Coalition put average global cyber claim severity at $116,000 for 2025, well under most policy limits. That means cyber insurance exclusions and sublimits, not the limit, decide what you collect.
Cyber insurance exclusions decide more claims than coverage limits do. A policy with a $1 million limit and a $150,000 social engineering sublimit pays $150,000 on a wire fraud loss, and that is the policy working as written. Reading the exclusions and sublimits before binding is how you find out what you actually bought.
The limit describes the ceiling. The exclusions and sublimits describe the shape of the room.
Why do cyber insurance exclusions matter more than the limit?
Because the limit is the least likely number to bind.
Coalition's 2026 Cyber Claims Report, drawn from more than 100,000 policyholders, puts average global claim severity at $116,000 for 2025, with ransomware averaging $269,000 and funds transfer fraud averaging $141,000. Most claims land well under a typical small business limit.
What determines the outcome at those sizes is whether the loss type is covered at full limit, covered at a sublimit, or excluded. That is a reading problem, not a purchasing problem.
Which sublimits should you look for first?
Social engineering and funds transfer fraud. This is the one to check before anything else. It is commonly carved into its own coverage line with a sublimit well below the policy limit. It is also the most likely loss to occur: Coalition found business email compromise and funds transfer fraud together accounted for 58% of observed incidents in 2025, with funds transfer fraud alone at 27% of claims.
Read whether the sublimit applies per claim or in the aggregate, and whether a callback verification requirement is a condition of coverage. Some forms require documented out-of-band verification of payment changes, which turns a process control into a coverage condition.
Ransomware and extortion. Often sublimited, sometimes with a coinsurance percentage. Note that dual extortion accounted for 70% of ransomware claims in Coalition's 2025 data, and claims involving data theft ran more than twice as expensive as encryption alone. A policy that handles restoration well but treats data exfiltration response thinly is matched to the older threat.
Business interruption and the waiting period. The waiting period is effectively a time deductible. An eight-hour waiting period on an outage that lasts six hours pays nothing. NetDiligence's 2026 Cyber Claims Study, covering 10,309 claims from 2021 through 2025, found that incidents involving business interruption cost small and mid-sized organizations more than five times as much on average as those without it. This is the coverage most worth understanding precisely.
Dependent business interruption. Your loss when someone else's outage stops your operation. If your business depends on a hosting provider or a managed service provider, this is the line that responds, and it is frequently narrower than the first-party equivalent. That dependency is the subject of what your vendor's security posture means for you.
A single policy limit usually sits above several smaller ones. The smaller ones decide most claims.
What exclusions come up most often?
War and hostile action. The language tightened substantially after the NotPetya litigation, and most current forms include an attribution mechanism. The question to ask is procedural: who decides attribution, on what evidence, and can you contest it. A clause that lets the insurer rely solely on a government statement is a different clause from one requiring objective evidence.
Failure to maintain standards. This is the exclusion that connects to the application. It conditions coverage on continuing to run the controls you described. It is the reason a quarterly check against your own answers is worth the hour.
Betterment. Insurers pay to restore, not to upgrade. If your recovery plan is to rebuild on better architecture, expect to fund the difference. Worth knowing in advance, because the rebuild decision gets made under time pressure.
Prior known circumstances. An unremediated vulnerability you already knew about can fall outside coverage. This is less a trap than an argument for tracking what you know and what you did about it.
Generative AI endorsements. A newer category. Some carriers now attach endorsements addressing AI-related exposures, which can restrict or clarify depending on the form. If your operations involve AI tooling, read this one rather than assuming it is boilerplate. The disclosure side of it is covered in building an AI policy before you need one.
How do you read a form without a coverage lawyer?
You do not need to become one. You need to run the form against your own likely losses.
The method that works is a short list of scenarios written before you read the policy, so the policy does not frame the question. Four that fit most small and mid-sized operations:
Someone in accounts payable wires funds to a changed bank account after a convincing email thread.
Your primary business system is encrypted, and the attackers also have a copy of the data.
Your hosting provider or managed service provider goes down for two days and you cannot operate.
A laptop with customer records is stolen, and you owe notification in several states.
For each one, find the coverage line, the sublimit, the retention, the waiting period if any, and the conditions. Write the number you would actually collect. That exercise takes about an hour and produces a more useful answer than a coverage summary, for the same reason a premortem beats a risk register.
Write the scenarios before reading the form. Otherwise the form decides which questions get asked.
What is worth negotiating?
More than most buyers assume, particularly in a softening market. Marsh recorded twelve consecutive quarterly declines in cyber rates through the second quarter of 2026, and competitive markets are where terms move.
In rough order of value for a small or mid-sized buyer: raising the social engineering sublimit, shortening the business interruption waiting period, broadening dependent business interruption to name your actual critical providers, and clarifying the attribution process in the war exclusion.
Price is not the only lever, and it is often not the most valuable one. A lower premium on a form that sublimits your most likely loss is a worse outcome than a slightly higher premium on a form that does not. That is the same trade described in the sticker price is the smallest line item.
In a competitive market, terms move more readily than price. The sublimit is usually the better ask.
Where coverage meets construction
Insurance transfers financial consequence. It does not transfer the outage, the notification obligations, or the week your team spends on recovery. Coalition reported that 64% of closed claims in 2025 resolved with no out-of-pocket cost to the policyholder, which is a good outcome and still not the same as the incident not happening.
The controls that make a policy affordable are the same ones that make an incident smaller, which is why we treat this as an engineering question rather than a purchasing one. That framing is build compliance in, stop bolting it on.
Brian Gagne handles security architecture at Kief Studio. For control design rather than policy language, briansgagne.com goes deeper, and JDR Security Solutions handles cloud posture and IAM review. The managed operations model is at ltfi.ai.
What are the most important cyber insurance exclusions to check?
Start with the social engineering and funds transfer fraud sublimit, since that is the most likely loss. Then read the war and hostile action exclusion, the failure to maintain standards condition, the betterment exclusion, and any generative AI endorsement attached to the form.
Is social engineering covered by cyber insurance?
Usually, but often as a separate coverage line with a sublimit well below the policy limit, and sometimes conditioned on documented out-of-band verification of payment changes. Check whether the sublimit is per claim or aggregate before binding.
What is a business interruption waiting period?
A time-based deductible. If the waiting period is eight hours and your outage lasts six, the coverage does not respond. Shortening it is one of the more valuable things to negotiate, because NetDiligence found interruption incidents cost small and mid-sized organizations over five times more than incidents without interruption.
Does cyber insurance pay to improve my systems after an incident?
Generally no. Betterment exclusions limit payment to restoring what existed rather than funding an upgrade. If your recovery plan involves rebuilding on better architecture, plan to fund the difference yourself.
Can small businesses negotiate cyber policy terms?
Often yes, especially in a competitive market. Marsh recorded twelve consecutive quarterly cyber rate declines through Q2 2026. Raising the social engineering sublimit and shortening the interruption waiting period are usually worth more than a small premium reduction.
Cyber resilience tools cost versus breach recovery and fines is a recurring number you choose against a one-time number you do not. IBM's 2026 average breach is $4.99 million globally and $11.5 million in the US. The fine is rarely the largest line.
Coalition found 64% of closed cyber claims in 2025 resolved with no out-of-pocket cost. Most claims pay. Here is what separates the ones that do not, and the five habits that close the gap.
Marsh recorded cyber rates down 4% globally in Q2 2026, the twelfth straight quarterly decline, while underwriting evidence standards tightened. What a cyber insurance renewal application asks now, and the folder to have ready.