Dependent Business Interruption: The Cyber Gap Most Policies Miss

Dependent business interruption coverage in a cyber policy replaces your lost income when a third party your operations rely on — your cloud host, your payment processor, a critical software vendor — suffers an outage or breach, even though your own systems were never touched. Standard cyber business interruption only responds when the failure happens on your network, and that difference is the gap most policies miss.

Most businesses now run on infrastructure they don’t own. The accounting system, the card terminal, the scheduling platform, the servers the whole operation lives on — they belong to vendors, and the policy language has not always kept up with that reality. A cyber policy can be generous about an attack on your systems and nearly silent about an outage at the vendor whose systems actually run your business. This article explains what dependent business interruption covers, why the standard coverage stops at your own network, which vendors qualify, and where the sublimits and waiting periods quietly shrink the protection.

A warmly lit storefront business at dusk with a single thin fiber service drop descending from a utility pole to a closed gray demarcation box on its brick wall — a visual metaphor for dependent business interruption: a healthy business whose income depends entirely on the vendors at the other end of the line.
A business’s income can stop at a vendor it has never met — dependent business interruption coverage is what responds when the cloud platform, payment processor, or software provider you rely on goes down and your own systems were never touched.

What is dependent business interruption in a cyber policy?

Start with the question that decides whether this coverage matters: in the event of a claim — cyber, property, a system you can’t easily replace goes down — what happens to your income?

Business interruption coverage exists to answer that question, and on the cyber liability side of a commercial insurance program it comes in two distinct pieces. The first-party version responds when your own network is compromised or fails and your revenue stops. Dependent business interruption — carriers also call it contingent business interruption — extends that income protection to outages and security failures at the third parties your operations depend on: businesses you don’t own, can’t control, and mostly can’t even inspect.

The distinction sounds technical until the day it isn’t. Your systems can be patched, backed up, and running perfectly — and your income still stops cold because someone else’s weren’t.

Why doesn’t standard cyber business interruption cover a vendor outage?

Because the insuring agreement says so. Standard cyber business interruption is written around a failure of *your* computer systems — your network, your servers, systems you own or lease and operate. A vendor’s platform going dark is not a failure of your systems; it’s a failure of theirs. Without dependent coverage, the policy can pay nothing while your revenue sits at zero, and the denial will be technically correct.

This is the keep-versus-transfer question hiding in plain sight. Every critical vendor a business signs up — the cloud host, the processor, the industry platform everyone in your sector uses — is risk the business is keeping until the policy is read against it. Recent years supplied the proof. When a software provider that thousands of car dealerships run their entire operations on was hit with ransomware in 2024, dealerships that had never been breached themselves lost weeks of normal operations. When a healthcare claims clearinghouse was breached the same year, providers across the country — including plenty in Iowa — couldn’t process claims for weeks. In both cases the businesses that suffered weren’t the ones attacked. That is precisely the loss dependent business interruption exists to cover, and precisely the loss the standard grant ignores.

Which vendors are covered — and which trigger applies?

Two questions decide almost every dependent BI claim, and both live in the definitions.

First, *which* third parties count. Some forms cover only named vendors scheduled on the policy; others grant blanket coverage for any “dependent business” or IT provider, sometimes with a broader definition for technology vendors than for everyone else. A business whose revenue runs through one processor and one cloud region needs to know whether those specific dependencies are inside the definition — not assume they are.

Second, *what has to happen* to the vendor. A security failure trigger requires an actual attack — someone breached the vendor. A system failure trigger is broader: it covers unplanned outages of any cause, including the vendor’s own operational or administrative error, with no attacker required. Plenty of policies grant dependent coverage for security failures but exclude or sharply sublimit vendor system failure — which matters, because most cloud and platform outages are self-inflicted, not attacks. For a company whose product is uptime, this seam sits right next to the tech E&O questions covered in the SaaS and tech piece — and for everyone else, it determines whether an ordinary vendor outage is a covered loss or just a bad week.

Where do the sublimits and waiting periods hide?

In the schedule, doing quiet work. Dependent business interruption is one of the most heavily sublimited grants in the cyber market: a policy can carry a full limit for your own business interruption and a fraction of it — sometimes a small fraction — for dependent losses, with system-failure dependent coverage sublimited below that again.

