A client has just sent over a service agreement for a new website build, with hosting, maintenance and GDPR wording tucked into the same contract. You spot a warranty promising secure systems, prompt incident reporting and uninterrupted service. The work looks straightforward, but one missed clause could turn a routine project into a liability you never planned for.
Insurance and contractual warranties are not the same thing. Insurance helps cover certain losses from incidents such as data breaches, phishing attacks and forensic costs, while a warranty is a promise in a client contract that can create liability if you fail to meet it. For web and digital agencies, the safest approach is often to compare both side by side before signing.
Cyber insurance vs warranty: the fast answer
Cyber insurance helps pay for certain losses after a cyber incident, while a contractual warranty sets out what you promise a client in the contract. If the promise is wider than the policy, the gap sits with your agency. That is where many small agencies get caught.
A warranty can widen your risk far beyond a normal cyber claim, and it can sit outside professional indemnity insurance, which is why people who manage websites, hosting or campaigns should not treat all cover as the same. The real test is not whether you have a policy. The real test is whether the policy still responds after you sign the contract.
If your agency stores client logins, runs hosting, or promises uptime, the contract can create a larger loss than the cyber event itself. Think of the policy as a safety net, and the warranty as the rope you agreed to carry.
With over 12 years of experience helping UK small and medium-sized businesses navigate the world of cyber insurance, this author is passionate about guiding companies through complex risks and protection strategies. I have seen a small London agency sign a broad uptime warranty and then face a claim after a supplier outage.
The cyber policy helped with response costs, but not with the contract claim for service failure. What changed was the final bill: the gap sat in the warranty, not the breach.
Cyber insurance usually helps with costs caused by a covered incident. That can include incident response, forensic review, data recovery, notification costs, and some third-party claims. In some cases it also helps with business interruption, which means lost income after a covered event stops normal work.
The policy is weaker when the loss comes from a promise you chose to make in a contract. That matters because many agency contracts include SLA language, indemnities, or security promises that are wider than the basic policy form. The National Cyber Security Centre keeps stressing simple controls such as MFA and patching, but controls alone do not stop a contract claim if you promised more than you can safely deliver.
For a web agency, the difference becomes much clearer when you compare the tools side by side in practice. Cyber insurance is designed to respond to a cyber incident such as a data breach, phishing attack or server compromise, so it may fund incident response, forensic review, data recovery and notification costs. A contractual warranty is different: it is a promise in the service agreement, such as guaranteed uptime, fixed patching times or compliance with a service level agreement. If the project fails because of a breach, the policy may help; if it fails because you promised more than you can deliver, the warranty can shift the loss back to your agency.
That is why the right answer is often not one or the other, but a clear split between technical risk, contract risk and the limits of professional indemnity insurance.
Quick comparison for agency owners
Use the table below before you sign a new agreement, renew an old one, or change your hosting or maintenance scope.
| Option |
Typical annual cost |
Main trigger |
Usual gap |
Best use case |
| Cyber insurance |
Often from about £300 to £2,500 for many UK SMEs, depending on turnover, data type and controls |
Data breach, phishing, ransomware, recovery costs |
Contractual penalties, assumed liabilities, some SLA breaches |
Agencies handling client data or hosting services |
| Contractual warranty |
No direct premium, but it can raise expected claim costs by thousands or far more |
Failure to meet a written promise in the contract |
May sit outside cyber cover and sometimes outside PI cover |
Only when you can match the promise to real controls and limits |
| Both together |
Usually the cheapest sensible answer when contracts are broad |
Incident plus contract claim |
Still limited by wording, excess, and policy cap |
Web, hosting and digital agencies with client data and SLAs |
A simple matrix helps agencies avoid expensive surprises. Use cyber insurance for incident-driven losses such as recovery after a data breach, business interruption, notification costs and third-party claims. Use a contractual warranty only when the wording is narrow, realistic and backed by controls you actually operate, such as a defined maintenance contract or documented website hosting process. Avoid warranties that create exposure for contract errors, late delivery, SLA penalties or responsibilities you have accepted through an indemnity clause.
If the client wants broader protection, the safer route is often to combine cyber cover with a capped warranty and a careful review of the GDPR wording, so the policy, contract and operational reality all line up.
What a warranty makes you promise
A contractual warranty is a promise written into your client agreement. If you break it, the client can say you failed your word and claim the loss tied to that failure. That is different from a normal cyber claim, which usually starts with an incident such as a breach or attack.
For agencies, the risky promises are often simple and buried in service schedules. They can include uptime, patching, backup frequency, data retention, response times, access control, or compliance with a named standard. Once you sign, that wording can matter more than the label on your policy.
What cyber insurance usually covers
Cyber insurance usually covers the cost of responding to a covered event, not every loss a client can imagine. For a small agency, that often means forensic work, incident response, legal help, notification letters, and some data recovery costs. Many policies also include some cover for third-party liability, which means claims from other people who say they were harmed.
Some insurers also offer help with business interruption after a covered event. That can matter when a ransomware event or server issue stops delivery and causes lost income. The Information Commissioner’s Office is clear that UK GDPR duties still apply after an incident, so the response path matters as much as the claim itself.
Cyber insurance often excludes or limits losses caused by promises you made in a contract. That can include contractual penalties, indemnities, and in some cases fines or amounts you agreed to pay under an SLA. It may also limit cover where the loss comes from a purely commercial dispute rather than a cyber event.
This is where people get caught. A policy can look broad on a summary page and still fail on the exact clause that matters. The wording around “assumed liability” is especially important, because it can remove cover for duties you took on voluntarily.
Where agencies get caught in real life
The real risk for web and digital agencies is not one thing. It is the mix of hosting, development, maintenance, media spend, and client data. Each service creates a different kind of claim, and the contract can shift that claim into a place your policy does not like.
A hosting failure may look like an IT issue, but if you promised uptime in the contract, it becomes a legal one. A campaign error may look like a simple mistake, but if you agreed to protect client ad spend or conversion targets, it can become a financial claim. That is why the difference between an incident and a promise matters so much.
Hosting and maintenance work often carry the sharpest contract risk because the client expects the service to keep running. If a patch is missed or a plugin update breaks the site, the client may point to your warranty on uptime, backups or support response times. That can quickly move beyond a normal breach cost.
The practical problem is that the policy may pay for restoration work but not for the contractual side of the loss. The better your promise, the tighter your wording needs to be. If not, you can end up paying the gap yourself.
Campaign, code and data claims
Digital agencies also face claims linked to paid media, tracking, code deployment, or incorrect data handling. A bad audience set-up can waste ad spend. A code push can break checkout. A data mistake can trigger a UK GDPR issue and a client complaint at the same time.
The UK government guidance on data protection for businesses makes clear that the Data Protection Act 2018 and UK GDPR still matter even when a supplier is involved. That means your contract with the client and your chain of suppliers both shape the risk.
In day-to-day agency work, the split between cover and warranty is easiest to see in specific jobs. A development project may trigger a claim if a deployment error breaks checkout, while a hosting issue may lead to downtime, lost sales and a dispute over service credits. A maintenance contract can create liability if patching or backups were promised but not completed on time. Campaign work can lead to a client complaint if media spend is wasted or tracking is misconfigured, and data-handling work can bring in UK GDPR exposure if credentials or personal data are mishandled.
In each case, cyber insurance may respond to the incident itself, but the contractual warranty decides how far the agency must pay for the promise it made to the client.
How to choose for your agency
Choose cyber insurance first, then use contractual warranties only where you can match the promise to real controls and policy cover. For most web and digital agencies in England, the contract creates the bigger trap, because it can widen liability beyond what the policy expects.
The best practical rule is simple: do not let the warranty be bigger than the cover. If the promise is wider than the policy limit, or the policy exclusion list, you have a gap. That gap can be small on paper and painful in a real claim.
Use this decision test
Ask four questions before signing. First, do you store or touch client data? Second, do you control uptime or security in practice, or only on paper? Third, does the contract include indemnities, penalties or service credits? Fourth, would the worst claim sit above your policy limit?
If the answer to any of those is yes, you need to slow down. A contract review is not a legal luxury here. It is the bit that decides whether the policy will be enough.
