Cyber Insurance Fine Print: The Endorsements, Triggers and Exclusions That Decide Your Claim

Binary code raining down around a dark umbrella that shelters a fingerprint with a padlock inside, representing cyber liability insurance protecting business data

Most business owners in our area have stopped arguing about whether they need cyber coverage. The harder question came next, and it is the one that decides whether a policy is worth what you paid: when something happens, does this thing actually pay?

Cyber is not standardized the way property and auto are. Two policies with the same limit and a similar premium can behave completely differently in a claim, because cyber is assembled from insuring agreements and endorsements rather than sold as one product. The differences hide in three places: which coverages you selected, how the policy is triggered, and what the exclusions page says.

This is a guide to those three places. If you are earlier in the process and want the basics and current pricing, start with what a 10-person DMV business actually pays for cyber. This picks up after that.

Key takeaways

  • Cyber policies are assembled from endorsements. The limit on the declarations page tells you very little about what is actually covered.
  • If defense costs sit inside your limit, legal bills can consume the policy before you reach a settlement. Ask whether defense is inside or outside the limit.
  • Almost all cyber is written claims-made, meaning the claim has to be reported during the policy period or an extended reporting period.
  • A failure to maintain exclusion lets an insurer deny a claim if your actual security fell below what you described on the application. Answer the questionnaire honestly.
  • Cyber does not cover stolen hardware, employee dishonesty, your own intellectual property, or professional mistakes. Those live in four other policies.

One: the coverages you have to ask for

Below are the pieces most commonly assembled into a business cyber policy. Some carriers include several by default. Others price each one separately. The only way to know which you have is to read your schedule of insuring agreements, not the marketing summary.

Coverage What it does Why it matters
Forensic investigation Pays for analysts to reconstruct how the breach happened and what was taken. Nearly every other coverage depends on this. You cannot notify people accurately, or prove you were not at fault, without it.
Breach response and notification Notification to affected individuals, call center, credit monitoring, public relations. Notification is legally required in all 50 states. This is the cost most owners underestimate.
Business interruption Lost income while your systems are down. Often the single largest number in a ransomware claim. Check the waiting period, usually 8 to 12 hours.
Dependent business interruption Lost income when a vendor you rely on goes down. Your payroll processor or hosting provider gets hit and you cannot operate. Frequently excluded unless added.
Cyber extortion and ransom Ransom payment plus professional negotiators. The negotiator matters more than the payment. Confirm sublimits, which are often well below the policy limit.
Data restoration Rebuilding corrupted or encrypted data and systems. Restoring from backup is labor, not magic. This funds the labor.
Regulatory defense and fines Defense of state or federal regulatory proceedings, and fines where insurable. Insurability of fines varies by state. Ask specifically.
Betterments Offsets required upgrades to hardware or software after a covered breach. Insurers and regulators often require remediation as a condition of settlement. Without this you fund it yourself.
Cyber crime and funds transfer fraud Money leaving your accounts through fraudulent instruction. Usually a low sublimit and frequently confused with employee theft, which it does not cover.
Media liability Claims arising from content you publish. Relevant if you market heavily or your social accounts are a business channel.
Response coaching Access to a breach coach, typically an attorney, before anything goes wrong. Underused. The first 48 hours determine cost, and having a number to call is worth real money.

Two: how the policy is triggered

This is the part that gets skipped, and it decides whether a claim is even eligible before anyone looks at coverage.

Term What it means What to check
Claims-made Covers claims first made against you and reported during the policy period. Nearly all cyber is written this way. A breach that happened during the policy but is reported after it ends may not be covered.
Retroactive date The earliest incident date the policy will respond to. If you switch carriers, keep the original retroactive date or you create a gap behind you.
Extended reporting period A window after expiration in which you can still report claims. Ask the length and the cost. Buy it if you are changing carriers or winding down.
Per-occurrence Covers incidents that happen during the policy regardless of when reported. Rare in cyber. If a broker tells you a cyber policy is occurrence-based, verify it in the form.
Aggregate limit The most the insurer pays for everything in the policy period. Two unrelated incidents share one limit. See our note on how aggregate limits work.

Three: defense inside the limit, and why it matters

On many cyber policies, legal defense costs are paid from the same limit as everything else. Lawyers are expensive and cyber litigation is slow, so defense can erode the limit substantially before a settlement, a fine or a notification bill is paid. Here is the same $750,000 policy under both structures.

Defense INSIDE the limit

Legal defense $650,000
$100k

Only $100,000 remains for settlement, fines, credit monitoring and data recovery.

Defense OUTSIDE the limit

Full $750,000 available for the loss

Defense is paid in addition to the limit. Costs more in premium, and in a litigated claim it is usually the difference that matters.

Ask the question in exactly these words: are defense costs inside or outside the limit? If they are inside, ask what it would cost to move them outside, or whether an excess layer makes more sense.

