Cyber Insurance Exclusions and Sublimits: Reading Before You Claim

Many organizations buy cyber insurance expecting that, if an attack happens, the policy will cover the damage. Then an incident occurs, and they discover that the policy pays far less than they assumed, or not at all for certain costs. The surprise is rarely about the existence of coverage. It is about the exclusions, sublimits and conditions buried in the policy language.

This article describes common areas where policyholders are surprised. It is general information, not insurance or legal advice. Policies vary widely, so review yours with your broker and counsel.

Why the details matter

A policy may advertise a headline limit, such as a seven-figure amount. Within that limit, individual categories of loss may be capped at much lower amounts, and certain events may not be covered at all. The headline number tells you the maximum, not what you will actually recover.

Sublimits

A sublimit is a cap on a specific type of loss within the overall policy. Commonly sublimited items include:

Ransomware or extortion payments and response costs, sometimes with a lower limit or a coinsurance share the policyholder must pay

Business interruption, including limits on how long lost income is covered and a waiting period before coverage begins

Regulatory fines and penalties, often covered only where insurable by law

Social engineering and funds transfer fraud, where an employee is tricked into sending money, frequently with a low sublimit

Notification and credit monitoring costs, which may be limited by number of people or dollar amount

Data restoration and system rebuilding

Ask your broker for a list of every sublimit and compare each to a realistic estimate of what that type of loss could cost you.

Common exclusions

Failure to maintain security controls

Some policies exclude or reduce coverage if the insured did not maintain the security measures described in the application, such as multi-factor authentication or regular patching. If your application said MFA was enforced everywhere and it was not, the insurer may dispute the claim.

War and state-backed activity

Many policies include exclusions for acts of war or attacks attributed to nation-states. The wording varies and has been the subject of disputes. Read the language closely and ask how attribution is determined.

Infrastructure failures

Outages of power, internet or cloud providers outside your control may not be covered, or may be limited to dependent business interruption coverage if you have it.

Prior known incidents

Events that began or were known before the policy start date, or the retroactive date, may be excluded.

Unencrypted data

Some policies limit coverage if lost devices or data were not encrypted.

Betterment

Insurers may not pay to upgrade your systems beyond their previous condition. If rebuilding after an attack requires stronger equipment, the difference may be your cost.

Bodily injury and property damage

Cyber policies often exclude physical harm. In care settings, consider how a technology failure that affects resident safety would be treated, and discuss it with your broker and your general or professional liability carriers.

Conditions that can void or complicate a claim

Notice requirements. You may need to notify the insurer within a short window of discovering an incident, sometimes within days.

Consent before action. Many policies require approval before you hire response firms, negotiate with attackers or make payments.

Panel vendors. Insurers may require you to use their approved incident response and legal firms.

Cooperation duties. You must preserve evidence and provide documentation.

Accuracy of the application. Misstatements, even honest ones, can be grounds for denial.

Questions to ask your broker

What are all sublimits and retentions, and how do they apply to a ransomware event?

How long is the waiting period for business interruption, and how is lost income calculated?

Does coverage include dependent business interruption from vendors and cloud providers?

Are regulatory fines covered, and under what conditions?

What security controls does the application assume, and what happens if one lapses?

Do we need insurer approval before engaging a response firm?

Is there coverage for social engineering fraud, and at what limit?

How are acts of war defined?

Make the application honest and accurate

Insurance applications ask detailed questions about your security practices. Have your IT provider review answers before you sign. Overstating your controls to secure a better rate can backfire when a claim is filed.

Prepare before an incident

Keep a printed copy of your policy and the claims hotline where you can find it if systems are down. Include the insurer in your incident response plan, and run a tabletop exercise that includes calling them.

Working with UnityCare IT

UnityCare IT helps organizations verify that the controls promised on an insurance application are actually in place and documented. That alignment protects both your security and your coverage.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172