An unauthorised high‑value card loss can wipe out a month’s cash flow for a 10‑person online shop. Many SMEs assume standard cyber cover will refund it.
Decision‑makers face mixed insurer definitions and overlapping products. They also meet costly exclusions that leave losses unpaid and compliance gaps unaddressed.
E‑commerce: cyber insurance vs payment‑fraud protection — if an online shop is at stake, know which losses each covers. Cyber insurance pays for data breaches, ransomware, forensic costs, third‑party claims and business interruption.
Payment fraud protection and anti‑fraud services aim to prevent or refund unauthorised card payments and chargebacks. These services are often excluded from standard cyber policies.
Understand when to buy each product. Match controls, evidence and budget to insurability.
Quick comparison table
This table shows typical responsibility, evidence required and price ranges so an SME owner can decide fast.
What each column means
The table maps common loss types to the most likely payer and the proof needed. Use it as a checklist when contacting a broker or payments provider.
How to read the table
Treat processor reimbursement as contractual, not guaranteed. Treat insurer reimbursement as conditional on policy wording and controls.
| Loss type |
Typical payer |
Evidence required |
Typical sublimit / cost (GBP) |
| Ransomware / extortion |
Insurer (if covered) |
Forensic report, system logs, incident timeline |
£10k–£250k (extortion limit varies) |
| Data breach costs (ICO, notification) |
Insurer for response; merchant for fines (subject to law) |
Breach report, data maps, ICO correspondence |
Forensic £5k–£50k; fines separate |
| Card‑not‑present (CNP) fraud / chargebacks |
Processor, card scheme or merchant depending on T&Cs |
3DS/authorisation records, delivery proof, device data |
Often excluded from cyber policies; refund equals transaction value |
| Authorised push payment / social‑engineering |
Usually merchant; sometimes bank/PSP or special APP schemes |
Communications trail, authentication logs, proof of instruction origin |
Often excluded; separate APP cover if available |
Use the table to decide who to call first: payments provider, insurer or broker. Preserve raw logs immediately. They are the single most persuasive item during dispute representment.
Keep logs for at least 12 months.
Cyber insurance
Cyber insurance covers incident response, forensic costs, legal defence and third‑party liabilities when the policy wording applies. The insurer pays these costs once the policy accepts the loss and the insured met policy conditions.
Pros
Pros: Pays forensic and legal bills quickly when accepted. It also covers business interruption and recovery costs in many policies.
Settlement timelines vary and insurers may take weeks to investigate before paying response invoices. Some elements have sub‑limits, waiting periods and evidential requirements.
Insurers can fund negotiation with extortionists and hire specialist response teams. That avoids the merchant paying those fees out of pocket.
Cons
Cons: Many policies exclude direct transactional losses such as CNP chargebacks and authorised push payments. Sub‑limits often cap social‑engineering payments or exclude them.
Claims get refused when notification deadlines are missed or when controls like PCI or MFA are weak. The policy wording and evidence matter more than a shop’s age.
Who it suits
Merchants that need cover for incident response, legal defence and business interruption should choose cyber cover. Shops with moderate revenue and basic digital infrastructure fit well.
Who it does NOT suit
If the only concern is direct reimbursement for fraudulent card payments, cyber insurance alone is unlikely to suffice. Relying on insurance alone risks uncovered refunds and chargeback fees.
Payment fraud protection
Payment fraud protection covers transaction losses, represents disputes and manages chargebacks with card schemes. Providers may offer representment services, automated dispute handling and reimbursement depending on contract terms.
Pros
Pros: Direct focus on recovering transaction value and disputing chargebacks. These tools integrate with checkout to reduce CNP fraud in real time.
Payment providers often act quickly to refund or reverse transactions before a full dispute runs. That reduces short‑term cash pressure for the merchant.
Cons
Cons: Reimbursement depends on strict T&Cs and on meeting processor rules. PCI compliance alone does not guarantee reimbursement.
Some processors shift liability to the merchant for weak fulfilment checks or missing proof. Representment success rates vary by evidence quality.
Who it suits
Merchants with high volumes of CNP payments should buy payment fraud protection. Marketplaces and shops that accept one‑off, high‑value sales benefit most.
Who it does NOT suit
If the primary risk is ransomware or data breach costs, payment fraud protection will not cover forensic bills or BI losses. Payment tools rarely fund incident response.
Third‑party anti‑fraud services
Anti‑fraud vendors detect suspicious payments before settlement and block risky transactions. These services complement processors and insurers and often reduce both fraud loss and insurance premiums.
