9 min read · Last updated September 11, 2026
- A common small business cyber wordform (Beazley’s Breach Response policy) caps notification, call center, and credit monitoring services at a stated number of “Notified Individuals,” commonly 2,500, separate from the dollar-based aggregate limit.
- The same wordform caps forensics investigation, legal counsel, and public relations spending at a combined dollar sublimit, commonly $50,000, that has nothing to do with the notification headcount cap.
- Florida’s breach notification law (Fla. Stat. 501.171) requires notifying every affected resident within 30 days of determining a breach occurred, regardless of what any insurance policy covers or how many people that policy will pay for.
- A federal court in Texas ruled in March 2026 that a cyber policy’s sublimit is a hard aggregate cap on the entire loss category, rejecting an insured’s attempt to split one incident into multiple claims to multiply the payout.
A cyber policy’s notification sublimit caps how many people the insurer will pay to notify after a breach, commonly around 2,500 individuals on a widely used small business wordform, while state breach notification law still requires notifying every affected resident within about 30 days regardless of that cap.
In this article
- Two Sublimits, One Breach, Two Different Rules
- How Many of Your Customers Does Your Policy Actually Cover?
- Check Your Notified Individuals Limit Before You Need It
- When Courts Read a Sublimit as a Hard Cap
- Frequently asked questions
Cyber insurance splits a data breach into two separate coverage buckets that run on two separate meters: one counts dollars, the other counts people.
Nadia Osman’s cyber insurer paid her $28,500 forensics bill without a hitch. It refused to cover notifying 4,300 of the 6,800 customers a vendor breach had just exposed.
Two Sublimits, One Breach, Two Different Rules
Nadia runs a home goods boutique out of a small warehouse in Tampa. She does not process credit cards directly. A third-party fulfillment vendor she uses for order tracking and returns does, and in July that vendor was breached, exposing names, addresses, emails, and partial payment data for 6,800 of her customers.
Her cyber policy’s declarations page followed a structure common to widely written small business cyber wordforms, the kind Beazley’s Breach Response policy uses. It listed two separate limits for what the insurer calls Privacy Breach Response Services. The first was an aggregate dollar cap of $50,000 covering forensics investigation, legal counsel, and public relations and crisis management expenses combined. The second was a completely different kind of cap: a Notified Individuals Limit of 2,500, covering notification letters, a call center, and credit monitoring enrollment, measured in people rather than dollars.
The policy’s own language spells out what happens once a breach crosses that headcount. Under a standard version of this clause, once the total number of people who need to be notified exceeds the stated limit, the insurer’s obligation to pay for notification, call center, and credit monitoring services for anyone past that number simply ends, and the policy specifies that any excess notifications get billed to the insured on a pro rata basis, split between what the insurer already covered and what fell outside the cap. Nadia’s forensics and legal costs came in at $28,500, comfortably inside her $50,000 combined sublimit, and that half of the claim closed clean. Her notification obligation did not work the same way, because it was never governed by a dollar limit at all.
How Many of Your Customers Does Your Policy Actually Cover?
The math is straightforward once you see both numbers side by side. Her vendor’s contracted rate for a full notification and response bundle, including a printed letter, a 90-day call center window, and 12 months of credit monitoring enrollment, worked out to $14.60 per customer. Multiply that across all 6,800 affected people and the full bundle would have cost $99,280.
Her policy’s Notified Individuals Limit covered the first 2,500 people in that bundle, which comes to $36,500. The remaining 4,300 people, the ones her policy’s headcount cap did not reach, cost another $62,780, and every dollar of that came out of Nadia’s own account. The math adds up cleanly: $36,500 paid by the insurer plus $62,780 paid by Nadia equals the full $99,280 bundle, covering all 6,800 people exactly once.
Florida law never asked whether her policy had room left. Under Fla. Stat. § 501.171, a business must notify affected residents “as expeditiously as practicable and without unreasonable delay,” and in no case “no later than 30 days after the determination of a breach.” Because more than 500 Florida residents were affected, the same statute required Nadia to notify the Florida Department of Legal Affairs on that same 30-day clock. Nothing in the statute cares whether the insurer’s headcount limit was 2,500 or 6,800. The legal deadline and the insurance sublimit are two unrelated numbers, and only one of them bends.
