A supplier outage can stop sales, delay fulfilment, and leave a small business paying for problems it never caused. For UK SMEs that rely on payment platforms, cloud software, logistics firms or payroll providers, the question is not whether a breach would hurt, but whether the cyber policy would respond when the disruption sits outside the business’s own systems.
Yes, but not always. Some cyber policies cover interruption or losses when a key supplier suffers a cyber incident, but only if the wording includes dependent business interruption, supplier business interruption, or similar terms. Many policies narrow this, require a named supplier, or exclude non-cyber failures. The key is to check the definitions, sub-limits and exclusions.
Will your cyber policy pay if a key supplier is hit?
A cyber policy may pay for a key supplier’s breach or outage, but only when the wording includes dependent business interruption, supplier business interruption, or a similar extension. If it does not, the loss often sits outside cover, even when the disruption is painful and expensive.
That is the bit many owners miss. A supplier can be hacked, locked out by ransomware, or lose access to its systems, and your own business can still be uninsured for the knock-on loss.
The practical test is simple: ask whether your policy reacts to a third-party breach that stops a service you rely on. If the answer is buried in a definition, a schedule, or a small extension, treat that as a warning light, not comfort.
The key question is not whether the supplier was hacked. The key question is whether your wording covers the loss that hit your business because of that hack.
Is a supplier breach always a covered loss?
No, a supplier breach is not always a covered loss. The policy has to turn that outside event into an insured trigger, and many do not.
Think of it like car insurance. If a road is flooded, the car may still be fine. If the policy only covers damage to the car, the flooded road itself does nothing for the claim. Dependent business interruption works in the same way.
The coverage often depends on three things. First, the supplier must fit the policy’s definition of a covered party. Second, the event must be cyber-related, not just a business failure. Third, the loss must happen during the covered period, with any waiting period already passed.
Which losses can actually be claimed?
The losses that can be claimed are usually lost income, extra costs to keep trading, and sometimes contract penalties. The exact answer depends on how the policy defines business interruption.
A good policy may also cover incident response costs linked to the supplier event, such as forensic support or legal advice, if your own business has a direct insured loss. A weaker policy may only pay a narrow slice and leave the rest behind.
In the UK, the real pain often shows up as cash pressure. A supplier outage can hit invoicing, payroll, fulfilment, and customer service in the same week. If the wording does not pick up that chain reaction, the claim may fail.
Customer BI, supplier BI, dependent BI
These terms sound similar, but they point in different directions.
Customer BI covers losses caused when your customer suffers an event that affects your sales or service. Supplier BI covers losses caused when your supplier fails. Dependent BI is the wider label many brokers use for both directions, though the wording still controls what actually pays.
The error most often seen here is simple. A buyer sees “business interruption” on the proposal and assumes every linked loss is covered. That is not how cyber wording works. The policy may protect only your own systems, not the systems of the people you depend on.
A useful rule of thumb is to buy or extend cover when a supplier outage would materially affect cash flow, contract performance or customer service within days, not weeks. If a key supplier breach would stop online sales, delay fulfilment, interrupt payroll, or trigger penalties under customer contracts, dependent business interruption becomes worth checking closely. By contrast, if you could switch to another provider quickly and the loss would be modest, self-insurance may be enough.
In practice, UK SME cyber insurance should be reviewed by, because the need for business interruption cover is much stronger where one named supplier controls payments, hosting, logistics or a core SaaS platform.
What supplier cover usually means in practice
Supplier cover helps only when the policy specifically responds to disruption at a third party you rely on. It is not a general promise to make whole every loss linked to a vendor.
This matters because many SMEs rely on software, payments, logistics, payroll, cloud hosting, and accountancy platforms. One weak link can stop trading for hours or days. A solid policy can help. A vague one often cannot.
How dependent BI differs from your own BI
Your own business interruption covers loss caused by an event in your business, such as ransomware on your network. Dependent business interruption covers the knock-on loss caused by someone else’s event.
That distinction sounds small. It is not. It is the difference between a claim for your own outage and a claim for a supplier’s outage that lands on your bottom line.
A UK SME often discovers this at renewal, after a scare. A payment processor, e-commerce platform, or managed service provider goes down for 48 hours. Sales fall. Staff sit idle. Customers complain. Then the policy wording is checked, and the supply-chain hook is missing.
Why supplier BI is often a bolt-on
Supplier BI is often a bolt-on because insurers price it as extra exposure. A supplier event can hit more than one insured, and the loss can spread fast.
That is why some policies offer it only as an extension, sometimes with a low sub-limit. In practice, that can mean cover exists on paper but not at a level that matches the real loss.
