Licensed Agency · NPN #22222940·Prefer a human? Call our Orlando team: +1 (689) 353-8505
Truscott Insurance SolutionsTruscott Insurance Solutions
FeaturesHow It WorksBlog
Truscott Insurance SolutionsTruscott Insurance Solutions

Your insurance ally. We simplify policies, coach you on claims, and monitor for gotchas, so you're never caught off guard.

Call us: +1 (689) 353-8505

Tools

  • Policy Simplified
  • Claims Coach
  • Blog

Products

  • Auto Insurance
  • Home Insurance
  • Business Insurance
  • Cyber Insurance

Legal

  • Privacy Policy
  • Do Not Sell My Personal Information
  • Terms of Service
  • Licenses

© 2026 Truscott Inc. All rights reserved.

Truscott provides insurance information tools. AI-generated analyses are for informational purposes only and do not constitute insurance advice, legal advice, or coverage guarantees.

Back to Blog
Cyber Insurance

What Is a Cyber Insurance Retention and How Does It Work?

Truscott Team
August 29, 2026
7 min read

When business owners read a cyber insurance quote for the first time, the number that usually causes confusion is the retention. It looks like a deductible, it behaves a little like a deductible, and it is often described as one by people who should know better. But cyber policies handle retentions differently than the auto and homeowners policies most people are used to, and there is a second, time-based version of the same idea buried in the business interruption section.

What a retention actually is

A retention is the portion of a covered loss your business keeps for itself before the insurer's money begins. If your policy has a $10,000 retention and you suffer a $75,000 ransomware event, the carrier pays $65,000 and you absorb the first $10,000. The concept is simple. What changes is how the dollars physically move.

On most cyber policies the retention is not paid up front in cash to anyone. Instead, the insurer arranges and pays for the forensics firm, the breach coach, the notification vendor, and the rest of the response, then applies the retention against the total. In practice you may be invoiced for your share afterward or see it netted out of the settlement. The important part is that the retention applies to the whole incident, not to each individual vendor bill.

Retentions on small-business cyber policies commonly run from $1,000 to $25,000. Larger organizations, or businesses in higher-risk classes such as healthcare and financial services, frequently see $50,000 or more. The size is negotiable at quoting time, and it interacts with your premium in ways worth understanding before you sign.

How a retention differs from a deductible

The technical distinction is about who pays first and who controls the money. With a traditional deductible, the insurer pays the full loss and then subtracts your deductible from the check. With a true retention, you are considered to be self-insuring that first layer, and the insurer's obligation, including in many cases its duty to defend you, does not attach until the retention is satisfied.

That difference matters in a few practical ways:

  • Defense costs usually erode the retention. On cyber policies, legal fees, forensics, and notification expenses typically count toward the retention rather than sitting on top of it.
  • You may need liquidity fast. If a policy requires you to fund the retention before panel vendors engage, you need that cash available in the first 48 hours of an incident.
  • Consent still applies. Even though you are paying the first layer, most policies require insurer approval before you hire counsel or forensics. Spending your own retention on an unapproved vendor can jeopardize the rest of the claim.

Some carriers use the words interchangeably and structure the retention to behave exactly like a deductible. Others do not. Reading the actual language, or having someone translate the policy for you, is the only way to know which version you bought.

Does one retention apply to the whole policy?

Rarely. Most cyber policies apply the retention per claim or per incident, meaning two unrelated events in the same policy year each carry their own retention. A phishing wire fraud in March and a ransomware attack in September are two separate retentions, not one.

It is also increasingly common to see different retentions for different coverage parts. A policy might carry a $5,000 retention for privacy liability and network security claims, a $25,000 retention specifically for ransomware or extortion events, and a separate, often much higher retention for social engineering and funds transfer fraud. Carriers do this because those coverages have different loss frequencies. If your quote shows one headline retention, ask whether any coverage part carries a higher one.

Watch for related-claims language too. If several incidents trace back to the same root cause, such as one unpatched server exploited repeatedly, they are usually treated as a single claim with one retention. That works in your favor on the retention side but can also mean they share a single limit.

Waiting periods: the time-based retention

Business interruption coverage on a cyber policy does not use a dollar retention as its primary trigger. It uses a waiting period, sometimes called a time retention. This is the number of hours your systems must be down before lost income coverage begins to accrue. Typical waiting periods are 6, 8, 12, or 24 hours, though 48 and 72 hours still appear on some contracts.

