Modern businesses outsource email, hosting, payments, payroll, customer relationship management and other critical functions. That efficiency creates concentration risk: one third-party outage can disrupt thousands of companies at the same time.
CISA recommends that small and medium-sized businesses assess the security posture of vendors and suppliers because third-party access and supply-chain dependencies can become a route into the organization’s own systems. Insurance can transfer part of the financial impact, but it does not replace vendor risk management.
What is cyber contingent business interruption?
Cyber CBI—sometimes called dependent business interruption—can cover lost income and extra expenses when an insured organization is disrupted because a defined third party suffers a covered cyber or system event. This differs from direct cyber business interruption, where the insured’s own systems are affected.
| Scenario | Potential coverage area | Key policy question |
|---|---|---|
| Your own network is encrypted by ransomware | Cyber business interruption | What security-failure triggers and waiting period apply? |
| Cloud provider outage stops your website | Contingent/dependent business interruption | Is that provider covered or scheduled? |
| Vendor breach exposes your customers’ data | Privacy response and third-party liability | Does the policy cover vendor-caused breaches and regulatory costs? |
| Supplier cannot deliver after a cyber event | Cyber CBI or supply-chain coverage | Are non-IT suppliers included? |
Why vendor definitions matter
Some cyber policies use a broad definition of dependent business, while others distinguish technology providers from non-technology suppliers. Coverage can also be limited to specifically named vendors. A business that depends on one cloud platform should not assume every provider is automatically within the definition.
Watch the waiting period
Business interruption benefits often begin only after a waiting period. A short outage may cause operational pain but produce no insured BI payment if it ends before the waiting period. The waiting period can differ for direct and contingent losses.
Common limitations to review
- Separate CBI sublimits lower than the main cyber limit.
- Narrow definitions of covered service providers.
- Exclusions for critical infrastructure or widespread system failures.
- Different treatment of malicious attacks versus accidental system outages.
- Proof requirements for lost income and extra expense.
- Longer waiting periods for dependent-provider losses.
- Territorial restrictions or cloud-provider concentration exclusions.
How to build a better vendor-risk insurance review
Create an inventory of business-critical third parties, rank them by operational impact, document backup options, and map each dependency to the cyber policy. The most important vendors should be tested in tabletop exercises so finance, IT and risk teams know what evidence would be needed for a claim.
Insurance should complement contracts
Vendor contracts can include security obligations, indemnification and insurance requirements, but contractual recovery may be limited by liability caps or disputes. The insured organization’s own cyber policy may provide a more direct recovery path, depending on terms, while subrogation or contractual rights are handled separately.
Frequently asked questions
Does cyber insurance cover a cloud outage with no hacking?
Some policies cover qualifying system failures as well as security failures, while others are narrower. Check the trigger definition.
Does the vendor need to be named in the policy?
Sometimes. Some policies cover broad classes of providers, while others schedule specific vendors or use lower limits for unscheduled providers.
Will CBI pay every lost sale?
No. Claims require proof of covered loss and are subject to waiting periods, deductibles/retentions, measurement methods and limits.
Can both the vendor’s insurance and my cyber policy respond?
Potentially, but priority, contractual indemnity and recovery rights depend on the policies and contracts.
Sources & further reading
Reviewed October 2, 2026. Cyber policy definitions, system-failure triggers, vendor classes and sublimits differ substantially by insurer and market.
