Contingent Business Interruption: Insuring a Loss You Didn't Cause
On this page
- When a Vendor's Outage Becomes Your Cyber Insurance Claim
- What is contingent business interruption in cyber insurance?
- Why is a loss you didn't cause still something a business needs insured?
- What kinds of third-party outages actually trigger contingent BI claims?
- How do insurers actually calculate a contingent business interruption loss?
- What should a business check in its policy before assuming this coverage exists?
- Sources
- Frequently Asked Questions
When a Vendor's Outage Becomes Your Cyber Insurance Claim
A business can run a tight security program, pass every underwriting question with flying colors, and still lose days of revenue because a cloud provider it depends on gets knocked offline by an attack that had nothing to do with the business itself. That's the exposure contingent business interruption coverage exists to address: a loss triggered by someone else's cyber event, flowing downstream into the policyholder's own bottom line.
What is contingent business interruption in cyber insurance?
Coverage for income lost when a third party the business relies on suffers a disruptive cyber event.
Unlike direct business interruption, which responds to an attack on the policyholder's own systems, contingent business interruption responds when the disruption originates somewhere else in the chain, a cloud hosting provider, a payment processor, a critical software vendor, and that outage still stops the insured business from operating normally.
Why is a loss you didn't cause still something a business needs insured?
Because modern operations depend on systems the business doesn't own or directly control.
Most businesses today run on a stack of outside services: cloud infrastructure, identity providers, payment rails, software-as-a-service platforms. A single outage at any one of those providers can halt operations just as effectively as a direct attack, and the business bears the same lost revenue and extra expense either way, regardless of whose systems actually failed.
What kinds of third-party outages actually trigger contingent BI claims?
Cyber events at providers the business measurably depends on for revenue-generating operations.
Not every outage anywhere in a business's vendor ecosystem qualifies. The event typically needs to be a genuine cyber incident, an attack, a system compromise, a malicious disruption, rather than routine downtime or scheduled maintenance, and it needs to produce a measurable interruption to the insured's own operations to trigger a claim.
Does a cloud provider outage count as a covered contingent BI event?
Often yes, provided the outage stems from a cyber event rather than ordinary technical failure.
A ransomware attack that takes down a hosting provider's infrastructure, or a targeted intrusion that forces a cloud platform offline for remediation, generally fits the kind of event contingent BI coverage is built to respond to. This is exactly the scenario explored in modeling BGP routing incidents as contingent cyber events, where a failure far outside a company's own network still produces a direct, insurable business interruption loss.
What about a vendor that gets hit with ransomware, not the policyholder?
This is one of the more common contingent BI triggers, and it connects directly to broader supply chain exposure.
If a critical software vendor or managed service provider gets hit with ransomware and that disruption knocks out a system the insured relies on daily, the resulting interruption can be a covered contingent BI loss, assuming the policy's definition of a qualifying third party is broad enough to include that vendor relationship. This is closely tied to the larger question of cyber insurance supply chain risk, where the insured often has little visibility into the vendor's own security posture.
How do insurers actually calculate a contingent business interruption loss?
Using the same lost income and extra expense framework as direct BI, but anchored to the third party's outage timeline.
| Element | Direct business interruption | Contingent business interruption |
|---|---|---|
| Triggering event | Attack on the insured's own systems | Cyber event at a dependent third party |
| Loss period start | Insured's own detection/incident timeline | Third party's outage timeline |
| Insured's control over cause | Direct, insured manages its own security | Indirect, insured relies on vendor's posture |
| Common sublimit treatment | Often at or near full policy limit | Frequently sublimited separately |
Because the insured has far less visibility into a vendor's actual security controls, insurers often price and sublimit this coverage more conservatively than direct business interruption, even within the same overall policy.
What should a business check in its policy before assuming this coverage exists?
Whether contingent BI is explicitly defined, what waiting period applies, and how broadly "dependent third party" is defined.
Some policies name specific categories of qualifying vendors, like cloud hosting or payment processing, while others define the term broadly enough to capture almost any critical service provider. A waiting period, often a set number of hours before the interruption clock starts counting toward a covered loss, also commonly applies and can meaningfully affect what a short outage actually pays out. Reading these definitions closely, rather than assuming "business interruption" automatically includes the contingent version, is the only way to know what's actually covered before a claim tests it.
Modern businesses don't fail in isolation anymore, and neither do their losses. A well-structured contingent business interruption endorsement recognizes that a cyber event three steps removed from a company's own network can still be the reason its revenue stops flowing, and makes sure that loss doesn't fall entirely on the business that didn't cause it.
Sources
- Cambridge Centre for Risk Studies: Emerging and Systemic Risks - research on cyber accumulation and critical-infrastructure interdependency behind contingent loss scenarios
- NAIC Cybersecurity - regulator overview of cyber insurance market coverage and structure
Frequently Asked Questions
What is contingent business interruption in cyber insurance?
Coverage for income lost when a third party the business depends on, like a cloud provider or vendor, suffers a cyber event that disrupts operations.
Is contingent business interruption automatically included in cyber policies?
Not always. Some policies include it as a core coverage, while others offer it only as an optional endorsement with its own sublimit.
Does a cloud provider outage count as a contingent BI event?
Often yes, if the outage stems from a cyber event like an attack or system failure rather than routine scheduled maintenance.
How is a contingent business interruption loss calculated?
Similar to direct BI: lost income and extra expense during the disruption period, but tied to the third party's outage timeline, not the insured's own.
What's the difference between contingent BI and supply chain cyber risk?
Supply chain risk is the broader exposure category; contingent BI is the specific coverage that responds when that exposure produces a loss.
Why is contingent BI harder for insurers to price than direct BI?
Because the insured has little visibility into or control over the third party's own security posture, making the risk harder to assess directly.
Does contingent BI cover a vendor's ransomware attack even if the insured wasn't hit?
It can, if the policy is written broadly enough and the vendor's outage caused a measurable interruption to the insured's own operations.
What should a business check before assuming this coverage applies?
Whether contingent BI is a named, defined coverage in the policy, what waiting period applies, and whether specific vendors are named or excluded.

Hitul Mistry
CEO, Insurnest
An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.
View LinkedIn profile →