Commercial Cyber Incident Business Interruption Estimator

Commercial Cyber Incident Business Interruption Estimator

Try an example

Load a sample incident to see how the estimate works — then edit any field.

Step 1 of 6

What type of incident are you estimating?
Incident scenario

What to Do With Your Results

Your estimate splits your exposure into two buckets: business income you lost while systems were down or degraded, and the extra expenses that came with responding to the incident — forensics, notification, remediation, legal, and crisis communications. Treat this number as a starting point, not a final figure.

The single most useful thing you can do next is replace every benchmark estimate with a real invoice. Benchmark figures exist so you're not stuck with a blank field, but an actual forensics bill or legal invoice will always carry more weight than a typical-cost placeholder once you sit down to prove your lost income claim to your insurer. Pull together your pre-incident financials — at least the prior 12 months of revenue and margin — so the "before" picture is as well-documented as the "after."

Also flag your waiting period result. If your estimate showed $0 in business income loss because your outage didn't outlast the waiting period, that doesn't mean you have no claim — it usually means the income-loss portion of your claim is weak, but your extra expense costs may still be substantial and independently recoverable.

A Common Mistake: Assuming You're Covered Before Checking

The most common misstep after a cyberattack is treating the insurance conversation as an afterthought — paying for remediation, notifying customers, or even paying a ransom demand before confirming what the policy actually requires. Many cyber policies include specific consent requirements before paying a ransomware demand or hiring an outside consultant, and skipping that step can jeopardize reimbursement for costs you've already incurred.

This mistake is especially costly when the incident originated outside your own systems — say, at a cloud host or payment processor you rely on. Standard cyber business interruption language is usually written around an attack on your own network. An outage caused by a vendor is a different question entirely, and assuming your policy treats it the same way is one of the fastest ways to end up with a denied or reduced claim.

Who Can Help Beyond This Calculator

This estimator gives you a number. Turning that number into a paid claim is a different job — one that involves reading your specific policy language, coordinating with forensic accountants to substantiate the loss, and negotiating directly with an insurance company that has its own team working to minimize the payout.

A licensed public adjuster works exclusively for you, not the insurer, and is typically compensated through a percentage-based fee tied to your actual settlement rather than an upfront cost — so there's no bill to worry about while you're focused on recovering operations. That's a meaningfully different relationship than the one you have with your insurer's own adjuster, whose job is to protect the company's exposure, not yours.

Frequently Asked Questions

What does my cyber business interruption exposure estimate mean, and what should I do with it?
The estimate is a starting point that shows the rough size of your potential claim, split between lost business income and extra expenses like forensics, notification, and legal costs. Use it to prioritize which invoices and financial records to start gathering, and bring it into your first conversation with your insurer, broker, or public adjuster so you're negotiating from an informed position rather than guessing.
Doesn't my cyber insurance policy automatically cover all my lost income after an attack?
No. Most cyber policies apply a waiting period — often 8 to 72 hours — before business interruption coverage even begins, and coverage for outages that originate at a vendor or cloud provider rather than your own systems frequently requires a separate dependent business interruption endorsement. Coverage limits, sublimits, and definitions of "interruption" also vary significantly by policy.
What documentation do I need to support a cyber business interruption claim?
Typically: financial statements showing pre-incident revenue and margin trends, invoices for forensics, remediation, notification, legal, and crisis communications costs, records of the outage timeline, and any regulatory correspondence. The more precisely these replace estimated figures, the stronger the claim.
Can my accountant or IT provider handle my cyber insurance claim instead of a public adjuster?
Your accountant and IT provider play essential roles — but neither is typically trained in insurance policy interpretation or claims negotiation. A public adjuster works exclusively for the policyholder, not the insurer, and coordinates with your accounting and forensic teams to build and negotiate the full claim.
How accurate is this cyber business interruption estimate?
It's a planning estimate, not a claim valuation. Extra expense figures use industry benchmark ranges when you don't have exact invoices yet, and the total is shown as a range rather than a single number for that reason. Actual claim value depends on your specific policy language, sublimits, and documentation.