Lloyd’s of London has long treated contingent forms of business interruption as a specialist exposure, not a default feature. The market still prices this cautiously, especially where the insured depends on cloud services, payment rails, or a single software provider.
| Cover type |
What triggers it |
Typical gap |
What to check |
| Own BI |
Your own systems are hit |
Does not reach supplier losses |
Definition of insured event |
| Supplier BI |
Named supplier is hit |
May need named suppliers only |
Schedule, named entity, sub-limit |
| Dependent BI |
A dependent third party is hit |
Often narrow and capped |
Waiting period, exclusions, trigger |
What does a named supplier clause mean?
A named supplier clause means the policy only covers suppliers listed in the schedule. If the supplier is not named, the cover may not respond.
This is common in small commercial programmes. It keeps wording neat. It also catches people out, because the business may rely on ten critical vendors but name only two.
Where self-insurance can make sense
Self-insurance can make sense when the supplier loss is small, short, or easy to replace. It is like keeping a spare bulb in the drawer instead of buying a service contract for every lamp.
That approach works best where the business can switch suppliers within a day or two. It works badly where one vendor controls payments, hosting, or order processing and a shutdown would take three or four weeks to unwind.
Which supplier failures are covered, and which are not?
A cyber policy usually pays when a supplier suffers a cyber event that directly stops your trading, but it often excludes ordinary business failure, telecoms problems, power cuts, and insolvency. The trigger matters more than the label on the incident report.
The cleanest way to think about it is this: cyber insurance usually wants a cyber cause. If the event is really an operational, financial, or infrastructure failure, the answer is often no.
When a third-party breach is likely covered
A third-party breach is more likely to be covered when the supplier suffers ransomware, data theft, system encryption, or account compromise that stops an insured service.
A common example is a payment processor locked out by ransomware for 36 hours. If your policy includes supplier BI and the processor is a covered material service provider, a claim may follow for lost sales and extra recovery costs.
The data points to this being a real exposure. IBM’s 2024 Cost of a Data Breach Report put the global average cost of a breach at $4.88 million, while the UK Government’s cyber breach surveys have shown that medium businesses are regular victims of cyber incidents. That combination is why supplier wording is no longer a niche issue. IBM’s 2024 Cost of a Data Breach Report
When a supplier outage is usually excluded
A supplier outage is usually excluded when the cause is not cyber. A power failure, telecoms cut, warehouse fire, or staffing collapse may look similar from the customer side, but many cyber policies reject it.
This is where many claims go wrong. The loss feels like a cyber event because systems are down. The insurer may still say the cause was electrical, mechanical, or operational, so the cyber wording never activates.
Does insolvency ever trigger cyber cover?
Usually, insolvency does not trigger cyber cover. Insolvency is a financial failure, not a cyber event.
That matters for SMEs because a supplier can fail for mixed reasons. A cyber incident may push a weak supplier over the edge, but the insurer may still ask what actually caused your interruption. If insolvency, not the hack, drove the loss, cover is far less likely.
In practice, the policy line between covered and not covered is often very sharp. A business interruption extension may respond to ransomware at a cloud host, a third-party breach at a payment processor, or account compromise that shuts down a service you rely on. It may not respond to ordinary system failure, telecoms outage, power cuts, insolvency, poor maintenance, or a gradual service disruption with no cyber trigger. Some wordings also require a named supplier, a minimum outage period, or direct loss to your own business before incident response costs or knock-on loss are paid.
That is why the cyber policy wording matters more than the headline summary: two policies that both mention supplier BI can produce very different outcomes at claim stage.
How to check your policy before renewal and what to do now
Review the schedule, definitions, exclusions, extensions, and wording before renewal. If the policy does not clearly name supplier dependency, assume it may not pay. This is not about reading every word like a lawyer; it is about finding the bits that decide whether a claim works. Three pages usually matter most: the schedule, the insuring clause, and the exclusion section.
Check the policy wording, list your critical suppliers, and ask whether each one is covered for a cyber-triggered outage. If the answer is unclear, treat that as a gap, not a comfort blanket. Then compare the likely loss with the premium. That is the real decision point. A cheap policy that misses a two-week payments outage is not cheap at all.
Is the supplier named in the policy?
If the supplier is named, the policy may only protect the listed entity. If it is not named, the policy may still cover a class of suppliers, but only if the wording says so.
Ask for the exact legal name of the provider. Group company names can trip people up. A claim can fail if the contract says one entity and the policy names another.
Is there a sub-limit or waiting period?