The mechanics matter more than the number. If your policy has a 12-hour waiting period and an outage lasts 10 hours, you collect nothing for business interruption even though the incident is otherwise covered. If the same outage lasts 40 hours, you generally collect for the income lost after hour 12, not from hour one. A small number of policies are written so that satisfying the waiting period retroactively opens coverage back to the start of the outage. That is a meaningfully better provision and worth asking about.

For a business that runs on real-time systems, a point-of-sale operation, a medical practice with scheduling and imaging, a logistics firm dispatching loads, the difference between a 6-hour and a 24-hour waiting period can be the difference between a useful claim and no claim at all. Most ransomware-driven outages last far longer than a day, but the more common events, cloud provider hiccups and short-lived denial-of-service attacks, often resolve inside 12 hours.

How the dollar retention and waiting period work together

A single incident can trigger both. Say ransomware takes your systems down for four days. The forensics, legal, and restoration costs fall under first-party incident response and are subject to the dollar retention. The revenue you lost while closed falls under business interruption and is subject to the waiting period. Depending on the carrier, the business interruption loss may also be subject to the dollar retention, or the waiting period may serve as the only retention for that coverage part.

Some policies stack both. Others apply whichever produces the greater deduction. A few apply the dollar retention once across the entire incident regardless of how many coverage parts respond, which is the most favorable structure. This is not a detail you can infer from the declarations page; it lives in the conditions section.

Choosing the right retention level

The instinct is to take the lowest retention available. That is not always right. Moving from a $25,000 retention to a $5,000 retention on a small-business policy might add a few hundred dollars of premium, which is usually worth it. But on larger accounts, buying down the retention can cost more over five years than the retention itself.

Three questions help set the number. First, what could you write a check for tomorrow without disrupting payroll? That is your realistic ceiling. Second, how likely is a claim in your industry? Firms handling protected health information, client trust funds, or large wire transfers claim more often, which makes a lower retention more valuable. Third, does a higher retention buy you something better elsewhere, such as a shorter waiting period or a higher sublimit on funds transfer fraud? Trading retention dollars for broader coverage is often the smarter move.

Businesses evaluating cyber insurance in Florida should also confirm that any retention buy-down does not come with tighter security warranties. Some carriers offer the lower retention only if you maintain multifactor authentication, offline backups, and endpoint detection. Those are good controls to have anyway, but you need to actually have them, because failing a warranty at claim time is worse than a high retention.

Frequently asked questions

Do I have to pay the retention before the insurer sends help?

Usually not. Most cyber carriers dispatch their panel forensics and legal team immediately and reconcile the retention later, because delaying response costs everyone money. A minority of policies do require the insured to fund the first layer directly, so confirm which arrangement yours uses before an incident, not during one.

Does the retention reduce my policy limit?

No. The retention sits below the limit, not inside it. A $1 million limit with a $10,000 retention means the insurer will pay up to $1 million after your $10,000, for a total available of $1,010,000 on that claim. What does erode the limit is defense and response spending above the retention.

What happens if my outage is shorter than the waiting period?

You get no business interruption payment for that event, though other coverage parts such as incident response and data restoration can still respond if their triggers are met. This is exactly why the waiting period deserves as much attention as the dollar retention when you compare quotes.

Can I change my retention mid-term?

Typically only by endorsement with the carrier's agreement, and usually at renewal rather than mid-term. If your revenue, headcount, or data volume has changed significantly, raise it at renewal when you also revisit limits and sublimits.

Is the retention tax deductible?

Retention amounts paid on a covered business loss are generally treated as ordinary business expenses, but the treatment depends on the nature of the payment and your accounting method. Ask your CPA rather than your agent on that one.

What Truscott recommends

Retentions and waiting periods are where two cyber quotes at the same premium quietly become very different policies, and the differences only surface when you are already in the middle of an incident. Before you renew, pull the declarations page and the conditions section together and confirm the per-claim retention, any coverage-specific retentions, and the business interruption waiting period. A Truscott coverage review will walk through those numbers alongside your actual downtime tolerance and cash position so the structure fits how your business really operates. Reach out or request a quote and we will compare the retention terms side by side.

Free tools from Truscott

  • Cyber insurance
  • Florida cyber insurance

More from the blog

Cyber Insurance

What Changes at Your Cyber Insurance Renewal?

Cyber renewals move more than most lines of insurance. Learn what underwriters re-examine each year, which security controls drive pricing, and how to prepare your application before it goes back to market.

Cyber Insurance

What Happens After a HIPAA Breach: Notification, Penalties, and Coverage?

A HIPAA breach starts a federal notification clock, a penalty assessment, and a cascade of costs. Here is what happens at each stage and which parts of a cyber policy respond.