Insurance & Risk Management Business & Commercial Insurance GDPR Art. 33 and US state breach notification statutes

Cyber Liability Coverage Limit Calculator

This calculator builds a breach-cost scenario from the four things that actually drive the bill — how many records you hold, what the forensics and legal response costs, how long you are down, and what a regulator could impose — and then runs that scenario against the policy limit and retention you are considering. It reports what you retain, what the policy pays, and what falls above the limit and lands back on the business. Cyber limits are usually bought against a peer benchmark rather than against a modelled loss, which is precisely why so many of them turn out to be a fraction of the event they were bought for.

Calculator

This calculator runs in your browser. Enable JavaScript for live results — the inputs, formula and worked example below remain fully readable without it.

Inputs this calculator takes, with typical values
InputWhat to enterExample
Personal records heldCount every individual whose personal data you hold, including former customers and employees, not just active accounts.50000 records
Cost per recordNotification, credit monitoring and call centre cost per affected individual; replace the placeholder with your broker's current benchmark.165 $
Forensics, breach counsel and PRThe fixed incident-response bill: digital forensics, privacy counsel, crisis communications and remediation.250000 $
DowntimeHours of interrupted operations after the waiting period, from your recovery-time objective or your last tabletop exercise.72 hours
Revenue lost per hour of downtimeGross earnings you lose per hour offline, not total revenue per hour — costs that stop are excluded.5000 $
Regulatory fines and defenceYour estimate of penalties plus the cost of defending a regulatory investigation, sized to the regimes you fall under.500000 $
Policy limit consideredThe aggregate limit on the cyber policy you hold or are quoting.2000000 $
RetentionThe self-insured retention that applies before the policy responds to a first-party cyber loss.50000 $

It returns

  • Modelled breach cost — Total cost of the scenario before any insurance is applied.
  • Retained by the business
  • Paid by the policy
  • Uninsured above the limit
  • Limit as % of the loss above retention

The formula

L=Nc+F+hv+R
Gap=max(0,LrM)

In plain text: Cost = records × cost/record + forensics + downtime hours × revenue/hour + regulatory; insured = min(max(0, Cost − retention), limit)

  • LModelled breach cost ($)
  • NPersonal records affected (records)
  • cNotification and monitoring cost per record ($/record)
  • FForensics, breach counsel and public relations ($)
  • hHours of downtime (hours)
  • vGross earnings lost per hour offline ($/hour)
  • RRegulatory fines, penalties and defence cost ($)

The insurance split assumes a single event, a single aggregate limit, and one retention applying to the whole loss. Sublimits on regulatory fines, ransom payments and business interruption are common and are not modelled here.

Updated Category Business & Commercial Insurance Verified against published test cases Reading time 11 min

Why cyber limits are bought badly

Most cyber limits are set by analogy. A broker reports what companies of similar size and sector are buying, the buyer picks a number in that range, and nobody models the loss the limit is supposed to absorb. That works acceptably for general liability, where a century of claims data has taught the market roughly what a bodily injury claim costs. It works badly for cyber, where the loss is assembled from four independent components that scale on completely different drivers.

Notification cost scales with the number of individuals in your database, which has almost nothing to do with your revenue. Forensics and breach counsel are largely fixed — a competent incident response engagement costs roughly the same whether 5,000 or 5,000,000 records were exposed. Business interruption scales with your hourly earnings and your recovery time, which is an engineering property of your infrastructure. Regulatory exposure scales with which regimes you fall under, and under GDPR Article 83 the ceiling is 4% of total worldwide annual turnover or €20 million, whichever is higher.

A company can be small on revenue and enormous on records. Another can hold few records and lose $100,000 an hour offline. Buying either a limit sized by revenue alone produces a number with no relationship to the loss. This calculator puts the four components side by side so you can see which one dominates your own exposure — that is usually the surprise.

The four components, and how the policy carves them up

Notification and monitoring. Every US state has a breach notification statute, and GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware. The cost is per individual: mailing, a call centre, and one or two years of credit monitoring. Per-record benchmarks published in the annual industry reports are useful for a first pass but are averages dominated by very large breaches; below a few hundred records the fixed costs dominate and a per-record figure understates badly.

Forensics, counsel and PR. This is the bill that arrives first and is the least elastic. Privacy counsel directs the investigation to preserve privilege, a forensics firm establishes scope, and communications work begins before you know what happened. On a serious incident this is a six-figure line whatever the record count.

Downtime. Hours offline multiplied by gross earnings per hour. Use gross earnings — revenue less the costs that stop — rather than revenue, or you overstate it. The business interruption coverage calculator derives that figure properly from an income statement, and cyber policies carry their own waiting period, typically 6 to 12 hours, before the clock starts.

