When business owners read a cyber insurance quote for the first time, the number that usually causes confusion is the retention. It looks like a deductible, it behaves a little like a deductible, and it is often described as one by people who should know better. But cyber policies handle retentions differently than the auto and homeowners policies most people are used to, and there is a second, time-based version of the same idea buried in the business interruption section.
A retention is the portion of a covered loss your business keeps for itself before the insurer's money begins. If your policy has a $10,000 retention and you suffer a $75,000 ransomware event, the carrier pays $65,000 and you absorb the first $10,000. The concept is simple. What changes is how the dollars physically move.
On most cyber policies the retention is not paid up front in cash to anyone. Instead, the insurer arranges and pays for the forensics firm, the breach coach, the notification vendor, and the rest of the response, then applies the retention against the total. In practice you may be invoiced for your share afterward or see it netted out of the settlement. The important part is that the retention applies to the whole incident, not to each individual vendor bill.
Retentions on small-business cyber policies commonly run from $1,000 to $25,000. Larger organizations, or businesses in higher-risk classes such as healthcare and financial services, frequently see $50,000 or more. The size is negotiable at quoting time, and it interacts with your premium in ways worth understanding before you sign.
The technical distinction is about who pays first and who controls the money. With a traditional deductible, the insurer pays the full loss and then subtracts your deductible from the check. With a true retention, you are considered to be self-insuring that first layer, and the insurer's obligation, including in many cases its duty to defend you, does not attach until the retention is satisfied.
That difference matters in a few practical ways:
Some carriers use the words interchangeably and structure the retention to behave exactly like a deductible. Others do not. Reading the actual language, or having someone translate the policy for you, is the only way to know which version you bought.
Rarely. Most cyber policies apply the retention per claim or per incident, meaning two unrelated events in the same policy year each carry their own retention. A phishing wire fraud in March and a ransomware attack in September are two separate retentions, not one.
It is also increasingly common to see different retentions for different coverage parts. A policy might carry a $5,000 retention for privacy liability and network security claims, a $25,000 retention specifically for ransomware or extortion events, and a separate, often much higher retention for social engineering and funds transfer fraud. Carriers do this because those coverages have different loss frequencies. If your quote shows one headline retention, ask whether any coverage part carries a higher one.
Watch for related-claims language too. If several incidents trace back to the same root cause, such as one unpatched server exploited repeatedly, they are usually treated as a single claim with one retention. That works in your favor on the retention side but can also mean they share a single limit.
Business interruption coverage on a cyber policy does not use a dollar retention as its primary trigger. It uses a waiting period, sometimes called a time retention. This is the number of hours your systems must be down before lost income coverage begins to accrue. Typical waiting periods are 6, 8, 12, or 24 hours, though 48 and 72 hours still appear on some contracts.
The mechanics matter more than the number. If your policy has a 12-hour waiting period and an outage lasts 10 hours, you collect nothing for business interruption even though the incident is otherwise covered. If the same outage lasts 40 hours, you generally collect for the income lost after hour 12, not from hour one. A small number of policies are written so that satisfying the waiting period retroactively opens coverage back to the start of the outage. That is a meaningfully better provision and worth asking about.
For a business that runs on real-time systems, a point-of-sale operation, a medical practice with scheduling and imaging, a logistics firm dispatching loads, the difference between a 6-hour and a 24-hour waiting period can be the difference between a useful claim and no claim at all. Most ransomware-driven outages last far longer than a day, but the more common events, cloud provider hiccups and short-lived denial-of-service attacks, often resolve inside 12 hours.
A single incident can trigger both. Say ransomware takes your systems down for four days. The forensics, legal, and restoration costs fall under first-party incident response and are subject to the dollar retention. The revenue you lost while closed falls under business interruption and is subject to the waiting period. Depending on the carrier, the business interruption loss may also be subject to the dollar retention, or the waiting period may serve as the only retention for that coverage part.
Some policies stack both. Others apply whichever produces the greater deduction. A few apply the dollar retention once across the entire incident regardless of how many coverage parts respond, which is the most favorable structure. This is not a detail you can infer from the declarations page; it lives in the conditions section.
The instinct is to take the lowest retention available. That is not always right. Moving from a $25,000 retention to a $5,000 retention on a small-business policy might add a few hundred dollars of premium, which is usually worth it. But on larger accounts, buying down the retention can cost more over five years than the retention itself.
Three questions help set the number. First, what could you write a check for tomorrow without disrupting payroll? That is your realistic ceiling. Second, how likely is a claim in your industry? Firms handling protected health information, client trust funds, or large wire transfers claim more often, which makes a lower retention more valuable. Third, does a higher retention buy you something better elsewhere, such as a shorter waiting period or a higher sublimit on funds transfer fraud? Trading retention dollars for broader coverage is often the smarter move.
Businesses evaluating cyber insurance in Florida should also confirm that any retention buy-down does not come with tighter security warranties. Some carriers offer the lower retention only if you maintain multifactor authentication, offline backups, and endpoint detection. Those are good controls to have anyway, but you need to actually have them, because failing a warranty at claim time is worse than a high retention.
Do I have to pay the retention before the insurer sends help?
Usually not. Most cyber carriers dispatch their panel forensics and legal team immediately and reconcile the retention later, because delaying response costs everyone money. A minority of policies do require the insured to fund the first layer directly, so confirm which arrangement yours uses before an incident, not during one.
Does the retention reduce my policy limit?
No. The retention sits below the limit, not inside it. A $1 million limit with a $10,000 retention means the insurer will pay up to $1 million after your $10,000, for a total available of $1,010,000 on that claim. What does erode the limit is defense and response spending above the retention.
What happens if my outage is shorter than the waiting period?
You get no business interruption payment for that event, though other coverage parts such as incident response and data restoration can still respond if their triggers are met. This is exactly why the waiting period deserves as much attention as the dollar retention when you compare quotes.
Can I change my retention mid-term?
Typically only by endorsement with the carrier's agreement, and usually at renewal rather than mid-term. If your revenue, headcount, or data volume has changed significantly, raise it at renewal when you also revisit limits and sublimits.
Is the retention tax deductible?
Retention amounts paid on a covered business loss are generally treated as ordinary business expenses, but the treatment depends on the nature of the payment and your accounting method. Ask your CPA rather than your agent on that one.
Retentions and waiting periods are where two cyber quotes at the same premium quietly become very different policies, and the differences only surface when you are already in the middle of an incident. Before you renew, pull the declarations page and the conditions section together and confirm the per-claim retention, any coverage-specific retentions, and the business interruption waiting period. A Truscott coverage review will walk through those numbers alongside your actual downtime tolerance and cash position so the structure fits how your business really operates. Reach out or request a quote and we will compare the retention terms side by side.
Business email compromise is the most common cyber claim small businesses file, but the money you lose is often covered by a sublimited add-on rather than the main policy. Here is how BEC losses are treated and what to check before you buy.
Cyber InsuranceCyber applications are now security questionnaires. Learn the controls underwriters ask about, how each one moves your price, and where applications most often get declined.