An online retailer may depend on a store platform, payment processor and fulfilment systems supplied by different companies. Cyber insurance comparison starts with identifying where a disruption would stop sales and which costs would remain with the retailer.

Incident response and cyber cover

Cyber policies can address different combinations of response services, the insured business’s own losses and third-party allegations. Check each section rather than relying on the product name. Security obligations and consent before spending can be important parts of the comparison.

Premiums, excesses and usable cover

Request quotations using the same business description, required limits and relevant dates. Put the annual premium, any instalment charges, excesses and important sublimits in one comparison. A cheaper premium can represent a different transfer of risk rather than the same cover at a better price.

Comparison item Question to resolve
Customer data and payment arrangements Which external-service disruptions are accepted?
Revenue dependent on external platforms Is fraudulent fund transfer a separate section?
Security controls and fraud-verification procedures Who authorises incident-response spending?

Request the proposed wording and schedule, not just a price or certificate. Mark any difference that affects a real activity before deciding whether the premium saving is worthwhile.

The decision that deserves the closest review

Distinguish a breach of customer information from payment fraud, supplier downtime and an internal system failure. Ask about dependent-service interruption, incident-response providers and consent before incurring costs. The payment provider’s protection should not be assumed to cover every merchant loss.

Prepare an accurate insurance enquiry

Give each adviser a consistent description of the activities being insured. Include important contracts, changes since the previous enquiry and matters the insurer asks you to disclose. Do not guess answers merely to obtain a faster or cheaper quote; ask for clarification when the proposal wording is unclear.

Follow the online order through a disruption

List the systems used for checkout, payments, order handling and customer communications. Identify which are controlled by the retailer and which belong to a platform or supplier. Then estimate the operational effect of losing each one, including the work needed to restore reliable order records.

Ask insurers to explain the proposed response to an intrusion, a payment-instruction fraud and a platform outage separately. These events can raise different wording questions. Keep proposed security controls, external service dependencies and any assumptions about interrupted trading in the same comparison document.

Include overseas work or sales in the UK business’s enquiry and confirm the accepted territories and jurisdictions.

A hypothetical example

A retailer cannot process orders after its fulfilment integration fails. Its loss depends on the trigger, duration and policy definition of interruption, not simply on whether the incident happened online.

A mistake to avoid

Assuming that every failed online transaction is an insured cyber event.

Check what happens after the policy starts

Ask who to contact when activities change or a potential claim arises. Understand the notification and consent process before arranging repairs, appointing specialists or settling a complaint. At renewal, compare the new documents with the accepted business description; continuity of a familiar brand does not prove continuity of every term.

Questions before choosing

Does PCI-related responsibility disappear when payments are outsourced?

Clarify retained responsibilities with the provider and insurer; outsourcing a function does not automatically answer the coverage question.

Does a payment processor’s security eliminate the retailer’s exposure?

The retailer still needs to examine its own accounts, systems and contracts. Explain the division of responsibility rather than assuming one provider protects every part of the transaction.

Sources and further reading

Research date: 6 October 2026. Refer to the current linked guidance and written provider or adviser terms when making a decision.