Aggregate Limit
An aggregate limit is the maximum total amount an insurer will pay for all covered claims during a single policy period, no matter how many separate claims arise. Once the insured has used up this ceiling across the policy period, the insurer typically will not pay more, even if additional covered losses occur. It is different from a per-claim or per-occurrence limit, which caps what the insurer pays on any single claim.
The aggregate limit is the ceiling on the insurer's total indemnity obligation for all claims made or losses incurred during the policy period, functioning as a cap that erodes as covered payments (and, depending on wording, defense costs and other loss adjustment expenses) are made. In a cyber policy this limit is generally shared across multiple insuring agreements spanning both first-party coverages (such as business interruption, data restoration, and cyber extortion) and third-party coverages (such as privacy liability and regulatory defense), unless specific sublimits, separate limits, or dedicated towers apply to particular coverage parts. Whether a given loss counts against the aggregate, and how the aggregate interacts with per-claim limits, retentions, sublimits, and reinstatement provisions, depends on the specific policy wording, applicable endorsements and exclusions, and jurisdiction. The aggregate limit is a coverage and financial-exposure term, not a resilience metric; it does not measure or reduce the likelihood or operational impact of an incident and is distinct from recovery objectives such as RTO or RPO.
Why it matters
The aggregate limit defines the outer boundary of an insurer's financial commitment for an entire policy period, which makes it one of the most consequential numbers in a cyber program. In cyber policies, a single aggregate is frequently shared across multiple insuring agreements, meaning that first-party losses such as business interruption, data restoration, and cyber extortion draw down the same ceiling as third-party liabilities such as privacy claims and regulatory defense. A severe or prolonged event, or a series of separate events within one period, can erode the aggregate to the point where later covered losses go unindemnified even though they would otherwise fall within the policy's scope.
For buyers, this creates a planning problem that per-claim limits alone do not solve. An organization may confirm that its per-claim limit is adequate for a single incident while overlooking the possibility that several incidents, or one incident spawning multiple coverage demands, could exhaust the aggregate. Where defense costs and other loss adjustment expenses erode the aggregate rather than sitting outside it, litigation and regulatory response can consume limits that the insured expected to remain available for indemnity. The precise treatment of these costs depends on the specific policy wording.
It is important to keep the aggregate limit in its proper category. It is a coverage and financial-exposure term, not a resilience metric. It does not reduce the likelihood of an incident, shorten downtime, or improve recovery, and it is unrelated to objectives such as RTO or RPO. Buying a higher aggregate transfers more potential financial loss to the insurer but does nothing on its own to mitigate operational impact, which remains the province of controls, continuity planning, and incident response.
Who it's relevant to
Inside Aggregate Limit
Common questions
Answers to the questions practitioners most commonly ask about Aggregate Limit.