Pros
Pros: Reduce false positives and stop many fraudulent transactions in real time. They create logs and device fingerprints that help with representment.
Vendors often integrate 3DS2, tokenisation and behavioural scoring. These measures make chargeback rebuttals more credible.
Cons
Cons: Cost and integration effort can be significant for a small team. False positives can block legitimate customers and harm conversion.
When controls are poorly tuned, vendors add complexity without easing insurer concern. Controls must be demonstrably active.
Who it suits
Shops with recurring fraud or high chargeback rates get most value from anti‑fraud services. They suit operations that can act on alerts promptly.
Who it does NOT suit
Very small sellers with low transaction volume may find the cost outweighs benefits. If there is no staff to investigate alerts, the tool will not help.
Technical integration and evidence standards for insurability: insurers and PSPs increasingly expect machine‑readable, exportable evidence and demonstrable retention policies. Minimum useful fields include 3DS2 authentication results, issuer authorisation codes, full payment transaction IDs and device fingerprint or token IDs.
Retention windows: keep structured transaction and 3DS logs for at least 12–24 months. Keep server and access logs for 90–365 days depending on insurer demand. Preserve immutable forensic snapshots under chain‑of‑custody when an incident is suspected.
Evidence formats should be exportable as timestamped JSON or CSV bundles with checksums such as SHA‑256. Include an incident manifest that records actions taken and who performed them.
API access to audit trails, a standard evidence bundle template and documented retention materially improves representment success. It also satisfies insurer forensic requests and shows fraud prevention controls to underwriters.
Keep a short, clear incident timeline with timestamps and hashes.
How to choose by situation
Match cover to likely losses and the contracts already signed with your PSP. Decide with three clear rules and a simple calculation method.
Three practical rules
- Buy cyber insurance if response and business interruption costs would threaten trading.
- Buy payment fraud protection when chargebacks form a recurring cash risk.
- Buy anti‑fraud tooling when staff can act on alerts and tune rules.
Simple coverage calculation
Start with monthly fixed costs plus expected lost gross margin rather than headline revenue. Multiply that sum by the desired BI period and add a forensics and legal buffer to set a realistic limit.
Example: monthly fixed costs £10,000 plus expected lost gross margin £5,000 equals £15,000. Multiply by three months for £45,000 then add a forensics buffer of £15,000 to £30,000.
Opinion with nuance
Cyber insurance pays for response and recovery costs, but it usually does not refund lost transaction revenue. For shops where chargebacks cause cash flow stress, payment fraud protection or a processor with strong representment is more useful.
The practical choice is to combine prevention, a payment‑fraud layer and a cyber policy that covers response and BI.
Indicative premium and coverage budgeting examples:
- SMEs should expect wide variance in premiums depending on sector risk, turnover, historical claims and controls. An online retailer seeking a £100k cyber response limit and three‑month BI limit might see annual premiums in the low thousands (£800–£4,000).
- Broader packages with six‑month BI limits and higher third‑party liability can run to tens of thousands.
- Payment‑fraud protection through a PSP or vendor is usually charged as a small percentage of transaction value (0.02–0.5%) or a per‑dispute fee (£0.50–£5), sometimes with a subscription.
Worked example: monthly fixed costs £12,000 plus lost margin £6,000 equals £18,000. Three months equals £54,000 then add an investigative buffer of £15k–£30k.
Compare that limit to premium quotes to judge affordability and whether to layer payment protection.
What nobody tells you
The most frequent error is assuming a cyber policy automatically covers all payment losses. Policies often exclude social‑engineering and authorised transfers, and claim refusals commonly cite failed controls.
This works well in theory; in practice many SMEs find claims limited by sublimits and evidence gaps.
Claims adjusters look first for proof of authentication and logging, not the merchant’s intent. A common case: a £750k turnover shop loses £12,500 to CNP fraud.
The processor treats the dispute under its chargeback rules and the insurer refuses reimbursement. The merchant ends up covering the refund and fees.
Key difference: cyber insurance buys time and expertise for recovery; payment‑fraud solutions aim to recover the money or stop it leaving. Use both when possible and keep logs for at least 12 to 24 months to support representment and claims.
Keep logs for at least 12 months.
Case study, timeline, costs and lessons:
- Day 0: a customer reports unauthorised card‑not‑present activity.
- Day 1: the merchant freezes fulfilment and preserves raw logs.
- Day 3: the payment service provider opens a chargeback and requests proof of fulfilment.
- Day 7: the merchant notifies its broker and starts a cyber claim while also engaging the PSP representment process.
