A single till hack, booking-system breach or GDPR fine can close a small pub or restaurant for days. Those events can cost tens of thousands and leave venues exposed to fraud, data loss and business interruption. Owners and managers of 1–50 staff often lack in-house IT and tailored cover.
Do I need cyber cover for my pub or restaurant?
If the venue processes cards, holds customer records or takes bookings online, specific cyber cover is very likely necessary. Insurers and regulators expect basic controls and will examine them during a claim.
When is cover essential?
Cover becomes essential when card transactions or online bookings form part of daily trade. If tills, EPOS or booking systems fail, takings stop and losses mount.
What risks are realistic now?
Ransomware can lock booking and till systems and force closure for days. POS compromises and supplier payment fraud are common threats to hospitality businesses.
What to check on existing policies?
Many general business policies exclude cyber or have low sub-limits for digital incidents. Always check for a named cyber endorsement that covers data breach response, forensics and POS fraud.
Keep simple logs; they will help when you make a claim.
What does a hospitality cyber policy include?
A suitable hospitality cyber policy combines first-party response for the venue and third-party liability for customers and regulators. Confirm limits and explicit wording for POS compromise, social engineering and ransomware.
What is first-party cover?
First-party cover pays costs the venue meets directly, such as forensics, notification, PR, legal fees and business interruption. Forensic costs and BI limits often drive claims.
What is third-party liability?
Third-party cover pays legal defence and settlements if customers, suppliers or regulators sue. This can include defence costs for UK GDPR breaches and related legal expenses.
Which exclusions matter for hospitality?
Watch for exclusions like acts of third parties, contractually accepted liabilities and limited cover for social engineering. The most frequent error at this point is assuming physical contents cover will also pay for digital loss.
A small local pub often pays between £150 and £600 per year. A standard restaurant typically pays between £600 and £1,500 per year. These ranges change with turnover, POS security and prior incidents.
"POS compromise extension: insurer will indemnify the insured for loss arising from unauthorised access to EPOS terminals resulting in fraudulent card transactions and chargebacks, including associated costs of customer notification and reasonable forensic investigation, subject to a sub-limit of £25,000 and an excess of £1,000."
"Social engineering / funds transfer fraud clause: cover for loss of money resulting directly from fraudulent instruction received by an employee impersonating a supplier or director, limited to £50,000 per policy period, provided that the insured can evidence written supplier payment verification protocols and staff training within the past 12 months."
"Forensic and BI wording example: insurer will pay reasonable and necessary forensic costs and business interruption losses directly resulting from a covered cyber event up to the stated forensic limit and BI limit. Forensic costs are to be agreed in advance with the insurer’s nominated responder if instructed."
Each example shows how a sub-limit, an excess and a condition (for example evidence of training or verified backups) are commonly framed. Comparing these short clauses across quotes makes differences in scope and conditionality visible when selecting pub insurance or restaurant insurance.
How much will cyber insurance cost my venue?
Expect premiums to vary by turnover, card volume and risk controls. The usual ranges are: small pubs £150–£600 pa; restaurants £600–£1,500 pa.
What raises the price?
Premiums rise when the venue has high card takings, no multi-factor authentication or no recent backups. Underwriters add surcharges for weak EPOS, online ordering and missing staff training.
What reduces the premium?
Proof of Cyber Essentials certification, recent staff training records and documented backups can reduce premium and improve terms. A tested disaster recovery plan also reassures underwriters.
Pricing example and common loading
A small pub with low card turnover and Cyber Essentials might see £150–£300 pa. A busy restaurant with online ordering and older EPOS often sees £900–£1,500 pa. Venues with prior breaches usually face a loading of several hundred pounds.
Choosing solely on price often leaves key gaps in cover that appear when claiming. A clear line by line comparison of sub-limits and exclusions shows the real differences. Insurers reward documented controls such as backups, training and Cyber Essentials. This advice helps get a quote that pays when needed, not just a low premium. Owners should ask for full wordings and forensics limits before they sign.
