A breach at your payment provider can stop online sales and trigger chargebacks. It can also create card-data duties, even if your own systems were not hacked.
The key question is where responsibility sits between your business, the gateway, acquirer and technology suppliers. Cyber insurance may help with response costs, customer notices, legal support and covered lost income.
It will not automatically cover every provider-related loss. Check supplier wording, PCI DSS costs, fraud exclusions, chargeback exclusions and contractual liability.
Prepare a practical 24, 48 and 72-hour response plan.
Payment processor cover depends on supplier wording
Cover depends on whether the processor is a covered third-party provider. It also depends on whether the loss fits an insured clause.
A malicious breach at a payment service provider can stop online checkout or card terminals. If cover includes contingent business interruption, it may pay for lost income.
This cover means lost income caused by a key supplier's insured cyber event. Think of it like cover for a closed road outside your shop.
Waiting periods commonly run between 6 and 24 hours. A short afternoon outage may fall below the excess period.
Cover should be based on gross profit, not all card takings. Gross profit is money left after direct costs, such as stock and card-processing fees.
A retailer may take £2,000 per hour but retain £700 gross profit. That retailer should normally insure the £700 exposure, plus response costs.
A retailer is not automatically insured because its processor was breached. Downtime is most likely to be covered where wording includes outsourced providers. The event must meet the policy's cyber incident definition. The loss must also exceed any waiting period and excess.
A payment service provider breach is not the only event that can stop retail takings. Ransomware at a processor can prevent payment authorisations.
A compromised gateway network can also stop payments. An attack on a hosting supplier may block checkout without taking cardholder data.
Retail cyber insurance should separate malicious security events from ordinary technology failure. Supplier cyber cover often requires an insured cyber incident as the direct cause.
Ask if response and gross-profit cover extend to a payment processor outage. Ask if ransomware is expressly covered.
Also ask if one shared sub-limit applies to online and in-store terminal failures.
Retailers can still owe duties after a provider breach
A provider's failure does not remove your UK data-protection duties. Your business may still need to assess the breach and inform people.
The parties in a payment chain
| Party | Usual role | Retailer exposure after a breach | Document to check |
|---|
| Retailer | Merchant and often data controller | Customer communication, sales loss, ICO duties | Cyber policy and privacy notice |
| Payment service provider | Processes transactions | Contractual recovery may be capped | Merchant agreement |
| Acquirer | Accepts card payments for the merchant | Card-scheme rules and assessments | Acquiring terms |
| Gateway or host | Connects or hosts checkout | Checkout outage and supplier dependency | Service-level agreement |
Card data and PCI DSS duties
PCI DSS means Payment Card Industry Data Security Standard. It sets security rules for businesses handling cardholder data.
It applies when a business stores, processes or sends cardholder data. The Payment Card Industry Security Standards Council maintains the standard.
Your acquirer may enforce PCI DSS through your merchant agreement. That agreement can set duties beyond your cyber policy.
ICO notification needs a fast decision
A personal data breach may need reporting to the Information Commissioner's Office within 72 hours. This applies where the breach risks people's rights and freedoms.
The ICO expects organisations to assess facts promptly. It does not expect them to wait for perfect certainty.
You may also need to tell customers where the risk to them is high. The processor's alert is evidence, but it is not your full assessment.
Claims split across response, cards and lost income
A cyber policy can pay different payment-breach losses. Each loss may have its own limit, excess and trigger.
Response costs often start first
Forensic investigation finds how the incident happened and what data was affected. Cyber policies may pay for approved forensic investigators and solicitors.
They may also pay for breach notices, call-centre support and public-relations advice. Data restoration may also be covered.
Insurers often require a call to their incident line before you hire experts. Urgent action may be allowed where it prevents further harm.
The most frequent mistake is appointing an IT firm before calling the insurer. That can make payment harder, even where the breach itself is covered.
Card-scheme costs need express cover
PCI DSS assessments, card-scheme charges and card reissue costs are separate losses. Fraudulent transactions and chargebacks are also separate.
A chargeback reverses a card payment after a cardholder dispute. A card-scheme assessment is a charge within the payment chain after a card-data incident.
Ask if payment card industry assessments are expressly insured. Ask whether a sub-limit applies.
A £1 million headline limit can contain a lower PCI-related sub-limit. That sub-limit may sit between £25,000 and £100,000.
Never assume a general privacy claim clause pays all card-scheme losses.
How a payment-breach claim usually moves
1. Detect
Processor alert or failed payments
2. Preserve
Keep logs and sales evidence
3. Notify
Insurer, advisers, ICO if required
4. Recover
Restore payments and evidence loss
Cyber insurance can help retailers that depend on card or online payments. Meaningful cover needs more than a large headline limit.
Confirm supplier cover, non-malicious outage treatment, PCI DSS sub-limits and waiting periods in writing. If your processor stores all card data, exposure may be lower.
Lost sales, customer data, website compromise and contract costs can still leave a serious gap.
Set cover limits from sales and recovery time
Set the limit from the cost of losing payments during your busiest realistic trading period. Use gross profit rather than total sales.
Model 24, 72 and 168-hour outages
Test a 24-hour outage, a 72-hour outage and a seven-day outage. Use the busiest trading week, not only an annual average.
Christmas, bank holidays, sale events and weekend footfall can change the result. One lost day may equal several normal weekdays.