A sub-limit is a lower cap inside the main limit. It works like a smaller drawer inside the bigger cupboard. The main policy may have £500,000 cover, while business interruption cover has only £50,000.
A waiting period is the time before cover starts. Three, six, or twelve hours are common in some wordings. For a fast-moving online business, that can wipe out the first day of loss.
Does the trigger require a cyber attack?
Many wordings require a cyber attack, not just a system failure. That can matter a lot.
If the supplier’s cloud service goes down because of bad code or an internal mistake, the insurer may argue there was no cyber attack. If the outage follows ransomware, the position is usually clearer.
The supplier-risk checklist most SMEs miss
A supplier-risk checklist helps decide which vendors deserve explicit cover. The point is to match insurance to real dependency, not to buy broad wording for every possible vendor.
The most useful approach is simple. List each critical supplier, then ask how badly the business would suffer if that supplier vanished for 24 hours, 72 hours, or two weeks.
Which suppliers are truly material?
A material supplier is one whose failure would stop trading, damage cash flow, or break contracts. For many SMEs, that means payment processors, core software providers, cloud hosts, telecoms, logistics platforms, or outsourced payroll.
A case that comes up often is a five-person e-commerce firm. It thinks the warehouse is the main risk. In practice, the payment gateway and stock system are the real weak points, because one outage stops orders and refunds at the same time.
What should you record for each supplier?
Record the supplier name, service provided, contract owner, replacement time, and the worst likely outage period. That gives a clean view of exposure.
The simplest version fits on one page. It does not need fancy software. It needs honesty about dependency.
| Supplier |
Service |
Could trading stop? |
Time to replace |
Named in policy? |
Claim gap to check |
| Payment processor |
Card payments |
Yes |
3-7 days |
Often no |
Sub-limit, trigger, waiting period |
| Cloud host |
Hosting and storage |
Yes |
1-4 weeks |
Sometimes |
Named provider, cyber trigger |
| Payroll provider |
Pay runs |
No, but cash pressure rises |
1-2 weeks |
Rarely |
Extra costs and contract cover |
| SaaS platform |
Orders or CRM |
Yes |
2-14 days |
Sometimes |
Dependency wording, exclusions |
When does a supplier become a material service
A supplier becomes a material service provider when your business cannot run properly without it. That is the point where wording matters most.
The mistake is to think only large suppliers count. A small niche software firm can be more material than a national company if it runs your booking system or payment flow.
How supplier dependency usually shows up
Supplier breach or outage
↓
Service stops or slows
↓
Sales, payroll, or fulfilment suffer
↓
Claim works only if the wording turns that loss into insured dependent BI
What to ask your broker or risk manager
Ask direct questions that force a wording-based answer. If the answer sounds like a sales pitch, ask again.
The right questions are plain and specific. They should expose whether the policy covers the event you are worried about, not the event the insurer prefers to discuss.
Does our policy include supplier BI?
This question checks the headline. If the answer is no, stop there and ask whether it can be added.
If the answer is yes, ask whether the cover is automatic or optional, and whether it applies to all suppliers or only listed ones.
Are customer BI and dependent BI both included?
This matters because many policies protect only one direction of dependency.
A business can lose money when a customer is hacked, when a supplier is hacked, or when its own systems fail. If only one of those is covered, the gap may be larger than expected.
What exclusions apply to third-party breaches?
Ask for the exclusions in plain English. Then ask which of them would block a supplier claim.
The most common exclusions to test are operational failure, insolvency, telecoms outage, power failure, and non-malicious system failure. Those are the ones that quietly wipe out apparently broad wording.
Is there cover for incident response and lost revenue?
This question separates response help from financial cover.
Incident response may pay for forensics, legal advice, or notification work. Lost revenue needs business interruption wording. A policy can cover one and miss the other.
One useful habit: ask the broker to mark up the policy PDF where dependent BI is covered and where it is excluded. In the image of the marked policy, the gap usually becomes obvious fast.
Common claims questions are straightforward and worth answering in the article. If a named supplier is breached by ransomware, will the policy pay for lost revenue? If the supplier is not named, does the policy still respond to any material third party? Does a third-party breach need to involve data theft, or is service disruption enough? Are cloud software providers and payment platforms treated as insured suppliers? And if the supplier outage lasts only a few hours, is there a waiting period that removes the claim entirely?
A short FAQ on these points helps readers compare dependent business interruption, supplier business interruption and cyber insurance exclusions without having to interpret the whole wording themselves.
