By Ryan Windt | Head of Growth Marketing | Updated September 2026
A sublimit is the quiet line in a cyber policy that decides how much you actually collect after a loss. Your policy might show a $3 million aggregate limit, but a ransomware or cybercrime sublimit buried in an endorsement can cap the payout for that specific loss at a fraction of it. Most buyers never test that language until a claim forces the question. In 2026, two federal courts in Texas tested it for them, and reached opposite results. Read together, the decisions are the clearest guidance in years on when a sublimit holds and when it collapses, and both come down to how the endorsement was written.
This is the litigation companion to our guide to how cyber insurance sublimits work. That guide explains the mechanics; this one shows how courts are actually enforcing them.
Why sublimits are suddenly being litigated
Sublimits are not new, but their stakes have grown. As ransom demands and social engineering losses climbed, insurers leaned harder on sublimits to contain exposure, often setting a $250,000 cap on the exact perils that now cause the largest losses. When a six or seven figure loss lands against a low sublimit, the gap between the headline limit and the real recovery becomes a dispute worth litigating. Two 2026 cases show how narrow the margin can be, and how much rides on wording that most policyholders never read closely.
CiCi v. HSB: when a sublimit does not hold
CiCi Enterprises, LP v. HSB Specialty Insurance Company, U.S. District Court for the Northern District of Texas, ruling issued February 23, 2026 (Judge Sam A. Lindsay).
CiCi Enterprises, a restaurant franchisor, was hit by a ransomware attack in May 2022. A threat actor encrypted its systems and threatened to publish stolen data. Working with its insurer’s approved vendors, CiCi negotiated an initial $2 million demand down to a $400,000 ransom payment and ultimately incurred roughly $1.2 million in total costs. The policy carried a $3 million aggregate limit, and the insurer acknowledged the loss triggered four separate insuring agreements, including Cyber Extortion.
The insurer then invoked a Ransomware Event Sublimit Endorsement and paid $250,000, treating that as the ceiling for the entire loss. CiCi sued. On cross motions for summary judgment, the court sided with the policyholder and held that the $3 million in coverage remained available, because the endorsement did not clearly do what the insurer claimed it did.
The drafting problems the court identified are the whole lesson:
- The endorsement said it applied “solely with respect to the coverage afforded under this endorsement,” but never identified which insuring agreements it modified.
- It was added to the policy’s Limits of Insurance section without any reference to changing the insuring agreements that actually granted coverage.
- It closed with boilerplate stating that all other policy terms remained unchanged, which undercut the insurer’s argument that it silently capped everything.
- The insurer’s own coverage letter had already recognized four triggered insuring agreements, none of which the endorsement named as limited.
The court’s conclusion was blunt: if the insurer intended a single $250,000 cap to apply across the whole policy regardless of which coverage was triggered, it was the insurer’s job to say so expressly. Ambiguity in a limiting endorsement is read against the party that drafted it.
Perry v. Cowbell: when a sublimit does hold
Perry & Perry Builders, Inc. v. Cowbell Cyber, Inc. and Obsidian Specialty Insurance Co., 2026 WL 673558, U.S. District Court for the Western District of Texas, March 9, 2026 (Judge Leon Schydlower).
Perry & Perry Builders, a construction company, received an email in December 2023 that appeared to come from its steel supplier, requesting payment on two outstanding invoices. The email was fraudulent. Perry’s business manager wired $874,863.70 to the fraudster-controlled account in two transfers, made about a minute apart, matching the two invoice amounts.
The insurers did not dispute that the loss was covered. They paid the policy’s $250,000 cybercrime sublimit and stopped there. Perry sued for a second $250,000, arguing that because the money moved in two separate transfers, each was a separate claim entitled to its own sublimit. The court rejected that and granted the insurers summary judgment.
Two points drove the result:
- The court held that the number of covered claims cannot turn on a policyholder’s own “bookkeeping choices.” Splitting one intended payment into two transfers a minute apart did not create two losses.
- The endorsement here was written the way the CiCi endorsement was not. It capped liability at $250,000 for all cybercrime loss during the policy period, expressly “regardless of the number and value” of the losses, so the court found no ambiguity to resolve in the policyholder’s favor.
