>> All posts

Understanding the terms in your cyber insurance quote

If you only compare the premium on a cyber quote, you are not comparing insurance. You are comparing invoices.

The number that hits Finance is real — and often the only line leadership scans. But the quote is a design for how loss will be shared if something goes wrong: what is covered, up to what amount, after what you pay first, with which carve-outs and sub-caps, for which legal entities, on which trigger. Two quotes with the same premium can be very different products.

This post is a field guide to the terms that usually matter on a cyber quote or indication. It is orientation for security and business leaders, not a substitute for your broker, coverage counsel, or the policy form itself. Wording varies by carrier, surplus-lines form, and year. When your packet disagrees with a blog, the packet wins.

Start with the shape of the deal

Before definitions, ask four structural questions:

  1. Is this standalone cyber, or cyber as part of a package? Package endorsements can look cheap and be narrow. Standalone forms are easier to compare — and still not identical.
  2. Claims-made or occurrence? Most standalone cyber is written on a claims-made (or claims-made and reported) basis: coverage often hinges on when the claim is made / reported, not only when the incident “happened,” and retroactive dates matter. Occurrence triggers are more familiar from other lines; do not assume cyber works that way.
  3. Who is the insurer of record? Admitted carrier, surplus-lines insurer, Lloyd’s syndicate, fronted program — your broker should say which, because complaint rights, filing, and form flexibility differ.
  4. What document are you holding? Indication, quote, binder, or specimen policy. Indications are directional. Binders and policies are where arguments get settled.

If those four are fuzzy, pause the premium debate.

The vocabulary that changes money and coverage

Limit (policy limit / each claim / aggregate)

The limit is the ceiling of what the insurer will pay for covered loss under the terms of the form — often expressed per claim / per occurrence and as a policy aggregate for the period.

What buyers miss: the headline limit is not always available for every insuring agreement. Sublimits (below) can make the big number feel larger than the coverage you will actually use for a given loss type.

Ask: Is the limit shared across all coverages? Are defense costs inside or outside the limit? (In cyber, defense and breach-response costs are often inside — they erode the limit as they are spent.)

Retention / deductible

What you pay before the insurer’s dollars attach for a covered loss. Higher retention usually means lower premium — you are keeping more frequency risk.

Ask: Is the retention each claim? Does it apply separately to each insuring agreement? Are there different retentions for ransomware, business interruption, or privacy liability? Can expenses you incur with an insurer panel vendor erode the retention?

Sublimits

Smaller caps inside the main limit for specific coverages — common examples in cyber conversations include social engineering / funds transfer fraud, contingent business interruption, hardware replacement, or certain regulatory fines where insurable. A $5M policy with a $250K social-engineering sublimit is not a $5M answer to a BEC wire fraud.

Read every sublimit. Premium shopping without sublimit shopping is how CFOs get surprised after a claim.

Aggregate vs each-claim

An aggregate caps total paid in the policy period across claims. Multiple incidents in a hard year can exhaust the aggregate even if no single event hit the each-claim limit. After the aggregate is gone, you are effectively self-insured for further covered loss in that period (unless other towers apply).

Waiting period (especially business interruption)

For business-interruption / system-failure style coverages, a waiting period (hours or days) often applies before BI loss begins to count. Short outages may never pierce it. That is not a “gotcha” unique to cyber — it is how time-element coverage is often designed — but it is easy to miss when IT is promising “we’ll be back up in a day.”

Coinsurance / participation

Some structures require you to bear a percentage of loss above the retention (not only a flat retention). Less common on every SME quote, more visible in some specialty structures. If you see a participation percentage, model a large ransomware event with it — not only the premium delta.

Named insured, additional insured, subsidiaries

Who is actually covered? Parent only? Named subsidiaries? Newly acquired entities after a waiting period or size threshold? Cyber incidents love to start in the affiliate nobody listed. Align named insured schedules with legal entity charts and the domains/systems you actually run.

Retroactive date / prior acts

On claims-made cyber, the retroactive date often defines how far back an incident can have occurred and still be eligible (subject to the rest of the form). A fresh policy with a retro date of “inception” is a different product than one that honors prior acts back several years. M&A and first-time buyers get burned here.

Insuring agreements (what “cyber” is made of)

Quotes often summarize several agreements under one premium. Typical buckets (names vary):

  • Breach response / privacy event services — forensics, legal, notification, call center, credit monitoring
  • Network security / privacy liability — third-party claims
  • Business interruption / dependent BI — your lost income / extra expense; sometimes a vendor’s outage
  • Cyber extortion / ransomware — negotiation, payment (where lawful and covered), related costs
  • Data recovery / system restoration
  • Funds transfer fraud / social engineering — often sublimited and conditioned

A cheap quote that gut-checks one of these agreements is not “the same coverage.”

Exclusions and endorsements (the quiet half of the quote)

War / hostile cyber ops, infrastructure failure, bodily injury, unencrypted devices, failure to maintain minimum controls, prior knowledge — the list is form-specific. Subjectivities (conditions you must meet before bind or as warranty) often matter as much as exclusions: MFA on remote access, EDR coverage, offline backups, privileged-access controls.

If the quote is attractive because subjectivities are light, ask whether the form is narrow instead.

A practical reading order for your next quote

  1. Insurer, form family, claims-made vs occurrence, retro date
  2. Named insured schedule vs your entity chart
  3. Each-claim and aggregate limits; defense inside/outside
  4. Retention(s) by agreement
  5. Every sublimit and waiting period
  6. Insuring agreements included vs optional
  7. Subjectivities / warranties / scanning requirements
  8. Then premium and commission math

Reverse that order and you will optimize for the wrong variable.

What “good” looks like in the room

A strong broker conversation sounds like: “Here are three structures. Same premium band, different retentions and ransomware sublimits. Here is a modeled $2M event under each.” A weak one sounds like: “Carrier A is $12K cheaper.”

Security leaders belong in that meeting — not to negotiate surplus-lines law, but to sanity-check whether subjectivities match reality and whether the loss scenarios finance is modeling match how you would actually get hurt.

Where BreachBits fits (and does not)

We do not draft policy wording and we do not sell insurance. Continuous outside-in assessment and a BreachRisk Score help you and your broker talk about exposures that are claim-relevant during application and renewal — the technical story next to the questionnaire. That is adjacent to underwriting quality. It is not a coverage opinion.

For how underwriting signal is changing beyond the form itself, see Kill the questionnaire — what underwriters actually need instead.

Authoritative starting points

Next in this series: who actually sits across from you — carrier, MGA, broker, reinsurer — and why you keep getting different answers from people who all somehow “do cyber insurance.”

See your cyber risk, proven.