The Coverage Memo
Cyber RiskLong read

Cyber Insurance Coverage for Third-Party Vendor Breaches

Vendor breaches leave most cyber policies with dangerous coverage gaps.

Features Editor · · 10 min read
Cover illustration for “Cyber Insurance Coverage for Third-Party Vendor Breaches”
Cyber Risk · October 1, 2026 · 10 min read · 2,227 words

Cyber insurance was built to answer one question: what happens when an attacker breaks into the policyholder's own network? That design choice made sense when most incidents worked that way. It leaves a hole in coverage now that the attacker rarely needs to touch the policyholder's systems at all, because compromising a single shared vendor gives access to every customer that vendor serves. A supply chain breach doesn't fit the assumptions baked into most policy wordings, and that mismatch is the reason so many businesses discover, only after a vendor incident, that the coverage they thought they had doesn't respond the way they expected. Supply chain compromises accounted for the largest share of sector losses in 2024, overtaking direct ransomware attacks as the leading cause of loss for the first time. That single fact should settle any argument about whether this is a marginal concern. The rest of this piece works through where standard policies still respond to a vendor-origin loss, where they stop, and what a business can do at the contract stage to close the space in between.

What a standard policy covers when a vendor is the breach source

A vendor breach does not automatically leave a policyholder uninsured. Whether the resulting loss falls inside the first-party or third-party components the policyholder already carries determines its recovery, regardless of where the intrusion started. Breach response costs, forensic investigation, notification to affected individuals, and credit monitoring generally respond when the policyholder's data was exposed through a vendor's systems, because the obligation to notify and remediate runs to the policyholder no matter where the compromise occurred. Legal liability to customers or regulators works the same way: the duty doesn't shift just because the vendor was the point of entry. Data recovery expenses apply when the policyholder's own systems or records were affected as a downstream consequence, even if the initial breach happened somewhere else.

The coverage that gets complicated is lost revenue. When a vendor goes down and that outage stops the policyholder's own operations, without the policyholder's network ever being touched, standard first-party business interruption language typically does not apply, because most of it is written to trigger on damage to the policyholder's own systems. Recovering that lost income requires Contingent Business Interruption coverage, a distinct policy component that has to be separately negotiated and added, not assumed as part of a standard cyber form. This distinction, between costs tied to the policyholder's own data and legal obligations versus revenue lost because a vendor stopped functioning, is where the real exposure sits. Allianz Commercial's 2025 Cyber Risk Trends report found that CBI supply chain events accounted for 15% of large cyber claims by value in the first half of 2025, a sharp increase from 2024, showing CBI as where claim dollars are concentrating as vendor dependency deepens. Understanding that split, breach response and liability on one side, business interruption on the other, is the necessary foundation for the exclusion language covered next.

Where exclusions and sub-limits cut off vendor breach recovery

The coverage gap doesn't operate through a single blanket exclusion. It runs through at least four distinct mechanisms, and the mechanism that applies to a given loss shapes whether a claim has any realistic path to payment.

The first mechanism is an explicit vendor-origin exclusion. Some policies contain language that excludes losses originating with a vendor breach rather than a direct attack on the policyholder's own systems. Insurers justify this narrowing by pointing to the difficulty of underwriting exposure they can't directly assess, since a policyholder's own security posture is auditable but a vendor's is not. Incidents now often involve a third-party vendor somewhere in the chain, so this exclusion touches a large share of the market.

The second mechanism concerns the malicious-act requirement, which appeared in full force in the CrowdStrike incident, discussed in detail in the next section: many CBI and business interruption provisions only trigger when the vendor's failure resulted from a cyberattack, not from a technical or operational failure.

The third mechanism is waiting period and restoration timing. CBI coverage typically includes a defined waiting period, often expressed in hours, before the coverage triggers. Companies that restored their systems before that period elapsed received no reimbursement, even where the underlying losses were substantial, a pattern that played out for many companies affected by the CrowdStrike outage. The incentive structure this creates is uncomfortable: a company that recovers fast can end up worse off financially, relative to its insurance recovery, than one that took longer.

The fourth mechanism is aggregate and catastrophe sub-limits. When a single event affects hundreds or thousands of policyholders simultaneously, the hallmark of a supply chain attack, insurers apply aggregate caps that reduce what any individual claimant can recover, because correlated losses are exactly the scenario these caps are designed to address.

A fifth mechanism involves nation-state attribution: if a vendor breach gets attributed to a state-sponsored actor, a war exclusion clause can void coverage entirely, independent of whether the policyholder had any connection to the underlying geopolitical conflict. Roughly a quarter of data breach claims are fully or partially denied through exclusion clauses of this kind, most commonly tied to unmet security requirements, unpatched systems, and nation-state attribution disputes. Each of these five mechanisms is a distinct clause type, and a policyholder reading their own wording needs to check for all five separately rather than assuming the absence of one means the absence of all.

Diagram: Five Mechanisms That Cut Off Vendor Breach Coverage. Visualizes: Show the five distinct policy mechanisms that block or reduce recovery from a vendor-origin cyber loss, presented as a ranked or sequential list with a brief descriptor for…

How recent incidents reveal these exclusions in practice

The CrowdStrike outage, the Change Healthcare and CDK Global ransomware attacks, and the Scattered Spider campaign against insurance carriers are not isolated anomalies. They are the clearest available tests of how vendor-breach policy language behaves once real money and real litigation are on the table.

CrowdStrike's July 2024 incident involved a faulty software update, not a cyberattack, and it caused simultaneous business interruptions across airlines, banks, and hospitals that depended on CrowdStrike's software. Because the trigger was negligence rather than malicious activity, many policies did not respond, exposing the malicious-event-only limitation described in the prior section. Many affected companies also restored their systems before the waiting period defined in their CBI provisions had elapsed, which meant they received no reimbursement despite significant losses. The episode made clear that Contingent Business Interruption coverage would have been the relevant instrument for recovery, and a large number of the affected policyholders simply did not carry it.

Change Healthcare's February 2024 ransomware attack disrupted thousands of healthcare providers and payors, and CDK Global's June 2024 ransomware attack affected thousands of car dealerships. Both were textbook third-party supply chain events triggered by malicious actors, which removes the malicious-trigger objection that limited CrowdStrike claims. Combined with losses from the MOVEit breach and the wave of attacks against Snowflake customers, the claims stemming from these events could produce a significant loss ratio impact to the insurance industry.

Scattered Spider's June 2025 campaign against the insurance sector itself carries a particular irony: companies that sell cyber insurance were disrupted by the same style of social-engineering-driven supply chain attack that their policies are meant to cover. Erie Insurance shut down its network on June 7 after detecting unauthorized activity, and the resulting interruption lasted nearly a month, severely disrupting customer service and prompting class-action litigation. Philadelphia Insurance disconnected its own network on June 9, and its service disruptions took weeks to resolve. Aflac disclosed in an SEC filing that it detected unauthorized access exposing customer data including Social Security numbers and health information. Attribution in this campaign rests on regulatory filings and initial disclosures rather than final legal determinations, but the pattern across three separate carriers within two weeks demonstrates that these attacks are sector-agnostic.

Marks & Spencer's experience in spring 2025 shows the same dynamic playing out in retail. Scattered Spider attacks cascaded through the company's supply chain, touching manufacturers, distributors, and downstream retail operations. The retailer's online ordering system needed a 46-day recovery period, reportedly costing the company £40 million a week.

Contingent Business Interruption coverage and how its terms determine claim value

Contingent Business Interruption coverage is the primary instrument available for recovering vendor-caused business losses, but its presence on a policy schedule guarantees nothing about what it will actually pay. The specific terms of the provision shape whether a claim recovers a meaningful amount or nothing at all.

CBI covers lost revenue and extra expenses incurred when a vendor's outage prevents the policyholder from operating, even when the policyholder's own systems were never touched, and insurers write it with more conditions attached than standard first-party business interruption for that reason.

The first condition is contractual. Gallagher's 2026 Cyber Insurance Market Outlook advised that carriers offering CBI coverage may require the insured to have a written contract in place with the impacted vendor before coverage will respond. A policyholder relying on an informal vendor relationship, a handshake arrangement, or a service used without a signed agreement, may find that CBI coverage does not respond even though the policy schedule lists it.

The second condition is time element wording, and Gallagher specifically flagged this as a place buyers need to look closely, because these provisions carry outsized weight in determining claim value. Defined waiting periods mean coverage only activates after an outage has persisted for a specified number of hours, and a business that restores operations quickly, or gets restored by the vendor before that period ends, recovers nothing under the provision. Period of restoration caps mean that payments stop once systems are deemed technically restorable, not once the business has actually recovered its lost revenue, so a company that regains system access but continues to lose sales during a slow customer-facing recovery may find its coverage has already lapsed.

The third condition concerns which vendors are covered. Some CBI endorsements list a fixed schedule of named vendors, and a breach originating with any vendor not on that list, even one central to daily operations, falls entirely outside the coverage. Broader unnamed vendor coverage exists, extending to any vendor relationship rather than a fixed list, but it commands higher premiums and often carries lower sub-limits than named-vendor coverage. Buyers need to weigh that trade-off against how concentrated their actual vendor dependencies are.

The fourth condition is the malicious-versus-non-malicious trigger already raised by the CrowdStrike case: CBI provisions written to require a malicious act will not respond to a negligent vendor failure, so buyers should confirm explicitly, in the policy language itself, whether a non-malicious technical failure at a vendor triggers coverage.

What vendor contracts must require to close the policy gap

Insurance alone cannot close every gap a vendor relationship creates. A well-drafted vendor contract is the most direct instrument available for closing what the policy leaves open, because a contract assigns liability and creates insurance obligations before any breach occurs, rather than sorting out responsibility after the fact.

Several contract provisions form the foundation of a defensible vendor cyber liability arrangement. The client should be named as an additional insured on the vendor's own policy, because without that designation, the vendor's coverage protects only the vendor and offers the client nothing directly. A waiver of subrogation should be included, since its absence leaves the vendor's insurer free to pursue recovery from the client after paying out a claim. The vendor's policy should be structured as primary and non-contributory, so the vendor's coverage pays out first, before the client's own policy is drawn on. The vendor's coverage should remain in force for as long as services continue, plus a minimum of five years after the contract ends, to account for breaches that are discovered long after the fact. Contracts should also prevent the vendor from canceling or materially modifying its policy without the client's consent.

Coverage limits need to be checked for internal consistency as well as adequacy. Where a vendor provides professional services and both errors-and-omissions and cyber coverage are relevant, the limits on each should match; a vendor carrying an E&O limit that substantially exceeds its cyber limit leaves the client exposed for the gap between them. A single combined policy covering both E&O and cyber removes the allocation disputes that arise when two separate insurers each try to push a claim onto the other. Where separate policies are unavoidable, the contract should require confirmation that the cyber form doesn't carry exclusions that quietly eliminate or narrow the coverage the client is depending on.

Data handling requirements bring their own contractual obligations. Where a vendor handles protected health information, a Business Associate Agreement required under the HITECH Act needs to be in place, specifying the technical controls involved and the procedures for identifying and disclosing a breach. Where a vendor handles personally identifiable information, the patchwork of state privacy laws means the contract needs to specify which jurisdictions' definitions govern the relationship, since a vendor based in Virginia doing business with clients in Texas, California, and Colorado faces different legal obligations in each of those states.

Finally, contracts should set maximum retention provisions and clear notification requirements, placing both the duty to notify and the financial responsibility for that notification squarely on the vendor when the vendor is the source of the breach. Combined, these provisions don't replace the policyholder's own cyber insurance. They fill the specific space that a first-party policy, even a well-structured one with strong CBI terms, was never designed to reach on its own.

Sources

  1. Cyber Insurance: Risks and Trends 2025 | Munich Re
  2. 30 Cyber Insurance Statistics for 2026
  3. Insure Against Data Breaches Suffered By Vendors and Service Providers: Ervin Cohen & Jessup LLP
  4. Five Issues to Watch for Cyber Insurance Coverage in 2025
  5. Coverage for the CrowdStrike Incident under Cyber Insurance?
  6. Contingent Business Interruption Insurance for Cyber Events - CoverLink Insurance - Ohio Insurance Agency
  7. When Sublimits Bite: Navigating Cyber Insurance Risks in Retail and Hospitality - Anderson Kill P.C.
  8. Third-party vendor risk drives insurance and legal scrutiny
Filed underCyber Risk

More in Cyber Risk