Check Your Notified Individuals Limit Before You Need It

Two other states show the same pattern with different numbers attached. California’s breach notification law, amended by Senate Bill 446 (SB 446) and effective January 1, 2026, requires notice “within 30 calendar days of discovery or notification of the data breach,” with a sample notice going to the Attorney General within 15 calendar days whenever more than 500 California residents are affected. New York’s General Business Law Section 899-aa, amended effective December 21, 2024, sets the same 30-day outer deadline and requires notice to the state Attorney General, the Department of State, and the Division of State Police whenever any New York resident is notified, with no headcount floor at all, while a further notice to the Department of Financial Services (DFS) applies specifically to businesses already regulated by DFS.
| State | Deadline to notify residents | When regulators must also be told |
|---|---|---|
| Florida | 30 days from breach determination (15-day extension possible for good cause) | Attorney General, within 30 days, if 500+ Florida residents affected |
| California | 30 calendar days from discovery or notification | Attorney General, within 15 calendar days, if 500+ California residents affected |
| New York | 30 days from discovery | Attorney General, Department of State, and State Police notified on every qualifying breach; DFS notice applies only to DFS-regulated businesses |
A policy’s Notified Individuals Limit is a line on the declarations page, usually sitting near the aggregate limit but governed by an entirely separate clause. Before a breach happens, not after, find that number and compare it to how many customer or employee records the business actually holds. A limit of 2,500 on a customer list of 6,800 is not a rounding error. It is a gap that state law will not let anyone ignore, no matter which side of the sublimit is paying for it.
When Courts Read a Sublimit as a Hard Cap
Cyber premiums have been falling. The Council of Insurance Agents and Brokers (CIAB) put Q2 2026 cyber pricing at negative 3.2 percent, and Marsh separately put the domestic cyber rate change at negative 2 percent for the same quarter, the smallest regional decline in its global survey. None of that changes sublimit structure. A cheaper policy with the same 2,500-person cap is still a 2,500-person cap, and Insurance Journal reported that the cyber market’s loss ratio climbed to 53 in 2025, its first time over 50 since the pandemic ransomware surge, with third-party claims trending up 30 percent. A softer market on price has not made insurers more generous on the sublimits that determine what a claim actually pays.
When a business tries to argue around a sublimit after a loss, courts have not been sympathetic to creative math. In Perry and Perry Builders, Inc. v. Cowbell Cyber, Inc., decided in the Western District of Texas in March 2026, a homebuilder was defrauded out of $874,863.70 by a vendor impersonation scheme carried out through two separate wire transfers. Its cyber policy carried a $250,000 sublimit for social engineering fraud. The insurer paid the full $250,000 and the builder argued each wire transfer should count as its own separate claim, entitled to its own separate sublimit. The court rejected that reading, holding that the endorsement “caps at $250,000 what [the insurer] must pay for all of [the company’s] cyber losses during the policy period, regardless of the number and value of [] such loss,” and rejecting an interpretation that would let the insured’s own bookkeeping choices multiply a stated cap. The case involved a fraud sublimit rather than a notification sublimit, but the principle is the same one that governed Nadia’s claim: a stated sublimit is a hard ceiling on the whole category, not a per-incident allowance that resets with every new wrinkle in the loss.
Before the next renewal, pull the actual declarations page rather than the summary a broker emails over. Find the Notified Individuals Limit specifically, separate from the aggregate limit and separate from the forensics and legal sublimit, and compare it against the largest customer or employee list the business holds today. A limit that looked generous three years ago can be several thousand records behind where the business actually stands now, and the gap does not show up until the mailing list is already final.
The notification cap is only one sublimit worth checking. A Business Owners Policy’s own cyber endorsement often carries a far smaller aggregate than a standalone cyber policy, card-brand assessments after a payment breach run under a separate grant entirely, and a claim can be denied outright if the application itself misstated a control like multi-factor authentication. None get checked unless someone looks first.
Frequently asked questions
What is a notification sublimit in cyber insurance? A notification sublimit is a separate cap inside a cyber policy that limits how many people the insurer will pay to notify, monitor, and support through a call center after a breach, expressed as a headcount rather than a dollar figure. It sits alongside, not inside, the policy’s dollar-based aggregate limit and its forensics and legal sublimit.
Does cyber insurance have to cover every customer I’m legally required to notify? No. State breach notification laws require notifying every affected resident regardless of cost, but the insurance policy only pays for notifying people up to its own stated Notified Individuals Limit. Anyone past that number still gets notified under the law, just without insurance dollars behind it.
How many days do I have to notify customers after a data breach? Most states set a deadline around 30 days from when the breach is discovered or confirmed, though the exact trigger and any extension varies by state. Florida, California, and New York all currently use a 30-day outer limit, with separate regulator-notification deadlines for larger breaches.
Can I buy more notification coverage if my sublimit is too low? Some carriers will raise a Notified Individuals Limit for an additional premium if requested before a breach happens, though not every wordform offers this as a simple add-on. The only reliable way to know is to ask a broker to check the current limit against the business’s actual customer count at every renewal, not just when a claim is already in progress.
What’s the difference between a cyber policy’s aggregate limit and a sublimit? The aggregate limit is the total dollar amount the policy will pay across an entire policy period. A sublimit is a smaller cap inside that aggregate, applying to one specific type of cost, like forensics, legal fees, or notification services, and it can run out well before the aggregate limit does.
Compare business insurance options built for small business budgets
See what a policy with the coverage limits your customer list actually needs would cost before your next renewal.
Compare Business Insurance Quotes
























