Cyber & Insurance Technology

Cyber Business Interruption Insurance: Waiting Periods, System Failure and Lost Income

An in-depth guide to cyber business interruption coverage, including waiting periods, system-failure triggers, dependent outages, period of restoration, lost-income calculations and claim preparation.

Rows of data-center servers illustrating cyber business interruption and network outage insurance coverage
Photo: Eric Stoynov / Unsplash
Short answer: Cyber business interruption coverage can reimburse certain lost income and extra expenses when a covered cyber event disrupts an insured organization’s computer systems. Coverage can depend on the event trigger, a waiting period, how the policy defines system failure, whether a third-party provider is involved, the period of restoration, sublimits and the insured’s ability to document what the business would have earned without the outage.

Traditional business-interruption insurance grew out of physical property losses such as fire. Modern businesses can stop operating even when the building is untouched: ransomware can encrypt servers, a cloud platform can fail, a denial-of-service attack can make a website unavailable, or a security incident can force systems offline for forensic work.

NAIC cybersecurity guidance identifies business interruption, data repair, hardware and software repair, litigation and other costs among the potential consequences of cyber incidents. Dedicated cyber policies developed in part because traditional property and liability forms were not designed to address every digital loss consistently.

What cyber business interruption is designed to protect

The core financial question is: what income did the business lose because a covered cyber event prevented normal operations? Depending on the policy, coverage may also include extra expense needed to continue operating or accelerate recovery.

Coverage concept What it addresses Key wording to check
Direct business interruption Outage of the insured’s own covered systems Security failure vs. systems failure triggers
Contingent/dependent interruption Outage at certain vendors or cloud providers Which providers qualify and whether named/unnamed dependencies are covered
Extra expense Additional cost to keep operating or restore service faster Reasonable/necessary standard and sublimits
Waiting period Time that must pass before time-element coverage applies Hours, trigger, and whether the period acts like a deductible
Period of restoration Time window used to measure recoverable loss When it begins/ends and how extended interruption is treated

Security failure vs. systems failure

Some cyber policies distinguish a malicious or unauthorized security event from a non-malicious systems failure. The difference matters. A ransomware attack may fit a security-failure trigger, while a software configuration error, provider outage or accidental system crash may require explicit systems-failure coverage.

The NAIC’s cyber-insurance reporting has noted market attention to coverage for outages caused by non-malicious events such as human error. Businesses that depend on uptime should not assume every outage is covered simply because the policy is labeled “cyber.”

The waiting period can function like a time deductible

Cyber interruption coverage often does not respond from the first minute of downtime. A waiting period may require the outage to exceed a specified number of hours. Policy structures differ on whether the covered loss is measured from the beginning of the event once the waiting period is satisfied, or only after the waiting period expires.

Coalition, for example, publicly describes direct and contingent business-interruption coverage with a designated waiting period and notes that its specific policy forms control the result. That is a useful market illustration, not a universal industry standard.

How lost income is calculated

The policy usually does not pay a flat amount simply because servers were down. The insured must support a financial loss model. That can involve historical sales, seasonal trends, budgets, prior-year performance, growth rates, cancelled orders and variable expenses that were not incurred during the shutdown.

A claim can become contentious when revenue was already volatile, the company was growing rapidly or multiple causes affected sales at the same time. Clean accounting data before the event is one of the strongest claim-preparation tools.

Extra expense can be as important as lost revenue

A company may spend money to reduce downtime: emergency cloud capacity, temporary call-center services, overtime, expedited hardware, forensic consultants, alternate payment processing or customer-notification infrastructure. If the policy covers extra expense, those costs may be recoverable when they meet the contract’s requirements.

Third-party dependency is a separate question

Many organizations do not own the infrastructure that keeps them operating. They depend on payment processors, SaaS providers, cloud hosts, managed service providers, electronic health-record platforms, logistics systems and other vendors. A standard direct business-interruption grant may not automatically extend to all vendor outages.

Contingent or dependent business interruption is designed for certain third-party failures. Read the definition carefully: some policies cover only specifically scheduled providers, others use broader categories, and sublimits may be lower than for an outage of the insured’s own systems.

Common cyber BI coverage questions

  • Does the policy cover both security failure and systems failure?
  • Is accidental outage covered or only malicious attack?
  • What is the waiting period for direct and dependent outages?
  • Are cloud, SaaS and payment providers included?
  • Is there a separate sublimit for contingent interruption?
  • How is the period of restoration defined?
  • Are reputational-loss or extended-interruption benefits included?
  • What proof is required for lost income?
  • Does a failure-to-maintain-security exclusion apply?
  • Are war, infrastructure, utility or widespread-event exclusions relevant?

First 24 hours of a potential interruption claim

  1. Notify the cyber insurer or approved breach-response contact promptly.
  2. Preserve logs and forensic evidence; do not wipe systems prematurely.
  3. Track the exact start time of operational impairment.
  4. Separate incident-response spending from ordinary IT expenses.
  5. Document which applications, locations and revenue streams are affected.
  6. Record mitigation decisions and why emergency expenses were reasonable.
  7. Start a daily financial-loss file while details are fresh.

Build the claim file before the incident

A useful cyber BI claim needs more than security evidence. Finance and operations teams should know where to find monthly revenue by business unit, gross-margin data, sales pipeline reports, cancelled transactions, supplier records and historical seasonality. A pre-loss worksheet can shorten the argument over what the business “would have earned.”

Why “silent cyber” matters

The NAIC Journal of Insurance Regulation has discussed the evolution of cyber-related business interruption and the uncertainty created when cyber losses were alleged under policies not explicitly designed for them. Modern insurance programs increasingly try to make cyber coverage affirmative—either clearly included or clearly excluded. Buyers should examine how cyber, property, crime and technology E&O policies fit together.

Frequently asked questions

Does cyber business interruption cover every internet outage?

No. The outage must meet the policy’s covered-event definition and other conditions, including any waiting period and exclusions.

What is contingent business interruption?

It addresses certain losses caused by outages at covered third-party service providers rather than the insured’s own systems.

Is the waiting period the same as a deductible?

It is a time-based threshold, but the financial effect depends on the wording. Some forms measure covered loss differently once the threshold is satisfied.

Will the insurer accept my revenue estimate?

Expect the claim to be supported with financial records, historical performance and a defensible calculation of income that would have been earned.

Reviewed October 5, 2026. Cyber policy triggers, waiting periods and sublimits are highly form-specific; the actual policy wording controls.