When your till, card terminal or booking platform fails, trading can stall within minutes. You may be unable to take payments, check guests in, view reservations or prove what was booked. The costly gap may not be the outage itself. It is whether your policy covers its cause and supports lost income, recovery costs and backup plans.
Cyber cover starts with the cause of the outage
Cyber insurance responds to a covered cyber event. This means a malicious or unauthorised digital incident. It does not cover every system that has stopped working.
Events that can trigger a cyber claim
Business interruption cover can pay lost income where a covered event caused the trading loss. Waiting periods are often between 12 and 48 hours. Indemnity periods may run between 3 and 12 months, depending on the wording.
A failed till is not automatically a cyber claim. The key question is simple: did a covered cyber incident cause the failure? If not, equipment breakdown, a supplier contract or ordinary business interruption cover may matter more.
Card data needs its own checks
A cyber incident involving guest details requires a different response from losing access to a till. Names, email addresses, passport details, stay dates or payment information may have been accessed. First, restrict affected accounts and preserve logs.
Tell the payment processor or acquiring bank if its rules require this. PCI DSS is a card-industry standard, not an insurance policy. Failing to meet processor security or reporting rules can create fees, investigation costs or contractual exposure.
A data breach needs a calm, recorded response.
Cyber insurance may fund forensic work, legal advice, notifications and credit monitoring where insured. It does not remove your UK GDPR duties. Record your decisions and assess the risk to people's rights promptly.
Match the outage to the policy that may respond
The right policy depends on the cause of the loss. It may be an attack, broken equipment, fraud, injury claim or physical damage.
| What happened | Cover to check first | Main limit to test |
| Ransomware locks EPOS | Cyber and cyber BI | Waiting period and income limit |
| Cloud PMS supplier is hacked | Contingent cyber BI | Named supplier and cloud exclusion |
| Terminal physically fails | Equipment breakdown | Repair and replacement terms |
| Fake bank-details email | Crime or social engineering fraud | Fraud sub-limit and checks |
Fraud cover is not always cyber cover
Fraud by an owner, employee or trusted insider is often excluded. Cover for it may require a separate crime policy condition. Social engineering fraud often needs an independent call-back before payment is released.
B&B booking systems need supplier outage cover
A B&B may rely on five separate services. These can include a PMS, channel manager, online travel agent, payment processor and cloud host.
A B&B booking journey can fail at several points, even when the property's Wi-Fi and computers still work. A PMS may hold room status and guest notes.
A channel manager may send availability to Booking.com and other OTAs. The payment processor may collect deposits. A cloud provider may host data behind each service.
Check-in and deposits during downtime
During a processor outage, staff may confirm a room but not take a deposit. A channel manager outage can cause duplicate bookings when staff update availability manually in several places.
Paper records keep the front desk moving.
Keep trading while systems are down
1. Take cash or approved backup payments
2. Log sales and bookings on paper
3. Tell guests when confirmation may be delayed
4. Preserve logs before systems are restored
Evidence insurers and suppliers need
Keep an offline arrivals list, deposit records and a clear rule for closing availability. Check supplier contracts for service levels, incident notices, data-export rights and liability limits. These terms may not match contingent cyber BI wording.
Avoid policy limits that catch tills and bookings
Hidden limits often sit in definitions, sub-limits and exclusions. They may not appear in the policy headline.
Questions to ask before renewal
Ask whether downtime at a payment processor, PMS, channel manager or cloud provider is covered. Check whether the supplier must be named and whether the event must be malicious.
Also ask when income loss starts. Many policies use a wait of between 12 and 48 hours.
A practical review before buying
This guidance is less relevant if your business does not rely on digital tills, card processing or online reservations. It is also less relevant where equipment breakdown cover handles a physical defect. Read your policy wording and endorsements. Get advice from an FCA-regulated insurance professional where needed.
Read exclusions alongside the headline cyber insurance limit. A terminal may fail because of age, wear, a power fault or poor maintenance. That is usually an equipment breakdown issue, not a cyber claim.
Lost income may be declined where no covered cyber event occurred. It may also be declined if the outage ended before the waiting period. You may need takings records from comparable trading days.
Policy wording decides the claim, not the label.
Third-party downtime varies sharply between policies. Some require a named cloud provider or technology supplier. Some exclude a general booking platform or processor outage without a qualifying cyber event.
Your questions answered
Will cyber insurance cover a broken card terminal?
Usually no if the terminal simply fails physically. Equipment breakdown cover may apply instead. Cyber cover may apply only where hacking or malware caused the failure.
Does cyber cover pay for a PMS outage?
It may pay if a covered cyber event affects the PMS or an insured supplier. Check whether contingent business interruption includes cloud and software-as-a-service providers.
How long must my pub be offline before claiming?
Many policies have a waiting period between 12 and 48 hours. The exact clock and loss threshold appear in the business interruption wording.
They are not automatically covered. Check whether your policy names OTAs or includes unnamed technology suppliers. Also check if it requires a malicious cyber event.
Does UK GDPR mean every breach must be reported?
No, but breaches that risk people's rights may need ICO notification within 72 hours. Keep a breach record even where no report is made.
Will cyber insurance pay for invoice-redirection?
Only if crime or social engineering fraud cover is included and its conditions are met. Many policies apply a separate, lower sub-limit.
What proof should I keep after an EPOS attack?
Keep outage logs, screenshots, daily takings, processor reports, booking records and supplier notices. Preserve evidence before resetting or replacing systems, where it is safe.
Make the cover test part of your continuity plan
The useful test is simple. Identify the cause, the affected supplier and the policy section.
Peter White recommends testing one busy Friday scenario before renewal. Assume no EPOS, no card payments and no PMS access for six hours. Check whether staff can take payment, check guests in and record losses.
If they cannot do this, the insurance review is not finished.