When a board asks “what would a cyber event cost us?” they’re asking the wrong question. The real loss in a ransomware event isn’t the data breach—it’s the business interruption that follows. Most cyber insurance policies were built for data breach scenarios, which means most boards are radically underinsured for their actual exposure.
How Cyber Insurance Has Been Sized Wrong
Cyber insurance evolved to address data breach liability and regulatory exposure. Both are quantifiable. A breach of 1 million records triggers notification costs, GDPR-mandated regulatory fines, and customer litigation. You can model it. You can price it. You can buy a cyber insurance policy around it.
Business interruption is harder to quantify. It depends on your revenue model, your system architecture, your incident response speed, and factors outside your control like customer behavior during recovery. So boards sidestep the question. They size cyber insurance based on data breach scenarios and regulatory exposure, not on what systems actually cost when they stay down.
This worked when most cyber losses were breach-related. It doesn’t work anymore.
Why Cyber Insurance Misses Business Interruption Losses
The ransomware event of 2020-2026 changed what cyber actually costs. Attackers don’t care about your data. They care about your operations. Lock your systems. Demand payment. You lose revenue while systems are offline. The longer the outage, the higher the loss.
For a SaaS platform losing $500,000 daily, two weeks offline is a $7 million revenue hole. For a retail business, two weeks is bankruptcy. For a supply chain company, two weeks is customer contracts voided and market share permanently lost.
This loss dwarfs the data breach indemnity. But most cyber policies are sized assuming the data breach is the primary loss driver.
Contingent Cyber Insurance Gaps Most Boards Ignore
Ask your board: “What would a two-week outage cost this business?”
Most boards can’t answer. They know the data they hold. They can estimate regulatory exposure. But they can’t model lost revenue, operational costs that don’t stop, contractual penalties, and customer churn in the weeks after recovery.
This gap between known exposure and unknown exposure is where underinsurance lives.
Business Interruption Is Sub-Limited, Often Below Real Exposure
Most cyber policies include business interruption coverage. But it’s often sub-limited well below the main aggregate. A $10 million cyber policy might include only $2 million in business interruption coverage. That $2 million covers a 4-day outage, not a 2-week outage.
Contingent business interruption—coverage for when your suppliers or vendors go down—is sub-limited even more aggressively. You depend on three critical vendors. One gets ransomware-attacked. Your operations stall. Your contingent business interruption sub-limit covers 10% of your actual exposure.
Boards rarely review these sub-limits. They see the main aggregate and assume they’re covered.
Reputational Harm Shows Up In Following Quarters
A public cyber event triggers customer churn immediately. But the full reputational cost extends across the following two to four quarters. Customers leave. New customer acquisition costs spike. Market share shifts. The revenue impact compounds.
Most cyber policies focus on the incident window. Coverage for notification costs, forensics, legal counsel, and ransom negotiation. But coverage for the 12-month revenue recovery that follows is absent or minimal.
Boards rarely budget for reputational recovery. They assume revenue bounces back the day systems recover. It doesn’t.
The Right Tower Reflects Operational Continuity, Not Just Compliance
A properly sized cyber tower reflects the scenario most likely to occur: a multi-week operational outage triggered by ransomware, followed by months of customer recovery and regulator investigation.
This tower includes:
Business interruption coverage sufficient for a multi-week outage across all revenue channels. Contingent business interruption coverage for suppliers and vendors. Reputational harm and customer churn coverage. Extended regulator investigation costs. Crisis communication and recovery support.
Most towers include fragments of this. Few boards have modelled the full scenario.
Why This Matters Now
Cyber events are no longer rare. They’re becoming routine. And they’re no longer small. A one-week outage for a mid-market business is a $10+ million loss. Most cyber policies have a $2-5 million indemnity limit.
The gap between actual exposure and insured exposure is widening, not shrinking.
The Board Conversation That Needs To Happen
Before renewing cyber insurance, boards should have this conversation:
First, model the outage scenario. What would a two-week outage cost across all dimensions: lost revenue, operational costs, penalties, customer churn, and regulator investigation?
Second, review your cyber tower against this model. Is your business interruption coverage sufficient? Are your sub-limits adequate? Do you have coverage for contingent business interruption? For reputational recovery?
Third, close the gap. Either increase your cyber cover to match your actual exposure, or accept the underinsurance risk explicitly.
Most boards skip this conversation. They renew their policy year after year without modelling what they’re actually exposed to.
Understanding Your Actual Cyber Exposure
Cyber insurance sizing should follow operational reality, not historical precedent. The dominant loss today is business interruption. Your tower should reflect that.
Continuum helps boards model the multi-week outage scenario and size cyber cover accordingly. We review your current tower, identify the gaps between your actual exposure and your insured exposure, and rebuild your cover around what a true operational continuity event would cost.
Before the next ransomware event locks your systems, know what that outage would cost. Contact Continuum to model your cyber exposure and size your cover correctly.