The practical sting: Perry was underinsured by more than triple. Even a second $250,000 payment would have left over $370,000 uncovered. This is the scenario our guide to funds transfer fraud and social engineering coverage warns about, where the sublimit, not the aggregate limit, is the number that matters.
Same question, opposite answers: what actually differed
Both cases asked the same thing: does a sublimit endorsement cap an otherwise covered loss? The outcomes diverged entirely on drafting, not on sympathy for the policyholder or the size of the loss.
| CiCi v. HSB | Perry v. Cowbell | |
|---|---|---|
| Loss type | Ransomware, ~$1.2M | Funds transfer fraud, ~$875K |
| Aggregate limit | $3,000,000 | Lower, cybercrime sublimited |
| Sublimit at issue | $250,000 ransomware | $250,000 cybercrime |
| Did the sublimit apply? | No | Yes |
| Why | Endorsement never said which coverages it limited | Endorsement expressly capped all such loss regardless of claim count |
| Result | Full $3M available | Capped at $250K |
The pattern is consistent with how courts read insurance contracts generally. A grant of coverage is read broadly; a limitation on coverage is read narrowly and strictly against the insurer that wrote it. A sublimit that clearly states its scope will usually be enforced. A sublimit that leaves its scope to inference often will not.
What this means for how you buy and read a policy
You cannot draft your insurer’s endorsements, but you can find the exposure before a loss does. These rulings translate into a short, practical checklist.
- Find every sublimit before you bind. Ransomware, cyber extortion, funds transfer fraud, social engineering, and business email compromise are the ones most often sublimited. Read the endorsements, not just the declarations page.
- Check what each sublimit actually modifies. A sublimit that names the specific insuring agreements it limits behaves very differently from one that gestures vaguely at the whole policy. The difference decided both cases above.
- Size the sublimit to your real payment flows. A $250,000 cybercrime cap is meaningless to a business that routinely wires six or seven figures to vendors. Perry lost most of its recovery to exactly this mismatch.
- Watch for aggregation language. Phrases like “regardless of the number of claims or incidents” mean multiple events collapse into one cap. That is what closed the door in Perry.
- Ask how much sits above the sublimit. A high aggregate limit is cold comfort if your most likely loss is capped far below it.
If reading this language is daunting, that is the point of working with a specialist. Our guides to reading a cyber insurance policyand sizing your coverage limits walk through where these traps hide.
Frequently Asked Questions
What is a cyber insurance sublimit?
A sublimit is a cap on the amount payable for a specific type of loss, set below the policy’s overall aggregate limit. A policy with a $3 million limit might still cap ransomware or cybercrime losses at $250,000 through an endorsement.
Can a sublimit reduce my payout below the policy limit?
Yes, if the endorsement is drafted clearly enough to apply to the coverage you are claiming under. In Perry v. Cowbell the sublimit held and capped an $875,000 loss at $250,000. In CiCi v. HSB the endorsement was too vague to apply, and the full limit remained available.
Does splitting a payment into two transfers create two claims?
No, according to Perry v. Cowbell. The court held that two wire transfers made a minute apart as part of one intended payment were a single loss, and that claim count cannot turn on the policyholder’s bookkeeping.
Are these rulings binding everywhere?
They are federal district court decisions applying Texas law, so they are not binding nationwide. But they reflect widely followed principles of insurance contract interpretation, and coverage lawyers are already treating them as influential guidance on sublimit disputes.
How do I know if my own sublimits are a problem?
Review each sublimited coverage against your realistic worst case loss for that peril, and confirm the endorsement clearly states its scope. A specialist can flag mismatches before you bind rather than after a claim.
Related Resources
- Cyber Insurance Sublimits Explained: Ransomware, Funds Transfer, and More
- Ransomware Coverage, Sublimits, and What Your Policy Actually Pays
- Funds Transfer Fraud vs. Social Engineering: Why the Distinction Matters
- Understanding Your Cyber Policy: Coverage Sections, Exclusions, and Limits
- Cyber Extortion Coverage: Ransomware, Data Extortion, and How It Works
Not sure whether your sublimits leave a gap between your headline limit and your real recovery? Talk to a cyber specialistwho reads this language every day, and we will help you find the exposure before a claim does.