Actualizado en May 2026

Yes. A suitable cyber policy can cover card fraud, EPOS malware, data breaches and business interruption. Keep clear evidence ready to satisfy insurers and speed any claim.
Cyber insurance for EPOS shops: what underwriters look for
Underwriters focus on transaction volume, the EPOS vendor and the shop's security controls. These three things decide premiums and claim acceptance.
What underwriters assess
Transaction volume matters more than staff numbers. Underwriters use TPV bands such as under £50k, £50k–£250k and £250k+.
The PCI DSS standard is treated by insurers as the main benchmark for card data security.
Insurers expect evidence of network segmentation, multi-factor authentication for admin accounts, endpoint protection and backups. The most common missing item is preserved EPOS logs covering the incident period.
One clear fact for underwriters is that they usually require patch logs and an asset list to pay EPOS claims.
Every shop should prepare TPV statements and preserved logs — pause and check your evidence pack now.
Controls insurers expect
Insurers expect EPOS to run on a separate network away from staff devices. Segmentation reduces contagion risk in a simple way.
Admin accounts should use MFA to limit credential theft. MFA logs often decide a claim outcome.
Endpoint protection and logging must run on terminals and servers. Regular backups and restore tests must show success.
Shops that keep tested backups and preserved logs tend to have more successful claims and pay lower premiums.
Profile: retail shops: EPOS, TPV and controls
Retail shops range from micro outlets with simple EPOS to busy high-street stores using cloud EPOS. Underwriters treat micro and busy shops very differently.
Micro shops often have no internal IT team. Underwriting then focuses on recent patching and basic evidence.
Busy shops need clear proof of controls and vendor contracts. Insurers ask for support SLAs and PCI attestations.
Insurers may want vendor liability clauses if the EPOS is cloud-based.
Indicative premiums and drivers
If TPV is under £50k, premiums might be about £200 to £600 per year. This depends on location, claims history and insurer appetite.
If TPV exceeds £250k, premiums often start around £1,800 and can go above £5,000. Controls and past claims change those numbers.
These figures are examples only. Actual premiums vary by insurer, past claims, local risks and policy wording.
Common causes of loss and insurer expectations
Largest losses come from lost sales during EPOS downtime and chargebacks from card schemes. Location in major shopping centres can raise premiums.
For micro shops, insurers often ask for backups, patching logs and recent TPV statements before binding cover. For busy shops using cloud EPOS, underwriters expect vendor evidence and documented controls.
Useful items include till batch CSVs, merchant statements, TPV reports, patching logs, MFA logs, vendor ticket IDs and proof of tested restores.
A common error is assuming a basic business policy covers EPOS incidents automatically.
Claims pitfalls for EPOS retailers
Many claims fail because shops overwrite or delete logs before telling the insurer. That action often ends claims before they start.
Insurers also deny claims when policies exclude losses from unmaintained systems. The Insurance Act affects disclosure rules and non-disclosure can hurt claims.
Insurers check internal fraud closely. Lack of segregation of duties often leads to refusal for theft or manipulation claims.
Evidence that wins claims
Raw EPOS logs, till batch reconciliations and merchant statements link lost card transactions to lost sales. Forensic images and vendor ticket IDs add credibility.
Evidence that causes denials
Overwritten logs, late notification beyond the policy timeframe, and missing backup tests commonly cause denials. The Insurance Act requires accurate disclosure at inception and renewal.
Insurers usually request preserved EPOS transaction logs, till reconciliation files and backup restore evidence during a card-related claim. Preserving those items immediately improves the prospects of a successful claim. Acceptance still depends on policy wording, declared controls and the forensics outcome.
Many refusals hinge on precise policy wording and not on a vague exclusion. Warranties (for example, failing to apply vendor critical updates) often bar cover.
Retailers should save vendor patch logs, PCI DSS statements and contractual liability clauses. Those items help compare vendor contracts to disputed policy terms.
What policies actually cover for EPOS incidents
Policies combine first-party and third-party cover, but limits and sub-limits vary widely. The policy wording decides if EPOS downtime, PCI investigation and chargebacks are included.
First-party cover often pays forensic costs, business interruption and some cyber extortion. Third-party cover usually covers defence costs and damages to customers or suppliers.
Some policies exclude regulatory fines but cover legal defence and notification costs. The ICO and UK GDPR expect notification within 72 hours when personal data is likely lost.
First-party cover details
Forensic investigation commonly covers an approved panel firm and their report costs. Business interruption covers lost sales during the indemnity period up to the policy limit.
Ransom payments sometimes attract a sub-limit. Restoration costs for EPOS and databases normally get first-party cover if backups exist and are tested.
Third-party and regulatory cover
Third-party cover includes defence costs for client claims and settlement amounts. Some policies include PR and notification costs to reduce reputational harm.
Regulatory fines are often excluded, but legal costs to respond to regulators are usually covered. The Network and Information Systems Regulations date from 2018 and apply to some operators.
Practical buying checklist and price guidance
Buy based on transaction volume and controls, not headcount. Compare standalone cyber with add-on cover and insist on clear wording for EPOS downtime and PCI investigation.
Standalone cyber offers broader wording and higher limits than an add-on policy. An add-on may be cheaper but can carry silent cyber exclusions and lower sub-limits.
Ask insurers for paid EPOS claim examples and written confirmation of cover for card scheme investigations and chargebacks. BIBA brokers can help interpret wording.
Indicative premium ranges by TPV
- Micro shop (TPV < £50k): £200–£600 per year.
- Small shop (TPV £50k–£250k): £600–£1,800 per year.
- Medium/high shop (TPV £250k+): £1,800–£5,000 plus per year.
Price depends on TPV, EPOS vendor, insurer panel, location and controls. London and large shopping centres often attract higher rates.
Standalone vs add-on comparison
| Feature |
Standalone cyber |
Add‑on to business policy |
| Typical limits |
£250k–£5m |
£25k–£250k |
| PCI/EPOS wording |
Explicit, clearer |
Often general, may exclude |
| Price |
Higher |
Lower |
| Best for |
Shops with high TPV or cloud EPOS |
Micro shops with low TPV |
When negotiating limits and excesses for EPOS risks, present controls that reduce underwriting risk. Key items are segmentation, MFA, documented backups and restore tests.
Target excesses often track TPV. Micro shops usually seek excesses in the £250–£1,000 band to keep premiums affordable.
Small shops aim for £1,000–£2,500 excess bands. Larger operations often accept £5,000+ and trade excess for higher BI limits.
Ask insurers to split excesses so forensic costs do not share the same deductible as ransom or BI losses. Get written endorsements that name EPOS downtime, chargebacks and PCI investigation fees.
Evidence insurers require before and after incidents
Insurers ask for pre-incident proof of controls and for post-incident raw evidence. The crucial items are EPOS logs, backup records, vendor correspondence and TPV reconciliations.
Pre-incident, insurers accept PCI DSS attestation or documented compensating controls. The PCI Security Standards Council keeps guidance at PCI SSC.
Post-incident, insurers want untouched logs, CCTV clips aligned to transaction timestamps and a clear incident timeline. Do not alter or delete original files before forensic advice.
Pre‑incident file list to hold
- Latest PCI attestation or compensating control statements.
- Backup logs and restore test records.
- Patch and asset inventory for EPOS and servers.
- MFA screenshots and admin user lists.
Post‑incident items to preserve
- Raw EPOS transaction logs and till batch CSVs.
- Merchant statements and chargeback notices.
- Vendor support tickets and incident IDs.
- CCTV clips with timestamps matching suspicious transactions.
Legal deadline: notify the ICO within 72 hours if personal data loss is likely, and notify your insurer within the policy time limit, commonly 24–72 hours.
Claims: step‑by‑step practical checklist
Notify the insurer immediately in writing and keep all communications timestamped. Early notification preserves entitlement and starts the insurer's response clock.
Preserve evidence and do not power down devices without forensic advice; overwriting logs or reconnecting infected terminals causes major harm.
Engage a forensic investigator; insurers may require a panel firm and will often fund an approved specialist. Keep a running incident timeline with precise times and actions.
- Notify insurer in writing and confirm the policy notice period.
- Isolate affected terminals from the network if it is safe to do so.
- Preserve logs, merchant statements and CCTV safely offsite.
Next 72 hours actions
- Engage forensics and capture images of affected devices.
- Notify the payment processor and card schemes and log all communications.
- Prepare a loss estimate for business interruption with till totals and any staff changes.
A broker can review claim strategy and policy wording before formal submission; for example, a BIBA broker can check policy wording and limits before renewal.
Worked example: a high-street shop with TPV about £320k finds irregular tills and a ransom demand on day zero. Immediate actions were to isolate terminals, capture CCTV, export raw EPOS logs and copy merchant statements offsite.
Day one: the shop notified the insurer in writing, told the cloud EPOS provider and the payment processor, and instructed a cyber forensics firm to image devices. Day two to three: forensics confirmed point of sale malware and the shop compiled a claim pack with till CSVs, acquiring statements, backup logs, vendor ticket IDs and a timeline.
Loss calculation used average daily TPV for the indemnity period. Seven days outage equalled seven times average daily TPV plus extra costs like temporary EPOS rental, chargebacks and negotiation fees.
Submitting the packet within the insurer's notice window with intact evidence improves chances of cover for BI, forensics and chargebacks.
Real claim examples: accepted and denied
Accepted claim: ransomware encrypted a local EPOS server but the shop produced tested backup logs and a restore plan. The insurer paid for forensics, a temporary EPOS rental and seven days of lost sales.
Denied claim: a POS compromise where terminals missed a vendor patch. The policy excluded losses from failure to apply critical updates and the claim was refused.
Accepted claim: card skimming found by the bank; the shop had prompt EPOS logs and the insurer paid for PCI investigation and customer notification costs.
Lessons from paid claims
Keeping backups and recorded restore tests reduces time to reopen and raises claim acceptance rates. Most paid claims included a clear audit trail of transactions and vendor interactions.
Lessons from denials
Late notification, missing logs and breached warranties on patching or access controls are the main denial reasons. The best defence is to keep EPOS evidence offsite the moment suspicious activity appears.
EPOS claim flow and evidence needed
EPOS claim flow
1. Detect
Suspicious transactions, errors or ransom note
2. Preserve
Isolate terminals, copy logs, save CCTV clips
3. Notify
Tell insurer, processor, and record times
4. Forensics
Forensic image, report and mitigation steps
Key evidence: EPOS logs, till reconciliation CSV, merchant statements, backup logs, vendor ticket IDs, CCTV snippet.
When a recommended approach may not apply
This guidance does not apply if the shop does not process electronic payments. It also does not apply when contract terms put payment liability on a payment processor who holds insurance. Seek legal advice where contract liability is unclear or when a formal legal opinion is needed.