A magenta line dividing a dark page into lit and unlit halves, cyber insurance exclusions defining the covered edge
Cyber Insurance • 8 min read

Cyber Insurance Exclusions That Decide Claims

Coalition put average global cyber claim severity at $116,000 for 2025, well under most policy limits. That means cyber insurance exclusions and sublimits, not the limit, decide what you collect.

Cyber insurance exclusions decide more claims than coverage limits do. A policy with a $1 million limit and a $150,000 social engineering sublimit pays $150,000 on a wire fraud loss, and that is the policy working as written. Reading the exclusions and sublimits before binding is how you find out what you actually bought.

I am Amelia S. Gagne, CEO of Kief Studio. This page covers the terms that shape a payout. Its companions are what a cyber insurance renewal application asks now and why cyber insurance claims get denied. For the coverage conversation itself, see cyber insurance questions for a small business.

A magenta line dividing a dark page into lit and unlit halves, cyber insurance exclusions defining the covered edge
The limit describes the ceiling. The exclusions and sublimits describe the shape of the room.

Why do cyber insurance exclusions matter more than the limit?

Because the limit is the least likely number to bind.

Coalition's 2026 Cyber Claims Report, drawn from more than 100,000 policyholders, puts average global claim severity at $116,000 for 2025, with ransomware averaging $269,000 and funds transfer fraud averaging $141,000. Most claims land well under a typical small business limit.

What determines the outcome at those sizes is whether the loss type is covered at full limit, covered at a sublimit, or excluded. That is a reading problem, not a purchasing problem.

Which sublimits should you look for first?

Social engineering and funds transfer fraud. This is the one to check before anything else. It is commonly carved into its own coverage line with a sublimit well below the policy limit. It is also the most likely loss to occur: Coalition found business email compromise and funds transfer fraud together accounted for 58% of observed incidents in 2025, with funds transfer fraud alone at 27% of claims.

Read whether the sublimit applies per claim or in the aggregate, and whether a callback verification requirement is a condition of coverage. Some forms require documented out-of-band verification of payment changes, which turns a process control into a coverage condition.

Ransomware and extortion. Often sublimited, sometimes with a coinsurance percentage. Note that dual extortion accounted for 70% of ransomware claims in Coalition's 2025 data, and claims involving data theft ran more than twice as expensive as encryption alone. A policy that handles restoration well but treats data exfiltration response thinly is matched to the older threat.

Business interruption and the waiting period. The waiting period is effectively a time deductible. An eight-hour waiting period on an outage that lasts six hours pays nothing. NetDiligence's 2026 Cyber Claims Study, covering 10,309 claims from 2021 through 2025, found that incidents involving business interruption cost small and mid-sized organizations more than five times as much on average as those without it. This is the coverage most worth understanding precisely.

Dependent business interruption. Your loss when someone else's outage stops your operation. If your business depends on a hosting provider or a managed service provider, this is the line that responds, and it is frequently narrower than the first-party equivalent. That dependency is the subject of what your vendor's security posture means for you.

Magenta bars of unequal height on black, sublimits inside a cyber insurance policy limit
A single policy limit usually sits above several smaller ones. The smaller ones decide most claims.

What exclusions come up most often?

War and hostile action. The language tightened substantially after the NotPetya litigation, and most current forms include an attribution mechanism. The question to ask is procedural: who decides attribution, on what evidence, and can you contest it. A clause that lets the insurer rely solely on a government statement is a different clause from one requiring objective evidence.

Failure to maintain standards. This is the exclusion that connects to the application. It conditions coverage on continuing to run the controls you described. It is the reason a quarterly check against your own answers is worth the hour.

Betterment. Insurers pay to restore, not to upgrade. If your recovery plan is to rebuild on better architecture, expect to fund the difference. Worth knowing in advance, because the rebuild decision gets made under time pressure.

Prior known circumstances. An unremediated vulnerability you already knew about can fall outside coverage. This is less a trap than an argument for tracking what you know and what you did about it.

Generative AI endorsements. A newer category. Some carriers now attach endorsements addressing AI-related exposures, which can restrict or clarify depending on the form. If your operations involve AI tooling, read this one rather than assuming it is boilerplate. The disclosure side of it is covered in building an AI policy before you need one.

How do you read a form without a coverage lawyer?

You do not need to become one. You need to run the form against your own likely losses.

