A standard cyber policy can look reassuring, yet fail when a phishing email redirects a client payment.
It can also fail when a freelancer’s login is compromised, and an ad account takeover presents another risk.
The cost is not limited to restoring access. Campaigns can stop, client ties can suffer, and spend may be lost.
Five endorsements beat the headline limit
A creative agency needs endorsements that match how it earns money. A large overall limit alone is not enough.
| Endorsement to request | Other policy names | Agency scenario | Wording test |
|---|
| Payment fraud | Social engineering, invoice manipulation, funds transfer fraud | A fake email changes a freelancer’s bank details | Does it cover an authorised employee’s mistaken payment? |
| Account takeover | Digital asset, social-media or cybercrime extension | A criminal controls a Meta Ads account and runs adverts | Are ad charges, recovery costs and client accounts included? |
| Dependent interruption | Contingent business interruption | A CRM or cloud platform outage delays a launch | Is the supplier named, and what waiting period applies? |
| Data restoration | Digital asset recovery | Campaign files are encrypted or deleted | Does it pay for restoration, rebuilding and forensics? |
| Media and privacy liability | Media liability, cyber privacy liability | A campaign triggers a copyright or privacy allegation | Are defence costs and IP exclusions clear? |
Payment fraud is not one label
Payment fraud cover matters when a producer, finance lead, or director can release money after an email request.
The common error is assuming a hacked email account means a bank transfer is insured. Many policies only respond if stated controls were followed.
Those controls may include a call-back to a known number. They may also require approval from two people.
A mistaken payment can be the agency’s largest immediate loss.
Privacy liability covers claims linked to personal data. Media liability can cover defamation, libel, or copyright claims in published work.
Professional indemnity may also cover client loss from poor advice or services. It may exclude cyber events or intentional acts.
🎯
Useful for this topic
An encrypted external drive can hold a separate copy of live campaign files. It helps while cloud-account access is restored.
It supports recovery planning. It does not replace tested backups or cyber cover.
- Keeps high-value creative files offline and away from a compromised cloud login
- Helps a team restart work during forensic checks and data restoration
- Reduces reliance on one SaaS storage provider for current campaign assets
Find on Amazon →
Priority should reflect the agency’s real cyber risk. Headcount alone does not show the likely loss.
A small studio may hold little personal data. It may still need payment fraud cover and campaign-file recovery first.
One diverted supplier payment or lost launch file can strain cash flow. An agency with many client ad accounts should rank account takeover higher.
It should cover unauthorised spend and digital asset recovery. A business reliant on one CRM, storage provider, or production platform needs outage cover.
Agencies using many freelancers should check each policy definition. Temporary workers, contractors, and outsourced IT firms must be included.
Ad accounts and SaaS create cover gaps
A hacked ad account or SaaS failure is covered only if the wording names the relevant account or supplier and trigger.
Ad-spend losses need express wording
Account takeover cover should state whether it pays for unauthorised advertising spend. It should also state whether it pays for recovery, crisis communications, and lost agency income.
Client repayment is a separate issue. Contractual liability may be excluded unless the relevant liability section covers the client’s loss.
SaaS failure has three tests
Dependent business interruption usually needs three things. It needs a defined supplier, a covered cyber event, and a waiting period.
The covered event must affect that supplier. Waiting periods often last 8, 12, or 24 hours.
A half-day outage can fall below the threshold.
Sub-limits decide what a policy pays
The lowest relevant sub-limit, excess, or waiting period sets the value of cyber insurance. The headline policy limit does not set it.
Ask for a one-page schedule comparison: Show the overall limit and each sub-limit. Show each excess, any waiting periods of 8 to 24 hours, the indemnity period, and whether limits apply per claim or policy year.
Small limits can be shared
Cyber extortion, forensics, breach notification, and data restoration may share one annual pot. “In the aggregate” means all yearly claims use that same pot.
Think of it as several household bills paid from one fixed account. One large claim can leave little for the next incident.
GDPR costs are wider than fines
A breach can create legal, notification, helpline, and PR costs. This can happen even if the ICO issues no penalty.
The ICO’s official guidance is the right starting point for reporting duties. The policy wording decides which costs the insurer pays.
These considerations matter less for businesses with no client or personal data. They also matter less where digital systems are not vital. Specialist crime, media liability, and business interruption policies may already cover these events. This cannot replace a wording review by an FCA-regulated broker or insurer.
A phishing-led mailbox breach can cause more harm than a single fraudulent payment. An attacker may enter a campaign email platform or CRM.
They may export client contacts, consumer data, mailing lists, creative briefs, and reporting files. They can then send convincing emails from a trusted address.
Costs may include forensic work, legal advice, notifications, call handling, PR, and data restoration. Clients may claim the agency failed to protect trusted information.
The error most agencies make is checking the overall limit first. They should check whether client-held data and rapid incident support are covered.
Check that privacy liability covers data held for clients. Check that it also covers the agency’s staff and prospects.
Check whether incident-response firms can be appointed quickly. Some policies require insurer approval first.
At renewal, give the broker a current list of key platforms. Include cloud storage, CRM, email marketing, payroll, and advertising tools.
State where personal data is stored. State the largest payment the agency can release and the value of active client ad spend.
Ask if social engineering cover includes invoice fraud after an employee follows a false instruction. Ask if cybercrime cover includes client-facing accounts.
Ask if supplier outage cover includes unnamed SaaS providers. These details can decide whether a claim is paid.
The schedule should show the media liability limit and any separate excess. It should also show payment checks and claim evidence requirements.
Useful evidence includes timesheets, invoices, and platform outage records.
Questions & answers
A hacked Meta Ads account is covered only if the wording includes account takeover or unauthorised advertising spend. Check client-owned accounts, ad charges, and recovery costs. Incident-response cover alone may not pay them.
Does cyber insurance pay ICO penalties?
Cyber insurance pays ICO penalties only where cover includes legally insurable fines and the law allows payment. It may still pay notification, legal, and investigation costs after a UK GDPR breach.
Creative agencies need media liability cover when published work could cause copyright, defamation, or privacy claims. Check whether professional indemnity already includes media and intellectual-property defence costs.
What does dependent business interruption mean?
Dependent business interruption can pay lost income when a covered cyber event disrupts a named supplier. General SaaS outages, planned maintenance, or losses below an 8 to 24-hour wait may not qualify.
How much cyber cover does a small agency need?
A small agency needs limits based on its largest likely payment fraud, ad-account loss, and outage cost. Compare each sub-limit. A £1 million headline limit does not guarantee £1 million for every event.
Key takeaways:- Buy payment fraud, account takeover, and supplier disruption cover before relying on the headline limit.
- Read alternative endorsement names carefully because insurer labels can mean very different cover.
- Test sub-limits, excesses, and waiting periods against a real agency loss.
- Check how client-owned accounts, freelancers, and outsourced IT are defined before renewal.
Related sources
These articles can help you explore the topic in more depth: