Does Cyber Liability Insurance Cover a Third-Party Breach?

Cyber liability insurance often pays only for incidents that originate inside the insured company's own systems. When a breach begins at a third-party vendor, many policies treat the loss as the vendor's responsibility unless vendor breach, dependent business interruption, or similar endorsements are included. Coverage can also fall short if exclusions apply, or if the application overstated security controls and the insurer later disputes the claim. Whether you are covered depends on your specific policy wording — so the details below are worth understanding before you need to file.

Nearly every business today relies on outside vendors: cloud tools, payment processors, HR systems, and IT providers that touch private data daily. When one of them is breached, many companies assume their cyber policy will respond. Often it does not, and the reason is in the policy language rather than the headlines.

Why do vendor breaches trigger cyber insurance claim denials? — Where the coverage gap begins

Many cyber liability policies restrict coverage to events that begin inside the insured network, which is why vendor incidents are a common reason claims are challenged. Customer data can be exposed through a cloud provider's breach while the insurer treats the loss as the vendor's problem — not yours to collect on.

Vendor-originated cyber incidents are breaches that start in a third-party provider but create losses for the insured company. Industry analyses have reported that a large share of cyber insurance claims — by some accounts more than 40 percent — were denied in 2024, with vendor-originated incidents among the common reasons.

Most cyber insurance covers problems that begin inside your own network. If your cloud provider is breached and your customer data is exposed as a result, many policies treat that as the vendor's responsibility. The logic resembles a home policy that covers your own house but not a flood that started on a neighbor's property.

What cyber insurance policy exclusions create a vendor blind spot? — What the policy language can exclude

Cyber insurance fine print can limit vendor losses through vendor-related carve-outs, dependent vendor outage clauses, and broad war exclusions. The practical result is that neither your policy nor the vendor's policy may pay unless the language explicitly extends coverage, or you are named on the vendor's policy.

Vendor-related carve-outs are built into many policies. If a company you hired — such as a payment processor — is breached, your policy may exclude that loss even though the vendor was working for you.

Vendor outage coverage usually costs extra. Without it, if a vendor's systems go down and your business cannot operate, you may have no claim. Even with the add-on, the vendor often has to be named in your policy in advance.

War-related exclusions are appearing more often. In a widely cited case, Merck filed a roughly $1.4 billion claim after the NotPetya attack, and the insurer initially refused to pay by arguing the attack was attributable to a foreign government, which it said triggered a war exclusion. The dispute settled in early 2024, but it showed how broadly such clauses can be read.

One point many companies miss: a vendor's own insurance likely will not help you. A vendor's cyber policy is designed to cover the vendor's costs, not the losses their clients face. Unless your company is named on the vendor's policy as a covered party, you generally cannot collect from their insurer — which is why vendor contracting matters as much as your own policy.

How can cyber insurance applications void coverage after a breach? — When your application becomes a condition

A cyber insurance application functions like a set of warranties about your security controls, and inaccurate answers can become a basis to deny a claim later. If a breach reveals a gap between what you stated and what you practiced, the insurer may decline to pay.

When you apply, the insurer asks pointed questions: Do you require multifactor authentication (MFA)? How often do you patch? Do you have an incident response plan? Your answers become part of the agreement. This has played out in court: in Columbia Casualty Co. v. Cottage Health System, the insurer argued it should not have to pay because the organization had not maintained the safeguards it represented on its application.

What is newer is how insurers detect these gaps: some now use external scanning to compare your public-facing controls against your application answers. If you stated that MFA is enabled everywhere but one system lacks it, that discrepancy alone can put coverage at risk. The same dynamic affects vendors, whose own coverage can be challenged when the safeguards they promised are not in place.

Why are cyber insurers suing security vendors after paying claims? — Litigation is widening

Insurer recovery actions are a growing pattern in which an insurer pays a cyber claim and then seeks damages from the technology or security providers it believes contributed to the loss. That puts a new kind of legal exposure on IT and security providers — and shows how broadly a single vendor breach can generate downstream liability.

In a case reported in September 2025, an insurer paid a breach claim and then sued the security vendors its client had engaged, arguing they failed to perform. In another widely reported matter, a laboratory company's debt-collection vendor was breached, exposing health and financial data on a large number of patients — and the company faced suits from affected individuals, shareholders who questioned the vendor selection, and its own insurer. The pattern is clear: a single vendor breach can generate claims from customers, shareholders, regulators, and even your own insurer.

What changes could tighten cyber insurance coverage in 2026? — What is changing in 2026

Vendor concentration, vendor outages, and AI tooling can all widen the gap between cyber risk and cyber coverage when one incident affects many insureds at once. The 2024 CrowdStrike outage is the kind of systemic event that leads insurers to tighten terms. New California cybersecurity audit requirements effective in 2026 add another layer of exposure for businesses that fall short.

As businesses adopt AI tools from outside vendors, they also take on risks that many policies do not clearly address, and AI's role in an incident can make causation harder to establish during a claim. New rules are raising the bar as well: California's privacy regulations introduce annual cybersecurity audit requirements for businesses that meet certain thresholds, effective in 2026. Falling short of obligations like these can create regulatory exposure and can also give an insurer another basis to question a claim. The net effect is stricter underwriting and more ways for coverage to fall short — which makes preparation more valuable, not less.

How can businesses close the vendor gap in cyber liability insurance? — How to close the gap

Closing the vendor coverage gap means aligning your policy wording, your vendor contracts, and your documented security controls before an incident happens. None of the steps below is legal or insurance advice, but each is a reasonable thing to review with a licensed broker and your counsel.

Review your policy wording so you understand whether it covers breaches that occur on vendor systems, not only your own, and whether vendor outage coverage is included or available as an endorsement.

Address vendor policy coverage in contracting. Rather than only requiring vendors to carry cyber insurance, many companies ask to be named on the vendor's policy as a covered party, often for the contract term plus a period afterward. Your broker and counsel can advise on what is appropriate for a given relationship.

Keep your application answers accurate, and keep the records that back them up: access controls, patch history, backup tests, and incident response plans. Those records are what make a claim defensible.

Strengthen vendor contracts so they specify the security practices vendors must maintain, breach notification timelines, and responsibility if something goes wrong. This connects directly to broader vendor data privacy and security vetting and to cybersecurity due diligence on the partners you rely on.

Verify rather than assume. The gap between stated and actual practice is where claims tend to fail, so routine checks of your own and your vendors' controls protect both your security and your coverage.

Frequently Asked Questions

Does cyber insurance cover a vendor breach?
Often only if the policy says so. Many policies pay for incidents that start on the insured company's own systems and include vendor-related carve-outs unless an endorsement extends coverage to vendor breaches or outages, sometimes requiring the vendor to be named in advance. The key variable is how the policy defines where an incident must originate.
What does cyber liability insurance typically not cover?
Common gaps include vendor-originated breaches without a specific endorsement, vendor outages without dependent business interruption coverage, losses where the application overstated security controls, and incidents an insurer attributes to war or nation-state activity under a war exclusion. Exact exclusions vary by policy, so the wording is what matters.
Why do war exclusions matter for cyber insurance claims?
War-related exclusions can bar coverage when an insurer argues a cyberattack is attributable to a foreign government or armed conflict. Merck's roughly $1.4 billion NotPetya claim, initially refused on that basis before settling in early 2024, shows how attribution debates can decide coverage — a risk that grows when exclusions are drafted broadly.
Will a vendor's cyber insurance pay for your company's losses?
Usually not. Vendor cyber policies are designed to cover the vendor's costs, not a client's losses. A client typically cannot claim against the vendor's insurer unless named on the vendor policy as a covered party, which is why named coverage language matters in vendor contracts.
What can companies do before a vendor breach to improve their odds?
Confirm whether the policy covers vendor-system breaches and outages, consider being named on a vendor's policy where appropriate, and keep records that prove controls, patching, backups, and response plans were actually in place. The goal is coverage that is defensible with documentation rather than assumptions.

Read more on this topic

For related guidance, see the top cybersecurity concerns for US businesses, how to vet vendors for data privacy and security, and our guide on cybersecurity due diligence.

Shayne Adler

Shayne Adler is the co-founder and Chief Executive Officer (CEO) of Aetos Data Consulting, specializing in cybersecurity due diligence and operationalizing regulatory and compliance frameworks for startups and small and midsize businesses (SMBs). With over 25 years of experience across nonprofit operations and strategic management, Shayne holds a Juris Doctor (JD) and a Master of Business Administration (MBA) and studied at Columbia University, the University of Michigan, and the University of California. Her work focuses on building scalable compliance and security governance programs that protect market value and satisfy investor and partner scrutiny.

Connect with Shayne on LinkedIn

https://www.aetos-data.com
Previous
Previous

How to Answer the AI Governance Section of a Security Questionnaire

Next
Next

How Can Startups Mitigate AI Risk When Processing Sensitive Customer Data?