A third-party breach can absolutely fall under cyber insurance. But there’s a catch. The policy wording decides what happens, especially when the breach starts with a vendor rather than inside your own network.

That distinction matters because businesses rarely operate alone anymore. A payment provider handles transactions. A software company stores data. Another vendor gets access to your systems. If one of them is breached and your business suffers a loss, you’ll want your cyber policy to respond.

Why Third-Party Breaches Get Complicated

The confusion usually comes from the word “third-party.” In insurance, it can mean different things depending on the policy. Sometimes it refers to a vendor or service provider. Sometimes it points to claims made against your business by customers or other outside parties.

So, don’t assume a policy covers every breach involving another company.

Check the Vendor Language

A strong cyber policy should clearly address incidents involving outside service providers. Look for wording around vendor breaches, outsourced services, or dependent business interruption. The exact language matters because one policy might cover a vendor-caused outage while another leaves a gap.

This is where I think buyers often go wrong. They read “cyber incident” and feel covered. Then a claim arrives, and the definition turns out to be much narrower than expected.

• Vendor access matters, especially if the provider can reach your customer data or internal systems.

• Dependent business interruption is a big one, because your own systems may be working while a supplier’s outage stops your business.

• A narrow exclusion buried in the wording can change the answer completely, and that’s the bit worth reading twice.

When Coverage Can Be Excluded

Some policies contain exclusions tied to outsourced providers or failures by certain vendors. Others may cover the resulting loss but exclude the vendor’s own responsibility. There’s also a difference between a data breach and a service outage, so a policy that handles one well may treat the other differently.

And contractual issues can complicate things further. Your agreement with a vendor might require the vendor to carry insurance or compensate you for certain losses. That doesn’t automatically mean your cyber insurer will pay first.

The Small Details Matter

Raj learned this during a routine policy review. He kept reopening the same five tabs every morning to compare his company’s vendor contracts with the insurance wording. The exercise was boring, but it showed one supplier had broad system access that nobody had really considered before.

That’s the kind of detail that gets missed until something breaks.

What Should You Look For?

Before buying or renewing cyber insurance, ask directly how the policy treats a breach at a third-party provider. Get the answer in writing if possible. A broker can also point out exclusions that aren’t obvious from the marketing summary.

• The definition of a covered cyber event should be broad enough to address vendor-related incidents.

• Look at dependent business interruption separately. It has its own rules, and those rules can be surprisingly specific.

• Check whether the policy requires the vendor to meet certain security standards, because that condition can matter after a claim.

Honestly, I’d rather spend an extra few minutes reading the exclusion section than discover it during a breach.

So, Is It Excluded?

No, not automatically. Third-party breaches aren’t universally excluded from cyber insurance. Coverage depends on the policy’s definitions, exclusions, limits, and the way the incident affects your business.

And that’s really the point. “We have cyber insurance” is only reassuring when you know what it actually covers.

If your biggest vendor were breached tonight, would your policy answer the phone?