Skip to main content
Category: Coverage Types

Contingent Business Interruption

Also known as: CBI, Dependent Business Interruption, Contingent or Dependent Business Interruption
Simply put

Contingent business interruption (CBI) coverage helps replace income a business loses when a supplier or service provider it depends on suffers a disruption, rather than when the business's own premises are damaged. For example, if a key supplier cannot deliver, the resulting loss of income to the insured may be covered. Whether a specific loss is covered depends on the policy's wording, including which suppliers or providers are named and what triggers apply.

Formal definition

CBI is a first-party coverage, typically written as an extension to business interruption insurance, that reimburses the insured's loss of income (and, where contingent extra expense coverage applies, additional expenses) arising from an interruption in service or supply from a third-party on which the insured depends, rather than from direct physical damage to the insured's own property. Coverage commonly turns on whether the affected supplier or provider is a named or otherwise qualifying dependency and on the trigger defined in the form; in many policies traditional CBI historically required physical damage to the third party's property, though the trigger, scope, and any waiting period or sublimit are subject to the specific wording, endorsements, and exclusions. In a cyber context, some forms extend CBI-type coverage to disruptions of a dependent technology or service provider, but the availability and precise trigger of such 'cyber CBI' or 'contingent dependency' coverage varies by insurer form and is defined by the applicable policy language. This entry addresses CBI as an insurance coverage and does not describe supply-chain resilience controls or continuity metrics such as RTO or RPO, which are distinct concepts.

Why it matters

Most business interruption coverage responds only when the insured's own property is damaged, yet modern organizations depend heavily on suppliers, service providers, and technology vendors they do not own or control. Contingent business interruption coverage exists to address that gap: it can respond to income lost because a business a company relies on, rather than the company itself, suffers a disruption. For risk managers and brokers, CBI is often where the difference between a well-structured program and a costly coverage gap becomes visible, because a disruption several links away in a supply or service chain can halt operations just as effectively as damage to the insured's own premises.

The practical significance of CBI lies in its conditionality. Because coverage commonly depends on whether the affected supplier or provider is named or otherwise qualifies as a covered dependency, and on the specific trigger the form uses, two insureds facing the same real-world disruption can experience very different outcomes based solely on how their policies were worded and which dependencies were scheduled. This makes dependency mapping and careful attention to policy language a central part of buying and placing the coverage rather than an afterthought.

It is important to keep CBI in perspective as a risk-transfer mechanism. Purchasing CBI does not make a supply chain more resilient, reduce the likelihood that a critical vendor fails, or substitute for continuity planning; it can only help replace income after a covered disruption occurs, subject to the policy's terms. Organizations that treat CBI as a complement to, rather than a replacement for, supplier diversification and continuity measures are better positioned to manage dependency risk.

Who it's relevant to

Risk managers
Risk managers responsible for identifying operational dependencies use CBI to transfer the financial consequences of supplier or service-provider disruptions that fall outside standard business interruption coverage. Because coverage often depends on which dependencies are named or otherwise qualify, mapping critical suppliers and providers is a prerequisite to structuring meaningful CBI. Note that CBI transfers income loss after a covered event and does not reduce the likelihood of a disruption or substitute for continuity planning.
Insurance brokers and underwriters
Brokers placing CBI must reconcile the insured's dependency profile with the trigger, named-supplier requirements, waiting periods, sublimits, and exclusions of available forms, since these terms determine whether a real-world disruption results in a recoverable loss. Underwriters assess the concentration and nature of the insured's dependencies and define the trigger and scope in the policy language. Both should recognize that historical physical-damage triggers and newer cyber-oriented dependency extensions differ materially by form.
CISOs and technology leaders
For organizations dependent on technology and service providers, CISOs are often the source of the dependency information that determines whether cyber CBI-type coverage responds. Because the availability and precise trigger of coverage for disruptions to a dependent technology provider varies by insurer form, alignment between security and vendor-management teams and the insurance program is essential. This coverage addresses income loss, not the security controls or resilience of third-party providers.
Business continuity and resilience planners
Continuity planners should treat CBI as a financial backstop distinct from resilience measures. Insurance does not improve the recoverability of a supply chain or replace supplier diversification and continuity arrangements. CBI is an insurance coverage and does not correspond to continuity metrics such as RTO or RPO, which are separate concepts; the two should be planned together rather than confused.
Legal and compliance professionals
Legal and compliance teams evaluating coverage disputes or contractual dependency obligations need to focus on the exact policy wording, because whether a CBI loss is covered depends on the trigger, named or qualifying dependencies, exclusions, and conditions in the specific form. Terminology and coverage scope vary across insurer forms, so definitions from one policy should not be assumed to apply to another.

Inside CBI

First-Party Coverage Character
Contingent Business Interruption (CBI) is a first-party coverage that responds to the insured's own income loss and continuing expenses, as distinct from third-party liability the insured owes to others. The loss is the insured's, but the triggering event occurs at another entity.
Dependency Trigger
CBI is triggered by a disruption at a party on which the insured depends, rather than a direct incident on the insured's own systems. The covered dependency is typically a supplier, service provider, or other business partner, and whether a given relationship qualifies depends on the specific policy wording.
Named versus Non-Named Dependents
Many cyber policies restrict CBI to specifically scheduled or named third parties (for example, named IT or cloud providers), while broader wordings may extend to unnamed dependent businesses. The distinction materially affects what is covered and is defined differently across insurer forms.
Waiting Period (Time Retention)
A waiting period is a period of time that must elapse before CBI loss begins to accrue as covered. It functions as a time-based retention and is not a resilience metric; it does not describe how quickly the business can recover, only when the policy begins to indemnify.
Sublimits and Retentions
CBI is frequently subject to a sublimit lower than the main policy limit and to a monetary retention. These are coverage-scoping terms set by the policy wording and negotiated at placement, not measures of operational preparedness.
Period of Restoration / Indemnity Period
The window over which lost income and continuing expenses are measured, typically running from the qualifying disruption until operations are or reasonably could be restored, subject to any policy cap on the indemnity period and to the specific wording.
Covered Peril Nexus
The dependent party's disruption generally must arise from a peril the policy covers (for example, a security failure or system failure at the third party, depending on wording). Losses stemming from causes falling under exclusions, such as war or infrastructure exclusions, may be excluded subject to the specific policy language.
Proof of Loss and Causation
Recovery depends on demonstrating the causal link between the third party's disruption and the insured's income loss, and on quantifying that loss under the policy's measurement basis, which is a condition to payment in many policies.

