Two cyber quotes can both say “$5 million limit” and still provide very different practical protection. One may have a $50,000 retention and $1 million social-engineering sublimit; another may have a $250,000 retention, $250,000 social-engineering sublimit and defense costs inside the aggregate limit.
The only reliable comparison is to map the structure: trigger, retention/deductible, sublimit, aggregate limit, waiting period and limit erosion.
Retention vs. deductible: similar purpose, potentially different mechanics
Both terms place part of the risk on the insured. IRMI defines a self-insured retention (SIR) as an amount the insured pays before the policy responds. A deductible also makes the insured bear part of the loss, but claim-handling and reimbursement mechanics can differ. Cyber policies use these terms inconsistently, so the contract controls.
| Term | General concept | Cyber question to ask |
|---|---|---|
| Retention / SIR | Amount the insured must absorb before covered insurance responds | Does the insurer control/participate in response before the retention is exhausted? |
| Deductible | Amount charged to the insured on a covered loss | How is it applied per event, per claim or per coverage? |
| Policy limit | Maximum available subject to terms | Is it per claim/event, aggregate, or both? |
| Sublimit | Lower cap for a particular category of loss | Is the sublimit part of—not added to—the main limit? |
| Waiting period | Time threshold often used for business interruption | When does covered time-element loss begin? |
What is a sublimit?
IRMI describes a sublimit as a limitation on coverage for a particular type of loss that is part of, rather than additional to, the broader policy limit. In a cyber policy, a $5 million aggregate could therefore contain a $250,000 sublimit for social-engineering fraud.
The NAIC has tracked cyber-market use of limits and sublimits, including more restrictive terms for certain high-severity exposures. That makes the sublimit schedule as important as the declarations page.
Common areas where cyber sublimits can appear
- Social-engineering / fraudulent-instruction loss.
- Cybercrime or funds-transfer fraud.
- Ransomware/extortion.
- Bricking or replacement of hardware.
- Reputational loss.
- Dependent/contingent business interruption.
- System failure not caused by a malicious attack.
- PCI assessments.
- Regulatory fines/penalties where insurable.
- Cryptojacking or telecom fraud.
Not every policy uses these sublimits, and the amounts vary widely by underwriting, industry and controls.
Example: the $2 million policy that pays far less for a phishing transfer
Assume a company has a $2 million cyber aggregate, a $50,000 retention and a $100,000 social-engineering sublimit. An employee is tricked into sending $400,000 to a criminal. If the claim satisfies the social-engineering insuring agreement, the recovery may still be capped by that $100,000 sublimit, subject to how the retention applies.
The exact arithmetic depends on whether the retention sits within or outside the stated sublimit and how the form defines covered loss. Never assume the $2 million headline limit is available.
Does the retention apply once or multiple times?
Check whether the retention applies per event, per claim, per coverage, per affected entity or through an aggregate structure. A ransomware incident can create several costs—incident response, business interruption, data restoration, notification and extortion. The policy’s related-claims language may determine whether those costs share one retention or trigger multiple amounts.
Defense costs: inside or outside the limit?
For third-party privacy/security liability, legal defense can be expensive. Some cyber forms include defense expenses within the liability limit, meaning every dollar spent defending a claim reduces what remains for settlements or judgments. Other structures may treat defense differently. Compare explicitly.
Business interruption has a second “deductible”: time
Cyber business-interruption coverage commonly uses a waiting period, such as a specified number of hours, before time-element loss becomes eligible. The waiting-period structure is separate from a dollar retention and can materially change a short outage claim.
Aggregate erosion across multiple incidents
If the cyber limit is an annual aggregate, earlier claims can reduce the amount left for later events. Ask how incident-response costs, notification, credit monitoring, legal expenses and regulatory proceedings erode the aggregate. A company that has a breach in February should know what remains for a ransomware event in November.
Layered cyber programs add another dimension
Larger organizations often buy primary cyber plus excess layers. The primary policy may absorb the retention and first dollars of loss, while excess insurers attach above it. Differences in exclusions, war clauses, definitions or sublimits can create gaps if excess policies do not follow the primary wording closely.
How underwriting affects retention and sublimits
Insurers can change retentions, sublimits and capacity based on revenue, industry, ransomware controls, privileged-access management, MFA, backup architecture, incident-response preparedness, prior losses and third-party dependencies. Strong controls can improve insurability but do not guarantee a particular price or structure.
Quote comparison worksheet
- Overall each-claim/event and annual aggregate limits.
- Retention/deductible for each first-party and third-party coverage.
- Social-engineering and cybercrime sublimits.
- Ransomware/extortion sublimit and coinsurance if any.
- Direct and contingent business-interruption limits.
- System-failure coverage and sublimit.
- Waiting period for business interruption.
- Incident-response panel requirements.
- Defense costs inside/outside limits.
- Related-claims/related-events wording.
- War/systemic-event exclusions.
- Excess-layer follow-form differences.
Do not optimize only for the lowest retention
A low retention can be attractive, but a broader policy with a somewhat larger retention may be more valuable than a low-retention policy filled with restrictive sublimits. Compare the loss scenarios your organization actually faces.
Frequently asked questions
Is a cyber retention the same as a deductible?
They serve a similar risk-sharing function, but claim-handling mechanics can differ. The policy definitions govern.
Is a sublimit extra insurance on top of the policy limit?
Usually no. A sublimit commonly restricts part of the overall limit rather than adding a new amount, but confirm the form.
Can ransomware have a lower limit than other cyber claims?
Yes. Insurers can use ransomware/extortion sublimits, coinsurance or other conditions.
Why does business interruption have a waiting period?
It prevents very short outages from triggering time-element coverage and functions as a time threshold before the benefit applies.
Sources and further reading
Reviewed October 5, 2026. Cyber policy structures are non-standardized; definitions, retentions, sublimits, waiting periods and limit erosion must be confirmed in the actual form.