Regulatory. Fines plus the cost of defending an investigation. Insurability of fines varies by jurisdiction, and most policies sublimit this.

The insurance arithmetic is then simple. The retention comes off the whole loss, the policy pays the next slice up to the limit, and anything beyond falls back on the balance sheet. Limit adequacy is the limit divided by the loss above the retention — the part the policy is actually being asked to absorb.

Worked example: a 50,000-record services firm with a $2m limit

A professional services firm holds personal data on 50,000 people, budgets $165 per record for notification and two years of credit monitoring, and expects a $250,000 incident response engagement. Its systems would be down 72 hours, during which it loses $5,000 an hour of gross earnings. It estimates $500,000 of regulatory penalties and defence. It carries a $2,000,000 aggregate limit with a $50,000 retention.

  1. Notification. 50,000 × $165 = $8,250,000.
  2. Forensics, counsel and PR. $250,000.
  3. Downtime. 72 h × $5,000 = $360,000.
  4. Regulatory. $500,000.
  5. Modelled breach cost. 8,250,000 + 250,000 + 360,000 + 500,000 = $9,360,000.
  6. Apply the policy. The retention takes $50,000. The loss above it is $9,310,000. The policy pays $2,000,000 of that, leaving $7,310,000 uninsured.
  7. Limit adequacy. $2,000,000 ÷ $9,310,000 = 21.5%.

Notification alone is 88.1% of the modelled cost ($8,250,000 ÷ $9,360,000), and it is the component the firm's revenue tells you nothing about. Downtime, which is what most people picture when they think about cyber loss, is 3.8%. The $2,000,000 limit that looked reasonable against a peer benchmark covers roughly one fifth of the event.

Change one input and watch the conclusion move. Drop the record count to 5,000 and the modelled cost falls to $1,935,000; the same $2,000,000 limit now covers the entire loss above the retention with room to spare. The limit did not change — the exposure did.

How to read the result

Limit adequacy is the headline. At 100% or above, the limit absorbs this specific scenario in full above the retention. Below 100%, the shortfall lands on the business. Do not read a single adequacy figure as a verdict on the policy: it is a verdict on the policy against the scenario you entered. Run three — a plausible incident, a bad one, and the worst credible one — and see where the limit stops working.

Look next at the component shares in the table. Whichever component dominates is where your risk management money buys the most. If notification dominates, the highest-return control is data minimisation: deleting records you no longer have a business reason to hold directly reduces the modelled loss, and it is the only control on this list that shrinks the exposure rather than the probability. If downtime dominates, invest in recovery time. If regulatory dominates, the question is jurisdictional scope rather than technical.

Treat the retention as a separate decision from the limit. A retention only has to be survivable; a limit has to be adequate. Buyers routinely accept a retention that is a rounding error and a limit that covers a fifth of the loss, which is the wrong shape. Money moved from lowering the retention into raising the limit buys protection against the events that actually threaten the business.

Finally, remember this models one event. A cyber policy's aggregate limit is consumed by every claim in the period, so a firm that has a moderate incident in March has less limit available in November.

How much limit each component consumes at different scales

Modelled breach cost at three record counts, holding forensics at $250,000, downtime at 72 hours × $5,000, regulatory at $500,000 and notification at $165 per record. The last column is the limit needed to cover the whole loss above a $50,000 retention.
Records heldNotificationFixed + downtime + regulatoryModelled costLimit needed above retention
1,000$165,000$1,110,000$1,275,000$1,225,000
5,000$825,000$1,110,000$1,935,000$1,885,000
25,000$4,125,000$1,110,000$5,235,000$5,185,000
50,000$8,250,000$1,110,000$9,360,000$9,310,000
100,000$16,500,000$1,110,000$17,610,000$17,560,000
250,000$41,250,000$1,110,000$42,360,000$42,310,000

Generated with the calculator's own expression. The middle column is constant because forensics, downtime and regulatory exposure do not scale with record count — which is exactly why record count decides the limit.

Sublimits are where a cyber policy stops matching this model

This calculator applies one limit to the whole loss. Real cyber policies rarely do. Regulatory fines and penalties, ransom and extortion payments, social engineering fraud, bricking of hardware and dependent business interruption are all commonly written at a sublimit — sometimes 10% or 25% of the aggregate. A $5,000,000 policy with a $500,000 regulatory sublimit responds to the scenario above with $500,000 against the $500,000 regulatory component and $4,500,000 against everything else, which is not what the headline limit implies. Read the sublimit schedule before you read the limit, and re-run this calculator once per sublimited component if any of them dominates your exposure.