The recommendation is straightforward: choose a policy that reflects real exposures and ask for specific sub-limits and wordings. This works well in theory. In practice, the cheapest quote often omits POS fraud or limits forensic costs. That omission causes problems at claim time.
Underwriting rewards specific and demonstrable technical controls. For EPOS security, run tills on a segregated VLAN and disable remote administrative access. Enforce role-based accounts and multi-factor authentication for management consoles and apply vendor patches promptly. Whitelisting trusted applications reduces malware risk.
Network best practice for an SME venue includes isolating guest Wi-Fi from payment systems and using a firewall with strict POS rules. Use TLS for any API connections to booking platforms and centralise logging of EPOS and router events. Retain logs for 90 days or more.
Maintain encrypted, offline backups and test restores regularly. Modern endpoint detection on back-office terminals helps detect lateral movement. Certification such as Cyber Essentials, regular staff cyber training and simulated phishing materially lower perceived risk and commonly produce premium reductions or better sub-limits for hospitality cyber insurance.
How to pick the right policy for your venue
Pick a policy that matches the venue's exposures: POS compromise, GDPR fines, ransomware and business interruption. Use a side-by-side matrix to compare limits, sub-limits and response services.
What must the comparison include?
Compare these items for each quote: annual premium, total limit, forensic limit, BI limit, POS/cyber-crime cover, PR and credit monitoring, excess, and prior claims loading. A single comparison table clarifies differences.
Broker or direct insurer
A specialist cyber broker or a hospitality-aware broker helps interpret sub-limits and negotiate wording. Direct insurer platforms may be cheaper, but often lack tailored wording for POS and social engineering.
What mistakes to avoid when choosing?
Choosing the cheapest quote without checking sub-limits, exclusions for POS fraud or whether crisis PR is included remains the most costly mistake. Ask to see full policy wordings before buying.
| Policy level |
Annual premium |
Forensic costs limit |
POS/cyber‑crime cover |
BI waiting period |
PR & notification |
| Basic |
£150–£500 |
£5,000 |
Limited / excluded |
48 hours |
Minimal |
| Standard |
£600–£1,200 |
£25,000 |
Included |
24 hours |
Included |
| Hospitality Plus |
£1,200–£3,000 |
£75,000 |
Comprehensive |
12 hours |
Full service |
Isolate affected systems, preserve logs and evidence, and notify the insurer or broker immediately. Quick action increases the chance of an accepted claim and reduces downtime.
What to do in the first hour?
Disconnect infected EPOS terminals or segment the network while keeping evidence intact. Record what happened, who noticed it and when.
How to involve staff and suppliers?
Instruct staff not to post on social media and channel all enquiries to one spokesperson. Contact the EPOS provider and payment processor and keep a clear audit trail.
How will insurers investigate?
Insurers typically require forensic evidence, incident timelines and proof of security controls. The ICO expects notification within 72 hours for reportable breaches under UK GDPR; insurers will want documentary evidence.
Not relevant for large multi-site chains with bespoke corporate cyber programmes, for businesses where a payment provider contractually accepts all cyber liability, or when an SME already has a tailored cyber captive policy arranged by a broker.
A common error is shutting down systems without preserving logs. That destroys evidence for forensics and can harm a claim. Keep systems powered where possible and isolate, rather than wiping, to preserve data.
1
Isolate affected till or network segment
2
Preserve logs, backups and evidence
3
Notify insurer or broker and follow their instructions
4
Engage forensics and PR if advised
After the immediate technical actions, follow a clear, insurer-centred claims flow to preserve cover and speed recovery. Notify your insurer or broker by phone and in writing within 24 hours. Record the claim reference and the name of the handler. Ask for the insurer’s incident plan.
Assemble a single incident pack containing a concise timeline of events (who, what, when), EPOS and network logs, copies of any suspicious emails or payment instructions, merchant acquirer correspondence and chargeback notices. Include screenshots of ransom notes or errors, evidence of backups and retention dates, staff training records and supplier contracts. Expect to share a forensic report (often commissioned or approved by the insurer) and to provide invoices for emergency costs such as forensic fees, PR and temporary card terminals.
