A property manager clicks a link in what appears to be a routine vendor invoice email. Within an hour, the criminal behind it has the association’s banking credentials, a list of residents’ payment records, and the ability to send a fraudulent wire transfer. That single email touches three separate categories of loss: stolen funds, exposed resident data, and the cost of investigating what happened. The community association board assumes its cyber insurance policy covers the whole mess with a single number. In reality, the coverage responds with three different numbers, each one capped separately.
What a Sublimit Actually Caps
A sublimit is a dollar cap on one specific category of loss inside a larger policy. The overall aggregate limit sets the ceiling for the policy as a whole, but individual insuring agreements, such as funds transfer fraud, breach response, or business interruption, often carry their own lower caps beneath that ceiling.
Carriers separate these categories because each one carries a different risk profile. A stolen password that leads to a wire transfer behaves differently than a ransomware attack that shuts down a payment portal for a week. Pricing each category separately allows a carrier to offer a large aggregate limit without pricing every category at the same level.
How One Incident Can Trigger Three Sublimits at Once
Go back to the phishing email. That single incident could touch a cyber insurance policy in three separate places:
- Funds transfer fraud sublimit, which responds to the fraudulent wire itself. If the policy caps this category at $100,000 and the wire went out for $180,000, the policy pays $100,000, and the association covers the remaining $80,000.
- Breach response sublimit, which pays for forensic investigation and notifying every resident of the exposure affected. Notification costs alone climb into the thousands once printing, postage, and legal review for several hundred households are factored in.
- Business interruption sublimit, if the association’s online payment portal has to go offline during the investigation and dues collection stalls for weeks.
That’s three different sublimits, three different dollar caps, all from one Tuesday afternoon phishing email. The board that reads only the aggregate limit on the declarations page has no way to see this problem coming.
Why the Aggregate Limit on a Cyber Insurance Policy Doesn’t Rescue You Here
An aggregate limit describes the maximum the insurer will pay across the entire policy period, not a pool of money that automatically covers whatever a sublimited category leaves behind. If the funds transfer fraud sublimit reaches $100,000, the remaining $900,000 of the $1 million aggregate limit doesn’t roll over to cover the rest of that same claim. It stays available for a different claim later in the policy period.
That structure catches boards off guard, specifically because the math looks reassuring at first glance. A $1 million cyber insurance policy sounds like ample protection until the sublimits underneath it get pulled apart, claim category by claim category.
How Agents Can Stress-Test a Policy Before a Claim, Not During One
A few concrete questions help agents pressure-test a client’s coverage before an incident forces the issue:
- List every sublimit by name and dollar amount, not just the aggregate limit on the declarations page.
- Ask whether funds transfer fraud, social engineering, and breach response draw from separate sublimits or share one combined cap.
- Model a single realistic incident against those sublimits to see where the gaps sit.
- Confirm whether sublimits reset each policy period or apply once across the full term.
The FBI’s Internet Crime Complaint Center tracks Business Email Compromise, the scam behind the scenario above, as a scheme that compromises legitimate business email accounts to redirect fund transfers. It’s exactly the kind of single event that can land in more than one sublimited category on the same policy.
Read the Sublimits Before the Claim Arrives
The aggregate limit on a cyber insurance policy describes what it could pay across an entire year, not what it could pay for a single incident that spans multiple coverage categories. Agents working with homeowners association and condo boards can contact Kevin Davis Insurance Services to walk through a client’s current policy, sublimit by sublimit, rather than limit by limit alone.
FAQ on Cyber Insurance Policies
What is a sublimit in a cyber insurance policy?
A sublimit is a cap on how much the policy pays for one specific category of loss, such as funds transfer fraud or breach notification. It sits below the overall aggregate limit and applies only to that category.
Can one cyber incident trigger more than one sublimit?
Yes. A phishing email that leads to a fraudulent wire transfer and exposes resident data can draw on both the funds transfer fraud sublimit and the breach response sublimit at the same time.
Does a high aggregate limit guarantee full coverage for a claim?
No. The aggregate limit caps total payouts across the policy period, but each sublimited category still applies its own lower cap to that portion of the claim.
How can a board determine which sublimits its policy includes?
The insuring agreement lists each coverage category and its specific dollar limit. Boards and agents should request this breakdown directly rather than relying on the aggregate limit shown in a summary or renewal notice.
About the Author
Kevin Davis is President of Kevin Davis Insurance Services, Inc. (KDIS) and managing general agent for Travelers Insurance — one of the largest specialty insurance writers for community associations in the United States, currently insuring more than 40,000 associations nationwide. With three decades in the insurance industry — 25 of them devoted exclusively to community associations — Davis brings rare depth of expertise to a highly specialized field. He founded KDIS in 2000 with a two-person team and has since grown it into a firm of more than 65 employees, establishing it as a trusted leader in its market. A nationally recognized authority on loss prevention, Davis writes and speaks regularly on the subject. He also serves as a faculty member for Community Associations Institute (CAI) training programs throughout the country.
About Kevin Davis Insurance Services
For over 35 years, Kevin Davis Insurance Services has built an impressive reputation as a strong wholesale broker offering insurance products for the community association industry. Our president, Kevin Davis, and his team take pride in providing the community association market with committed service and unparalleled access to high-quality coverage, competitive premiums, superior markets, and detailed customer service. To learn more about the coverage we offer, contact us toll-free at (855) 790 -7393 to speak with one of our representatives.

