FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE

Cyber insurance for businesses with $10M+ in revenue

Revenue alone does not determine an appropriate cyber insurance limit. The review should consider interruption losses, recovery costs, information exposure, contractual obligations, critical vendors, retentions, and relevant sublimits. A $3M, $5M, or $10M option should be assessed against those exposures and its actual policy wording.

Who this page is for

A cyber insurance review should reflect how your company earns revenue, depends on technology, handles information, and meets contractual obligations. A senior broker can help compare coverage terms and evaluate $3M, $5M, $10M, or higher limits in the context of those exposures.

For a technology or nontechnology business with $10M+ in annual revenue, the work is not simply choosing a headline number. It is identifying the events the policy recognizes, the costs available under each insuring agreement, and whether primary and excess terms remain aligned.

Discuss your cyber program with a senior broker

Start with a conversation. No application or documents required.

Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.

No insurance application or document upload required.

Six areas a cyber program review should cover

Cyber insurance is relevant beyond software companies. A distributor may depend on an order platform, a real estate operator on building and payment systems, and a professional firm on confidential client files. The review should connect each dependency to a defined covered event and to the part of the policy expected to respond.

  • Interruption and dependent interruption: Identify the company's own systems and outside providers whose outage could stop revenue, then read the event definition, waiting period, covered period, and sublimit.
  • Incident response and recovery: Compare access to forensic, legal, notification, public-relations, data-restoration, and system-restoration costs, including consent and vendor requirements.
  • Privacy and network liability: Review third-party claims arising from information handling or network security, who qualifies as an insured, defense treatment, and contractual-liability wording.
  • Extortion terms: Examine the covered threat, consent requirements, sanctions conditions, response services, retention, and any separate extortion sublimit.
  • Fraud-related coverage and overlap with crime: Separate computer fraud, funds-transfer fraud, and deceptive voluntary transfer; then coordinate cyber wording with the commercial crime policy.
  • Shared limits, sublimits, exclusions, and excess layers: Determine which costs share an annual aggregate, which have smaller caps, what is excluded, and whether each excess layer follows the primary form.

The result is a map of available coverage, not a prediction that every cyber event will be insured. Technology businesses also need to coordinate cyber with Tech E&O when a service failure harms a customer; nontechnology businesses still need to test operational interruption, information, payment, and vendor exposures.

How should $3M, $5M, and $10M cyber limits be compared?

Each amount below measures an aggregate cyber limit for a policy period, not annual revenue and not an amount automatically available to every category of loss. The practical comparison uses an interruption model, response-cost estimate, information exposure, contract requirements, and the sublimits that apply to the event being tested.

A higher headline aggregate can still produce less useful protection if dependent interruption, funds-transfer fraud, restoration, or extortion carries a small sublimit. Retentions also matter: a deductible generally reduces the insurer's payment after a covered loss, while a self-insured retention generally requires the insured to fund the stated amount before the insurer's obligation begins, subject to wording.

Each row evaluates an annual aggregate cyber limit. It is not annual revenue, a guarantee of availability, or proof that every cyber coverage part receives the full amount.

Limit being evaluatedWhat to investigateWhat the number does not establish
$3M aggregate cyber limitInterruption and response scenarios, relevant sublimits, retention, and whether defense costs erode the aggregateThat $3M is available for fraud, dependent interruption, or every covered cost
$5M aggregate cyber limitContract requirements, vendor concentration, shared limits, policy definitions, and whether one or more layers provide the amountThat a $5M headline aggregate removes exclusions or fits every $10M-revenue company
$10M total cyber towerPrimary and excess attachment, exhaustion, follow-form wording, reporting, exclusions, and coordination between layersThat this is a $10M excess layer above an additional primary limit

How primary and excess cyber layers stack

A primary cyber policy responds first to a recognized claim or event, after the applicable retention, up to the available limit or sublimit. An excess cyber policy attaches above a stated underlying amount and responds only after qualifying underlying loss exhausts that amount in the manner its wording requires. A $3M excess layer above a $2M primary layer can create a $5M total cyber tower for aligned coverage; it is not a $5M excess layer.

The tower below is a generic liability illustration, not a cyber quote or recommendation. Cyber excess layers must follow the primary form's definitions closely—including covered event, insured, loss, claim, reporting, exclusions, and erosion—or a loss recognized by the primary may not qualify in the same way above it. The diagram's $2M primary, $3M first excess, and $5M second excess illustrate a $10M total tower only when coverage and exhaustion align.

Actual cyber towers may use different layer sizes, carriers, sublimits, and retentions. Confirm whether defense and response costs erode each layer and whether an excess policy recognizes payments by the insured, an underlying insurer, or both for exhaustion.

  • Primary: $2M; combined limit through this layer is $2M.
  • First excess: $3M excess of $2M; combined limit through this layer is $5M.
  • Second excess: $5M excess of $5M; combined limit through this layer is $10M.

Illustrative structure only, assuming aligned coverage and applicable limits. Actual availability, attachment, exhaustion, and policy terms vary.

Higher-limit options versus the $1M/$2M program

The site's homepage cyber/Tech E&O program describes $1M and $2M limits under its stated current terms. The small-business explainer for the $1M/$2M program is the appropriate background page for that offering. It should not be read as promising a $3M, $5M, or $10M option within the same program.

Higher-limit cyber brokerage options discussed here are individually evaluated and subject to placement availability. A senior broker develops the exposure submission, identifies feasible primary and excess structures, and compares actual quotations and wording; no limit or capacity is guaranteed. The review should also establish whether cyber and Tech E&O are separate or share one aggregate, because a service claim could reduce the amount left for a later cyber event.

