A SaaS outage, payment processor failure or managed IT breach can halt trading, even when your own systems work. Supply-chain exposure: insurance for SMEs with vendor risk may cover lost income, extra costs and incident response. Cover applies only when the supplier trigger, waiting period and sub-limit match your dependency.
Can your policy cover a supplier cyber incident?
Supplier cover is often separate from cover for your own cyber attack. Test the wording before a disruption.
Your outage versus a supplier outage
Your own business interruption section usually responds when a covered cyber event disrupts your network, devices or data. Supplier interruption cover deals with a different chain of events. A cloud platform, managed IT firm, payment processor or outsourced warehouse is affected first. Your business then loses income.
A policy may offer a £1 million overall limit for your own incident. It may allow only a £100,000 sub-limit for a supplier event. It may also have a 12-hour waiting period.
The supplier’s problem can become your trading problem very quickly.
Which event triggers payment?
A supplier outage is covered only where the wording says it is. Many policies require ransomware, malicious code, unauthorised access, or a network security failure at the provider. Some policies accept another defined cyber event.
Planned maintenance, a contract dispute, a utility fault and non-malicious cloud failure may sit outside the clause. If the incident may involve a personal-data breach, assess it promptly. Notify the ICO where required, without undue delay and within 72 hours where feasible.
A supplier cyber claim normally needs four things. It needs a qualifying supplier, a qualifying cyber event, loss beyond the waiting period, and proof. You must show that the outage caused your financial loss. The overall policy limit alone does not answer these questions.
Policy labels are not always interchangeable. Business interruption usually concerns a covered event affecting your own systems. Contingent business interruption (CBI) addresses loss after an event at a third party.
Some insurers call this extension dependent business interruption or supplier interruption cover. The scope can differ a great deal. A policy may cover a direct SaaS supplier but exclude its hosting provider.
It may cover a malicious supplier cyber event but not an accidental cloud service failure.
Treat these labels as starting points, not promises of equal protection. The supplier definition, covered trigger and sub-limits set the true third-party cyber risk protection.
Which vendors create the largest uninsured gaps?
The largest gaps often involve suppliers that control revenue, customer data or fulfilment. These suppliers also cannot be replaced quickly.
A SaaS provider hosts an application that you access online. Examples include accounting, CRM, booking, payroll and e-commerce software. Think of it as rented software that lives elsewhere.
Its failure can halt work within minutes. Staff may be unable to see orders, issue invoices or access customer records. Check whether the definition includes technology providers.
It may cover only direct contractual suppliers or vendors named in the schedule. Sub-processors and other fourth parties may not be included.
A fourth party is a supplier used by your supplier.
Can an MSP affect every device?
A managed service provider, or MSP, runs some or all of your IT. It may have remote access to laptops, servers, backups, email administration and security tools. This access can make its outage or ransomware incident especially serious.
Insurers increasingly ask about multi-factor authentication, separate admin accounts and protected backups. These checks matter where an MSP has privileged access. Privileged access means power to change key systems.
The most common mistake is treating an MSP as just another supplier. An MSP may hold the keys to every device and backup.
Payments and logistics need separate checks
Payment processors and logistics providers can cause direct revenue loss. They may do this without touching your office network. A payment outage may stop checkout for six hours.
A cyber incident at a fulfilment partner can block dispatch. It can create refunds and missed commitments. The cloud or warehouse systems used by those suppliers may not be insured.
This gap remains unless the policy extends to indirect providers.
Map critical vendors and calculate your loss
A useful vendor register ranks suppliers by what happens if they fail today. It does not simply list software subscriptions.
Classify vendors by business impact
Start with providers that affect customer orders, payment collection, delivery, IT access or regulated data. Record the contract owner and service location. Record relevant sub-processors, incident terms and available alternatives.
| Vendor type | Critical when | Evidence to retain | Likely cover question |
|---|
| Cloud or SaaS | Orders, payroll or records stop | Contract, uptime terms, backup export | Is system failure included? |
| MSP | Remote access or backups fail | MFA proof, access list, recovery plan | Does provider compromise qualify? |
| Payments | Customers cannot pay | Fallback payment process, outage logs | Does a 6-24 hour wait apply? |
| Logistics or OT | Goods cannot be dispatched or made | Manual process, alternative carrier terms | Is this supplier within the definition? |
Calculate contingent interruption loss
Calculate lost gross profit or turnover, depending on the wording. Then deduct costs not incurred. Add reasonable extra expense.
A two-day payment outage might stop £30,000 of sales. It may leave £9,000 of product and delivery costs unpaid. If £4,000 of manual processing and refunds follows, the loss may be near £25,000.
This figure is before the excess and waiting period.
Record the lack of an alternative
No alternative supplier increases business risk and insurer concern. Record the real time needed to approve, configure and test an alternative. Do this for payment providers, warehouses and SaaS platforms.
Do not record the time hoped for during a crisis. Record the time that a tested switch actually needs.
Build the estimate around the policy's maximum indemnity period. Also assess the first hours of downtime. A business interruption loss can continue after a supplier restores service.
Orders may need re-entry. Deliveries may need rescheduling. Customers may need refunds. Staff may need to do manual work.
For one payment processor or warehouse, model a realistic recovery curve. Use 24 hours, 72 hours, one week and the full maximum indemnity period. Do not assume revenue returns at once.