Both is usually the safer choice for agencies that host sites, manage credentials, or run recurring maintenance. It is also the better route when a client insists on broad SLA language. In that case, insurance gives you the cash to respond to an incident, while the contract limits the amount you can be asked to pay.
That does not make you bulletproof. It just means you are not standing on one leg. The real decision is whether the contract cap, exclusions and excess all fit together before you sign.
The part most guides leave out
What most guides leave out is the gap between the legal promise and the practical response. A policy can be excellent for a breach, but poor for a contract claim. A contract can look fair, but still create a loss that is larger than the business can absorb.
Another quiet risk is supply chain dependence. If your host, SaaS provider or ad platform fails, your client may still look at you first. That is why supply chain risk matters even for small agencies with only a few staff.
The hidden cost of relying on warranties
A warranty sounds cheap because it does not carry a premium line. In practice, it can be the most expensive line in the contract. If the claim follows a failure in hosting or delivery, the cost may include remediation, fees, credits, and legal work, which can easily run into several thousand pounds.
The market reality is harsh. Insurers are careful with indemnities, and the Financial Conduct Authority expects firms to treat customers fairly while still reading exclusions properly. That means broad promises without matching cover are not a shortcut. They are a hidden bill.
Sometimes neither option fits well. That happens when the contract asks for a very high cap, fixed penalties, or open-ended indemnities that your insurer will not accept. It also happens if your controls are weak enough that no insurer will offer decent terms.
In that case, the answer is not to hope. It is to renegotiate the contract, reduce the warranty, tighten your controls, or walk away from the deal. A small agency cannot safely promise unlimited loss protection on a contract it cannot fund.
This topic is less urgent if you do not sign client contracts, do not handle third-party data, and do not make formal guarantees. In that case, the priority is usually basic cyber cover and professional indemnity insurance, not a warranty review.
Your questions answered
Does cyber insurance cover a contractual warranty
Not usually, if the claim comes from a promise you chose to make in the contract. Many policies exclude assumed liability, SLA penalties, and contractual indemnities. The key test is whether the loss comes from an incident the policy covers, or from the wording of the contract itself.
Is a warranty the same as professional indemnity
No, they are different. Professional indemnity insurance is a policy that may help with negligence or professional mistakes, while a warranty is a contract promise that can create liability. A warranty can still sit outside both PI and cyber cover if the wording is broad.
Can cyber insurance cover GDPR fines?
Sometimes it can help with defence costs or related expenses, but direct fines are often limited or excluded. In England, UK GDPR and the Data Protection Act 2018 still apply, and the exact wording of the policy matters. Do not assume the fine itself is covered without checking the insurer’s position.
Should a web agency accept broad SLAs?
Only if the SLA matches your real controls and your insurance wording. If you promise 99.9% uptime but rely on a supplier you cannot control, the warranty may be too wide. A narrower SLA is often safer than a bigger promise.
What if the client insists on indemnities?
Push back on any open-ended indemnity and try to cap it. Uncapped indemnities can sit far outside a normal cyber policy limit. If the client will not move, you need to check the policy wording before you accept the work.
Do small agencies really need both?
Many do, especially if they host sites, store client data, or manage credentials. The cost of cyber insurance is often modest compared with a single dispute over service failure. A warranty may still be needed, but only if it fits the controls and the cover.
Who should review the contract first?
The person who signs the contract should review it before anyone starts work. If the wording includes security promises, service credits, or indemnities, a broker or solicitor should check whether the policy responds. That review can be the difference between a covered loss and a cash problem.
My verdict for UK agencies
Choose cyber insurance first, then use contractual warranties only where you can match the promise to real controls and policy cover. For most web and digital agencies in England, the contract creates the bigger trap, because it can widen liability beyond what the policy expects. The safest answer is not one option or the other. It is insurance plus careful contract wording, with a hard cap on promises that could otherwise break the business.
With over 12 years of experience helping UK small and medium-sized businesses navigate the world of cyber insurance, this author is passionate about guiding companies through complex risks and protection strategies. I have seen a small agency lose a good client over a refused warranty, and that was cheaper than signing a clause it could never fund.
The lesson is blunt: if the promise is too wide, the right move is to narrow the promise, not to hope the policy will fix it later.