Then comes the waiting period: the hours of outage a business absorbs before coverage starts, functioning as a time-based deductible. Eight hours, twelve hours, sometimes more — and for a retailer whose card processing dies on a Saturday, most of the loss can live inside the waiting period entirely. The right way to set it isn’t actuarial, it’s a cash-tolerance question: how long can the business wait for this money in the event of a loss? Insurance is for things you can’t pay for, not things you don’t want to pay for — a short outage the balance sheet can absorb is a thing you can pay for; three weeks of a dead platform is not.

Read together — the definition, the trigger, the sublimit, the waiting period — this is how a business ends up with coverage that looked fine on paper and failed when it actually mattered.

How is this different from the dependent coverage on your property policy?

Same instinct, different perils, and neither replaces the other. The property side of business interruption insurance covers dependent losses too — a key supplier’s plant burns, off-premises power fails, a customer whose orders sustain you shuts down — but it requires *physical* damage from a covered peril, and it prices the loss with the same machinery as business income and extra expense coverage. A cloud outage damages nothing physical, so the property policy sits it out; a tornado doesn’t touch your network, so the cyber policy sits that one out. A business that depends on both physical suppliers and digital vendors — which is nearly every business now — needs the two dependent grants read side by side, with the gaps between them identified on purpose rather than discovered at claim time.

How should a business size — and buy — this coverage?

Start by mapping the actual dependencies: where does revenue physically flow, and which vendor going dark stops it? For most businesses the list is short and concentrated — a processor, a cloud platform, one or two industry systems — and in Iowa that concentration is easy to see: main-street retailers, restaurants, and dealerships across the state run their payments and operations through the same handful of national platforms, so one vendor’s bad day closes doors in a hundred towns at once. Then size the exposure the way business income is always sized — revenue, margin, and how long a realistic outage runs — remembering that cyber is a whole another animal: restoration isn’t measured in construction months, but the sublimits are smaller and the waiting periods do real damage.

The timing favors doing this now. As of mid-2026 the cyber market has softened substantially, and accounts that go to market are seeing broader coverage — including better dependent BI terms — at the same or better cost than their expiring policies.

Mapping vendor dependencies against the policy’s actual definitions, triggers, sublimits, and waiting periods is exactly the work the Business Risk Diagnostic™ does before any quote: identify the risk the business is keeping, decide what to transfer, and then take the cyber program and the rest of the commercial program to market as a complete, deliberate file.

Frequently Asked Questions

What is dependent business interruption in cyber insurance?

It’s the coverage that replaces your lost income when a third party your operations depend on — a cloud host, payment processor, or critical software vendor — suffers an outage or security failure, even though your own systems were never affected. Carriers also call it contingent business interruption. Standard cyber business interruption only responds to failures of your own network.

Does standard cyber insurance cover a cloud outage?

Usually not. Standard cyber business interruption is written around failures of your own computer systems. An outage at your cloud provider is a failure of their systems, which only dependent (contingent) business interruption reaches — and even then, coverage depends on whether the policy’s trigger includes vendor system failures of any cause or only actual security breaches.

What’s the difference between a security failure and a system failure trigger?

A security failure trigger requires an actual attack on the vendor — a breach, ransomware, unauthorized access. A system failure trigger is broader and covers unplanned outages of any cause, including the vendor’s own operational error, with no attacker involved. Many policies cover dependent security failures but exclude or heavily sublimit dependent system failure, even though most major vendor outages are not attacks.

What waiting period applies to dependent business interruption?

Cyber business interruption coverage typically applies only after a waiting period — a set number of hours of outage the business absorbs itself, functioning as a time-based deductible. Waiting periods on dependent coverage are often eight to twelve hours or longer, and for short vendor outages the entire loss can fall inside the waiting period. Setting it is a cash-flow tolerance decision, not a default to accept.

Is dependent business interruption on my property policy the same thing?

No. The property version requires physical damage from a covered peril at a dependent property — a supplier’s building burns, off-premises power equipment fails. A cloud or processor outage involves no physical damage, so only the cyber policy’s dependent coverage responds. Most businesses depend on both physical suppliers and digital vendors and need the two grants read side by side.

Want to compare your options?

Click the button below to head to our quotes page where you can enter some basic information to have our team help with your insurance!

Ready to get started?

Start Your Quotes Today

Enter some basic information below to get the process started.

Service Options