Note key external deadlines. ICO notification must usually be within 72 hours for reportable breaches. Many insurers expect initial notice and basic evidence within 1 to 3 days. Expect a formal forensic report within 7 to 14 days to validate BI and forensic cost claims.
Combining cyber with liability, stock and contents
Buy cyber to complement public liability, contents and stock insurance, not to duplicate cover. Clarify which policy pays for what before a claim happens.
When does contents cover apply?
Contents covers physical loss or damage to property such as tills and hardware. Contents does not usually cover data loss or business interruption caused by a cyberattack.
What does dependent business interruption mean?
Dependent BI covers loss when a supplier or payment processor fails. Venues relying on third-party booking systems should consider dependent BI endorsements.
How to avoid gaps and double recovery?
Map exposures and assign likely claim responsibility to each policy. Where overlaps exist, keep detailed sales and stock records to show which policy applies.
Real incident case studies for hospitality operators
Small hospitality incidents often start with simple failures then escalate without proper controls. The following case studies show how modest changes reduce cost and disruption.
POS compromise: micro pub example
A micro pub used an old EPOS system and suffered card skimming over weeks. Costs included chargebacks, customer notifications and lost takings totalling several thousand pounds.
Ransomware: restaurant example
A mid-sized restaurant lost bookings and till access for two days after ransomware. The insurer appointed a responder who limited downtime and negotiated recovery, but payment required proof of backups and staff training.
Supplier payment fraud example
A bar manager authorised a supplier invoice after a convincing email. Funds were diverted and the venue lost payments. The claim failed where staff training and supplier verification steps were absent.
Frequently asked questions
What does cyber insurance cover in the UK?
Standard cover includes forensic investigation, data-breach notification, legal defence, business interruption, ransomware/extortion and sometimes social engineering and POS fraud. Check policy wordings for sub-limits and exclusions.
What insurance does a restaurant need in the UK?
Core covers include public liability, employers' liability where staff exist, contents and stock, and cyber insurance where digital payments, bookings or customer data are present. Add BI where needed.
What insurance do you need for a pub?
Core covers include public liability, employers' liability, buildings or property cover, contents and stock, plus cyber cover if EPOS, guest Wi-Fi or online bookings are used.
How do I know if I need cyber insurance?
If card payments, Wi-Fi logins, online bookings or stored customer records form part of daily trade, cyber insurance is advisable. Certification and records of controls improve terms.
How quickly must I notify the ICO?
Under UK GDPR, a reportable breach should be notified to the ICO within 72 hours of becoming aware, unless the breach is unlikely to result in risk to individuals (a standing requirement under the regulation). See ICO guidance for details ICO guidance.
Can a payment provider accept all cyber liability?
Sometimes a payment provider contractually accepts liability, but this is not common for small venues. Where it exists, review the contract carefully and confirm coverage for POS compromise and chargebacks.
For a practical next step, ask a hospitality-focused broker or two insurers for full policy wordings and a side-by-side matrix showing forensic cost limits, POS cover and BI waiting periods before deciding.
What to do next
Gather these items before you seek quotes: annual turnover, monthly card takings, EPOS provider details, any prior incidents, Cyber Essentials certificate if held, and records of staff training. Having documents ready speeds underwriting and avoids last-minute surprises.
Quick buying checklist
- Prepare turnover and card volumes.
- Collect EPOS, booking and payment provider names.
- Document backups, multi-factor authentication and staff training dates.
What to ask a broker or insurer
- Ask for full policy wordings and confirm POS and social engineering coverage.
- Ask about incident response providers and whether the insurer permits an independent forensic firm.
If a claim happens
Notify your insurer immediately, preserve evidence, and follow the insurer's incident plan. Keep all receipts and maintain a clear timeline of events for the adjuster.