Retail and E-commerce Clients: Why Cyber Insurance Is Getting Harder and How to Turn It Around

Retail and e-commerce businesses are under sustained pressure from cybercriminals, and the insurance market knows it. Retail cyberattacks rose 34% in 2025 compared with 2024, and the high-profile incidents at major UK retailers that year confirmed what underwriters had already started to act on: the retail sector is a target-rich environment, and the consequences of a successful attack can be severe and far-reaching. The UK Cyber Monitoring Centre has since classified the combined ransomware attacks on Marks & Spencer and Co-op as a Category 2 systemic event, with the financial impact across the affected retailers estimated at £270 million to £440 million, underlining just how far the consequences of a single incident can spread.
For brokers with retail and e-commerce clients, this creates a familiar tension. The clients need good cyber cover. Underwriting scrutiny is tightening even as headline pricing stays soft, and standard proposal forms are producing submissions that underwriters are scrutinising ever more carefully, and in some cases declining. The question is how to change that dynamic.
Infoprotect's white paper on retail and e-commerce cyber insurability sets out the detail, but the scale of the problem is worth sitting with first. Ransomware featured in 44% of confirmed retail breaches in 2025, up from 32% the year before, and third- party involvement in breaches doubled to 30%. Bot activity is a growing part of that picture too: 64% of bot attacks on retail now target API business logic, and bad bot traffic accounts for 39% of all traffic to online retailers. These are the areas standard compliance assessments tend to miss, and they're exactly what Infoprotect's Cyber Assess framework is built to cover.
The human factor matters most in retail, and the M&S and Co-op attacks are the clearest illustration available. The UK Government's Cyber Security Breaches Survey 2025/2026 found that the attackers behind those incidents, the Scattered Spider group, used pretexting against IT help desks rather than a purely technical exploit to gain access. Customer-facing businesses tend to have high staff turnover and variable levels of security awareness across the workforce, and that combination is exactly what this kind of social engineering exploits. It's a good example of why a technical security assessment on its own leaves a real gap in the picture underwriters see.
That gap is what Cyber Assess is designed to close, and the white paper walks through exactly how, from the specific risk vectors it examines to the governance and human-risk factors most standard assessments overlook. The short version: brokers who've taken a retail client through the process get a validated report rather than a self-declared questionnaire, and that credibility difference tends to show up directly in coverage terms and premium.
It's also worth noting what the M&S, Co-op, and Harrods incidents tell us about the direction of travel, more than a year on. All three were significant businesses with real security investment, and the attacks still succeeded, at a combined cost now put at up to £440 million. That has sharpened insurer focus on governance and resilience rather than just technical controls. The businesses in the strongest position at renewal are those that can show they've assessed their risk honestly, identified gaps, and acted on them.
Download the Retail and E-commerce white paper and get in touch with Brad or Hazel to discuss how Cyber Assess could work for your retail sector clients.
Sources:
https://heimdalsecurity.com/blog/retail-cybersecurity-statistics/
https://www.swif.ai/blog/retail-cybersecurity-statistics
https://www.cloudswitched.com/news/uk-cyber-security-breaches-survey- 2025-2026-sme-wake-up-call)
https://www.swif.ai/blog/retail-cybersecurity-statistics
https://www.cloudswitched.com/news/uk-cyber-security-breaches-survey- 2025-2026-sme-wake-up-call
About Infoprotect UK
Infoprotect helps businesses achieve cybersecurity compliance, maturity and customer satisfaction.
We also have a symbiotic relationship with Insurance Brokers to provide effective “cyber risk management” for their clients, which is critical for organisations of all sizes and types as cyber threats continue to evolve and become more sophisticated. It can help prevent data breaches, reduce the impact of cyber-attacks, and protect an organisation’s reputation and financial stability.
Our agile, personalised human approach differentiates us. We deliver business value to our clients through our commitment and dedication to service delivery.
Our Cyber Assess, Cyber GRC and Cyber Protect solutions are industry-leading cybersecurity services.
