Does Cyber Liability Insurance Cover a Third-Party Breach?
Nearly every business today relies on outside vendors: cloud tools, payment processors, HR systems, and IT providers that touch private data daily. When one of them is breached, many companies assume their cyber policy will respond. Often it does not, and the reason is in the policy language rather than the headlines.
On This Page
- Why vendor breaches trigger claim denials — where the gap begins
- Policy exclusions that create a vendor blind spot
- How insurance applications can void coverage after a breach
- Why insurers are suing security vendors after paying claims
- What is changing in 2026
- How to close the vendor coverage gap
- Frequently Asked Questions
Why do vendor breaches trigger cyber insurance claim denials? — Where the coverage gap begins
Vendor-originated cyber incidents are breaches that start in a third-party provider but create losses for the insured company. Industry analyses have reported that a large share of cyber insurance claims — by some accounts more than 40 percent — were denied in 2024, with vendor-originated incidents among the common reasons.
Most cyber insurance covers problems that begin inside your own network. If your cloud provider is breached and your customer data is exposed as a result, many policies treat that as the vendor's responsibility. The logic resembles a home policy that covers your own house but not a flood that started on a neighbor's property.
What cyber insurance policy exclusions create a vendor blind spot? — What the policy language can exclude
Vendor-related carve-outs are built into many policies. If a company you hired — such as a payment processor — is breached, your policy may exclude that loss even though the vendor was working for you.
Vendor outage coverage usually costs extra. Without it, if a vendor's systems go down and your business cannot operate, you may have no claim. Even with the add-on, the vendor often has to be named in your policy in advance.
War-related exclusions are appearing more often. In a widely cited case, Merck filed a roughly $1.4 billion claim after the NotPetya attack, and the insurer initially refused to pay by arguing the attack was attributable to a foreign government, which it said triggered a war exclusion. The dispute settled in early 2024, but it showed how broadly such clauses can be read.
One point many companies miss: a vendor's own insurance likely will not help you. A vendor's cyber policy is designed to cover the vendor's costs, not the losses their clients face. Unless your company is named on the vendor's policy as a covered party, you generally cannot collect from their insurer — which is why vendor contracting matters as much as your own policy.
How can cyber insurance applications void coverage after a breach? — When your application becomes a condition
When you apply, the insurer asks pointed questions: Do you require multifactor authentication (MFA)? How often do you patch? Do you have an incident response plan? Your answers become part of the agreement. This has played out in court: in Columbia Casualty Co. v. Cottage Health System, the insurer argued it should not have to pay because the organization had not maintained the safeguards it represented on its application.
What is newer is how insurers detect these gaps: some now use external scanning to compare your public-facing controls against your application answers. If you stated that MFA is enabled everywhere but one system lacks it, that discrepancy alone can put coverage at risk. The same dynamic affects vendors, whose own coverage can be challenged when the safeguards they promised are not in place.
Why are cyber insurers suing security vendors after paying claims? — Litigation is widening
In a case reported in September 2025, an insurer paid a breach claim and then sued the security vendors its client had engaged, arguing they failed to perform. In another widely reported matter, a laboratory company's debt-collection vendor was breached, exposing health and financial data on a large number of patients — and the company faced suits from affected individuals, shareholders who questioned the vendor selection, and its own insurer. The pattern is clear: a single vendor breach can generate claims from customers, shareholders, regulators, and even your own insurer.
What changes could tighten cyber insurance coverage in 2026? — What is changing in 2026
As businesses adopt AI tools from outside vendors, they also take on risks that many policies do not clearly address, and AI's role in an incident can make causation harder to establish during a claim. New rules are raising the bar as well: California's privacy regulations introduce annual cybersecurity audit requirements for businesses that meet certain thresholds, effective in 2026. Falling short of obligations like these can create regulatory exposure and can also give an insurer another basis to question a claim. The net effect is stricter underwriting and more ways for coverage to fall short — which makes preparation more valuable, not less.
How can businesses close the vendor gap in cyber liability insurance? — How to close the gap
Review your policy wording so you understand whether it covers breaches that occur on vendor systems, not only your own, and whether vendor outage coverage is included or available as an endorsement.
Address vendor policy coverage in contracting. Rather than only requiring vendors to carry cyber insurance, many companies ask to be named on the vendor's policy as a covered party, often for the contract term plus a period afterward. Your broker and counsel can advise on what is appropriate for a given relationship.
Keep your application answers accurate, and keep the records that back them up: access controls, patch history, backup tests, and incident response plans. Those records are what make a claim defensible.
Strengthen vendor contracts so they specify the security practices vendors must maintain, breach notification timelines, and responsibility if something goes wrong. This connects directly to broader vendor data privacy and security vetting and to cybersecurity due diligence on the partners you rely on.
Verify rather than assume. The gap between stated and actual practice is where claims tend to fail, so routine checks of your own and your vendors' controls protect both your security and your coverage.
Frequently Asked Questions
Read more on this topic
For related guidance, see the top cybersecurity concerns for US businesses, how to vet vendors for data privacy and security, and our guide on cybersecurity due diligence.