What insurers and regulators expect you to know
UK insurers expect buyers to know which suppliers matter and how a failure would hit the business. Regulators also expect sensible risk management where personal data or essential services are involved.
That does not mean every SME needs a complex control framework. It does mean the business should know its weak points and not guess at cover.
How cyber essentials helps reduce exposure
Cyber Essentials helps reduce the chance that one weak password or exposed device opens the door. It is not a cover, and it does not insure anything, but it lowers one common cause of supply-chain pain.
The National Cyber Security Centre keeps saying the same thing in plain language: basic controls still stop a lot of harm. That is especially true where a vendor account compromise could spread into your own systems. National Cyber Security Centre guidance on Cyber Essentials
Why FCA, ICO, and NCSC guidance matters
The Financial Conduct Authority cares because supplier failure can affect operational resilience, payments, and customer outcomes. The Information Commissioner’s Office cares because a supplier breach can expose personal data and trigger notification duties under the UK GDPR and Data Protection Act 2018.
For many SMEs, the practical message is simple. If a provider handles customer data or payment data, the breach may be both a service problem and a data problem.
Where the companies act and UK GDPR intersect
The Companies Act 2006 pushes directors to act with care and proper judgment. UK GDPR and the Data Protection Act 2018 push the business to protect personal data and report breaches where needed.
That mix matters because a supplier breach can create two losses at once. One is the insured trading loss. The other is the compliance burden, which the policy may or may not cover.
A policy can cover the money you lose while trading stops and still exclude the cost of fixing every downstream issue. That split catches plenty of SMEs out.
Extra cover is worth buying when a single vendor could stop sales, payments, or fulfilment for days. It is less useful when the business can switch providers quickly or absorb the hit from cash reserves.
The strongest view is practical. Buy cover where the dependency is real, the numbers hurt, and the wording clearly follows the loss. Skip it where the cost is high and the interruption would stay small.
"The policy is only as good as the trigger you can prove."
Extra cover is usually worth it when the supplier handles payments, hosting, booking, or core customer data. Those are the jobs that can stop revenue quickly.
It is also more sensible when the business has tight cash flow. A two-week interruption can cause more damage than the annual premium for a modest extension.
When self-insurance may be enough
Self-insurance can be enough when the business can move to another supplier in a day or two. That is common with ordinary office services and some non-core software.
It can also work where the loss would be annoying rather than dangerous. If the business can ride out a short outage without missing payroll or contracts, buying broad supplier BI may not give good value.
Frequently asked questions about cyber insurance for UK SMEs
What is not covered under cyber insurance?
Cyber insurance often excludes losses caused by ordinary equipment failure, power cuts, telecoms outages, insolvency, and contract disputes. Many policies also exclude issues that happen before the waiting period ends. The exact answer depends on the wording, but most gaps appear around events that are not clearly cyber in nature. That is why supplier cover needs careful checking.
What does cyber insurance coverage cover?
Cyber insurance usually covers response costs, data breach costs, ransomware events, and business interruption from an insured cyber incident. Some policies also cover dependent business interruption when a supplier or customer is hit. The key point is that cover only works if the policy wording includes the right trigger and the right type of third-party event.
Is supply chain a cyber attack?
Supply chain is not always a cyber attack, but it can be part of one. If a supplier is hacked, ransomware may spread into your operations through lost access, stolen credentials, or a shutdown of a key service. The policy will usually care about the cyber cause, not the supply chain label. That is why the trigger wording matters so much.
What cyber incidents are covered by insurance?
Many cyber policies cover ransomware, data breaches, malware, phishing-related losses, and some forms of service interruption. Some also cover supplier incidents under dependent BI or supplier BI extensions. Coverage varies a lot by insurer, so two policies that look alike on price can behave very differently after a breach.
Does a supplier breach count as business interruption?
It can, but only if the policy treats that supplier breach as a covered source of interruption. Business interruption from your own systems is not the same as dependent business interruption from someone else’s breach. The loss may feel identical, yet the claim outcome can be very different. The policy wording decides that.
Should a small company buy supplier breach cover?
A small company should buy supplier breach cover if one provider could stop trading, delay payments, or break customer contracts. If the business can switch suppliers quickly and survive a short outage, extra cover may not be worth the cost. The best test is simple: if the supplier vanished for 72 hours, would cash flow wobble badly?
How do I know if my policy has a gap?
A policy gap often appears when the wording mentions cyber insurance, but not supplier BI, dependent BI, or named third parties. A gap can also appear through a low sub-limit, a waiting period, or an exclusion for operational failure. If the broker cannot show exactly where supplier loss is covered, assume the gap still exists.