headline prices.
Checklist for comparison
- Insuring clauses: what events are explicitly covered (hacking, ransomware, social engineering, human error)?
- Exclusions: look for exclusions for card-present data loss, unapproved third-party apps, or outdated terminals.
- Conditions precedent: are certain security measures required before cover applies (patching, MFA, backups)?
- Retroactive date and prior acts: ensure the policy covers incidents discovered after inception if they occurred earlier.
- Sub-limits and aggregate limits: some policies have small sub-limits for cardholder data or PCI-related costs.
- Claims handling and panel suppliers: does the insurer use a panel for forensics/PR, and can the insured choose providers?
Common policy differences
- Ransomware cover may be optional or limited; payment of ransom is often subject to strict conditions.
- Social engineering cover is sometimes excluded or limited; verify what types of instruction fraud are covered.
- Card scheme fines are rarely covered in full; many policies exclude fines imposed by card schemes or acquirers.
Red flags when comparing
- Ambiguous definitions of "personal data" or "payment data".
- Broad exclusions for third-party failure without clear allocation of responsibility.
- Excessive evidential burdens for the insured to show controls were in place.
Claims examples: data breaches in small shop EPOS
These anonymised examples illustrate common scenarios and practical lessons.
Case 1, Malware on an EPOS terminal
- Scenario: An intergrated EPOS package had an outdated Windows-based terminal. Malware captured payment magnetic stripe data and transmitted to a remote server. Customers reported fraudulent card transactions.
- Outcome: Forensic costs, customer notification and liaison with the acquiring bank cost ~£42,000. The insurer covered forensic and notification costs but applied a small sub-limit for cardholder liabilities.
- Lesson: Keep EPOS OS and firmware updated and document maintenance. If terminals are merchant-owned, consider higher limits for card-related liabilities.
Case 2, Phishing leads to social-engineering transfer
- Scenario: A shop manager was tricked by an email from a supplier impersonator and authorised a funds transfer to a fraudulent account for stock purchase.
- Outcome: Insurer paid a proportion of the financial loss under social engineering cover after investigation; cover depended on proof of the fraud and bank recovery efforts.
- Lesson: Implement dual-authority payment controls for larger transfers and train staff to verify unusual supplier requests.
Case 3, Stolen unattended tablet (till) with unencrypted data
- Scenario: A tablet used as a mobile till was stolen from a van. The device held cached customer details and sales data without full-disk encryption.
- Outcome: The insurer paid for forensic investigation and limited notification costs. Greater losses were avoided because the payment tokens were stored off-device by the payment provider.
- Lesson: Use disk encryption and remote wipe; avoid storing PANs locally.
Practical checklist: cyber controls for EPOS retailers
Minimum controls insurers commonly expect
- Unique administrative passwords for EPOS and terminals (no defaults).
- Timely application of vendor updates and security patches.
- Network separation: guest Wi‑Fi segregated from EPOS network.
- Regular backups of sales and stock data, with offline copies.
- Multi-factor authentication (MFA) for cloud EPOS admin accounts.
- Written supplier contracts clarifying responsibility for PCI compliance.
- Incident response plan with contact details for the bank, acquirer and accountant.
What insurers commonly ask during quoting
- Evidence of patching and update schedule.
- Details of payment provider and PCI responsibility.
- Average monthly card takings and peak trading days.
- Details of previous incidents or losses.
Common errors to avoid
- Using the same login for multiple tills or for supplier interfaces.
- Allowing staff to install arbitrary apps on payment tablets.
- Not documenting maintenance or support contracts with the EPOS vendor.
EPOS security checklist at a glance
✓ Basic hygiene
Unique admin logins, regular updates, MFA on cloud accounts.
✓ Payments
Confirm PCI responsibility with acquirer; avoid storing PANs locally.
✓ Backups
Nightly encrypted backups and offline copy of sales records.
✓ Staff training
Short, recurring briefings on phishing and payment authorisation.
Balance strategic: what is gained and what is at risk with EPOS cyber insurance
✅ Scenarios of success
- Small shop with documented controls and a reputable EPOS provider reduces claim friction and receives timely forensic support.
- Shops that buy appropriate BI limits recover lost takings quickly after a payment outage.
- Businesses that combine moderate limits with good controls often see affordable premiums and rapid claim resolution.
⚠️ Red flags and failure points
- Out-of-date EPOS terminals and undocumented supplier responsibilities leading to declined claims.
- Policies with narrow definitions of "data breach" or broad exclusions for payment card liabilities.
- Reliance on insurance without basic security measures; insurers frequently refuse claims where negligence is evident.
Common questions about cyber insurance for EPOS retailers
How does cyber insurance help if a till is compromised?
Cyber insurance can pay for forensic investigation, customer notification and some business interruption costs. It does not replace required security fixes or contractual liability to payment providers.
Why do insurers ask about PCI and payment providers?
Payment security affects the likelihood and scale of cardholder data incidents. Insurers assess responsibility and may apply sub-limits if PCI obligations are not met by the provider.
What happens if a shop stores customer card details locally?
Storing PANs locally greatly increases risk and may breach PCI requirements. Insurers may reduce cover or exclude cardholder liabilities if local storage caused the breach.
Which limits are sensible for a small boutique taking mostly card payments?
Sensible banding is often a data breach response limit of £50k–£150k and BI cover equal to 30–60 days of typical card takings. Exact needs depend on turnover and margin.
Resolution times vary; forensic work and notifications can take weeks, while financial recovery or litigation may take many months. Quick reporting to insurer and acquirer speeds response.
How to prove the EPOS provider met its responsibilities?
Keep supplier contracts, maintenance logs, firmware update records and PCI attestation letters. These documents are commonly requested by insurers.
What if a customer sues after a breach involving loyalty data?
Policies that include third-party liability and legal defence costs can help. Confirm whether consumer litigation and defence are included and any sub-limits.
How does GDPR enforcement interact with insurance?
Insurance may cover defence costs for ICO investigations in some policies, but fines are often excluded or capped. Legal advice is recommended when regulatory action is possible.
Why do some insurers offer lower premiums to shops with stronger EPOS controls?
Lower risk of incident reduces expected claims. Documented patching, MFA and network segregation demonstrate reduced exposure and attract better terms.
Next steps: a three-step action plan for retailers with EPOS
Quick start checklist to act in under 10 minutes
- Verify and record the EPOS provider and payment acquirer contact details (support, PCI status). Keep copies of contracts and statements.
- Check that EPOS admin accounts use unique passwords and enable multi-factor authentication for cloud dashboards.
- Export a recent sales report and store an encrypted offline copy; note average daily card takings to inform BI limits.
Small, documented actions now make insurer conversations faster and reduce the chance of claim disputes later.
Useful resources
- Advice on incident response and cyber basics: NCSC
- ICO guidance on data breaches and notification: ICO
- PCI DSS information for merchants: PCI SSC