FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE

How to evaluate $3M, $5M, $10M, and higher business insurance limits

Evaluate each limit against the contracts that require it and the loss scenarios that could consume it, one coverage at a time. Revenue tells you the size of the business, not the size of the loss a particular policy has to absorb. A $3M, $5M, or $10M figure only means something once you know whether it is a per-occurrence limit, a per-claim limit, an annual aggregate, a sublimit, an excess layer, or the total of a tower, and once you have read the wording that sits behind it.

Who this page is for

Established businesses are often asked for a specific limit by a customer, a landlord, a lender, or an acquirer, and just as often they are offered a round number by a carrier without an explanation of what it buys. This guide explains how a senior broker evaluates a limit for one coverage at a time: what the number measures, which contracts and loss scenarios test it, and what the number does not establish. It is written for companies with $10M+ in annual revenue, where the limits being discussed are commonly $3M, $5M, $10M, or higher.

Discuss your limits with a senior broker

Start with a conversation. No application or documents required.

Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.

No insurance application or document upload required.

Start by naming what the number measures

Every dollar figure in an insurance conversation should be attached to one of a small number of definitions. Annual revenue is what the business earns. Total insured value is what the property schedule is worth. A per-occurrence limit is the most a liability policy pays for one event; a per-claim limit is the most a claims-made policy pays for one claim. An annual aggregate is the most the policy pays across the whole policy year. A sublimit is a smaller cap inside the policy for one category of loss. An excess layer is a separate policy that pays only after the layer beneath it is exhausted, and the total tower is the sum of the primary and excess layers for the same coverage.

Mixing these up is the most common reason a limit discussion goes wrong. A $5M umbrella above a $1M general liability policy is not a $6M general liability limit for every kind of loss, and it is not $5M of cyber coverage. A $10M cyber policy with a $500,000 sublimit for funds-transfer fraud pays up to $500,000 for that fraud, not $10M. Before a senior broker compares options, each option is restated in these terms so that like is compared with like.

$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage.

How to evaluate a limit: contracts first, then loss scenarios

Contracts set the floor. Customer master service agreements, commercial leases, construction subcontracts, lender covenants, and acquisition agreements commonly specify a minimum limit for a named coverage, and sometimes specify how it must be structured (for example, whether an umbrella may be used to satisfy the requirement, whether the limit must be dedicated to the project, or whether the certificate must show a particular aggregate). A senior broker collects these requirements, checks whether the language matches the policy form rather than a generic label, and notes where two contracts ask for inconsistent things.

Loss scenarios test the ceiling. For each coverage the question is practical: what is the largest plausible loss this policy would respond to, how quickly would defense costs accumulate, and would more than one insured entity or more than one claimant be involved? For a liability policy that means a severity scenario such as a serious injury or a systemic error affecting many customers. For a cyber policy it means an interruption scenario measured in days of lost income plus recovery costs, not a headline breach statistic. For a property policy it means replacement cost and the time to restore operations at a specific location.

The limit that survives both tests is a candidate, not a conclusion. The remaining work is reading the wording: retentions, sublimits, exclusions, defense treatment, and how the policy responds when another policy also applies.

A decision table for $3M, $5M, $10M, and higher

The table below is a way to organize the review for one coverage at a time. Read each row as a question about that coverage, and resist the temptation to pick a row because it matches the size of the company. The third column matters as much as the second: it lists what the number, on its own, does not tell you.

Each row evaluates a limit for one specified coverage. The amounts are per-coverage limits being evaluated, not annual revenue and not a total across unrelated policies.

Limit being evaluatedWhat to investigateWhat the number does not establish
$3M for a specified coverageContract wording, relevant loss scenario, whether the amount is primary or combined, and how claims/aggregates are countedSuitability for every company above a particular revenue level
$5M for that coverageDifferences in terms as capacity changes; shared aggregates, retentions, sublimits, and whether excess is involvedThat every loss category has access to the headline limit
$10M total for that coveragePrimary and excess structure, attachment/exhaustion, exclusions, reporting, and carrier coordinationA $10M excess policy sitting above an additional primary limit
More than $10M for that coverageSeverity, concentration, contracts, risk tolerance, and feasible market capacityGuaranteed availability or a required amount based on revenue alone

How a $10M liability tower is put together

A higher liability limit is often assembled from layers rather than bought as one policy. The primary policy pays first, up to its own limit. Each excess policy attaches at the point the layer beneath it is exhausted and pays up to its own limit. The combined limit through any layer is the sum of the layers up to and including it, provided every layer covers the same event under aligned terms.

The illustration below shows a hypothetical $10M liability tower with a $2M primary layer, a $3M layer above it, and a $5M layer above that. It is an educational diagram, not a coverage recommendation, and the layers are for one coverage. It would be wrong to add a general liability tower, a cyber limit, and a D&O limit together and describe the total as protection for one incident.

  • Primary: $2M; combined limit through this layer is $2M.
  • First excess: $3M excess of $2M; combined limit through this layer is $5M.
  • Second excess: $5M excess of $5M; combined limit through this layer is $10M.

Illustrative structure only, assuming aligned coverage and applicable limits. Actual availability, attachment, exhaustion, and policy terms vary.

Cyber example: measuring the interruption, not the revenue

Consider a hypothetical distributor with $40M in annual revenue whose order-management system runs on a third-party platform. A meaningful cyber limit review starts by estimating what a multi-day outage at that provider would cost in lost income and extra expense, then adds incident response, forensic, notification, and system restoration costs, and then checks whether the policy treats an outage at the provider as a covered dependent business interruption event at all. The waiting period, the length of the covered period, and the method used to calculate the loss all change the answer more than the headline limit does.

With that work done, a $3M option, a $5M option, and a $10M option can be compared honestly. One may carry a low dependent-interruption sublimit that makes the headline figure irrelevant to the scenario; another may achieve $10M only through an excess layer with a narrower definition of a covered event. The number the company should care about is the amount actually available for the scenario it worries about.

Casualty example: general liability and the umbrella above it

Consider a hypothetical contractor with $25M in revenue whose largest customer requires $5M per occurrence of general liability, dedicated to the project, with the customer named as an additional insured for ongoing and completed operations. The senior broker's questions are whether a $1M or $2M primary policy plus an umbrella satisfies the wording, whether the umbrella follows the primary policy's additional insured grant, whether the per-project aggregate endorsement the contract expects is in place, and whether completed operations coverage continues for the period the contract specifies.

The size of the umbrella then follows from severity: a serious injury on a job site or a construction defect affecting many units is the scenario that consumes limits, and defense costs may sit inside or outside the limit depending on the form. A $10M total casualty program can be entirely sensible for a contractor of this size and entirely unnecessary for a software company with similar revenue, which is the point of evaluating coverage by coverage.

E&O example: claims-made limits and who is insured

Consider a hypothetical accounting firm with $15M in revenue that has acquired two smaller practices. Its professional liability policy is claims-made, so the review asks when the retroactive date falls for each acquired practice, whether prior acts of the acquired firms are covered, and whether the acquired entities have been added as named insureds. A $5M per-claim limit means little if the claim arises from work performed before the retroactive date or by an entity the policy does not recognize.

Aggregate structure matters here too. If the firm's cyber and professional liability coverage share one aggregate, a large cyber loss early in the year reduces what is available for a later professional liability claim. When a client engagement letter requires $10M of professional liability, the broker checks whether that figure is per claim or aggregate, whether defense costs erode it, and whether an excess E&O layer is available on terms that follow the primary form.

Distinctions that change the answer

  • An ordinary casualty umbrella is not automatically an extension of cyber, E&O, D&O, or property coverage. Most umbrellas sit above general liability, auto liability, and employers liability only.
  • More limit does not remove exclusions or broaden the insured service definition. A $10M policy with a narrow definition of professional services covers the same services as a $1M policy with the same definition.
  • Defense costs can affect available limits depending on wording. When defense is inside the limit, every dollar spent defending a claim reduces what is left to pay it.
  • A deductible and a self-insured retention are not interchangeable terms. A retention typically must be paid by the insured before the carrier's obligation begins, which can include the obligation to defend.
  • Prior acts, reporting obligations, insured entities, acquisitions, and policy periods can affect claims-made coverage. A limit is only available for claims the policy recognizes.
  • Social engineering and funds-transfer fraud require careful definition review. A headline cyber limit does not answer every fraud question; the applicable figure is often a sublimit with verification conditions.
  • Property-related and cyber-related business interruption can have different triggers and conditions. One responds to physical damage at a location; the other responds to a defined network event, often with a waiting period.
  • Statutory workers' compensation benefits are set by state law. They should not be presented as selectable $3M, $5M, or $10M packages; the negotiable figure is the employers liability limit, which an umbrella may sit above.

Why $10M in revenue does not mean $10M of every coverage

Revenue is a reasonable proxy for how much attention a program deserves, because larger companies sign more contracts, employ more people, and operate in more places. It is a poor proxy for any single limit. A $10M-revenue software company may carry $5M of Tech E&O because its enterprise contracts require it, $3M of cyber because its interruption scenario supports it, $2M of general liability because its premises exposure is modest, and a $5M umbrella above the general liability and auto policies. A $10M-revenue contractor with the same revenue might reasonably carry a $10M casualty tower and a $1M cyber policy.

The senior broker engagement exists to make those choices deliberately, coverage by coverage, with the contracts and the wording in front of you, and to explain the trade-offs when a higher limit costs more than the scenario justifies or is not available on the terms you expected.

What your senior broker should examine

  • Which contracts specify a minimum limit, and do they name the coverage, the structure (dedicated, per project, umbrella permitted), and the additional insured wording precisely?
  • For each coverage, what is the largest plausible loss scenario, and are defense costs inside or outside the limit?
  • Where a limit is reached through excess layers, does each layer follow the primary form, and where does each attach and exhaust?
  • Which categories of loss are subject to a sublimit, and how does the sublimit compare with the scenario that matters to the business?
  • Do any policies share an aggregate, and what happens to the remaining limit after a large loss early in the year?
  • For claims-made policies, do the retroactive dates, named insureds, and acquired entities match how the business actually operates today?
  • Is the retention a deductible or a self-insured retention, and can the business fund it while the claim is defended?

Questions businesses ask

Is there a standard limit for a company with $10M in revenue?

No. Limits are evaluated per coverage against contracts and loss scenarios. Two companies with identical revenue can reasonably carry very different limits because their contracts, operations, and severity scenarios differ.

Does a $5M umbrella give me $5M of cyber or professional liability coverage?

Usually not. A casualty umbrella typically sits above general liability, auto liability, and employers liability. Cyber, professional liability, and D&O limits are increased with their own excess layers, if at all.

What is the difference between a $10M total limit and a $10M excess policy?

A $10M total limit is the combined amount available through every layer for one coverage. A $10M excess policy is one layer that pays only after the underlying limit is exhausted, so the total program limit is the underlying limit plus $10M. The two are often confused in contracts and certificates.

How do defense costs affect the limit I am evaluating?

It depends on the form. When defense costs are inside the limit, they reduce the amount available to pay a judgment or settlement. When they are outside the limit, the full limit remains available for indemnity. A senior broker confirms which applies to each policy before comparing headline figures.

Can I add my policies together to describe my total protection?

Only within one coverage tower. Adding a general liability tower, a cyber limit, and a D&O limit together and describing the sum as protection for one incident is misleading, because a single incident typically triggers one coverage or, at most, a few with different triggers and conditions.

Sources

Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.