Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Cyber Insurance by Industry

Cyber Insurance for Retailers: M&S Claimed £100m, Co-op Did Not

By the Assured Cyber Protection team · Updated 2026 · Reviewed

The case for cyber insurance for retailers was settled in the spring of 2025, and it was settled by three British high street names being hit within ten days of each other. Marks and Spencer took a hit it valued at around £300m of operating profit and prepared a claim of up to £100m against a policy that was already in place. The Co-op lost £206m of revenue and around £80m from first-half operating profit, and its finance chief put the full-year earnings impact at roughly £120m. Harrods contained an attempted intrusion inside about a day. The difference between those outcomes was not luck, and it was not the size of the security budget.

This page covers what those attacks actually exploited, why retailers underwrite badly, and the specific evidence a UK retail business needs before an insurer will quote sensibly.

Why retailers are targeted specifically

Retail sits at the intersection of three things attackers want: card data, large customer databases, and revenue that stops the moment the tills or the website stop. That last point is the one most shop owners underestimate. In a professional services firm, a ransomware incident is disruptive. In a retailer, it is an immediate revenue outage, and it compounds every hour.

The 2025 attacks demonstrated the mechanism plainly. The M&S breach was traced back to February 2025 and disclosed on 22 April, and it did not begin with a clever exploit. Attackers socially engineered a service desk into resetting an internal password, working through a third-party contractor, and then deployed DragonForce ransomware. Personal data from as many as 9.4 million online accounts was taken, including names and contact details. Payment card details and passwords were not compromised.

The Co-op detected its incident on 29 April 2025 and pre-emptively pulled access to systems before encryption could complete. That decision limited the ransomware damage and caused the revenue loss, because payments failed and shelves emptied while systems were down. Personal data for all 6.5 million members was still taken: names, dates of birth and contact details, with no financial data or passwords exposed. Harrods confirmed an attempted unauthorised access on 1 May 2025 and contained it within roughly 24 hours by restricting internet access.

Three retailers, one attack pattern, and the common entry point was a person on a help desk rather than a firewall. Our guide to social engineering and business email compromise cover covers why that specific route causes so many coverage arguments.

Reported cost of the 2025 UK retail cyber attacks, in millions of pounds Horizontal bar chart. Marks and Spencer operating profit impact 300 million pounds. Co-op lost sales revenue 206 million pounds. Co-op projected full-year earnings impact 120 million pounds. Marks and Spencer insurance claim prepared, up to 100 million pounds. Co-op first-half operating profit hit 80 million pounds. Revenue and profit measures are not directly comparable and are labelled separately. What the 2025 retail attacks cost, and what insurance covered Figures as reported by each company. Revenue and profit measures are separate; do not add them together. M&S operating profit impact £300m Co-op lost sales revenue £206m Co-op full-year earnings hit £120m M&S insurance claim prepared up to £100m Co-op H1 operating profit hit £80m Green bar = the only figure an insurer was expected to pay. Co-op held front-end incident response cover only and did not expect to claim for its back-end losses. Sources: M&S and Co-operative Group reported figures, 2025 to 2026. Chart by Assured Cyber Protection.
Chart by Assured Cyber Protection. Reported costs of the April 2025 attacks on M&S and the Co-op, with the portion expected to be recovered from insurance.

What the insurance actually did

M&S had a policy arranged through a broker with a tower running up to £100m, and it prepared to claim close to that. Even so, the recovery covers roughly a third of the profit hit. Cyber insurance did not make M&S whole, and it was never going to.

The Co-op position is more nuanced than the headlines suggested. It is widely repeated that the Co-op had no cyber insurance. What the group actually described was front-end cover, the immediate incident response services from third parties, without the back-end balance sheet protection, and it did not expect to claim for the bulk of its losses. That distinction matters when you buy a policy, because a cheap policy that only funds a response retainer will pay for the forensics and nothing else.

The practical lesson for a smaller retailer: read what the policy pays for, not what it is called. Our breakdown of first-party versus third-party cyber cover and how to read a cyber insurance policy walk through the sections that decide this.

The cover a retailer actually needs

Ranked by what would have mattered in the 2025 incidents:

Business interruption, including systems you do not own. Lost trading income while tills, the website or the warehouse system are down is the largest number in a retail cyber loss. Check whether the definition extends to outages at your payment processor, ecommerce platform or logistics provider, because plenty of retail interruptions start somewhere else. Check the waiting period too: cover that starts after 24 hours is worth far less to a shop than to an office.