Assumptions and what this does not model

  • One event, one limit, one retention. No allowance is made for a second incident in the same policy period consuming the same aggregate.
  • No sublimits. If your policy sublimits regulatory fines, ransom or business interruption, the insured figure here is optimistic.
  • No waiting period on business interruption. Cyber policies typically apply a 6 to 12 hour waiting period before downtime is covered. Deduct it from the downtime hours if you want the covered figure rather than the economic one.
  • Fines may not be insurable. Whether a regulatory penalty can be insured at all depends on jurisdiction and on the nature of the penalty. The regulatory input mixes fines with defence costs, which are more reliably covered.
  • No third-party liability claims. Class actions by affected individuals and contractual claims from business customers are separate from the response cost modelled here and can dwarf it.
  • Per-record benchmarks are averages. They are dominated by large breaches and understate the per-record cost of a small one, where fixed costs are spread over few records.

How this fits with the rest of the insurance programme

Cyber sits deliberately outside the property and general liability towers, because the standard property form requires direct physical loss or damage and a ransomware event that encrypts data without harming hardware generally fails that trigger. Do not assume the business interruption limit on your property policy responds to a network event; in most programmes it explicitly does not, which is why the downtime component belongs in this calculation rather than in the property one.

Professional liability overlaps at the edges. A technology or professional services firm whose failure to protect client data causes the client a loss faces an errors-and-omissions claim as well as a first-party cyber loss, and which policy responds turns on wording rather than on facts. Size that side separately with the professional liability limit calculator, and check for a joint retention or an other-insurance clause that could leave a gap between the two.

The most useful discipline this calculator enforces is annual re-modelling. Record counts grow, retention policies rarely delete anything, and hourly earnings rise, so a limit that was adequate at inception erodes without anybody changing the policy. Re-run it with current record counts at every renewal, and treat the record count as a number the business can actively manage rather than as a fact about it.

Frequently asked questions

How much cyber insurance does a business actually need?

Enough to cover the loss above your retention in the worst scenario you consider credible, which for most data-holding businesses means the limit is set by record count rather than by revenue. Model the scenario before you shop the limit. A firm holding 50,000 personal records faces a notification bill in the millions regardless of how small it is, while a firm holding 500 records and losing $50,000 an hour offline needs the same limit for a completely different reason.

What is a realistic cost per record?

Take it from a benchmark you can cite, such as the annual Cost of a Data Breach Report, and adjust for your data type and breach size. Health and payment data cost more per record than marketing contact data; heavily regulated sectors cost more than unregulated ones; and small breaches cost far more per record than large ones because the fixed costs of counsel and forensics are spread over fewer individuals. The $165 default here is a placeholder, not a finding.

Should the retention be as low as I can afford?

No. A retention only needs to be survivable out of working capital; a limit needs to be adequate against the loss. Premium spent buying a retention down from $100,000 to $25,000 protects you against a $75,000 swing, while the same premium moved into limit may protect against a seven-figure one. Set the retention at the largest number the business can absorb without disruption, then spend everything else on limit.

Does cyber insurance cover regulatory fines?

Sometimes, partly, and usually at a sublimit. Insurability of fines and penalties varies by jurisdiction — some prohibit insuring punitive penalties as a matter of public policy — and policies commonly cover the fine only where insurable by law. Defence costs for a regulatory investigation are covered much more reliably than the penalty itself. Enter the two together in this calculator, then check your policy for a separate regulatory sublimit.

Does my property policy's business interruption cover a ransomware attack?

Almost certainly not. The standard commercial property form requires direct physical loss or damage to covered property, and encrypted data on undamaged hardware does not meet that trigger in most jurisdictions. Many forms now carry an explicit cyber exclusion as well. The downtime component in this calculator therefore belongs to the cyber policy, which brings its own waiting period, usually measured in hours rather than days.

What is limit adequacy telling me if it comes out over 100%?

That the limit absorbs this particular scenario in full above your retention, with the excess over 100% representing headroom. That headroom is not wasted: it covers a second incident in the same policy period, a worse version of the same scenario, and the third-party liability claims this calculator does not model. Adequacy well above 100% on your worst credible scenario is a sign the programme is sized sensibly, not a sign you are overbuying.

Why does the calculator show no insured loss on a small incident?

Because the whole modelled loss falls inside your retention, so the policy is never reached. That is the normal and intended behaviour of a retention: it removes the attritional claims from the policy in exchange for premium. If most of your credible scenarios sit below the retention, the retention is doing its job — but check that a genuinely severe scenario still produces an adequate limit, since that is the event the policy exists for.

How do I estimate downtime hours?

Use the recovery time objective your IT team has actually tested, not the one written in the plan. If you have run a tabletop or a real restore, use that elapsed time and add the period spent deciding what happened before recovery began, which is routinely longer than the restore itself. Where nothing has been tested, model a range and use the upper end — an untested recovery plan is an assumption, not a control.

References