Four: the exclusions that actually get claims denied

Exclusion What happens What to do about it
Failure to maintain If your real security controls fall below what you described on the application, the insurer can deny the claim as negligence. Answer the questionnaire truthfully even if it raises your premium. Then keep doing what you said you do. Re-check it at every renewal.
Dishonest or criminal acts A breach caused by an employee, contractor or volunteer is generally excluded. Add employee crime coverage or a fidelity bond. See how insider incidents are handled.
ERISA exposures Claims tied to your retirement or health plan data are typically excluded. Fiduciary liability coverage fills this. Relevant to nearly every employer offering a plan.
Your own intellectual property Client data is covered. Your trade secrets, designs and source code usually are not. Separate intellectual property coverage, or accept the exposure knowingly.
Prior known incidents Anything you were aware of before the policy started is excluded. Report suspected incidents before you switch carriers, not after.
War and infrastructure State-sponsored attacks and utility failures carry broad carve-outs. Wording varies widely by carrier. This is worth comparing form to form.

Where cyber stops and another policy starts

Cyber is narrower than the name suggests. These are the situations we see business owners assume are covered when they are not.

The situation Which policy responds
A client sues because the site you built for them was breached, or the technology you recommended failed. Technology errors and omissions. Not cyber.
You publish something defamatory in a newsletter or campaign. Media liability. Cyber may respond only if the account was hacked and you can prove it.
Laptops are stolen in a break-in. Commercial property replaces the hardware. Cyber responds to the data that was on it.
A bookkeeper moves money to their own account. Employee crime or fidelity. Cyber crime coverage does not apply to your own people.
Retirement plan participant data is exposed. Fiduciary liability, alongside cyber.

One incident, four policies

Here is how those overlap in practice. A break-in at a 30-person firm in Rockville. Three laptops taken, client records on two of them.

  1. Commercial property replaces the laptops.
  2. Cyber funds forensics to establish what data was on the machines, then notification, credit monitoring and legal defense.
  3. Cyber business interruption covers lost revenue while the network is remediated.
  4. Betterments covers the security upgrades you are required to make before resuming normal operations.

If the exposed records included card data, PCI reissue fees and assessments land on top. As an illustration, 2,000 cards reissued at roughly $10 each is $20,000 before any penalty for falling short of PCI standards. A PCI fines and penalties endorsement is what absorbs that.

Four coverages, one event. Miss any one and you fund that piece yourself.

What the law requires of you locally

Two different sets of rules apply, and business owners routinely conflate them.

Breach notification laws apply to nearly everyone. Maryland, Virginia and the District each require businesses that hold personal information to notify affected individuals after a breach. There is generally no employee-count or revenue threshold. If you hold customer data, this reaches you.

Comprehensive privacy laws have thresholds, and most small employers fall below them. The Maryland Online Data Privacy Act took effect October 1, 2025, with enforcement beginning April 1, 2026, and it applies to businesses handling data on at least 35,000 Maryland consumers, or 10,000 if more than 20 percent of revenue comes from selling personal data. Virginia Consumer Data Protection Act works similarly. Most 20 to 250 employee firms are under those thresholds, which is worth confirming rather than assuming in either direction.

One trap worth naming: if a vendor holding your client data is breached, you are often the one obligated to notify, not the vendor. Ask every vendor that touches client data for a certificate of insurance showing their own cyber coverage.

Frequently asked questions

Is my business too small to be a target?

No. Smaller firms are targeted precisely because their defenses are lighter and the effort required is lower. Attackers are not selecting by prestige, they are selecting by ease of entry.

We do not store Social Security numbers or card data. Do we still have exposure?

Yes. Names, email addresses, phone numbers and business relationships have value because they make the next social engineering attempt more convincing. Beyond that, ransomware does not care what your data is, only that you need it back.

Are defense costs inside or outside my limit?

It depends on the form, and it is the single most useful question you can ask about a cyber policy. Inside means legal bills reduce the money available for everything else. Outside means they do not.

What is a failure to maintain exclusion?

It permits the insurer to deny a claim if your actual security controls were weaker than what you represented on the application. It is why the questionnaire should be answered accurately even when a truthful answer raises the premium.

Does cyber insurance cover an employee who steals data?

Usually not. Dishonest acts by employees, contractors and volunteers are commonly excluded. Employee crime coverage or a fidelity bond addresses that exposure.

Talk it through with us

If you have a cyber policy and cannot answer the defense costs question, or you are not sure which endorsements you bought, send us the policy. We will read it and tell you plainly where the gaps are. We advise businesses across Maryland, DC and Northern Virginia, and we would rather find this now than during a claim.

Get in touch with Capitol Benefits

Related reading

Ready when you are

Let's take a look at what you've got.

A real review of your current coverage. No deck, no pressure, and usually some money saved along the way.