Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. A twelve hour waiting period looks like a pricing detail next to a limit of several million. Why is it not?
Because most incidents resolve below it and those that pass it pass it by a long way: that time deductible therefore decides whether the vast majority of claims enter the cover at all
The distribution of cyber incidents is very uneven, and that is what gives those few hours their power: they do not trim claims, they sort them. The three other answers describe calculation effects, all plausible and two of them true in some wordings, but all of a far smaller order. Accumulation with the monetary deductible is a drafting question. Recounting at each interruption exists in some wordings and is negotiated. Shifting the indemnity period confuses the waiting period, which delays entry into cover, with the maximum duration, which runs from the loss. None of those three effects changes the fate of most files; the sorting does.
Glossary entry · delai-carence2. A policy limits the indemnity period to technical restoration of the systems. What does that wording leave out?
The weeks between the IT restart and the return to expected activity: the systems run, the customers have not come back, and lost orders are not all recovered
An IT restart almost always precedes a commercial recovery by several weeks, and that interval is what such wording removes: it covers half the real loss while appearing to cover all of it. The three other answers name scopes argued elsewhere and settled by other clauses. Increased costs of working do belong to a separate cover, present or not, and their fate does not turn on this cut-off. The compromise period before discovery is not an interruption: the business was running. Subsidiaries are a matter of the definition of insureds and of scope, not of when the indemnity period ends.
Glossary entry · perte-exploitation3. Production back to forty percent after six days. The company considers it has restarted. What does the calculation say?
That it is not a recovery but a sixty percent loss still running, indemnified period by period on the gap between expected and achieved gross margin
The word restart is what misleads, because it states a true technical fact and draws a false financial conclusion from it. The two answers that either cut off or hold the full rate err in opposite directions for the same reason: they treat interruption as a binary state, when the indemnity is computed on a gap, period by period. The one stopping on day six is the error insureds themselves make, and it costs them most of the file. The one holding the full rate turns against the insured as soon as the insurer produces the production figures. The one invoking the duty to mitigate calls on a real duty and makes it say the opposite of its purpose: mitigating is what the insured did by getting back to forty percent, it is not a reason to leave it uncompensated.
Glossary entry · principe-indemnitaire4. An outage at a hosting provider interrupts an insured whose own systems are untouched. What decides whether cover responds?
Supplier failure cover, with its own sub-limits and its own waiting period, and often requiring the suppliers to be NAMED: an insured that never listed its host discovers at claim time that it was a named cover
The insured believes its cover is general because it reasons about the effect, a halted business, while the contract reasons about the source. The answer keeping only the waiting period describes exactly that belief and is the most common: it treats the external origin as irrelevant when it is the very subject of a separate cover. The one requiring fault by the host imports liability reasoning into a damage cover, which responds to a fact and not to a fault. The one making the insured a third party beneficiary of its host's policy invents a stipulation that does not exist, and it is attractive because it describes what an insured would wish: that cover follow dependency without having to be declared.
Glossary entry · carence-fournisseur5. What do these files most often founder on, and when is that settled?
On the evidence, which is built DURING the incident: the exact start time, the real daily activity level, and what normal activity would have been. Afterward the insured argues from impressions against an insurer that paid a team to keep a log
The asymmetry is the module's point: the insurer funded providers who document as they go, while the insured is busy surviving. The three other answers name real difficulties in these files, which is why they get chosen. None is settled in the first days. Characterizing the event and the reach of exclusions are argued weeks later, on documents; the choice of adjuster costs time, not the file. Evidence cannot be recovered: a company that did not timestamp its restart will not be able to reconstruct it, and the technical logs it would need are sometimes encrypted along with everything else.
Glossary entry · declaration-de-risque