Compare lost gross profit, saved costs and reasonable extra expense. Compare them against the supplier sub-limit, excess and waiting period. This shows whether cover funds real recovery or just early loss.
Read supplier wording before you buy cover
Policy wording decides whether a supplier incident is insured. Test the clause against your three to five most critical vendors.
Check the supplier definition
Ask whether cover applies to named suppliers or direct contractual suppliers. Ask if it includes all technology providers. Ask if it covers only entities listed in the schedule.
Also ask whether subsidiaries, overseas providers and sub-processors are covered. Territorial wording can affect where an event happens. It can also affect claims and breach-response costs.
The words around the supplier name can decide the claim.
Compare limits, waits and excesses
A sub-limit is a smaller maximum payment for one loss type. It sits within the wider policy limit. An excess is the amount you pay yourself.
A waiting period is time that must pass before interruption cover starts paying. Think of it like a time-based excess. A short outage may end before cover begins.
| Wording feature | Why it changes a claim | Question for broker or insurer |
|---|
| Supplier trigger | A non-malicious outage may not qualify | Does system failure include this provider? |
| Waiting period | Short outages may produce no payment | Is it 6, 12 or 24 hours? |
| Supplier sub-limit | It can be lower than the main limit | What is the maximum for dependent loss? |
| Cloud exclusion | A key SaaS platform may be carved out | Which cloud services remain insured? |
Regulatory fines and penalties are covered only where law permits and the policy says so. A supplier breach can still leave your business with duties. This applies if you control data under the Data Protection Act 2018.
You may need to notify affected people and handle complaints. You may also need to answer the Information Commissioner's Office.
Prepare evidence and act within 72 hours
Insurers want proof that you understand critical providers. They also want proof that you can work around a failure.
Keep the evidence insurers request
Keep a critical-vendor register, contracts and data-processing terms. Keep supplier security checks and cyber questionnaires. Keep proof of MFA for email and remote access.
Also keep backup test records, patching records and endpoint protection details. Keep incident-reporting clauses and business continuity plans.
Clear records make a supplier claim easier to evidence.
⭐
Picked for you
A FIDO2 USB security key gives directors and finance staff a stronger second sign-in check. It helps protect supplier portals and email. It is most useful where a password alone could expose payment, cloud or MSP access.
- It reduces phishing-led access risks for cloud administration accounts.
- It provides a physical second factor for finance and payment-provider logins.
- It supports MFA evidence often requested in cyber insurance proposals.
View on Amazon →
Take these steps after a vendor incident
Notify your broker or insurer as soon as the policy requires. Do this even if the supplier has not confirmed every detail. Preserve outage messages, screenshots, order records, payment logs and extra-cost invoices.
During the first 24 hours, confirm the affected service and restrict unsafe access. Activate workarounds. Between 24 and 72 hours, assess personal-data exposure and the ICO notification threshold.
This cover is less relevant where the concern is only physical supply disruption. Examples include a port delay, factory fire or fuel shortage without a cyber trigger. Property, marine, trade credit or specialist supply-chain insurance may fit these risks better. Cover also has limited value without meaningful digital or outsourced operational dependency.
Practical scenarios test whether workarounds will work under pressure. During a SaaS outage, keep records of status-page updates and check for read-only exports. Check if manual order capture can continue.
During MSP ransomware, isolate affected remote access. Confirm that backup administration is independent of the MSP. A payment outage may require a secure alternative route and abandoned-basket records.
A logistics-provider attack may need a temporary carrier and customer messages. Keep evidence of additional fulfilment costs.
In each case, contact the broker promptly and avoid admissions of liability. Keep time-stamped evidence. Confirm whether ransomware cover or supplier interruption cover has a relevant trigger.
Your questions answered
Does cyber insurance cover supply-chain attacks?
Cyber insurance may cover a supply-chain attack when contingent interruption cover applies. The supplier event must also meet the policy trigger. Check the supplier definition, sub-limit and waiting period before relying on it.
Does a SaaS outage count as a cyber claim?
A SaaS outage counts only if the wording covers that provider and cause. Planned maintenance, a contract dispute or a non-malicious outage may be excluded.
What is contingent business interruption?
Contingent business interruption cover pays for qualifying loss from a defined third party's disruption. It differs from cover for an attack on your own systems.
Will UK GDPR fines be covered after a vendor incident?
UK GDPR fines are covered only when the policy says so and law allows it. Your SME may still need to assess ICO notification within 72 hours. This applies when it controls the affected data.
What should I tell a cyber insurer about?
Tell the insurer about vendors controlling revenue, customer data, remote IT access or fulfilment. Give contracts, MFA proof, backup details, incident clauses and realistic alternative operating plans.
Can a short payment outage produce a claim?
A short payment outage may produce no interruption payment before the waiting period ends. Waiting periods can be 6, 12 or 24 hours. Extra costs may be treated differently, depending on the wording.
- Supplier cyber cover is separate from cover for attacks on your own systems.
- Your critical vendor list should include SaaS, MSP, payment, logistics and relevant fourth-party dependencies.
- Test the supplier definition, cyber trigger, sub-limit and waiting period against likely loss.
- Notify the broker early and assess UK GDPR reporting duties within 72 hours where personal data may be involved.
Learn more
Here are some additional resources on this subject: