Covered-event language
Which definitions would respond to ransomware, business email compromise, accidental disclosure, vendor outage, system failure or privacy allegations?
First-party costs
How are forensics, counsel, restoration, notification, crisis communications, extortion response and business interruption addressed?
Third-party claims
How are privacy claims, customer demands, regulatory proceedings, contract disputes and defense costs treated?
Limits and erosion
What are the overall limit, annual aggregate and category sublimits? Do defense costs reduce the available limit?
Retention and waiting periods
Which deductibles, retentions, coinsurance or time waiting periods apply to each coverage part?
Notice and consent
Who must receive notice, how quickly, and which response actions or vendors require prior consent?
Vendor and dependent interruption
Does coverage respond when a cloud, payment, software or managed-service provider causes interruption or data exposure?
Prior acts and known circumstances
What retroactive dates, continuity terms, prior-knowledge exclusions or application representations matter?
Contract and Tech E&O boundary
Could customer promises, indemnities or service-performance allegations fall outside the cyber form?
Claim evidence
What financial, technical, legal and operational support would be expected for the most important scenarios?