Choose cover by payment model, not by cheap price
A low-cost cyber insurance policy may pay breach-response costs but exclude diverted funds. UK fintechs should match cover to their payment activity, exposure and regulatory status.
Match the policy to the loss
Cyber insurance covers events such as hacked credentials, malware, leaked KYC data and disruption. KYC means checks used to confirm a customer's identity.
It often pays forensics, legal advice, customer notices, data recovery and ransomware response. It may also pay insured lost income.
PI covers claims about negligent services or advice. Crime or funds-transfer fraud cover may address defined fraudulent payment instructions or stolen credentials.
The policy must fit the way money moves through your firm.
| Business model | Main exposure | Cover to consider | Starting limit discussion |
|---|
| PSP | API attack, processor outage, payment fraud | Cyber, crime, PI | £1m to £5m cyber, then test fraud exposure |
| PISP or AISP | Open-banking access, service error | PI, cyber, crime where relevant | £1m to £2m, subject to FCA requirements |
| EMI | KYC breach, client-money fraud, outage | Cyber, crime, PI, D&O | £2m to £5m, separate crime review |
| Fintech SaaS | Customer data breach, software failure | Cyber, PI, D&O | £1m to £3m, driven by contracts |
FCA PI cover is not cyber cover
PISPs and AISPs may need PI insurance or a similar guarantee. This can arise under the Payment Services Regulations 2017 and PSD2 rules.
That requirement is separate from cyber cover. PI may address a service error.
Cyber cover can fund a response to a digital break-in, ransomware event or insured outage. Think of PI as cover for faulty professional work.
Cyber cover is for the digital break-in itself.
A policy schedule is not enough. Ask for the full wording. Confirm in writing whether social engineering fraud, client funds, regulatory defence costs and dependent business interruption are insured.
Regulated payment firms should assess FCA PI requirements apart from voluntary cyber cover. The Payment Services Regulations 2017 may require PI insurance or a similar guarantee.
This can apply to firms offering payment initiation or account information services. The amount should reflect the firm's activities.
An AISP or PISP should check its position with the FCA and regulatory advisers. Review it when volumes, territories or outsourced services change.
Open banking insurance does not automatically mean cyber cover. PI protects stated professional liabilities.
Cyber cover responds to defined security incidents. EMI insurance should also address safeguarding, crime, resilience and management risks.
Protect client funds separately from breach costs
Cyber cover can help after an account takeover or compromised API. An API is a software link that lets systems exchange data.
It is not a blanket guarantee for every payment loss. Client funds often need separate crime or fraud cover.
A payment firm should test each policy against real money flows. This includes money held, sent and received through partners.
Fraud extensions often have small caps
A £2m cyber policy may limit social-engineering fraud to £100,000 to £250,000. That can leave a large gap where payment values are high.
Social engineering is fraud that tricks a person into approving a payment. It can arrive by email, portal message or changed bank details.
Insurers may require direct unauthorised system access. They may reject a claim where an employee was deceived.
The most frequent error is treating the headline limit as the fraud limit.
Test realistic payment loss scenarios
Before buying, ask the broker to test a compromised API token. Also test business email compromise, processor outage and a KYC data leak.
For each case, confirm the clause that responds. Check the excess, sub-limit, evidence needed and type of loss.
Ask whether the loss concerns response costs, client funds, company funds or third-party liability. An excess is the amount your firm pays first.
A payment service provider insurance programme should separate the loss cause from the claimant. Cyber insurance may pay forensics, notices, recovery and insured business interruption.
This may follow a compromised API token or KYC data breach. Payment fraud cover aims to address defined theft events.
It often excludes losses outside its wording or sub-limit. PI can respond when a customer claims negligent payment, API or compliance services.
D&O protects directors and officers against some management claims. It does not replace cover for client-money fraud.
A single incident can trigger more than one policy. The wording should state which policy pays first.
It should also state whether defence costs reduce the available limit. Defence costs pay lawyers and experts to fight a claim.
Set limits, excesses and outage periods realistically
The limit should meet the largest believable event. It should not follow the lowest quote-screen premium.
