Contingent Business Interruption Clause – Cyber
The cyber contingent business interruption clause extends cyber business interruption cover to income loss caused by a cyber incident at a third-party service provider (e.g. a cloud provider or IT vendor).
- Clause type
- Extension
- Origin/Market
- International programme
- Favours
- Insured
- Negotiability
- Negotiable
Purpose
Standard cyber BI cover only responds when the insured’s own IT systems fail. As businesses increasingly depend on cloud platforms, SaaS applications and outsourced IT providers, the contingent business interruption clause closes this gap: it extends cover to income loss caused by a cyber incident or system failure at a contractually defined or broadly described third-party provider.
Effect and limits
The trigger definition is central: some wordings only cover outages resulting from a security incident at the provider (“security failure”), while others also cover technical failures with no attack element (“system failure”, for instance a misconfiguration). A further distinction is whether the clause covers a closed list of named providers (“scheduled provider”) or a broader (“blanket”) basis for all relevant third parties. Contingent BI cover is almost always sub-limited, often well below the main limit, and is subject to the same waiting-period logic as primary cyber BI cover.
Negotiation and practice
Heavily cloud-dependent organisations should check whether the clause also captures system failures with no attack origin (relevant, for example, in large cloud outages caused by misconfiguration rather than a cyberattack) and whether the sub-limit is realistic relative to the revenue share attributable to the affected providers. A “blanket” wording without an exhaustive provider list avoids coverage gaps as new suppliers are added.