Contingent and supply chain exposure. The M&S entry point ran through a third-party contractor. If your policy only responds to incidents on your own network, a supplier compromise that stops your trading may sit outside it entirely.

Data breach response and notification. Six and a half million records is a Co-op-scale problem, but even a modest customer database triggers ICO obligations on a tight clock. Our 72-hour ICO breach notification calculator sets out the deadline.

PCI fines and assessments. Card industry fines and forensic investigation costs are a retail-specific head of loss and are frequently sub-limited or excluded. Check for an explicit PCI extension rather than assuming general cover picks it up.

Social engineering and funds transfer fraud. Usually a separate insuring clause with its own, much lower limit. Given how the 2025 attacks started, do not treat it as optional.

PCI DSS 4.0 is now an underwriting question

Since 31 March 2025, all 64 of the new PCI DSS v4.0 requirements are mandatory. As of April 2026 there is no grace period and no legacy v3.2.1 to fall back on, so a retailer still running the old controls is simply non-compliant. The current standard is documented by the PCI Security Standards Council.

Two consequences for insurance. First, underwriters increasingly want documented proof that the controls are live rather than an annual self-attestation, and retailers who can produce it get through underwriting faster with fewer follow-up questions. Second, insurers can and do dispute claims where compliance evidence cannot be produced, which turns a paperwork gap into an uninsured loss.

The gaps that come up most often are payment page script inventory and tamper detection under requirements 6.4.3 and 11.6.1, followed by incomplete multi-factor authentication on vendor and third-party access. That second one is exactly the route the 2025 attackers used.

Merchant level sets the workload. Broadly, ecommerce retailers processing between 20,000 and one million transactions a year need a self-assessment questionnaire plus quarterly scans, while those under 20,000 need the questionnaire. Confirm your level with your acquirer rather than guessing.

Alongside this, Cyber Essentials certification is the cheapest way for a small retailer to evidence baseline controls, and some insurers bundle a limited policy with it. See free cyber insurance with Cyber Essentials for what that cover does and does not include.

What a small retailer should do this quarter

You are not going to build an M&S security programme. You do not need to. Four things move the needle:

  1. Lock down password resets. Every 2025 attack ran through identity, not malware. Require verified identity for any help desk reset, and enforce MFA on admin and supplier access paths.
  2. Know your worst trading day. Work out what one day, three days and a week of downtime costs you. Our downtime cost calculator does the arithmetic, and that number sets your business interruption limit.
  3. Get the PCI evidence into a folder. Script inventory, tamper detection, MFA coverage, scan reports. You need it for compliance anyway, and it shortens underwriting.
  4. Buy for interruption, not just for breach. Most small retail policies are sold on notification costs. The money in a retail cyber loss is in the trading you could not do.

For pricing context, see cyber insurance costs for UK small businesses in 2026, and the official baseline guidance for small organisations from the NCSC.

Frequently asked questions

Do small shops really need cyber insurance? If your revenue stops when your systems stop, yes. The relevant number is not the size of your customer database, it is how much trading you lose per day of downtime. That figure is often larger than a small retailer expects.

What did the 2025 M&S and Co-op attacks actually cost? M&S put the impact at around £300m of operating profit for the year to March 2026 and prepared a claim of up to £100m. The Co-op reported £206m of lost revenue, roughly £80m off first-half operating profit, and a projected £120m full-year earnings impact.

Does cyber insurance cover PCI fines? Sometimes, and usually under a specific extension with its own sub-limit. Card scheme fines and forensic investigation costs are commonly carved out of general cover, so check for a named PCI clause rather than assuming.

Will an insurer refuse to pay if I am not PCI compliant? It can create a serious dispute. Underwriters increasingly require documented evidence that controls are operating, and inability to produce that evidence after an incident is a common reason claims stall or are reduced.

Does cyber insurance cover an attack that started at a supplier? Only if the policy includes contingent or supply chain business interruption. The M&S breach reached the network through a third-party contractor, so a policy limited to your own systems can leave that route uncovered.

What is the single most effective control for a retailer? Multi-factor authentication combined with a strict identity check before any password reset. Each of the 2025 retail attacks began by manipulating a person into granting access, not by defeating a technical control.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.