The method that works is a short list of scenarios written before you read the policy, so the policy does not frame the question. Four that fit most small and mid-sized operations:

  1. Someone in accounts payable wires funds to a changed bank account after a convincing email thread.
  2. Your primary business system is encrypted, and the attackers also have a copy of the data.
  3. Your hosting provider or managed service provider goes down for two days and you cannot operate.
  4. A laptop with customer records is stolen, and you owe notification in several states.

For each one, find the coverage line, the sublimit, the retention, the waiting period if any, and the conditions. Write the number you would actually collect. That exercise takes about an hour and produces a more useful answer than a coverage summary, for the same reason a premortem beats a risk register.

Four magenta paths diverging across black, loss scenarios tested against cyber insurance exclusions
Write the scenarios before reading the form. Otherwise the form decides which questions get asked.

What is worth negotiating?

More than most buyers assume, particularly in a softening market. Marsh recorded twelve consecutive quarterly declines in cyber rates through the second quarter of 2026, and competitive markets are where terms move.

In rough order of value for a small or mid-sized buyer: raising the social engineering sublimit, shortening the business interruption waiting period, broadening dependent business interruption to name your actual critical providers, and clarifying the attribution process in the war exclusion.

Price is not the only lever, and it is often not the most valuable one. A lower premium on a form that sublimits your most likely loss is a worse outcome than a slightly higher premium on a form that does not. That is the same trade described in the sticker price is the smallest line item.

A magenta edge shifting outward against black, negotiating cyber insurance exclusions and sublimits
In a competitive market, terms move more readily than price. The sublimit is usually the better ask.

Where coverage meets construction

Insurance transfers financial consequence. It does not transfer the outage, the notification obligations, or the week your team spends on recovery. Coalition reported that 64% of closed claims in 2025 resolved with no out-of-pocket cost to the policyholder, which is a good outcome and still not the same as the incident not happening.

The controls that make a policy affordable are the same ones that make an incident smaller, which is why we treat this as an engineering question rather than a purchasing one. That framing is build compliance in, stop bolting it on.

Brian Gagne handles security architecture at Kief Studio. For control design rather than policy language, briansgagne.com goes deeper, and JDR Security Solutions handles cloud posture and IAM review. The managed operations model is at ltfi.ai.

Related reading

Frequently Asked Questions

What are the most important cyber insurance exclusions to check?

Start with the social engineering and funds transfer fraud sublimit, since that is the most likely loss. Then read the war and hostile action exclusion, the failure to maintain standards condition, the betterment exclusion, and any generative AI endorsement attached to the form.

Is social engineering covered by cyber insurance?

Usually, but often as a separate coverage line with a sublimit well below the policy limit, and sometimes conditioned on documented out-of-band verification of payment changes. Check whether the sublimit is per claim or aggregate before binding.

What is a business interruption waiting period?

A time-based deductible. If the waiting period is eight hours and your outage lasts six, the coverage does not respond. Shortening it is one of the more valuable things to negotiate, because NetDiligence found interruption incidents cost small and mid-sized organizations over five times more than incidents without interruption.

Does cyber insurance pay to improve my systems after an incident?

Generally no. Betterment exclusions limit payment to restoring what existed rather than funding an upgrade. If your recovery plan involves rebuilding on better architecture, plan to fund the difference yourself.

Can small businesses negotiate cyber policy terms?

Often yes, especially in a competitive market. Marsh recorded twelve consecutive quarterly cyber rate declines through Q2 2026. Raising the social engineering sublimit and shortening the interruption waiting period are usually worth more than a small premium reduction.

Cybersecurity Sep 19, 2026 • 8 min

Cyber Resilience Tools Cost vs Breach Recovery and Fines

Cyber resilience tools cost versus breach recovery and fines is a recurring number you choose against a one-time number you do not. IBM's 2026 average breach is $4.99 million globally and $11.5 million in the US. The fine is rarely the largest line.

Cybersecurity Oct 1, 2026 • 8 min

Why Cyber Insurance Claims Get Denied

Coalition found 64% of closed cyber claims in 2025 resolved with no out-of-pocket cost. Most claims pay. Here is what separates the ones that do not, and the five habits that close the gap.

Cybersecurity Sep 24, 2026 • 7 min

What a Cyber Insurance Renewal Application Asks Now

Marsh recorded cyber rates down 4% globally in Q2 2026, the twelfth straight quarterly decline, while underwriting evidence standards tightened. What a cyber insurance renewal application asks now, and the folder to have ready.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe