Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do merchants get wrong about outsourcing card…
Cyber Security

What do merchants get wrong about outsourcing card processing and cyber insurance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

A common mistake is assuming outsourcing or insurance transfers the underlying risk. Outsourcing card processing does not remove the need to secure refunds, reversals, chargebacks, and partner dependencies. Cyber insurance may help cover response costs, but it does not prevent breaches, restore compliance, or remove liability from the merchant when card data is exposed.

What merchants misunderstand about outsourcing card processing

Outsourcing the payment flow changes where certain operational tasks sit, but it does not change who owns the business outcome. A merchant still has to manage refund workflows, reconcile reversals, handle chargebacks, and monitor the third-party dependency that now sits between the customer, the card network, and the merchant’s own systems. If the processor fails, the merchant still feels the impact.

The practical mistake is treating the processor as a shield instead of a shared-control relationship. Payment processors can reduce direct handling of card data, but they do not eliminate obligations around customer service, dispute handling, settlement timing, fraud review, incident coordination, or contract management. Merchants that stop thinking about payment risk once the integration is live usually discover the hardest problems only after a dispute or outage.

That is why the relevant control question is not “did we outsource it?” but “what did we retain?” Retained obligations often include error handling, fallback processing, transaction evidence, monitoring of processor status, and escalation paths when a partner is down or compromised. In other words, outsourcing can reduce exposure, but it also adds dependency risk that must be managed explicitly.

Why cyber insurance does not transfer compliance or liability

cyber insurance is a financial backstop, not a preventive control. It may help with breach response costs, forensics, notification, or some legal expenses, but it does not stop card data exposure, restore trust, or erase the merchant’s contractual and regulatory obligations once an incident occurs. Coverage language also matters, because exclusions, sublimits, and notice requirements can leave the merchant with far less protection than expected.

Merchants often overread the policy and underread the operating conditions attached to it. Insurers usually expect basic security hygiene, evidence of controls, and timely incident reporting. If the merchant has weak logging, poor segmentation, stale access paths, or undocumented card data handling, the insurer may still pay something, but the merchant remains responsible for the operational failure and any compliance consequences tied to it.

For payment environments, the cleaner mental model is to separate financial indemnification from security responsibility. Insurance can soften the loss after a breach; it does not make the breach less likely, less disruptive, or less reportable. The merchant still needs card-data governance, vendor oversight, and a response plan that works even if the claim process is slow or contested.

Risk and Threat Considerations

The main risk is assuming a commercial contract removes technical and operational exposure. In practice, a processor or insurer can become a single point of failure, a dispute bottleneck, or a false sense of security if the merchant does not preserve its own monitoring, evidence, and fallback processes. For payment data, the most damaging failures are often not initial compromise alone, but delayed detection, weak reconciliation, and unclear accountability after a partner incident.

Failure mechanism: Card-processing outsourcing shifts transaction handling outward, but refunds, chargebacks, settlement errors, and incident response still depend on the merchant’s own controls and the processor’s availability. Cyber insurance similarly fails as a risk transfer mechanism when exclusions, notification delays, or unmet control expectations limit coverage.

Impact: The merchant can still face business interruption, regulatory scrutiny, customer dispute losses, and compliance fallout even when a third party is involved. If card data is exposed, the merchant may also carry reputational damage and operational recovery work that insurance reimburses only partially, if at all.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
PCI DSS v4.012 — Support Information Security with Organizational Policies and ProgramsMerchant card handling still needs security governance and incident planning.
10 — Log and Monitor All Access to System Components and Cardholder DataOutsourced processing still depends on visibility into disputes, failures, and possible card-data exposure.
12.10 — Incident Response PlanInsurance does not replace the need to respond to a payment incident or processor compromise.
Recommendation — Maintain documented payment-security responsibilities, evidence, and incident response procedures for retained merchant obligations. Retain logs and monitoring that support dispute handling and breach investigation for the merchant environment. Keep an incident response plan that covers processor outages, card-data exposure, and notification duties.
CIS Controls v814 — Security Awareness and Skills TrainingMerchants need staff who can handle chargebacks, outages, and breach procedures correctly.
17 — Incident Response ManagementThe question centers on what remains after outsourcing or insurance, including response coordination.
Recommendation — Train payment and support teams on retained incident, dispute, and escalation responsibilities. Define and rehearse incident response roles for merchant-managed payment and third-party failures.
NIST CSF 2.0GV.OC-01 — Organizational ContextThe merchant must understand what payment risk remains after outsourcing and insurance.
RS.CO-02 — Communicate Response InformationProcessor incidents and chargeback events require clear coordination and communication paths.
RC.RP-01 — Recovery Plan Is ExecutedOutsourcing creates dependency risk that must be covered by a merchant recovery path.
Recommendation — Document retained payment and insurance responsibilities in the organization’s operating context. Establish communication paths for processor incidents, disputes, and claim-related notifications. Test recovery steps for payment outages, settlement issues, and alternate processing arrangements.

Practitioner Guidance

What to verify: Confirm which payment responsibilities remain with the merchant after outsourcing, especially refund authority, chargeback evidence, incident escalation, and recovery from processor outages. If those steps are not documented, the merchant has not actually transferred the operational burden.

Decision rule: If a control, dispute, or outage would still require the merchant to act, treat that obligation as retained risk and design for it explicitly. If the merchant cannot prove how it would continue operations during a processor failure, the arrangement is fragile regardless of contract wording.

What practitioners underestimate: Insurance is often purchased as reassurance, but the policy only helps after an event and only within its terms. The better test is whether logging, evidence retention, vendor oversight, and response coordination would still support a defensible recovery if the claim were delayed or denied.

Practitioner takeaway: Outsourcing and insurance reduce some loss scenarios, but they do not remove merchant accountability for payment continuity, evidence, and compliance, so the real job is to retain enough control to survive the third party’s failure.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org