How Much Cyber Insurance Do I Need?
Choose limits by modeling plausible response, interruption, restoration, and liability costs, then account for sublimits, retentions, and waiting periods.
There is no universal limit that fits every company. Build a loss estimate around the information you hold, how long critical operations could be unavailable, dependence on cloud and other vendors, contractual duties, and the costs of forensic response, legal advice, notification, restoration, and claims. The FTC’s first-party and third-party categories can help you organize those estimates, but they do not prescribe a limit.
Compare the overall aggregate with any lower sublimits for extortion, funds transfer fraud, business interruption, or response services. Model the retention and time waiting period against cash reserves, and ask whether defense expenses reduce the liability limit. Check event aggregation language, dependent-system coverage, and restoration-period definitions. The selected limit should reflect a documented risk estimate, not a generic revenue multiple.
Related Coverage
Providers That List This Coverage
Sources
- Cyber Insurance. Federal Trade Commission; What Should Your Cyber Insurance Policy Cover; First-Party Coverage; Third-Party Coverage. Accessed 2026-09-25.
- CyberEdge specimen policy. AIG; General Terms §§4–6, PDF pp.3–6; Security and Privacy §§1–3, PDF pp.11, 14–18; Event Management §§1–2, PDF pp.19–20. Accessed 2026-09-25.
- Cyber insurance coverage & products. Chubb; Cyber insurance coverage; First party coverage; Third-party liability coverage; Cyber crime (by endorsement); Products and services. Accessed 2026-09-25.





