Skip to main content
News

Three Things to Check in Your Cyber Insurance Policy Today

By May 4, 2026No Comments
AdobeStock_597219067

Cyber insurance tends to get discussed in one of two ways: either someone is throwing alarming statistics at you, or they’re trying to sell you something. Neither is particularly helpful if you’re a business owner who just wants to understand whether your coverage is actually doing its job.

So, let’s take a different approach. Instead of starting with fear or a pitch, let’s start with your current policy and three specific areas where middle-market companies are quietly under protected.

First, a Quick Reset on How We Should Think About Cyber Coverage

For a long time, cyber insurance was treated like an add-on. Something you tacked onto your renewal conversation as an afterthought, right when everyone was already checked out. That way of thinking is outdated.

Cyber coverage has earned its place alongside foundational policies like general liability and property insurance. It is not a nice-to-have anymore. The risk landscape has shifted enough that treating it as optional is genuinely dangerous.

Ransomware gets most of the headlines, but that’s just one piece of it. Supply chain attacks can take your operations offline because a vendor you depend on got hit, not even you directly. Deepfake fraud is a growing problem where bad actors impersonate executives on video calls to authorize fraudulent wire transfers. And business email compromise, which essentially means someone manipulating your team into sending money or sensitive data to the wrong place, is consistently the most common claim we see. It’s also the one businesses are least ready for.

With that context in mind, here are the three things worth pulling up in your current policy.

1. Your Retroactive Date

Cyber policies are written on a claims-made basis. What that means practically is that coverage applies to incidents that happen and get reported within your active policy period. The exception is if you have prior acts coverage, which extends protection back to a specific date called the retroactive date.

This date matters more than most people realize. If your retroactive date is recent, or if it shifted when you switched brokers or carriers, you could have a window of time where incidents that were already developing aren’t covered. A breach doesn’t always look like a breach right away. 

Sometimes the exposure existed for months before anyone noticed. If that period falls outside your retroactive date, you may be on your own financially.

Most companies have no idea this gap exists. It’s worth confirming exactly where your retroactive date sits.

2. Your Social Engineering or Funds Transfer Fraud Sublimit

This is the coverage that kicks in when an employee gets deceived into wiring money to a fraudulent account. It’s the most frequent cyber claim in the middle market by a wide margin, which makes the next part especially worth paying attention to.

This coverage almost always comes with its own sublimit. That means it has a separate, lower cap than the rest of your policy. A policy with one million dollars in total cyber coverage might only provide fifty thousand dollars in protection for social engineering losses. That gap is significant and it happens far more often than it should.

The good news is that it’s fixable. With the right combination of policies, limits up to five hundred thousand dollars are achievable. But you can’t address it if you don’t know it’s there. Check your declarations page and look for how this coverage is listed and what the limit actually says.

3. Whether Your Overall Limit Still Makes Sense

When many businesses first bought cyber insurance, a one-million-dollar limit felt reasonable. For some operations, it still might be. But here’s a useful exercise: think through what a week of downtime would actually cost your business in lost revenue and productivity.

For a lot of companies, when they do that math honestly, one million dollars doesn’t cover it. A ransomware event that locks you out of your systems for a week or more can generate losses well above that threshold before you’ve even factored in remediation, legal fees, or regulatory exposure.

The question to ask yourself is how functional you could be without access to your computer systems and for how long you’d want insurance to carry the financial weight. When we walk clients through that conversation, almost every time we end up going back to the carrier for a higher limit. 

It’s a more common outcome than you’d think.

Putting It Together

The three areas worth reviewing are your retroactive date, your social engineering sublimit, and your overall limit relative to what a real incident would cost you. These aren’t abstract policy concepts. They’re the specific places where meaningful coverage gaps tend to hide.

Pull out your policy and look at each one. If anything seems unclear or off, that’s worth a conversation with your broker before you need to use the coverage.

Skip to content