For each channel, multiply average hourly gross profit by likely lost hours. Reduce the result only where customers can genuinely use another payment route.
Cash, bank transfer or a backup provider may reduce loss. A shopper leaving the queue is not deferred income if they buy elsewhere.
Add response and card exposure
Add legal support, forensic work and customer contact costs. Include temporary terminals, overtime, public relations and likely PCI DSS investigation costs.
For a small retailer, response bills can range between £10,000 and £50,000. These bills can arise before a long trading interruption.
A retailer with many online customers may need a higher allowance. The same applies where customer accounts are stored.
Check the indemnity period
The indemnity period is the time when an insurer may measure insured lost income. Think of it as the claim's measuring window.
Three months may suit a brief gateway failure. It may not suit ransomware affecting stock systems and payments.
Check whether the period starts on the outage date. Check whether it includes time needed to regain normal sales.
Exclusions can defeat a payment-breach claim
Key gaps often involve non-malicious failure, weak controls and dishonest acts. Cyber war and undefined suppliers can also create gaps.
Security controls must match reality
Policies may require multi-factor authentication, timely patching and backups. They may also require restricted admin access and PCI DSS compliance.
Multi-factor authentication uses two proofs of identity. A password and phone code are a common example.
If your proposal says it is used everywhere, that must be true. An unprotected administrator account makes a dispute more likely.
This works well in theory, but practice often differs. A forgotten admin account can matter more than a written security policy.
Contracts can shift losses back to you
Processor terms often cap liability at recent fees paid. Your lost sales may be much higher.
They may exclude indirect loss, lost profit and reputational harm. They may also exclude third-party claims.
A cyber policy may pay some of those costs. A contractual liability exclusion may restrict cover where you accepted wider responsibility.
Use a 72-hour plan and compare protections
A payment-breach plan should protect evidence and cashflow before liability arguments begin. Fast records make both recovery and claims easier.
First 24 hours: contain and record
- Notify the insurer or broker through the cyber incident route. Ask before appointing forensic or legal suppliers.
- Ask the processor, gateway and acquirer for written facts. Request affected services, data exposure, start time and restoration estimates.
- Preserve terminal logs, website logs and payment reports. Keep failed-order records and customer messages.
- Keep affected systems available for evidence where safe. Do not wipe them before forensic advice.
Between 24 and 48 hours: assess harm
- Use legal and forensic advice to identify exposed personal data. Also check card data and credentials.
- Start a loss log for gross profit, refunds and extra staff hours. Include temporary payment costs.
- Check whether the acquirer requires a PCI DSS forensic investigation. Check if it requires card-scheme notice.
- Review the processor agreement for notice deadlines and liability caps. Check its cooperation duties too.
Between 48 and 72 hours: notify carefully
- Assess whether an ICO report is required within the UK GDPR's 72-hour window.
- Prepare customer messages with known facts and practical safety steps. Give customers a contact route.
- Record why you did or did not notify each body. Include the ICO, customers, card schemes and insurers.
- Check National Cyber Security Centre advice for technical containment. Keep insurer-approved experts involved.
| Protection | Most relevant loss | Common limit or restriction |
|---|
| Cyber insurance | Response, privacy liability, covered outage | Supplier wording, waiting period, sub-limits |
| Crime or fidelity insurance | Theft, staff dishonesty, some payment fraud | May exclude processor system failure |
| Processor contract | Provider's breach of contract | Fee-based liability cap and excluded lost profit |
| Professional indemnity | Claims about professional advice | Usually not retailer payment interruption |
This cover is less relevant if your business accepts neither card nor online payments. It is also less relevant where external payment technology is not needed. It is not a substitute for urgent incident response. If a breach is suspected, follow the processor's procedure and preserve evidence. Seek legal, technical and insurer notification support rather than waiting to research insurance.
FAQs
Does cyber insurance cover a payment processor breach?
It may cover response costs and covered lost income. The wording must include the processor or outsourced provider.
The event must meet the policy trigger. Check whether malicious breaches, non-malicious outages and PCI DSS costs differ.
Can cyber insurance pay GDPR fines in England?
It is not guaranteed. Payment depends on policy wording, legal insurability and the Information Commissioner's Office action.
Response and legal costs may be covered separately. The incident facts will also matter.
How long do I have to report a data breach?
An ICO report may be required within 72 hours of awareness. The breach must be a qualifying personal data breach.
Your cyber policy may require notice sooner. Call the incident line immediately.
Are chargebacks covered by cyber insurance?
Sometimes, but chargebacks may have separate exclusions or sub-limits. Fraudulent transactions and card-scheme assessments may also be treated separately.
Ask for written confirmation of the payment-card section. Do not rely on a general data-breach benefit.
How much cyber insurance does a small retailer need?
Start with gross profit lost over 24, 72 and 168 hours. Then add response, legal and card-exposure costs.
Many SMEs review limits between £250,000 and £1 million. A high-volume online retailer may need more after peak-day modelling.
What should I do if my payment provider says it has been breached?
Notify your insurer and preserve logs and payment records. Request written facts from the processor, gateway and acquirer.
Do not wipe systems or promise customer compensation before legal advice. This matters most during the first 72 hours.
Will my processor repay lost sales after a breach?
Usually not in full. Processor contracts often cap liability at fees paid over a set period.
They also often exclude lost profit. Read the service-level agreement and indemnity clause first.
Learn more
Here are some additional resources on this subject: