When switching cyber insurers, choose prior acts wording that matches your firm's cyber history. Full prior acts can protect events before the switch. A stated retroactive date limits cover to later events. Cover from inception starts only with the new policy.
Switching insurers need not remove protection for past events. The new policy must keep the right claims-made dates and terms. Check the schedule for its retroactive date or prior acts wording. Disclose known incidents before you switch.
Match your cyber history to the right cover
A retroactive date is the earliest date an insurer may consider a cyber event. Prior acts cover may include events before the new policy starts. The claim must still meet the policy terms.
A claims-made policy works like a postbox with a closing time. The insurer needs the claim or notice within its policy period. The event itself may have happened earlier.
The five dates and exclusions to compare
A pending or prior date often relates to earlier claims, court cases, or notified matters. A known circumstances exclusion can remove cover for facts known before the new policy began.
- Old policy expiry: The last day the existing insurer can receive a claim or notification.
- New policy inception: The first day the replacement insurer is on risk.
- Retroactive or prior acts date: The earliest date an underlying event may have happened.
- Pending or prior date: A separate boundary for earlier disputes, claims, or proceedings.
- Notification deadline: The time and method required to report a claim or circumstance.
Keep evidence of every renewal
Keep schedules, endorsements, proposal answers, insurer emails, and claims notices. Keep them while you retain relevant data and contract records. Historic unauthorised access may first be discovered years later.
A former cloud account can create this problem. Archived files may still hold personal data. The error most firms make here is relying on a renewal email rather than retaining the relevant policy documents.
Prior acts and a stated retroactive date are not the same thing. Prior acts is an insurer's agreement to consider earlier qualifying events. A retroactive date is the cut-off for those events.
Events before that date fall outside cover. This applies even if the claim arrives during the new policy period. Full prior acts may have no stated retroactive date.
The schedule and endorsements decide what cover actually applies.
Long data histories usually need full prior acts
Full prior acts is often the strongest choice for an established England-based SME. It suits firms holding years of customer, staff, payment, or supplier data. It remains subject to exclusions and declared facts.
Choose full prior acts if old information still exists. Also choose it where legacy systems remain connected. Long contracts can also create delayed claim risks.
This can include outsourced IT, payroll platforms, customer databases, and cloud storage. Changing suppliers does not erase old cyber exposure.
Check every insuring clause
A policy may apply prior acts to cyber liability only. Response costs, ransomware cover, and business interruption may have different rules. Ask whether the date applies to every relevant section.
Check data breach liability and regulatory investigation costs as well. Do not assume one clause covers the whole policy.
For an SME with a long digital record, full prior acts cover is usually the safer starting point. It works only if the new insurer accepts the declared history. It also fails where a prior-knowledge exclusion applies. Compare old and new schedules line by line before cancelling.
A full prior acts promise is useful only when every relevant section carries it. The next choice explains when a fixed date can be reasonable.
Use a stated retroactive date only with proof
A stated retroactive date can suit a firm with a clear historic risk break. Examples include destroyed old records or a fully evidenced system replacement. A separate new trading operation may also qualify.
The proof matters more than the date itself. Keep records showing when data was deleted and systems were replaced. An insurer may test those facts after a claim.
A practical choice comparison
| Wording choice | Best fit | Historic risk left outside | Premium effect |
|---|
| Full prior acts | Established firm with retained data and older contracts | Known or excluded matters | Often highest |
| Stated retroactive date | Documented data or system boundary | Events before that stated date | Often mid-range |
| Cover from inception | New venture with no meaningful earlier exposure | Almost all pre-policy events | Often lowest |
Inception-only cover has narrow uses
Cover from inception normally does not look back before its start date. It may suit a genuinely new business. That business needs no inherited data, systems, contracts, or earlier operations.
A new Companies House registration alone proves very little. Directors may bring old systems or client data into the new company.
How historic cover changes when you switch
Full prior acts
Earlier events may qualify.
Fixed date
Only events after that date qualify.
From inception
Earlier events usually stay outside cover.
Known incidents and missed notification deadlines can still prevent cover under every option.
The practical conclusion is clear. Full prior acts is usually safest for firms with retained data. A fixed date can work where a real boundary is documented. Inception-only cover suits only a new venture without inherited exposure. Check each policy section, because historic wording can differ between liability and response costs.
Useful for this topicA plain-English cyber security book can help a director ask better questions before completing an insurer proposal form.
- It can help identify old systems and cloud accounts holding personal data.
- It explains common ransomware and phishing routes relevant to insurance disclosures.
