Guide / Business Resilience

Read Your Cyber Policy Before You Need to Use It

Sublimits, coverage triggers, and vendor panel requirements decide whether a claim gets paid. A worksheet for reviewing your own policy line by line.

The short answer

The headline limit on a cyber policy is not the limit. Sublimits for social engineering fraud, business interruption waiting periods, claims-made retroactive dates, approved vendor panels, and warranted security controls decide whether a claim gets paid. Reading the policy for the first time during an incident is the preventable failure.

There is a specific and preventable failure that happens to small businesses after an incident. The company has a cyber policy, believes it is covered, calls a forensics firm on Monday, notifies the carrier on Wednesday, and discovers that both of those steps were done in the wrong order and the coverage is now in dispute.

The policy is not the problem. Reading it for the first time during an incident is the problem.

Here is the review to do at your desk, on a normal day, with a highlighter.

Find the sublimits

The headline limit is not the limit. Most cyber policies carry a top-line number and then a series of much smaller sublimits for specific coverages.

The ones to check. Social engineering or funds transfer fraud, which is frequently sublimited to a fraction of the policy limit and is also the coverage a small business is most likely to need. Business interruption, and specifically whether contingent business interruption from a vendor's outage is included at all. Ransom payment. Regulatory fines and penalties, where insurability varies by jurisdiction. Data restoration costs.

Write each sublimit next to the scenario it covers and compare it to what you modeled in your recovery planning. A $2 million policy with a $100,000 social engineering sublimit is a $100,000 policy for the event most likely to happen to you.

Understand the waiting period

Business interruption coverage typically does not begin until an outage has run for a defined period, often eight to twelve hours. If your realistic recovery time is under that, the coverage never triggers.

This cuts both ways and it is worth knowing. A shorter waiting period costs more premium and may be worth it for a business where a half day is genuinely expensive.

Check how the coverage triggers

Most cyber policies are claims-made. Coverage responds to claims made during the policy period, not incidents that occurred during it. Two consequences.

The retroactive date matters. Incidents before that date are excluded even if you discover them later, which matters enormously when you switch carriers.

Late notice can void coverage. Report promptly, and understand that many policies require notice of circumstances that might give rise to a claim, not only of confirmed claims.

Find the vendor panel

Nearly every cyber policy requires you to use approved vendors for forensics, legal counsel, and notification, or to get consent before engaging your own. Hiring your trusted local firm without approval can mean those costs are not reimbursed.

Get the panel list now. Better, ask your broker to pre-approve the specific firms you would want to use, which is often possible at binding and nearly impossible at 2am on a Saturday.

Write the carrier's incident hotline number on the same page as your incident response plan. That number, not your IT provider, is the first call.

Read the conditions you must maintain

Applications now ask detailed questions about your controls, and the answers become warranties. Look for conditions requiring multi-factor authentication on email and remote access, offline or immutable backups, endpoint detection, patching timelines, and employee training.

Then verify you actually meet them. Right now, not at renewal. Coverage disputes over misrepresented controls are a real and growing category, and the exposure is worse than having no policy, because you paid premium and planned around protection you do not have.

If something changed since your last application, tell your broker. A mid-term disclosure is inconvenient. A discovered discrepancy during a claim is catastrophic.

Look at the exclusions

War and hostile act exclusions have been redrafted across the market following litigation over state-attributed attacks. Read yours and ask your broker how the carrier interprets it, since attribution is often contested and the exclusion can be broad.

Also check for exclusions around unsupported software, which some carriers now include. If you are running an operating system past end of support, that clause may matter.

Prior known circumstances, betterment, and infrastructure failure exclusions are also worth reading in full.

The questions for your broker

Five, in writing, with written answers.

Is social engineering fraud covered, at what sublimit, and does it require the loss to involve a forged instrument.

Is contingent business interruption included, and does it cover a cloud provider outage.

What is my retroactive date and does it carry over if I change carriers.

What is the vendor panel, and can we pre-approve our preferred firms.

Which of my application answers are warranties, and what happens if one changes mid-term.

Get the worksheet

The Cyber Policy Review Worksheet is a structured review form: a sublimit table to fill in from your declarations page, the coverage trigger checklist, the maintained-conditions verification list with a column for evidence, the exclusion review, the broker question sheet, and a one-page incident contact card you can print.

An hour with your policy today is worth more than any control you could buy with the same hour.

Frequently asked questions

Why do cyber insurance claims get denied?

Common causes are a sublimit far below the headline number for the coverage you actually needed, engaging a forensics firm without carrier consent, late notice on a claims-made policy, and discrepancies between the security controls warranted in your application and what you actually had in place.

What is a cyber insurance sublimit?

A smaller cap applying to a specific coverage within the policy. Social engineering fraud is frequently sublimited to a fraction of the total, which matters because it is the coverage a small business is most likely to need. A two million dollar policy with a hundred thousand social engineering sublimit is effectively a hundred thousand dollar policy for the likeliest event.

Who should I call first after a cyber incident?

Your carrier's incident hotline, not your IT provider. Nearly every cyber policy requires approved vendors for forensics, legal counsel, and notification, or consent before engaging your own. Write that number on the same page as your incident response plan.

What questions should I ask my insurance broker about cyber coverage?

Five, in writing: is social engineering fraud covered and at what sublimit and does it require a forged instrument, is contingent business interruption included and does it cover a cloud outage, what is my retroactive date and does it carry across carriers, can we pre-approve our preferred vendors, and which application answers are warranties.

Related reading

Put this into practice

AEGITz Cyber Policy Review Worksheet

Use the working resource connected to this guide. No sales gate and no dead-end file link.

Download Excel workbookView resource details

Related reading

Keep following the decision.

Need help applying it?

Bring the real operating problem.

Schedule a Discovery Conversation