Why cyber limits are bought badly
Most cyber limits are set by analogy. A broker reports what companies of similar size and sector are buying, the buyer picks a number in that range, and nobody models the loss the limit is supposed to absorb. That works acceptably for general liability, where a century of claims data has taught the market roughly what a bodily injury claim costs. It works badly for cyber, where the loss is assembled from four independent components that scale on completely different drivers.
Notification cost scales with the number of individuals in your database, which has almost nothing to do with your revenue. Forensics and breach counsel are largely fixed — a competent incident response engagement costs roughly the same whether 5,000 or 5,000,000 records were exposed. Business interruption scales with your hourly earnings and your recovery time, which is an engineering property of your infrastructure. Regulatory exposure scales with which regimes you fall under, and under GDPR Article 83 the ceiling is 4% of total worldwide annual turnover or €20 million, whichever is higher.
A company can be small on revenue and enormous on records. Another can hold few records and lose $100,000 an hour offline. Buying either a limit sized by revenue alone produces a number with no relationship to the loss. This calculator puts the four components side by side so you can see which one dominates your own exposure — that is usually the surprise.
The four components, and how the policy carves them up
Notification and monitoring. Every US state has a breach notification statute, and GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware. The cost is per individual: mailing, a call centre, and one or two years of credit monitoring. Per-record benchmarks published in the annual industry reports are useful for a first pass but are averages dominated by very large breaches; below a few hundred records the fixed costs dominate and a per-record figure understates badly.
Forensics, counsel and PR. This is the bill that arrives first and is the least elastic. Privacy counsel directs the investigation to preserve privilege, a forensics firm establishes scope, and communications work begins before you know what happened. On a serious incident this is a six-figure line whatever the record count.
Downtime. Hours offline multiplied by gross earnings per hour. Use gross earnings — revenue less the costs that stop — rather than revenue, or you overstate it. The business interruption coverage calculator derives that figure properly from an income statement, and cyber policies carry their own waiting period, typically 6 to 12 hours, before the clock starts.
Regulatory. Fines plus the cost of defending an investigation. Insurability of fines varies by jurisdiction, and most policies sublimit this.
The insurance arithmetic is then simple. The retention comes off the whole loss, the policy pays the next slice up to the limit, and anything beyond falls back on the balance sheet. Limit adequacy is the limit divided by the loss above the retention — the part the policy is actually being asked to absorb.
Worked example: a 50,000-record services firm with a $2m limit
A professional services firm holds personal data on 50,000 people, budgets $165 per record for notification and two years of credit monitoring, and expects a $250,000 incident response engagement. Its systems would be down 72 hours, during which it loses $5,000 an hour of gross earnings. It estimates $500,000 of regulatory penalties and defence. It carries a $2,000,000 aggregate limit with a $50,000 retention.
- Notification. 50,000 × $165 = $8,250,000.
- Forensics, counsel and PR. $250,000.
- Downtime. 72 h × $5,000 = $360,000.
- Regulatory. $500,000.
- Modelled breach cost. 8,250,000 + 250,000 + 360,000 + 500,000 = $9,360,000.
- Apply the policy. The retention takes $50,000. The loss above it is $9,310,000. The policy pays $2,000,000 of that, leaving $7,310,000 uninsured.
- Limit adequacy. $2,000,000 ÷ $9,310,000 = 21.5%.
Notification alone is 88.1% of the modelled cost ($8,250,000 ÷ $9,360,000), and it is the component the firm's revenue tells you nothing about. Downtime, which is what most people picture when they think about cyber loss, is 3.8%. The $2,000,000 limit that looked reasonable against a peer benchmark covers roughly one fifth of the event.
Change one input and watch the conclusion move. Drop the record count to 5,000 and the modelled cost falls to $1,935,000; the same $2,000,000 limit now covers the entire loss above the retention with room to spare. The limit did not change — the exposure did.
How to read the result
Limit adequacy is the headline. At 100% or above, the limit absorbs this specific scenario in full above the retention. Below 100%, the shortfall lands on the business. Do not read a single adequacy figure as a verdict on the policy: it is a verdict on the policy against the scenario you entered. Run three — a plausible incident, a bad one, and the worst credible one — and see where the limit stops working.