Typical costs for an SME scenario (illustrative): disputed transaction value £12,500. Chargeback fees and penalties £1,000. Immediate forensic triage £4,000–£8,000.
Legal advice £1,500–£4,000 and operational disruption a further £2,000–£6,000. Total cash impact £20k–£32k before any insurer or PSP recovery.
Lessons: preserve 3DS and authorisation records, courier tracking and email headers immediately. Notify the PSP and broker within the smaller of contractual timescales, often 24–72 hours.
Keep a clear incident timeline with timestamps and hashes of exported evidence. Representment and insurer investigations depend on coherent, time‑stamped forensic evidence rather than post‑hoc statements.
Claim flow and decision points
1. Detect
Transaction alert or customer report triggers review.
2. Preserve
Snapshot logs, export 3DS and authorisation data and save email headers.
3. Map
Check processor T&Cs and insurance exclusions to decide the next step.
4. Notify
Tell the PSP and broker within contractual or policy timescales.
Clause examples and wording to watch
Insurers often refuse claims citing specific exclusions or late notification. Read policy clauses for words like authorised, social‑engineering and chargeback exclusions.
Example wording to review
Sample wording to watch: "We do not cover losses arising from payments made by the insured as a result of social engineering or deceptive instruction unless a named endorsement applies." Treat this as a red flag if the business processes manual payments.
Sample wording for chargebacks: "Loss resulting from card scheme chargebacks is excluded unless a policy schedule item specifies merchant reimbursement." If that wording appears, the insurer will not refund sales that the merchant must return.
Exceptions apply when the PSP or merchant acquirer contract explicitly indemnifies the merchant for fraud, when the business does not process customer payments online, or when bespoke enterprise insurance explicitly lists payment fraud cover.
For a practical next step, share the RFP checklist below with your broker and payments provider to get concrete quotes and integration plans.
RFP checklist for brokers and anti‑fraud vendors
The checklist below maps controls to evidence insurers expect and to items a payments partner should confirm. Copy and paste it into a broker or vendor brief.
RFP: Payment fraud & insurability checklist
1) Business profile
- Annual online revenue: [£]
- Average basket value: [£]
- Monthly transaction volume: [#]
2) Controls asked of vendors
- 3DS2 support and logs (yes/no)
- Tokenisation (yes/no)
- Device fingerprinting (yes/no)
- Rate limiting and velocity checks (yes/no)
- Admin MFA and logs (yes/no)
3) Evidence retention
- Transaction logs retained for at least 12 months (yes/no)
- Server and access logs retained for 90 days (yes/no)
- Backup snapshot policy described: [days]
4) Dispute handling
- Representment service available (yes/no)
- Average representment success rate (% if known)
- SLA for dispute initiation (hours)
5) Integration & reporting
- API audit trail available (yes/no)
- Real‑time alerts to staff (yes/no)
- Exportable evidence package for insurer (yes/no)
6) Pricing
- Fee model: % of transaction / monthly / per dispute
- Estimated annual cost: [£]
7) Insurance alignment
- Will the vendor provide demonstrable logs for insurer claims? (yes/no)
- Can vendor provide a written compatibility statement for insurers? (yes/no)
Frequently asked questions
What is the difference between cyber crime and cyber fraud?
Cyber crime means criminal acts using networks or systems. Cyber fraud means deception that leads to financial loss, such as phishing or social engineering.
Regulators, insurers and payment providers treat each type differently for claims and evidence.
Is cyber insurance worth it for an online shop?
Cyber insurance is worth it when incident response or business interruption could end trading. If a single event would cause weeks of lost revenue, the policy pays forensic and recovery costs.
For shops with low fraud exposure and limited admin capacity, the focus should be prevention and payment‑fraud services.
What evidence helps win a chargeback?
Clear 3DS or authorisation records, delivery proof and device or IP data win most disputes. Also include email headers, customer communication and courier tracking when available.
Representment fails without a coherent timeline and matching evidence.
How long should transaction logs be kept?
Keep critical transaction logs for at least 12 months and preferably up to 24 months. Payment disputes and insurer investigations can open long after an event, so retention matters.
Check processor and insurer requirements and record retention policies in writing.
Can PCI DSS compliance guarantee insurance cover?
PCI DSS helps, but it does not guarantee cover. Insurers check how controls operate in practice, not just attestations.
Maintain demonstrable evidence of SCA, MFA and logging and document incident response steps.
Sources and references
NCSC guidance on incident management and logging informs the evidence insurers expect. National Cyber Security Centre
Relevant legal data and guidance.