Skip to main content
Category: Policy Structure & Terms

Retention

Also known as: self-insured retention, SIR
Simply put

In cyber insurance, a retention is the portion of a covered loss that the insured must pay out of pocket before the insurer's payment obligation begins. It functions somewhat like a deductible, meaning the policyholder absorbs an agreed initial amount of each qualifying claim. The specific amount, how it applies, and whether it must be exhausted before coverage responds all depend on the wording of the particular policy.

Formal definition

A retention is a risk-financing feature of an insurance policy specifying the amount of loss the insured retains before the insurer indemnifies the balance up to applicable limits and subject to sublimits. It is a form of risk retention (a component of risk financing) distinct from risk transfer, since the insured bears this layer itself rather than shifting it to the carrier. Practitioners often distinguish a self-insured retention (SIR), which the insured typically pays and administers directly and which may sit outside the limit, from a deductible, which the insurer may pay first and then seek reimbursement and which is often applied within the limit; the exact mechanics vary by form and jurisdiction. Retentions apply to both first-party losses (for example, business interruption or data restoration) and third-party liability, and may be expressed as a monetary amount and, for time-element coverages, coordinated with a separate waiting period rather than replaced by it. This entry does not address the unrelated marketing, memory, employee, or customer meanings of 'retention,' which are out of scope for cyber insurance usage. Whether and how a retention applies to a given claim is subject to the specific policy wording, endorsements, and conditions.

Why it matters

The retention determines how much financial exposure a policyholder keeps rather than transfers to the insurer, and it directly shapes the economics of a cyber program. A higher retention generally lowers premium but means the insured absorbs more of each qualifying loss out of pocket; a lower retention shifts more of the early loss to the carrier at greater premium cost. Because the retention is the layer the insured bears itself, it is a form of risk retention (risk financing) rather than risk transfer, and understanding exactly where it sits relative to the limit is essential to knowing what protection a policy actually provides.

The retention also functions as a practical threshold that governs when the insurer's payment obligation begins. Whether a claim clears the retention affects whether coverage responds at all, and for smaller incidents the insured may find that the entire cost falls within the retained layer. This matters across both first-party losses, such as business interruption or data restoration, and third-party liability, so the retention can influence the response to a wide range of cyber events. The specific mechanics, including whether the retention must be exhausted before coverage responds, depend on the wording of the particular policy.

Because practitioners distinguish a self-insured retention (SIR) from a deductible, the label alone does not tell the full story. An SIR is typically paid and administered directly by the insured and may sit outside the limit, whereas a deductible may be paid by the insurer first and then reimbursed and is often applied within the limit. These differences affect cash flow, claims handling, and the effective amount of coverage available, so buyers and their advisors need to read the exact form rather than assume a standard treatment.

Who it's relevant to

Risk managers
Risk managers set the level of loss their organization is willing to retain versus transfer, and the retention is the direct expression of that decision within a cyber policy. Choosing a retention involves balancing premium savings against the out-of-pocket exposure the organization must be able to fund on each qualifying claim, so it should be aligned with the organization's tolerance and cash position.
Insurance brokers and underwriters
Brokers structure programs around the retention to balance coverage and cost, and must explain to clients whether a given form uses a self-insured retention or a deductible and how it interacts with limits, sublimits, and any waiting period. Underwriters use the retention as a pricing and risk-financing lever, since it defines the layer the insured bears before the carrier's obligation begins.
CISOs and finance leaders
Because losses within the retention fall to the organization itself, CISOs and finance leaders need to understand which portion of a cyber loss the business will absorb directly. The retention does not reduce the likelihood of an incident, so it should be considered alongside, not as a substitute for, security controls and resilience planning.
Legal and compliance professionals
Legal and compliance teams should review the precise wording governing the retention, including whether it must be exhausted before coverage responds, whether it sits inside or outside the limit, and any conditions precedent. Because these mechanics vary by form and jurisdiction, the label 'retention,' 'SIR,' or 'deductible' alone does not determine how the layer actually operates.

Inside Retention

Self-Insured Amount
The portion of a covered loss the insured bears itself before the insurer's obligation to pay is triggered. Unlike a deductible that the insurer may pay and then seek reimbursement for, a retention is typically satisfied by the insured directly, subject to the specific policy wording.
Per-Claim or Per-Event Application
Retentions commonly apply on a per-claim or per-incident basis, meaning the insured may bear the retention amount separately for each qualifying event, depending on how the policy defines a single claim, occurrence, or related claims.
Interaction with the Waiting Period
For first-party business interruption coverage, a time-based waiting period (a qualifying number of hours before loss becomes recoverable) operates distinctly from a monetary retention. Both may apply to the same loss, and they are not interchangeable.
Relationship to Limits and Sublimits
The retention sits at the bottom of the coverage tower; the policy limit and any applicable sublimits cap recovery at the top. Covered loss between the retention and the applicable limit or sublimit is what the insurer pays, subject to exclusions and conditions.
Scope Across Coverage Types
A single policy may apply different retentions to different insuring agreements, for example distinguishing first-party coverages (such as data restoration, business interruption, or cyber extortion) from third-party coverages (such as privacy liability or regulatory defense). The applicable retention depends on which insuring agreement responds.

Common questions

Answers to the questions practitioners most commonly ask about Retention.

Is a retention the same thing as a deductible?
The two terms are often used interchangeably, but they are not always structured identically. Both refer to the portion of a covered loss the insured bears before the insurer pays, and in many cyber policies the retention functions much like a deductible. Subject to the specific wording, differences can arise in how the amount is applied, whether the insurer pays the full loss and seeks reimbursement, or whether the insured must fund its portion first. Always check the policy's definitions and conditions rather than assuming the mechanics from the label alone.
Does carrying a retention mean I am accepting risk instead of transferring it?
In a sense, yes for that layer. The retention is the portion of loss you retain rather than transfer to the insurer, so it reflects an element of risk acceptance within an overall risk transfer arrangement. This is a matter of degree: the policy still transfers loss above the retention up to applicable limits and sublimits. The retention does not reduce the likelihood of an incident and is not a resilience measure; it simply allocates who funds the first portion of a covered loss, subject to policy wording, exclusions, and conditions.
How should I decide what retention level to select?
Selection typically balances premium cost against the amount of loss your organization can absorb without material harm to its finances or operations. Higher retentions generally lower premium but increase what you must self-fund per claim. Considerations often include available liquidity, loss history, risk appetite, and how the retention interacts with sublimits and waiting periods on specific coverages such as business interruption. Because these trade-offs depend on your circumstances and the specific policy wording, discuss options with your broker rather than treating any figure as standard.
Does the retention apply per claim, per event, or across the whole policy period?
This depends entirely on the policy wording. In many forms a retention applies per claim or per event, but aggregate retentions across a policy period also exist. Related incidents may be treated as a single event under a policy's interrelated-claims or single-occurrence provisions, which can affect how many retentions apply. Review the definitions of claim, event, and any interrelated-wrongful-acts language, and confirm how the retention interacts with the coverage in question.
How does the retention interact with a business interruption waiting period?
A monetary retention and a time-based waiting period are distinct mechanisms and can apply together, subject to the specific wording. A waiting period is a resilience-adjacent coverage trigger: business interruption loss is typically only covered after the outage exceeds a stated number of hours. A retention is the monetary amount the insured absorbs on a covered loss. Depending on the policy, you may need to satisfy both before the insurer indemnifies business interruption loss, so review how each provision is defined and sequenced.
Are incident response costs subject to the retention?
It depends on the policy structure. Some cyber policies apply the retention to first-party costs such as incident response, forensics, and legal or breach-notification expenses; others provide certain response services outside the retention or under separate terms. Whether a given cost erodes the retention, counts toward the limit, or is handled through a panel arrangement is governed by the specific wording and endorsements. Confirm the treatment of incident response costs before an incident so response decisions are not delayed by uncertainty over funding.

Common misconceptions

A retention and a deductible are the same thing and the terms can be used interchangeably.
While both represent an amount of loss the insured absorbs, they can differ mechanically. With a deductible the insurer may advance the full amount and recover the deductible from the insured, whereas a retention is typically borne by the insured directly and the insurer's payment obligation begins above it. Whether a given policy's terms operate this way depends on the specific wording.
The retention is the same as the business interruption waiting period.
A retention is a monetary threshold, while a waiting period is a time-based threshold measured in hours before business interruption loss becomes recoverable. They are separate mechanisms and can both apply to the same first-party loss; conflating them can lead to misestimating what the insured will ultimately bear.
Choosing a higher retention weakens an organization's resilience.
A retention is a risk-financing and risk-transfer structuring choice, not a resilience metric. It determines how loss is shared between insured and insurer but does not by itself change the likelihood of an incident or the organization's ability to recover. Resilience is built through mitigation, continuity, and recovery capabilities, which are distinct from how the policy allocates loss.

Best practices

Confirm from the policy wording whether the self-insured amount operates as a true retention or as a deductible, and how the insurer's payment obligation is triggered relative to it.
Map the retention against the applicable limits, sublimits, and any coverage-specific retentions, so you understand what the insured actually bears for each first-party and third-party insuring agreement.
Analyze how the retention interacts with, but remains separate from, any business interruption waiting period, and model both a monetary and a time-based threshold when estimating retained loss.
Clarify whether the retention applies per claim, per event, or on an aggregate basis, and how the policy treats related claims, before relying on a single retained-loss estimate.
Size the retention as a deliberate risk-financing decision aligned with the organization's balance sheet and risk appetite, recognizing it is a risk-transfer structuring choice rather than a substitute for mitigation or continuity investment.
Because whether a loss reaches or exceeds the retention depends on exclusions, conditions precedent, and jurisdiction, review these alongside the retention rather than assuming any loss above the retention amount is automatically payable.
Promotional banner for the Penetration Report Template Kit