Look next at the component shares in the table. Whichever component dominates is where your risk management money buys the most. If notification dominates, the highest-return control is data minimisation: deleting records you no longer have a business reason to hold directly reduces the modelled loss, and it is the only control on this list that shrinks the exposure rather than the probability. If downtime dominates, invest in recovery time. If regulatory dominates, the question is jurisdictional scope rather than technical.
Treat the retention as a separate decision from the limit. A retention only has to be survivable; a limit has to be adequate. Buyers routinely accept a retention that is a rounding error and a limit that covers a fifth of the loss, which is the wrong shape. Money moved from lowering the retention into raising the limit buys protection against the events that actually threaten the business.
Finally, remember this models one event. A cyber policy's aggregate limit is consumed by every claim in the period, so a firm that has a moderate incident in March has less limit available in November.
How much limit each component consumes at different scales
| Records held | Notification | Fixed + downtime + regulatory | Modelled cost | Limit needed above retention |
|---|---|---|---|---|
| 1,000 | $165,000 | $1,110,000 | $1,275,000 | $1,225,000 |
| 5,000 | $825,000 | $1,110,000 | $1,935,000 | $1,885,000 |
| 25,000 | $4,125,000 | $1,110,000 | $5,235,000 | $5,185,000 |
| 50,000 | $8,250,000 | $1,110,000 | $9,360,000 | $9,310,000 |
| 100,000 | $16,500,000 | $1,110,000 | $17,610,000 | $17,560,000 |
| 250,000 | $41,250,000 | $1,110,000 | $42,360,000 | $42,310,000 |
Generated with the calculator's own expression. The middle column is constant because forensics, downtime and regulatory exposure do not scale with record count — which is exactly why record count decides the limit.
Sublimits are where a cyber policy stops matching this model
This calculator applies one limit to the whole loss. Real cyber policies rarely do. Regulatory fines and penalties, ransom and extortion payments, social engineering fraud, bricking of hardware and dependent business interruption are all commonly written at a sublimit — sometimes 10% or 25% of the aggregate. A $5,000,000 policy with a $500,000 regulatory sublimit responds to the scenario above with $500,000 against the $500,000 regulatory component and $4,500,000 against everything else, which is not what the headline limit implies. Read the sublimit schedule before you read the limit, and re-run this calculator once per sublimited component if any of them dominates your exposure.
Assumptions and what this does not model
- One event, one limit, one retention. No allowance is made for a second incident in the same policy period consuming the same aggregate.
- No sublimits. If your policy sublimits regulatory fines, ransom or business interruption, the insured figure here is optimistic.
- No waiting period on business interruption. Cyber policies typically apply a 6 to 12 hour waiting period before downtime is covered. Deduct it from the downtime hours if you want the covered figure rather than the economic one.
- Fines may not be insurable. Whether a regulatory penalty can be insured at all depends on jurisdiction and on the nature of the penalty. The regulatory input mixes fines with defence costs, which are more reliably covered.
- No third-party liability claims. Class actions by affected individuals and contractual claims from business customers are separate from the response cost modelled here and can dwarf it.
- Per-record benchmarks are averages. They are dominated by large breaches and understate the per-record cost of a small one, where fixed costs are spread over few records.
How this fits with the rest of the insurance programme
Cyber sits deliberately outside the property and general liability towers, because the standard property form requires direct physical loss or damage and a ransomware event that encrypts data without harming hardware generally fails that trigger. Do not assume the business interruption limit on your property policy responds to a network event; in most programmes it explicitly does not, which is why the downtime component belongs in this calculation rather than in the property one.
Professional liability overlaps at the edges. A technology or professional services firm whose failure to protect client data causes the client a loss faces an errors-and-omissions claim as well as a first-party cyber loss, and which policy responds turns on wording rather than on facts. Size that side separately with the professional liability limit calculator, and check for a joint retention or an other-insurance clause that could leave a gap between the two.
The most useful discipline this calculator enforces is annual re-modelling. Record counts grow, retention policies rarely delete anything, and hourly earnings rise, so a limit that was adequate at inception erodes without anybody changing the policy. Re-run it with current record counts at every renewal, and treat the record count as a number the business can actively manage rather than as a fact about it.
