Cyber Liability Insurance for the $5M Business: Where Gaps Usually Hide
John Russo
Aug 19 2026 13:00

Middle‑market businesses in the $1M–$25M revenue range are often shocked to learn that standard cyber policies frequently under‑cover the three loss types that cause most six‑figure claims: business interruption from ransomware, social engineering fraud (including wire fraud and business email compromise), and breaches caused by third‑party vendors. These gaps are common even in “good” cyber programs. For a $5M business with tight operational dependencies, any one of these exposures can halt revenue, disrupt payroll, or compromise client data.

KJE Insurance works with middle‑market companies across NYC, Long Island, Westchester, and Los Angeles to help them understand how cyber liability actually responds — and where a typical policy quietly stops.

Below is a practical walkthrough designed for CFOs, COOs, and operations leaders who need a clear, non‑technical understanding of what their cyber policy should (and shouldn’t) do.

Why Middle‑Market Businesses Face Outsized Cyber Risk

For a business doing between $1M and $25M in annual revenue, cyber incidents can be disproportionately damaging. You may not have in‑house security teams, dedicated IT staff, or enterprise‑grade backups — but your clients and vendors still expect you to operate like a larger organization. That tension creates real exposure.

Most six‑figure cyber claims fall into three buckets:

  • Business interruption from ransomware: Systems are locked, operations halt, and revenue pauses.
  • Social engineering fraud: A fraudulent email or spoofed message convinces staff to wire money or release sensitive info.
  • Third‑party vendor breaches: A payroll provider, IT vendor, or cloud platform is compromised — and you’re pulled in.

These are exactly the areas where many standard policies are weakest.

First‑Party vs. Third‑Party Cyber Coverage: What’s the Difference?

A strong cyber policy includes both first‑party and third‑party protection. Understanding the difference is crucial for a $5M business because the financial fallout typically touches both sides.

First‑Party Coverage

This covers losses your business incurs directly. Common first‑party components include:

  • Data restoration – Recovering or recreating corrupted or encrypted files.
  • Business interruption – Lost revenue and extra expenses during downtime.
  • Ransomware response – Negotiation, payments (where legal), and recovery services.
  • Cyber extortion – When someone threatens to release or destroy your data.
  • Incident response costs – Forensics, breach consultants, legal counsel.

If your business runs billing, scheduling, order processing, or client portals online — this is where you feel the financial pain.

Third‑Party Coverage

This protects you when clients, partners, or regulators claim your business caused a cyber incident. Third‑party coverage often includes:

  • Defense costs – Legal representation if you’re sued.
  • Regulatory fines and penalties – Especially important under NYDFS, California privacy laws, or GDPR if you have international clients.
  • Liability for leaked personal information – Customer, patient, or employee data.
  • Contractual liability – When a client contract requires you to hold certain cyber limits.

If you handle sensitive data or operate under compliance frameworks, third‑party protection is non‑negotiable.

The Gaps Most Commonly Found in Middle‑Market Cyber Policies

1. Business Interruption That Doesn’t Actually Address Ransomware Impact

Many cyber policies include business interruption wording — but with restrictions that make them unusable. Common gaps include:

  • Long waiting periods (8–24 hours before coverage starts)
  • Limited recovery windows (e.g., coverage only for 7–14 days)
  • Coverage only for “complete shutdown,” not partial outages
  • Low sublimits that don’t match payroll or revenue levels

A $5M business might lose tens of thousands of dollars per day during downtime. If your policy doesn’t specifically address ransomware‑driven outages, revenue loss may fall far short of what you need.

2. Social Engineering & Wire Fraud: The Most Frequent Six‑Figure Loss

The most common real‑world cyber claim for middle‑market companies isn’t ransomware — it’s money being wired to the wrong place. Standard cyber liability policies often exclude:

  • Fraudulent instructions sent via email
  • Impersonation scams (CEO fraud, vendor spoofing)
  • Payment diversion caused by compromised inboxes

Even when included, social engineering coverage is usually a small sublimit — $25K, $50K, or $100K — nowhere near the typical loss amount. A proper policy should offer:

  • $250K+ social engineering limits
  • Coverage for both outbound and inbound fraud
  • Protection when a vendor, not your employee, is compromised

3. Third‑Party Vendor Breaches (a Huge, Underestimated Exposure)

Middle‑market businesses rely heavily on outsourced partners — IT companies, payment processors, HR platforms, cloud software. But when your vendor is breached, your business is still responsible for:

  • Client notifications
  • Crisis response
  • Regulatory requirements
  • Forensic costs
  • Contractual liability

This exposure is called dependent business interruption or contingent business interruption, and it often has very low limits in standard cyber programs.

Endorsements That $5M Businesses Should Always Ask About

Here are the key add‑ons that often determine whether a cyber policy performs during a real claim.

Social Engineering Fraud Endorsement

This closes the gap on payment diversion and fraudulent instructions. Look for:

  • $250K minimum limit
  • Coverage for misdirected payments initiated by employees or automated systems
  • Vendor and client impersonation protection

Dependent Business Interruption Endorsement

This protects your revenue when a vendor goes down — not just your own systems. Ideal for businesses using:

  • Cloud‑based CRMs or ERPs
  • Online scheduling or order systems
  • MSPs handling infrastructure
  • E‑commerce or digital payment platforms

Reputational Harm Coverage

This pays for lost revenue tied to negative publicity after a breach. For middle‑market firms that rely on trust — financial services, legal, tech, healthcare, hospitality — reputational harm coverage is becoming essential.

What Triggers a Cyber Claim?

CFOs and operations leads often ask what actually activates a policy. Common triggers include:

  • Unauthorized access to systems or data
  • Encryption or corruption of files (ransomware)
  • Compromised email accounts
  • Lost or stolen devices
  • Data sent to the wrong party
  • Vendor incidents that impact your operations or data

One critical point: you only need a “suspected incident” to trigger most policies — you don’t have to prove the breach yourself.

How KJE Insurance Helps Middle‑Market Businesses Build Better Cyber Programs

KJE Insurance works closely with $1M–$25M businesses across NYC, Long Island, Westchester, and Los Angeles to build cyber programs that actually match operational reality. We focus on:

  • Identifying gaps in business interruption and ransomware protections
  • Ensuring social engineering limits match the size of potential transfers
  • Analyzing vendor dependencies and recommending the right endorsements
  • Reviewing policy language for exclusions that impact real‑world claims

To learn more about cyber liability and how stronger insurance programs are built, visit our resource page here: Cyber Liability Insurance. You can also explore our broader commercial insurance offerings here: Business Insurance.

FAQ

Do cyber policies cover ransom payments?

Yes, most policies include cyber extortion support, but only if the payment is legal and approved by the carrier.

Is cyber insurance only for tech companies?

No — any business with email, payroll, billing systems, or client data has exposure.

How long does a typical cyber claim take to resolve?

Initial response is immediate, but business interruption claims can take weeks or months depending on forensic findings.

Does my IT provider’s insurance protect me?

No. Their policy protects them. You’re still responsible for your own business interruption and client liability.

How much cyber coverage does a $5M business need?

Most choose limits between $500K and $3M depending on revenue concentration, vendor reliance, and data sensitivity.

If you’d like a clearer understanding of your cyber posture — or want to review your current program for gaps — call KJE Insurance at 212‑786‑2018 for a cyber policy review.