Measure outage costs by real recovery time
Business interruption can cover defined lost income and extra operating costs. It applies after an insured cyber event.
Check the waiting period and indemnity period. The waiting period is the delay before cover starts.
The indemnity period is the time during which the insurer may pay. Dependent business interruption matters when a key supplier fails.
This can include a cloud host, processor or KYC supplier. Your own systems may still work during that failure.
Price reflects security evidence
Set limits using KYC record volumes, payment values and contract liability caps. Include the cost of working manually during disruption.
Early-stage firms often test £1m to £3m cyber limits. Higher-volume PSPs and EMIs may need £5m or more.
Assess fraud sub-limits separately. A fraud sub-limit is a smaller maximum within the main policy limit.
The National Cyber Security Centre and the Cyber Essentials scheme provide useful UK security guidance that can improve insurer confidence.
There is no standard UK cyber premium for fintechs. Insurers price the likely size and chance of each loss.
They do not base price on turnover alone. Underwriters often assess annual revenue, payment volume and the largest transaction size.
They also assess KYC record numbers and sensitivity. Other factors include served countries, past claims and supplier dependence.
Contract terms with enterprise customers also matter. Higher limits usually increase the cost.
Lower excesses can also increase the cost. Longer outage cover and wider fraud extensions can cost more too.
A firm can improve terms by showing phishing-resistant MFA and EDR. MFA requires more than one proof of identity.
EDR watches devices for harmful activity. Tested backups, fraud rules and supplier checks can also help.
A rehearsed incident plan gives underwriters more confidence. Compare fraud sub-limits, waiting periods and exclusions, not just premium.
Pass underwriting without hiding payment risks
Underwriting checks how your firm stops fraudulent payments. It also checks how you spot compromised accounts.
Insurers want to know how you recover if a key provider fails. Give full and accurate answers.
Controls insurers expect to see
Insurers expect proof of practical controls. Email, payment approval and production access receive close attention.
- Use phishing-resistant MFA for email, admin accounts and payment approval.
- Use EDR on laptops, servers and staff devices that access production systems.
- Keep immutable backups that ransomware cannot alter.
- Use least-privilege access and review it regularly.
- Test APIs and internet-facing systems at least once each year.
- Check cloud hosts, processors, KYC providers and outsourced support firms.
- Test an incident plan with customer, FCA and ICO escalation routes.
- Use dual approval, call-back checks and limits for changed bank details.
These controls show how your firm handles a payment attack.
Exclusions decide the hard cases
Read exclusions for dishonest acts, known events and cyber war. Also check uninsurable fines and contract promises beyond normal legal duties.
Do not understate API use or cloud dependence. Disclose outsourced KYC, overseas processing, card data and past incidents.
Missing facts can cause a dispute about cover. An application may look complete in theory, but insurers compare answers with your real systems after a claim.
This approach does not replace legal advice on FCA rules, PSD2 duties, contract duties or client-money safeguarding. It is less relevant where a business processes no data, payments or material digital systems. In that case, dedicated cyber cover may have lower priority.
Frequently asked questions
Does cyber insurance cover stolen customer money?
Not automatically. Stolen customer money often needs crime, funds-transfer fraud or social-engineering cover with a stated sub-limit.
Do PISPs and AISPs need cyber insurance?
Cyber insurance is separate from PI insurance or a guarantee. Many PISPs and AISPs need that PI cover or guarantee.
A regulated firm may need both types of cover.
How much cyber cover should a payment startup buy?
Many firms test £1m to £3m at first. Limits should reflect records, contracts, payment volumes and supplier reliance.
Can security controls reduce cyber insurance cost?
Yes. MFA, EDR, immutable backups and tested incident plans can improve terms.
Revenue and payment exposure also affect pricing.
Buy the policy that pays for your real loss
A sensible programme combines cyber cover for breach and outage costs. It also uses PI for service errors.
Add crime or funds-transfer fraud cover where money could be diverted. Before signing, ask insurers to confirm each realistic payment-loss scenario.
Confirm the limit, excess, fraud sub-limit and exclusions. Get those answers in writing.