
Middle‑market businesses in the $1M–$25M revenue range are often shocked to learn that standard cyber policies frequently under‑cover the three loss types that cause most six‑figure claims: business interruption from ransomware, social engineering fraud (including wire fraud and business email compromise), and breaches caused by third‑party vendors. These gaps are common even in “good” cyber programs. For a $5M business with tight operational dependencies, any one of these exposures can halt revenue, disrupt payroll, or compromise client data.
KJE Insurance works with middle‑market companies across NYC, Long Island, Westchester, and Los Angeles to help them understand how cyber liability actually responds — and where a typical policy quietly stops.
Below is a practical walkthrough designed for CFOs, COOs, and operations leaders who need a clear, non‑technical understanding of what their cyber policy should (and shouldn’t) do.
Why Middle‑Market Businesses Face Outsized Cyber Risk
For a business doing between $1M and $25M in annual revenue, cyber incidents can be disproportionately damaging. You may not have in‑house security teams, dedicated IT staff, or enterprise‑grade backups — but your clients and vendors still expect you to operate like a larger organization. That tension creates real exposure.
Most six‑figure cyber claims fall into three buckets:
- Business interruption from ransomware: Systems are locked, operations halt, and revenue pauses.
- Social engineering fraud: A fraudulent email or spoofed message convinces staff to wire money or release sensitive info.
- Third‑party vendor breaches: A payroll provider, IT vendor, or cloud platform is compromised — and you’re pulled in.
These are exactly the areas where many standard policies are weakest.
First‑Party vs. Third‑Party Cyber Coverage: What’s the Difference?
A strong cyber policy includes both first‑party and third‑party protection. Understanding the difference is crucial for a $5M business because the financial fallout typically touches both sides.
First‑Party Coverage
This covers losses your business incurs directly. Common first‑party components include:
- Data restoration – Recovering or recreating corrupted or encrypted files.
- Business interruption – Lost revenue and extra expenses during downtime.
- Ransomware response – Negotiation, payments (where legal), and recovery services.
- Cyber extortion – When someone threatens to release or destroy your data.
- Incident response costs – Forensics, breach consultants, legal counsel.
If your business runs billing, scheduling, order processing, or client portals online — this is where you feel the financial pain.
Third‑Party Coverage
This protects you when clients, partners, or regulators claim your business caused a cyber incident. Third‑party coverage often includes:
- Defense costs – Legal representation if you’re sued.
- Regulatory fines and penalties – Especially important under NYDFS, California privacy laws, or GDPR if you have international clients.
- Liability for leaked personal information – Customer, patient, or employee data.
- Contractual liability – When a client contract requires you to hold certain cyber limits.
If you handle sensitive data or operate under compliance frameworks, third‑party protection is non‑negotiable.
The Gaps Most Commonly Found in Middle‑Market Cyber Policies
1. Business Interruption That Doesn’t Actually Address Ransomware Impact
Many cyber policies include business interruption wording — but with restrictions that make them unusable. Common gaps include:
- Long waiting periods (8–24 hours before coverage starts)
- Limited recovery windows (e.g., coverage only for 7–14 days)
- Coverage only for “complete shutdown,” not partial outages
- Low sublimits that don’t match payroll or revenue levels
A $5M business might lose tens of thousands of dollars per day during downtime. If your policy doesn’t specifically address ransomware‑driven outages, revenue loss may fall far short of what you need.
2. Social Engineering & Wire Fraud: The Most Frequent Six‑Figure Loss
The most common real‑world cyber claim for middle‑market companies isn’t ransomware — it’s money being wired to the wrong place. Standard cyber liability policies often exclude:
- Fraudulent instructions sent via email
- Impersonation scams (CEO fraud, vendor spoofing)
- Payment diversion caused by compromised inboxes
Even when included, social engineering coverage is usually a small sublimit — $25K, $50K, or $100K — nowhere near the typical loss amount. A proper policy should offer:
- $250K+ social engineering limits
- Coverage for both outbound and inbound fraud
- Protection when a vendor, not your employee, is compromised
3. Third‑Party Vendor Breaches (a Huge, Underestimated Exposure)
Middle‑market businesses rely heavily on outsourced partners — IT companies, payment processors, HR platforms, cloud software. But when your vendor is breached, your business is still responsible for:
- Client notifications
- Crisis response
- Regulatory requirements
- Forensic costs
- Contractual liability
This exposure is called dependent business interruption
or contingent business interruption, and it often has very low limits in standard cyber programs.
Endorsements That $5M Businesses Should Always Ask About
Here are the key add‑ons that often determine whether a cyber policy performs during a real claim.
Social Engineering Fraud Endorsement
This closes the gap on payment diversion and fraudulent instructions. Look for:
- $250K minimum limit
- Coverage for misdirected payments initiated by employees or automated systems
- Vendor and client impersonation protection
Dependent Business Interruption Endorsement
This protects your revenue when a vendor goes down — not just your own systems. Ideal for businesses using:
- Cloud‑based CRMs or ERPs
- Online scheduling or order systems
- MSPs handling infrastructure
- E‑commerce or digital payment platforms
Reputational Harm Coverage
This pays for lost revenue tied to negative publicity after a breach. For middle‑market firms that rely on trust — financial services, legal, tech, healthcare, hospitality — reputational harm coverage is becoming essential.
What Triggers a Cyber Claim?
CFOs and operations leads often ask what actually activates a policy. Common triggers include:
- Unauthorized access to systems or data
- Encryption or corruption of files (ransomware)
- Compromised email accounts
- Lost or stolen devices
- Data sent to the wrong party
- Vendor incidents that impact your operations or data
One critical point: you only need a “suspected incident” to trigger most policies — you don’t have to prove the breach yourself.
How KJE Insurance Helps Middle‑Market Businesses Build Better Cyber Programs
KJE Insurance works closely with $1M–$25M businesses across NYC, Long Island, Westchester, and Los Angeles to build cyber programs that actually match operational reality. We focus on:
- Identifying gaps in business interruption and ransomware protections
- Ensuring social engineering limits match the size of potential transfers
- Analyzing vendor dependencies and recommending the right endorsements
- Reviewing policy language for exclusions that impact real‑world claims
To learn more about cyber liability and how stronger insurance programs are built, visit our resource page here: Cyber Liability Insurance. You can also explore our broader commercial insurance offerings here: Business Insurance.
FAQ
Do cyber policies cover ransom payments?
Yes, most policies include cyber extortion support, but only if the payment is legal and approved by the carrier.
Is cyber insurance only for tech companies?
No — any business with email, payroll, billing systems, or client data has exposure.
How long does a typical cyber claim take to resolve?
Initial response is immediate, but business interruption claims can take weeks or months depending on forensic findings.
Does my IT provider’s insurance protect me?
No. Their policy protects them. You’re still responsible for your own business interruption and client liability.
How much cyber coverage does a $5M business need?
Most choose limits between $500K and $3M depending on revenue concentration, vendor reliance, and data sensitivity.
If you’d like a clearer understanding of your cyber posture — or want to review your current program for gaps — call KJE Insurance at 212‑786‑2018 for a cyber policy review.

