Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Does Your Cyber Policy Cover the Fine or Just the Defense?Regulatory & Privacy Compliance
5 min readFor Enterprise Risk Managers

Does Your Cyber Policy Cover the Fine or Just the Defense?

If you're carrying a $25 million cyber policy, you might assume it covers a $25 million regulatory penalty. It doesn't. For most programs, the regulatory fine sub-limit sits somewhere between $1 million and $5 million, or the fine is excluded entirely. The defense costs are covered up to the full limit; the penalty itself is capped or absent.

TikTok's $400 million COPPA settlement with the Department of Justice makes this gap impossible to ignore. Global regulators issued approximately $542 million in fines during Q1 2026 alone, and your policy was likely designed when those numbers were a fraction of what they are now. This checklist walks you through the specific provisions you need to review before your next renewal.

Prerequisites

Before you start, gather the following:

  • Current cyber and D&O policy declarations pages and full policy wordings
  • Any regulatory correspondence received in the past 36 months (warning letters, civil investigative demands, consent decrees, settlement agreements)
  • A list of all jurisdictions where your organization processes personal information, particularly from users under 13
  • Your broker's most recent placement summary showing sub-limits and retentions by coverage section

Policy Coverage Review

1. Identify your regulatory fine sub-limit

Pull the declarations page and locate the sub-limit labeled "Regulatory Fines and Penalties" or "Civil Penalties." If it's not listed as a separate sub-limit, check the exclusions section for language that excludes fines entirely while carving back defense costs.

What good looks like: You can state the exact dollar amount your policy would pay toward a regulatory penalty, separate from what it pays for defense costs. If the number is below $10 million and you operate a platform business or process data at scale, flag it for discussion at renewal.

2. Confirm whether punitive penalties are excluded

Review the regulatory coverage section for language distinguishing between "compensatory" and "punitive" fines. Many policies exclude punitive penalties as a matter of public policy, even if they provide a sub-limit for other regulatory awards.

What good looks like: You understand which portion of a multi-part settlement (compensatory damages, civil penalties, disgorgement) your policy would cover. If the policy excludes "punitive" penalties but doesn't define the term, you have a coverage ambiguity that needs clarification in writing from your insurer.

3. Check defense cost treatment for regulatory investigations

Confirm that regulatory defense costs are covered separately from the fine sub-limit and apply to the full policy limit. This is standard, but verify the retention that applies when a regulatory investigation trigger is invoked.

What good looks like: Defense costs for responding to a civil investigative demand or FTC inquiry are subject to a defined retention (often $25,000 to $100,000) and then covered up to the full policy limit, not the regulatory fine sub-limit.

Prior-Knowledge and Retroactive Date Review

4. Map prior regulatory contact against your policy's retroactive date

If your organization received any regulatory correspondence, warning letters, or consent decrees before your current policy's inception date, pull the prior-knowledge exclusion language. Determine whether a subsequent enforcement action that references or builds on that earlier contact would be excluded as a "related" or "interrelated" claim.

What good looks like: You can articulate whether the DOJ referencing conduct that predated your policy's retroactive date would trigger an exclusion. If you've had prior regulatory contact and your policy's prior-knowledge language is broad, you may be uninsured for the next enforcement action even if it involves new conduct.

5. Review the definition of "prior circumstances"

Check whether your policy excludes claims arising from circumstances that a reasonable person in your position "could have foreseen" or "should have known" might give rise to a claim. This is broader than actual knowledge and can sweep in situations where you received regulatory guidance or industry warnings.

What good looks like: The exclusion is limited to circumstances you actually knew about and failed to disclose on your application, not circumstances you "should have known" might lead to enforcement. If the language is broader, document it and request a narrowing endorsement.

Retention and Trigger Analysis

6. Confirm your retention for regulatory investigation triggers

Identify the retention (self-insured amount) that applies when a regulatory body opens an investigation or issues a civil investigative demand. Some underwriters have increased these retentions as privacy enforcement frequency has risen.

What good looks like: Your retention for regulatory triggers matches your organization's appetite for absorbing investigation costs before insurance responds. If it was set three years ago at $50,000 and you're now seeing multiple inquiries per year, the retention may no longer reflect your actual exposure frequency.

7. Verify whether COPPA-specific amendments increased your exposure

If your organization processes data from users under 13, review whether the FTC's 2025 COPPA Rule amendments (effective June 23, 2025) expanded the categories of personal information you collect or changed your data retention obligations. The amendments broadened the definition of personal information and imposed more prescriptive security requirements.

What good looks like: You've mapped the expanded COPPA definition against your current data practices and confirmed that your cyber policy's regulatory coverage doesn't carve out children's privacy violations. Some older policies exclude COPPA specifically.

Common Mistakes

Assuming the headline limit applies to everything. The $25 million limit on your cyber policy applies to defense costs and certain first-party losses. The regulatory fine is probably capped at a fraction of that number.

Treating all prior regulatory contact the same. A warning letter is different from a consent decree. The latter is far more likely to trigger a prior-knowledge exclusion if subsequent enforcement references the same conduct.

Not distinguishing between cyber and D&O coverage for the same event. A COPPA settlement might trigger both your cyber policy (data practices) and your D&O policy (regulatory action against the company). Review both policies for how they coordinate and whether one provides broader regulatory fine coverage than the other.

Waiting until a claim to discover your retention doubled at the last renewal. Retentions for regulatory triggers have been increasing. If your broker didn't flag the change, you may not realize you're now self-insuring the first $100,000 of an investigation that used to attach at $25,000.

Next Steps

Schedule a 30-minute call with your broker before your next renewal. Walk through items 1, 2, 4, and 6 on this checklist with your current policy wording in hand. If your regulatory fine sub-limit is below $10 million, ask what it would cost to increase it. If you've had prior regulatory contact, get a written opinion on whether your current prior-knowledge exclusion would bar coverage for a subsequent enforcement action.

If your organization operates in a jurisdiction with expanding privacy enforcement or processes data from minors, request a manuscript endorsement that clarifies how COPPA settlements and similar penalties are treated. The standard policy language was written when these fines were in the single-digit millions. That's no longer the case.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like