Common questions

Answers to the questions practitioners most commonly ask about CBI.

Is contingent business interruption the same as ordinary business interruption coverage?
No. Ordinary (or direct) business interruption responds to income loss arising from an incident affecting the insured's own systems or operations. Contingent business interruption (CBI) responds to the insured's income loss caused by a disruption at a third party the insured depends on, such as a supplier, service provider, or in the cyber context an IT or cloud vendor. Both are first-party coverages, but the triggering event occurs outside the insured's own environment. Whether CBI applies at all depends on the specific policy wording, as many policies address direct and contingent exposures under separate insuring agreements, sublimits, and conditions.
Does having CBI coverage mean my business is protected from supply chain and vendor cyber disruptions?
Not on its own. CBI is a risk-transfer mechanism that may reimburse certain financial losses after a covered dependency failure; it does not reduce the likelihood of a vendor outage and does not constitute resilience. Whether a given loss is paid is conditional on policy wording, applicable sublimits, waiting periods, and exclusions, and coverage is often limited to named or scheduled dependencies or to specific perils. Reducing actual exposure requires mitigation measures such as vendor diversification, contractual protections, and continuity planning, which sit alongside rather than inside the insurance.
How is the waiting period applied to a CBI claim, and how does it differ from a retention?
In many cyber policies CBI is subject to a time-based waiting period, meaning income loss during an initial period following the triggering disruption is not indemnified before coverage begins to respond. This functions differently from a monetary retention, which is a dollar amount the insured absorbs. Some policies apply both. The precise duration, whether the waiting period runs from the dependency's outage or from the insured's resulting loss, and how it interacts with any monetary retention all depend on the specific wording and endorsements.
Are all of my vendors and suppliers covered, or only specified ones?
This varies by form and is subject to the specific wording. Some CBI grants apply only to dependencies named or scheduled in the policy, while others extend more broadly to unnamed third parties that the insured relies on. Coverage may also distinguish between direct dependencies and further-tier dependencies (for example a supplier's own supplier). Reviewing how the policy defines the covered dependent entities, and confirming that critical vendors fall within that definition, is a key implementation step.
What documentation supports quantifying a CBI loss?
CBI loss quantification generally rests on demonstrating the causal link between the third-party disruption and the insured's income loss, and on financial records that establish the level of income that would have been earned absent the event. Relevant materials often include historical financial statements, evidence of the dependency's outage and its timing, and records showing mitigation efforts. Because policies commonly impose proof-of-loss conditions and cooperation requirements, the exact evidentiary expectations depend on the wording; establishing measurement methodology and preserving records before a loss occurs is advisable.
How should CBI limits and sublimits be evaluated against actual dependency exposure?
CBI is frequently subject to a sublimit that is lower than the overall policy limit, so the amount available may not correspond to the full potential loss from a critical vendor failure. Evaluating adequacy involves assessing which dependencies could cause material income loss, estimating the possible duration and magnitude of such loss, and comparing that against the applicable sublimit, waiting period, and any per-dependency constraints. Because insurers, brokers, and risk managers may weigh concentration risk and aggregation across insureds differently, the appropriate sublimit is often a point of negotiation rather than a fixed standard.

Common misconceptions

CBI covers liability the insured owes to customers or partners affected by a third-party outage.
CBI is a first-party coverage for the insured's own income loss and continuing expenses. Liability owed to others is a third-party matter addressed, if at all, under separate coverage parts. The two should not be conflated.
Any disruption at any vendor or supplier the insured relies on will trigger CBI.
Coverage frequently depends on whether the dependent party is named or scheduled, whether the disruption arose from a covered peril, and whether exclusions apply. Whether a particular dependency qualifies is subject to the specific policy wording and endorsements.
Having CBI coverage means the organization is resilient to supply-chain and provider outages.
CBI is risk transfer, not risk mitigation. It does not reduce the likelihood of a dependent party's outage or shorten recovery, and it does not substitute for business continuity or disaster recovery planning. The waiting period and indemnity limits mean some loss is typically retained by the insured.

Best practices

Inventory and map critical dependencies, then compare that map against the parties named or scheduled in the policy to identify gaps between operational reliance and coverage scope.
Confirm with your broker whether CBI applies only to named/scheduled dependents or extends to unnamed dependent businesses, and negotiate endorsements where material dependencies are unaddressed.
Model expected loss against the waiting period, sublimit, retention, and any cap on the indemnity period to understand how much loss the organization retains rather than transfers.
Review which perils at the dependent party trigger coverage and how exclusions (such as war or infrastructure exclusions) and failure-to-maintain conditions may apply, using the actual policy wording rather than summaries.
Maintain documentation and monitoring sufficient to evidence the causal link between a third party's disruption and the insured's income loss, since proof of loss and causation are typically conditions to payment.
Treat CBI as complementary to, not a replacement for, business continuity and disaster recovery planning that reduces the likelihood and duration of dependency-driven disruption.
Application Security Isn’t Optional Anymore.