- It can support clearer talks with outsourced IT providers before renewal.
Find on Amazon
Report suspected incidents before changing insurer
A suspected breach known before switching may need reporting to the existing insurer. This can apply before a customer claim or ICO contact. A new insurer may exclude that known circumstance.
It may also exclude later claims arising from it. This is often the most costly switching mistake.
What may be a notifiable circumstance?
Examples include unexplained data exports and ransomware indicators. They also include phishing account compromise, supplier alerts, and failed backups after intrusion. A data-subject complaint or ICO contact may also count.
Read the old policy definition of “circumstance”. It can be wider than a formal legal claim.
Run-off cover, also called an extended reporting period, can allow later claims or notices. It relates to acts that happened before policy expiry. It can matter after closure, sale, or a gap in replacement cover.
Consider three common switching cases. Ransomware may enter before the switch but stay hidden until later. Full prior acts may help if nobody knew about it.
A former cloud account may reveal historic unauthorised access after renewal. That can lead to breach liability and response costs years later.
A managed service provider's earlier failure may trigger a customer claim. It may also prompt an ICO enquiry under UK GDPR. Check when the event happened and when it became known.
The next check prevents a good quote becoming a poor policy.
Check the final schedule before cancelling
Compare the issued schedule and endorsements with the expiring policy. Do not compare only price or a sales summary. Confirm dates, limits, excesses, territory, supplier terms, and exclusions.
The final schedule is the document most likely to control the outcome. Ask for unclear wording in writing.
Use this switching checklist
- Confirm no lapse exists between old expiry and new inception, including the time of day.
- Record old and new retroactive, continuity, and pending or prior dates.
- Check prior acts for liability, response costs, ransomware, and business interruption.
- Compare aggregate limits, sub-limits, and excesses with client contract needs.
- Check territory and jurisdiction wording for UK, European, and global customers.
- Notify the old insurer about any known or suspected circumstance before expiry.
- Save the schedule, endorsements, proposal form, and notice acknowledgement together.
Test supplier and procurement wording
Procurement teams in London and across England often ask for cyber liability limits. They may also ask for UK GDPR support. They can require cover that extends to service providers.
Match those requests against contractual liability wording. Check exclusions for unapproved or unmanaged suppliers.
This guidance is less relevant for occurrence-based cover. It also matters less for a first policy without historic exposure. A known incident already handled by the existing insurer needs separate advice. This is not broker, insurer, or legal advice for a live incident.
Before asking for terms, send your broker both schedules and every relevant endorsement. Ask them to confirm historic cover in writing.
FAQs
Does switching cyber insurers reset prior acts?
Switching does not reset prior acts if the new policy clearly preserves suitable historic cover. Matching renewal dates alone do not prove continuity.
What is a retroactive date in cyber insurance?
A retroactive date is the earliest date an underlying cyber event may qualify for cover. The claim must also meet notification and policy terms.
Is a continuity date the same as a retroactive date?
A continuity date is not always the same as a retroactive date. Each may have a different meaning in the schedule or endorsements.
Can a ransomware attack before renewal be covered?
A pre-renewal ransomware event may be covered by the old insurer if correctly notified. The new insurer may exclude it if you knew about it before inception.
Do I need full prior acts cover for a new company?
A new company needs full prior acts only where it has inherited data, systems, contracts, or historic exposure. Incorporation alone does not decide this.
Can an ICO complaint count as a known circumstance?
An ICO complaint can count as a known circumstance under the policy definition. Notify the current insurer promptly and keep its acknowledgement.
Is a broker email enough to confirm cyber cover?
A broker email is not enough if it conflicts with the insurer-issued schedule. Ask for the relevant clause and endorsement in writing.
When should I buy run-off or tail cover?
Run-off cover may help after closure, sale, or a gap in replacement cover. It rarely fixes a known matter that required earlier notification.
A safer renewal decision in five checks
The safest renewal choice matches your real digital past. It is not always the lowest annual premium. Treat the final schedule as the controlling document.
Keep a clear record of every disclosure and notification. This gives your firm evidence if a later claim raises questions.
- The essentials: Full prior acts often suits firms with older data, systems, or contracts.
- The essentials: A stated retroactive date needs a genuine, documented risk boundary.
- The essentials: Notify suspected incidents before expiry, even without a formal claim.
- The essentials: Compare dates, exclusions, limits, excesses, and supplier wording before cancellation.
For your next comparison, review cyber limits and excesses. Then check ransomware and business interruption sub-limits for a UK SME claim.
Learn more
Here are some additional resources on this subject: