Insurance

Contingent Business Interruption: Insuring a Loss You Didn't Cause

On this page

When a Vendor's Outage Becomes Your Cyber Insurance Claim

A business can run a tight security program, pass every underwriting question with flying colors, and still lose days of revenue because a cloud provider it depends on gets knocked offline by an attack that had nothing to do with the business itself. That's the exposure contingent business interruption coverage exists to address: a loss triggered by someone else's cyber event, flowing downstream into the policyholder's own bottom line.

What is contingent business interruption in cyber insurance?

Coverage for income lost when a third party the business relies on suffers a disruptive cyber event.

Unlike direct business interruption, which responds to an attack on the policyholder's own systems, contingent business interruption responds when the disruption originates somewhere else in the chain, a cloud hosting provider, a payment processor, a critical software vendor, and that outage still stops the insured business from operating normally.

Why is a loss you didn't cause still something a business needs insured?

Because modern operations depend on systems the business doesn't own or directly control.

Most businesses today run on a stack of outside services: cloud infrastructure, identity providers, payment rails, software-as-a-service platforms. A single outage at any one of those providers can halt operations just as effectively as a direct attack, and the business bears the same lost revenue and extra expense either way, regardless of whose systems actually failed.

What kinds of third-party outages actually trigger contingent BI claims?

Cyber events at providers the business measurably depends on for revenue-generating operations.

Not every outage anywhere in a business's vendor ecosystem qualifies. The event typically needs to be a genuine cyber incident, an attack, a system compromise, a malicious disruption, rather than routine downtime or scheduled maintenance, and it needs to produce a measurable interruption to the insured's own operations to trigger a claim.

Does a cloud provider outage count as a covered contingent BI event?

Often yes, provided the outage stems from a cyber event rather than ordinary technical failure.

A ransomware attack that takes down a hosting provider's infrastructure, or a targeted intrusion that forces a cloud platform offline for remediation, generally fits the kind of event contingent BI coverage is built to respond to. This is exactly the scenario explored in modeling BGP routing incidents as contingent cyber events, where a failure far outside a company's own network still produces a direct, insurable business interruption loss.

What about a vendor that gets hit with ransomware, not the policyholder?

This is one of the more common contingent BI triggers, and it connects directly to broader supply chain exposure.

If a critical software vendor or managed service provider gets hit with ransomware and that disruption knocks out a system the insured relies on daily, the resulting interruption can be a covered contingent BI loss, assuming the policy's definition of a qualifying third party is broad enough to include that vendor relationship. This is closely tied to the larger question of cyber insurance supply chain risk, where the insured often has little visibility into the vendor's own security posture.

How do insurers actually calculate a contingent business interruption loss?

Using the same lost income and extra expense framework as direct BI, but anchored to the third party's outage timeline.

ElementDirect business interruptionContingent business interruption
Triggering eventAttack on the insured's own systemsCyber event at a dependent third party
Loss period startInsured's own detection/incident timelineThird party's outage timeline
Insured's control over causeDirect, insured manages its own securityIndirect, insured relies on vendor's posture
Common sublimit treatmentOften at or near full policy limitFrequently sublimited separately

Because the insured has far less visibility into a vendor's actual security controls, insurers often price and sublimit this coverage more conservatively than direct business interruption, even within the same overall policy.

What should a business check in its policy before assuming this coverage exists?

Whether contingent BI is explicitly defined, what waiting period applies, and how broadly "dependent third party" is defined.

Some policies name specific categories of qualifying vendors, like cloud hosting or payment processing, while others define the term broadly enough to capture almost any critical service provider. A waiting period, often a set number of hours before the interruption clock starts counting toward a covered loss, also commonly applies and can meaningfully affect what a short outage actually pays out. Reading these definitions closely, rather than assuming "business interruption" automatically includes the contingent version, is the only way to know what's actually covered before a claim tests it.

Modern businesses don't fail in isolation anymore, and neither do their losses. A well-structured contingent business interruption endorsement recognizes that a cyber event three steps removed from a company's own network can still be the reason its revenue stops flowing, and makes sure that loss doesn't fall entirely on the business that didn't cause it.

Sources

Frequently Asked Questions

What is contingent business interruption in cyber insurance?

Coverage for income lost when a third party the business depends on, like a cloud provider or vendor, suffers a cyber event that disrupts operations.

Is contingent business interruption automatically included in cyber policies?

Not always. Some policies include it as a core coverage, while others offer it only as an optional endorsement with its own sublimit.

Does a cloud provider outage count as a contingent BI event?

Often yes, if the outage stems from a cyber event like an attack or system failure rather than routine scheduled maintenance.

How is a contingent business interruption loss calculated?

Similar to direct BI: lost income and extra expense during the disruption period, but tied to the third party's outage timeline, not the insured's own.

What's the difference between contingent BI and supply chain cyber risk?

Supply chain risk is the broader exposure category; contingent BI is the specific coverage that responds when that exposure produces a loss.

Why is contingent BI harder for insurers to price than direct BI?

Because the insured has little visibility into or control over the third party's own security posture, making the risk harder to assess directly.

Does contingent BI cover a vendor's ransomware attack even if the insured wasn't hit?

It can, if the policy is written broadly enough and the vendor's outage caused a measurable interruption to the insured's own operations.

What should a business check before assuming this coverage applies?

Whether contingent BI is a named, defined coverage in the policy, what waiting period applies, and whether specific vendors are named or excluded.

Hitul Mistry

Hitul Mistry

CEO, Insurnest

An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.

View LinkedIn profile →
ShareLinkedInX

Read our latest blogs and research

Featured Resources

Reinsurance

Internet Routing Outages: Modeling BGP Incidents as Contingent Cyber Events

Internet routing outages from BGP hijacks and leaks are contingent cyber events most reinsurance treaties never modeled. Learn how internet telemetry is turning routing incidents into measurable accumulation scenarios.

Read more
Insurance

Cyber Insurance Supply Chain Risk: Pricing Exposure You Cannot Fully Audit

Cyber insurance supply chain risk is one of the hardest exposures for underwriters to price, since the weak link often sits several layers away from the policyholder. Here is how carriers approach it anyway.

Read more
Reinsurance

Identity Provider Outages: Modeling the Single Point of Failure in Digital Commerce

Identity provider outages are the single point of failure most cyber portfolios overlook. Learn how dependency maps and contingent-loss scenarios turn authentication risk into modelable accumulation for reinsurance treaties.

Read more

Meet Our Innovators:

We aim to revolutionize how businesses operate through digital technology driving industry growth and positioning ourselves as global leaders.

circle basecircle base
Pioneering Digital Solutions in Insurance

Insurnest

Empowering insurers, re-insurers, and brokers to excel with innovative technology.

Insurnest specializes in digital solutions for the insurance sector, helping insurers, re-insurers, and brokers enhance operations and customer experiences with cutting-edge technology. Our deep industry expertise enables us to address unique challenges and drive competitiveness in a dynamic market.

Get in Touch with us

Ready to transform your business? Contact us now!