{
  "id": "clause-contingent-bi-cyber",
  "type": "clause",
  "languages": {
    "en": {
      "id": "clause-contingent-bi-cyber",
      "lang": "en",
      "type": "clause",
      "title": "Contingent Business Interruption Clause – Cyber",
      "shortDefinition": "The cyber contingent business interruption clause extends cyber business interruption cover to income loss caused by a cyber incident at a third-party service provider (e.g. a cloud provider or IT vendor).",
      "synonyms": [
        "Dependent Business Interruption"
      ],
      "linesOfBusiness": [
        "Cyber insurance"
      ],
      "jurisdictions": [
        "Global"
      ],
      "tags": [
        "Cyber",
        "Business interruption",
        "Supply chain"
      ],
      "relations": {
        "relatedTerms": [],
        "partOf": [],
        "appliesTo": [
          "cov-cyber"
        ],
        "regulatedBy": [],
        "relevantFor": [],
        "insurableVia": [],
        "mitigatedBy": [],
        "comprises": [],
        "alternativeTo": [],
        "complementedBy": []
      },
      "attribute": null,
      "profile": null,
      "coverageProfile": null,
      "clause": {
        "kind": "extension",
        "origin": "international-programme",
        "favours": "insured",
        "negotiability": "negotiable",
        "standardWordings": []
      },
      "legalBasis": [],
      "standards": [],
      "reviewStatus": "expert-reviewed",
      "reviewedBy": "Guido Hesse, Hesse Group Holding AG",
      "lastReviewed": "2026-09-04",
      "version": "0.1.0",
      "updated": "2026-09-03",
      "generated": {
        "by": "cursor-agent/claude-sonnet-5",
        "at": "2026-09-03T00:00:00.000Z"
      },
      "verified": [
        {
          "by": "human:ghesse",
          "at": "2026-09-04T00:00:00.000Z",
          "method": null
        }
      ],
      "staleAfter": null,
      "url": "https://hgh.ch/lexikon/en/knowledge/clause/contingent-business-interruption-clause-cyber/",
      "alternateUrl": "https://hgh.ch/lexikon/de/wissen/klausel/contingent-bi-klausel-cyber/",
      "body": "## Purpose\n\nStandard cyber BI cover only responds when the insured's own IT systems fail. As businesses increasingly depend on cloud platforms, SaaS applications and outsourced IT providers, the contingent business interruption clause closes this gap: it extends cover to income loss caused by a cyber incident or system failure at a contractually defined or broadly described third-party provider.\n\n## Effect and limits\n\nThe trigger definition is central: some wordings only cover outages resulting from a security incident at the provider (\"security failure\"), while others also cover technical failures with no attack element (\"system failure\", for instance a misconfiguration). A further distinction is whether the clause covers a closed list of named providers (\"scheduled provider\") or a broader (\"blanket\") basis for all relevant third parties. Contingent BI cover is almost always sub-limited, often well below the main limit, and is subject to the same waiting-period logic as primary cyber BI cover.\n\n## Negotiation and practice\n\nHeavily cloud-dependent organisations should check whether the clause also captures system failures with no attack origin (relevant, for example, in large cloud outages caused by misconfiguration rather than a cyberattack) and whether the sub-limit is realistic relative to the revenue share attributable to the affected providers. A \"blanket\" wording without an exhaustive provider list avoids coverage gaps as new suppliers are added."
    },
    "de": {
      "id": "clause-contingent-bi-cyber",
      "lang": "de",
      "type": "clause",
      "title": "Contingent-BI-Klausel Cyber",
      "shortDefinition": "Die Contingent-BI-Klausel (Cyber) erweitert die Cyber-Betriebsunter­brechungs­deckung auf Ertragsausfälle, die durch einen Cybervorfall bei einem Drittdienstleister (z.B. Cloud-Anbieter, IT-Dienstleister) verursacht werden.",
      "synonyms": [
        "Contingent Business Interruption",
        "Dependent Business Interruption"
      ],
      "linesOfBusiness": [
        "Cyberversicherung"
      ],
      "jurisdictions": [
        "Global"
      ],
      "tags": [
        "Cyber",
        "Betriebsunterbrechung",
        "Lieferketten"
      ],
      "relations": {
        "relatedTerms": [],
        "partOf": [],
        "appliesTo": [
          "cov-cyber"
        ],
        "regulatedBy": [],
        "relevantFor": [],
        "insurableVia": [],
        "mitigatedBy": [],
        "comprises": [],
        "alternativeTo": [],
        "complementedBy": []
      },
      "attribute": null,
      "profile": null,
      "coverageProfile": null,
      "clause": {
        "kind": "extension",
        "origin": "international-programme",
        "favours": "insured",
        "negotiability": "negotiable",
        "standardWordings": []
      },
      "legalBasis": [],
      "standards": [],
      "reviewStatus": "expert-reviewed",
      "reviewedBy": "Guido Hesse, Hesse Group Holding AG",
      "lastReviewed": "2026-09-04",
      "version": "0.1.0",
      "updated": "2026-09-03",
      "generated": {
        "by": "cursor-agent/claude-sonnet-5",
        "at": "2026-09-03T00:00:00.000Z"
      },
      "verified": [
        {
          "by": "human:ghesse",
          "at": "2026-09-04T00:00:00.000Z",
          "method": null
        }
      ],
      "staleAfter": null,
      "url": "https://hgh.ch/lexikon/de/wissen/klausel/contingent-bi-klausel-cyber/",
      "alternateUrl": "https://hgh.ch/lexikon/en/knowledge/clause/contingent-business-interruption-clause-cyber/",
      "body": "## Zweck\n\nStandard-Cyber-BU-Deckung greift nur, wenn eigene IT-Systeme des Versicherten ausfallen. Da Unternehmen zunehmend von Cloud-Plattformen, SaaS-Anwendungen und externen IT-Dienstleistern abhängen, schliesst die Contingent-BI-Klausel diese Lücke: Sie erstreckt die Deckung auf Ertragsausfälle, die durch einen Cybervorfall oder Systemausfall bei einem vertraglich definierten oder generell umschriebenen Drittanbieter verursacht werden.\n\n## Wirkung und Grenzen\n\nZentral ist die Auslöserdefinition («trigger»): Manche Wordings decken nur Ausfälle infolge eines Sicherheitsvorfalls beim Dienstleister («security failure»), andere auch technische Störungen ohne Angriffshintergrund («system failure», z.B. eine Fehlkonfiguration). Weiter ist zu unterscheiden, ob die Klausel eine geschlossene Liste benannter Dienstleister («scheduled provider») oder eine generelle («blanket») Deckung aller relevanten Drittanbieter vorsieht. Contingent-BI-Deckung ist praktisch immer sublimitiert, oft deutlich unter dem Hauptlimit, und unterliegt der gleichen Wartezeit-Logik wie die primäre Cyber-BU-Deckung.\n\n## Verhandlung und Praxis\n\nBei stark cloud-abhängigen Unternehmen ist zu prüfen, ob die Klausel auch Systemausfälle ohne Angriffsursprung erfasst (relevant z.B. bei grossen Cloud-Ausfällen durch Fehlkonfiguration statt Cyberangriff) und ob das Sublimit realistisch zum Umsatzanteil der betroffenen Dienstleister steht. Eine «blanket»-Fassung ohne abschliessende Anbieterliste vermeidet Deckungslücken bei neu hinzukommenden Lieferanten."
    }
  }
}