A central policy may leave your unit uninsured
A central cyber policy does not automatically insure every outlet using the brand. Your local company, branch or franchisee must meet the policy definition of insured. That means the person or business allowed to claim.
Check the policy schedule for named insureds, covered subsidiaries, trading names and endorsements. An endorsement is a written change to the policy. A logo above the door is not insurance status.
A franchisor owns or licenses the brand and operating model. A franchisee runs a local business, often through its own limited company. Each may have different rights after an attack.
The paperwork decides who can claim.
An additional insured may have limited protection under the central policy. It may not claim for its own lost turnover. Lost turnover means income lost while the business cannot trade.
The franchise agreement still matters
The franchise agreement may say who buys insurance and pays the excess. It may also say who manages an incident. An excess is the first part of a covered loss paid by the insured.
But the agreement cannot force an insurer to cover an entity outside its policy wording. Think of it like a guest list. The franchise contract cannot add a name after the insurer has set it.
Check the franchise agreement, policy schedule and endorsements together. The most frequent mistake is checking only the certificate or policy summary.
| Arrangement | Who can claim? | Cost trigger | Main remaining risk |
|---|
| Central cyber policy | Entities within the insured definition | Policy excess and relevant sub-limits | Local company omitted from the schedule |
| Standalone franchisee policy | The franchisee's named legal entity | A separate excess, usually per claim | Gaps between policies or shared systems |
| No local cover | No direct claim right against the insurer | The business pays immediate invoices | Forensics, downtime and legal liability |
Six policy features can restrict a local claim
A declined or reduced cyber claim usually links to an exclusion, condition, sub-limit or factual finding. A sub-limit is a smaller cap within the full policy limit. Read the schedule, endorsements, exclusions and proposal answers.
Do not rely only on the policy summary. It is like reading a film trailer instead of watching the full film.
Timing and prior knowledge can decide
Many cyber policies are claims-made. This means you must usually make and report the claim during the policy period. A retroactive date can exclude incidents that started earlier.
Notice rules may require contact with the insurer's breach team within 24 to 48 hours. Report promptly, even if you do not know the full scale yet. Late notice can give the insurer grounds to restrict a claim.
Short reporting windows can matter more than the attack itself.
Limits, controls and proposal answers
Cyber extortion, forensics, notification, legal defence and business interruption may each have separate limits. Business interruption pays for insured lost income and extra costs. It does not always cover every cost of closure.
If the proposal said multi-factor authentication was in place, that must be true. The same applies to offline backups and patching. The insurer may investigate under the Insurance Act 2015 duty of fair presentation.
A usual case is a franchisee using central email but local payment terminals. A ransomware attack stops local sales. The central policy may cover its own systems, but not the outlet's lost income.
How a local cyber claim can narrow
1. Entity
Is the local company insured?
2. Event
Does the wording cover it?
3. Conditions
Were notice and controls met?
4. Payment
Excess and sub-limits apply
Shared technology creates a separate cover question. A POS provider, payment processor, managed-service provider or cloud platform is not automatically insured. This remains true even when every franchise must use that supplier.
The supplier's contract may require it to investigate outages and preserve logs. It may also require quick notice or payment for some losses. Those promises do not extend the franchise cyber policy to the supplier.
Check who controls customer data and who can isolate systems. Check whether the supplier's own insurance responds to its error. This separates the franchisor's cover from local cover for lost income and customer claims.
Act before costs and evidence get harder to recover
Notify the insurer or broker immediately and preserve evidence. Ask for a written coverage position. Record what happened, when you found it, affected systems and every cost.
Do not hire a ransom negotiator, IT firm or public-relations firm without consent. The policy may require approved incident-response suppliers. Unapproved costs can be harder to recover.
Speed protects both evidence and your claim.
Ask for the exact refusal reason
Ask for the exact clause, endorsement, exclusion or condition used. Ask for the factual reason, relevant limit or sub-limit, and complaints process. A refusal is not always final.
A refusal can be challenged if the insurer used the wrong entity, date or notice clause. Compare the insurer's letter with your incident logs. Also compare it with the schedule, endorsements and proposal form.
Decide whether separate cover is needed
Separate cover may suit a franchisee with its own limited company, customer records or payroll. It may also suit outlets with local POS devices. Review who bears business interruption risk.
Before renewal, compare the central schedule with every franchisee legal entity. Compare it with the incident duties in the franchise agreement. This works well in theory, but schedules often lag behind new outlets or changed company names.
Where cover is declined or restricted, follow a written sequence. First, get the insurer's written coverage position. Then identify whether it cites exclusions, sub-limits, excess, late reporting or an insured-entity issue.
For claims-made policies, check both the reporting date and retroactive date. Compare the claimed facts with incident logs, endorsements and proposal answers. Ask the broker to challenge factual errors.
Separate forensic, notification and business interruption costs in one cost schedule. Each type of cost may face a different limit. Use the insurer's formal complaints process if the dispute remains.
This guidance is less relevant if the outlet is a wholly owned branch. It must also be clearly listed under the same legal entity. This guidance does not decide non-cyber losses, such as property damage. The policy wording, franchise agreement and regulated advice remain decisive.
A franchisee should send its broker the schedule, franchise agreement and refusal letter before renewal or after an incident. Ask the broker to confirm, in writing, whether the legal entity can claim for local lost income. This is general education, not legal, claims or regulated insurance advice.
FAQs
Can a franchisor’s cyber policy cover my outlet?
Yes, but only if your outlet or legal entity falls within the insured definition, schedule or a valid endorsement. Brand membership alone is not enough.
What should I do if a cyber claim is declined?
Ask for the exact clause and factual reason in writing. Give it to your broker with the schedule and franchise agreement.
Does the franchise agreement make me insured?
No. It can allocate costs, but it cannot change an insurer's policy wording.
Can ransomware at one POS terminal affect the whole network?
Yes. Shared credentials, customer data or central systems can be exposed. Cover may still differ between separate insured entities.
Does cyber insurance pay ICO fines?
Sometimes, but only where the law allows insurance and the policy includes that cover. ICO notification may be required within 72 hours where a breach risks people's rights and freedoms.
Is a separate cyber policy always necessary?
No. It may not be needed where the branch is clearly scheduled under the same legal entity. The policy limits must also suit its risk.
How long do I have to challenge an insurer’s decision?
Act immediately because the policy may impose short notice duties. An eligible Financial Ombudsman Service complaint is commonly limited to six months after the insurer's final response.