By Ryan Windt | Head of Growth Marketing | Updated June 2026
Most buyers of cyber insurance focus on limits, deductibles, and premium. Few stop to ask which type of policy they are actually buying.
That question matters more than it sounds. Whether your policy is written on a claims-made basis or an occurrence basis determines when coverage applies, what happens when you switch carriers, and whether a claim filed years from now will be covered by a policy you no longer hold.
This post explains the difference between the two forms, why virtually all cyber insurance is claims-made, and what you need to understand before you bind, renew, or cancel a policy.
The Two Policy Forms, Defined
Insurance policies can be structured around two different triggering events: when a loss occurs, or when a claim is made. These produce meaningfully different coverage outcomes.
Occurrence-Based Coverage
An occurrence policy responds based on when the underlying event happened. If an incident takes place during the policy period, that policy covers the resulting loss, regardless of when the claim is eventually filed.
General liability insurance is the most familiar example. If a contractor causes damage to a client’s property in 2022, the 2022 general liability policy responds even if the client doesn’t file suit until 2024. The policy that was in force when the incident occurred is the one that pays.
This creates what insurers call a “long tail.” Carriers may face claims years or even decades after a policy expires, which makes occurrence-based pricing more complex and reserves harder to set.
Claims-Made Coverage
A claims-made policy responds based on when the claim is reported, not when the underlying incident occurred. The policy in force at the time you discover and report the incident is the policy that responds.
Professional liability and errors and omissions insurance are typically written this way. Cyber insurance is almost universally claims-made.
The practical difference: if you have a claims-made policy and you cancel or switch carriers, incidents that happened during your prior policy period may not be covered unless you maintain continuous coverage or purchase extended reporting protection.
Why Cyber Insurance Is Almost Always Claims-Made
The nature of cyber incidents makes occurrence-based coverage extremely difficult to underwrite.
With a fire or a vehicle accident, the date of loss is clear. Cyber intrusions are different. Attackers routinely spend weeks or months inside a network before any visible damage occurs. In some of the largest ransomware cases, initial access was gained more than a year before the eventual extortion demand. Under an occurrence form, that would require the policy in force at the time of initial access to respond, often long before the insured or the carrier had any idea a breach was underway.
Occurrence-based cyber coverage would also require carriers to hold reserves against claims that could surface years after a policy expires. The volatility of cyber loss is already difficult to model on a claims-made basis. Extending that tail indefinitely makes pricing nearly impossible.
Claims-made coverage solves this by tying coverage to the point of discovery and reporting, which is a knowable, documentable event. It also gives carriers a cleaner picture of their liability at any point in time.
The overwhelming majority of cyber insurance policies in the market today are written on a claims-made basis. If your policy does not specify otherwise, assume it is claims-made.
What Claims-Made Coverage Actually Requires
A claims-made policy has two conditions that must both be satisfied for coverage to apply:
First, the claim must be made during the policy period. “Made” typically means you discovered the incident and reported it to your carrier within the policy period, or within any extended reporting window provided by your policy.
Second, the underlying incident must not predate your retroactive date. Most claims-made cyber policies include a retroactive date, which sets a floor on how far back coverage reaches. Even if you report a claim during the active policy period, coverage will be denied if the breach began before your retroactive date.
For a full explanation of how the retroactive date works and what happens when it creates a gap, see our guide to retroactive dates in cyber insurance.
The Continuity Requirement
The most important practical implication of claims-made coverage is what happens when a policy lapses, is cancelled, or is replaced.
Under an occurrence form, past policies remain available to respond to past incidents indefinitely. Under a claims-made form, your coverage is only as good as your current, active policy. If there is a gap in coverage, incidents that occurred during that gap may fall through entirely.
This matters most in three situations:
Switching carriers at renewal. When you move from one carrier to another, you need to confirm that your new policy’s retroactive date reaches back far enough to cover incidents that may have begun before the switch. If your new carrier sets a retroactive date at the new policy’s inception, you lose coverage for anything that happened before that date, even if you had continuous insurance.
Cancelling a policy without a replacement. If you cancel and do not replace your cyber insurance, you lose the ability to make claims for incidents that may have already occurred but haven’t yet been discovered. In a threat environment where dwell time frequently runs six months or longer, this is a meaningful risk.
Allowing a policy to lapse. A lapsed policy is the same as a cancelled one from a coverage standpoint. A gap of even a few days can create exposure, particularly for incidents that were underway before the lapse.
Extended Reporting Periods
Most claims-made cyber policies include an extended reporting period provision, sometimes called a tail. This gives you a defined window after a policy expires or is cancelled during which you can still report claims for incidents that occurred during the prior policy period.
Extended reporting periods vary by carrier. A 30-day or 60-day automatic tail is common. Some policies offer optional extended tails of one to three years for an additional premium.
Tails are most relevant when you are cancelling coverage entirely or when there is an unavoidable gap between the end of one policy and the start of a replacement. They are not a substitute for continuous coverage, but they provide a buffer against claims that surface shortly after a policy ends.
If you are cancelling a cyber policy without an immediate replacement, ask your carrier what extended reporting period is included and whether you can purchase additional tail coverage. Doing this after the fact is usually not possible.
Claims-Made vs. Occurrence: Side-by-Side
| Factor | Claims-Made | Occurrence |
|---|---|---|
| Coverage trigger | When the claim is reported during the policy period | When the incident occurs during the policy period |
| Policy that responds | The policy in force when you report the claim | The policy in force when the incident happened |
| Retroactive date required | Yes, in virtually all cases | No |
| Coverage after cancellation | Only within extended reporting period | Indefinitely, for incidents during policy period |
| Risk at carrier switch | Retroactive date gap is possible | No gap; prior policies remain available |
| Common in cyber insurance | Yes, nearly universal | Rare to nonexistent |
What to Check in Your Policy
Whether you are reviewing a new quote or an upcoming renewal, four things are worth confirming before you bind:
Confirm the policy form. The declarations page or insuring agreement should state whether the policy is claims-made. If it is not explicit, ask your broker.
Identify your retroactive date. Check whether your retroactive date is listed on the declarations page and confirm whether it has moved from the prior policy period. A retroactive date that rolls forward each year is one of the most common and damaging changes that gets overlooked at renewal.
Understand what “claim” means under your policy. Different carriers define a claim differently. Some require you to report the incident itself; others require a formal demand or legal filing. Understand what triggers the reporting obligation and whether you need to notify your carrier of circumstances that might give rise to a future claim, even before a claim is formally made.
Know your extended reporting window. Confirm what tail is provided automatically and what additional tail you can purchase if needed. This is relevant even if you are not planning to cancel, because circumstances change.
For a section-by-section walkthrough of how to review a full cyber policy, see our guide to how to read a cyber insurance policy.
A Note on Prior and Pending Litigation Exclusions
Most claims-made policies include a prior and pending litigation exclusion. This prevents coverage for claims that were already known, pending, or reasonably anticipated at the time the policy was purchased.
In practice, this means that if you are aware of a potential breach, a regulatory inquiry, or a circumstance that could give rise to a claim before you bind coverage, your new policy may not cover it. Full and accurate disclosure during the application process is not only required, it protects you from later coverage disputes based on what you knew and when.
For a detailed look at what misrepresentations on a cyber application actually cost at claim time, see our post on cyber insurance application errors and claim denials.
Frequently Asked Questions
Is all cyber insurance claims-made?
Nearly all of it, yes. The structure of cyber risk, particularly the long and often unknown gap between initial intrusion and discovery, makes occurrence-based underwriting impractical. A small number of specialty or manuscript policies may be structured differently, but for the overwhelming majority of businesses buying standard market cyber insurance, claims-made is the form they will encounter.
What happens to my coverage if I switch cyber insurance carriers?
Your old policy expires and your new policy activates. The risk at a carrier switch is that your new carrier sets a retroactive date at the new policy’s inception, leaving a gap for incidents that began before that date. Work with your broker to ensure your new policy’s retroactive date reaches back at least as far as your prior policy’s retroactive date, and ideally to your original policy inception.
Can I still file a claim after my policy expires?
Under a standard claims-made form, you can only file a claim during the active policy period or within the extended reporting period provided by your policy. Once that window closes, you lose the ability to report. Extended tails can preserve this window for a defined period after expiration or cancellation.
What is a “claims-made and reported” policy?
Some policies require both that the claim arise and that it be reported to the carrier during the same policy period. This is a stricter standard than a policy that only requires the claim to be made during the period. If your policy is claims-made and reported, notify your carrier of any potential incident or circumstance as soon as you become aware of it, even before a formal claim has materialized.
Does my retroactive date change at renewal?
It can, and this is one of the most consequential and least-noticed changes that can occur at renewal. Carriers will sometimes move the retroactive date forward when renewing a policy, especially if the account has had claims activity or if underwriting appetite has changed. Always confirm your retroactive date at each renewal and push back if it has moved.
Related Resources
- What Is a Retroactive Date in Cyber Insurance and Why It Can Sink Your Claim
- How to Read a Cyber Insurance Policy: A Section-by-Section Guide
- Cyber Insurance Application Errors: What Misrepresentations Actually Cost You at Claim Time
- Cyber Insurance Exclusions: What Most Policies Won’t Cover
- How to Get Cyber Insurance
- The Right Way to Move Your Cyber Policy to a New Carrier
Not sure whether your current policy has the right retroactive date or what tail coverage you have in place? SeedPod Cyber works with businesses across industries to make sure the structure of their coverage actually holds up at claim time. Get in touch and we’ll take a look.