Contractual limits are a floor to test rather than evidence of adequate scope. A customer may require a $5M cyber aggregate while the company's modeled provider outage points to a different amount, and the contract may also demand notice, additional insured status, or a coverage feature the offered form does not provide.

Eight distinctions that a headline cyber limit misses

Limit comparisons are only reliable when the same coverage is being compared. These distinctions identify where a seemingly larger option can still leave a different result:

  • Funds-transfer fraud, social engineering, and voluntary transfer wording differ; the relevant amount may be a sublimit with verification conditions, and a crime policy may overlap.
  • Property business interruption usually requires covered physical damage, while cyber interruption requires a defined network or security event; neither trigger should be assumed from the other.
  • A casualty umbrella is not automatically cyber insurance and ordinarily does not extend cyber, E&O, D&O, or property limits.
  • More limit does not remove exclusions, broaden a covered-event definition, or make an excluded service insurable.
  • A deductible and self-insured retention are not interchangeable; timing, defense obligations, and who handles costs can differ.
  • Defense and response costs may sit inside an aggregate and reduce the amount left for settlements, judgments, or later events.
  • Prior acts, reporting obligations, insured entities, acquisitions, and policy periods can determine whether claims-made coverage recognizes a matter before any limit applies.
  • Statutory workers' compensation is not a selectable $3M, $5M, or $10M cyber package; it is a separate coverage governed by law, and casualty excess concerns employers liability rather than cyber.

The review documents these differences next to each option instead of treating price and aggregate limit as the whole comparison. Definitions, exclusions, sublimits, and retentions determine how much of the headline number is relevant to a specific scenario.

What additional revenue and operational scale change

As operations grow, a cyber event can affect more entities, locations, customers, records, payment flows, and systems. Acquisitions may introduce older networks or entities not yet named, while larger contracts can impose notification, indemnity, and minimum-limit obligations. Vendor concentration becomes more consequential when one cloud, payment, logistics, or managed-service provider supports a substantial share of revenue.

Scale also changes the quality of the information needed for underwriting: tested incident-response and continuity plans, backups, access controls, provider contracts, revenue by operation, and a defensible calculation of business income loss. A senior broker uses that detail to explain the risk and compare differences in waiting periods, covered periods, coinsurance or loss calculations, sublimits, and excess terms.

$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage.

How to prepare the cyber review

Begin with current policies, endorsements, applications, loss runs, customer requirements, provider contracts, and a list of legal entities. Build a system-and-vendor dependency map with business owners, not only IT, and quantify an outage in terms of lost gross profit, continuing expense, extra expense, and restoration cost over realistic time periods.

Then compare each option in a written coverage matrix: covered events, insureds, waiting period, covered period, retentions, sublimits, exclusions, consent provisions, defense treatment, and aggregate sharing. If excess is needed, review every layer and its schedule of underlying insurance rather than assuming the primary wording carries upward.

Cyber controls and insurance inform each other but are not substitutes. Frameworks such as the NIST Cybersecurity Framework can organize control discussions, while the policy review determines which insured events and costs are actually described in the contract.

Hypothetical scenario: Hypothetical distributor: an order-system provider incident

A hypothetical regional distributor with $40M in annual revenue loses access to its order-management system after an incident at a technology provider. The review must determine whether that provider qualifies as a dependent business under the policy and whether the event meets the defined trigger; neither point should be assumed. It must then apply the waiting period, identify when the covered period begins and ends, and calculate lost income and extra expense using the policy's method. Finally, the company should compare the applicable dependent-interruption sublimit, overall aggregate, retention, and any excess-layer terms. This illustration identifies what needs review and does not state that any policy would pay.

What your senior broker should examine

  • Which systems and technology providers support revenue, and does the policy's dependent-interruption definition include them?
  • What outage duration, waiting period, covered period, and loss-calculation method should be used for the interruption scenario?
  • Which response, restoration, privacy, extortion, and fraud costs have separate sublimits or retentions?
  • Do cyber, Tech E&O, crime, or other coverage parts share an aggregate or contain competing-other-insurance provisions?
  • How are acquisitions, subsidiaries, prior acts, and newly discovered incidents treated?
  • If excess layers are proposed, do their definitions, exclusions, reporting terms, and exhaustion provisions align with the primary form?
  • Which customer contracts impose cyber limits or terms, and do the offered policies actually satisfy those words?

Questions businesses ask

Does a company with $10M in revenue need a $10M cyber limit?

Not automatically. Revenue is an audience and complexity signal, not a limit formula. The decision should use interruption and response scenarios, information exposure, contracts, sublimits, retentions, and available policy wording.

Can a nontechnology company have a material cyber exposure?

Yes. Distributors, property operators, manufacturers, and professional firms can depend on networks, outside technology providers, payment systems, and confidential information. The relevant policy triggers and costs differ by operation even when the company does not sell technology.

Is funds-transfer fraud covered by the full cyber limit?

It should not be assumed. Funds-transfer fraud or social engineering may have a separate sublimit, conditions, or no coverage under a particular cyber form, and a crime policy may be relevant. Compare definitions, verification requirements, and other-insurance wording.

What does dependent business interruption mean in cyber insurance?

It generally refers to covered interruption caused by a qualifying event at a specified or qualifying outside provider. Provider and event definitions, waiting periods, covered periods, loss calculations, and sublimits vary, so the exact form controls.

Does a higher cyber limit remove exclusions?

No. Increasing a limit changes the potential amount available for covered loss; it does not broaden the covered-event definition or remove exclusions. Excess wording can introduce additional restrictions if it does not follow the primary form.

Sources

Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.