A $250K ransomware cap failed in Dallas. A $250K wire-fraud cap held in Waco. One endorsement named the coverage. One didn't.


LION Specialty

Skim time: 5 minutes · Listening time: 7 minutes. Prefer to listen? Flip reads this week's Brief here.


In May 2022, a ransomware crew locked up the systems at CiCi Enterprises, the company behind the Cicis pizza chain, and threatened to publish what it had taken. The demand was $2 million. The negotiators got it to $400,000. By the time the systems were back, the bill was more than $1.2 million.

CiCi had a $3 million cyber policy.

The carrier paid $250,000.

The claim was covered. The carrier's own coverage letter said four insuring agreements were triggered, four of the policy's separate promises to pay. The $250,000, though, instead of the full limits? That came from a ransomware endorsement added to the limits section when the policy was issued. In February, a federal judge in Dallas read that endorsement and ruled it never reached the cyber extortion coverage the carrier was using it to cap.

Two weeks later, a federal judge in Waco read a different $250,000 endorsement on a different cyber policy and enforced it to the dollar. That insured had wired $874,863 to a fraudster. It collected $250,000.

Insurers, MGAs, insurtech operators: why should you read about a pizza chain or a builder? Because the wording on their policies is the wording on yours. The cyber policy you buy carries a social engineering sublimit like the one that held in Waco, and the policies you issue carry sublimit endorsements that face the same test the Dallas endorsement failed. Last week was the directors and officers (D&O) endorsement that cut Kaiser's $95 million tower to $1 million. This week is the cyber sublimit, and it reads from both sides of your desk.

I've been talking about these two claims for months, mostly to make the case for reading your sublimits at every renewal. A few of you asked for the full write-up instead of the summary, so here it is.

  • A ransomware endorsement that capped "the coverage afforded under this endorsement." The endorsement afforded none.
  • Two wires, one minute apart, paying two real invoices. The court said the count came down to the insured's own bookkeeping choices.
  • Both policies came through programs. If you write policies, CiCi is about your endorsement library too.

The ransomware cap that capped nothing

The endorsement never named the coverage it capped.

CiCi's policy with HSB Specialty Insurance Company carried a $3 million aggregate limit, one total for the policy year. HSB's coverage letter said the attack triggered four insuring agreements, cyber extortion among them. Then HSB applied the Ransomware Event Sub-Limit Endorsement and paid $250,000.

The endorsement opened with ten words: "Solely with respect to the coverage afforded under this endorsement." It capped any single ransomware event at $250,000. It closed with "all other terms, conditions, and exclusions to the Policy shall remain unchanged."

On February 23, 2026, Judge Sam A. Lindsay granted CiCi partial summary judgment on the coverage question. The endorsement does not modify cyber extortion coverage, and the court declared the $3 million limits available for the claim. What HSB owes under them is still for trial. So are CiCi's Texas Insurance Code claims, the state's statutory bad-faith counts.

(sources: CiCi Enterprises, LP v. HSB Specialty Insurance Co., No. 3:23-cv-2155-L (N.D. Tex. Feb. 23, 2026), memorandum opinion and order; Hunton Andrews Kurth, February 27, 2026; Insurance Business)

So what?

The word the court started with was "solely."

It looked it up. Merriam-Webster, last visited February 20, 2026: "to the exclusion of all else." So the endorsement capped only the coverage afforded under the endorsement. It never said what that coverage was, never named an insuring agreement, and never mentioned cyber extortion.

Two more things sank it. HSB's other endorsements in the same policy named the insuring agreement they modified, so the court knew HSB could do it when it meant to. And the endorsement added "Ransomware Event" to the policy's list of cyber events next to "Extortion Threat," not inside it. Saying ransomware is a kind of extortion after the claim arrived was not enough. The court read the list the way HSB drafted it.

Texas construes unclear policy wording against the insurer. How hard that rule bites varies with governing law, the insured's sophistication, and how much the form was negotiated. Read your governing-law clause before you lean on this ruling.

The first public reading of this endorsement against the insuring agreements came in litigation, nearly four years after the policy was issued. In our experience, that is when many buyers first learn what an endorsement does.

Monday morning action: pull every endorsement on your cyber policy with "limit" or "sub-limit" in the title. For each one, find the sentence that names the insuring agreement it modifies. If that sentence isn't there, you don't know what the cap applies to. Neither does the carrier.


Two wires, one minute apart, one $250,000

Perry & Perry Builders paid two real invoices to the wrong bank account and found out how much "all" means.

In December 2023, an email that looked like it came from Perry's steel vendor asked that two outstanding invoices be paid to a new account. Perry sent two electronic bank transfers (ACH) less than a minute apart, $272,997.45 and $601,866.25. The account belonged to a fraudster.

Coverage was never in dispute. Cowbell Cyber, which runs the program, and Obsidian Specialty Insurance Company, which issued the policy, paid the $250,000 Cyber Crime sublimit. Perry argued two transfers, two invoices, two incidents, and a second $250,000.

On March 9, 2026, the Western District of Texas granted the insurers summary judgment. The endorsement made the limit the most the insurer would pay for all claims under each insuring agreement, "regardless of the number of" cyber crime incidents. Perry was, in the court's words, "hard-pressed to make the argument that the number of 'claims' or 'losses' that it can assert under the policy depends on its own bookkeeping choices." Six months on, we have not found a reported appeal.

(sources: Perry & Perry Builders, Inc. v. Cowbell Cyber, Inc., et al., No. 6:25-cv-00106 (W.D. Tex. Mar. 9, 2026), 2026 WL 673558; Wiley Rein, March 2026; Saxe Doernberger & Vita, March 2026; Phelps Dunbar)

The LION Lens

What happened — In Dallas, a sublimit that pointed at itself capped nothing. In Waco, a sublimit that named its insuring agreement turned two wires into one $250,000 (CiCi memorandum opinion, February 23, 2026; Saxe Doernberger & Vita, March 2026).

Why it matters — The number on the declarations page, the policy's front summary, and the number you collect are decided on different pages. The outcomes turned on endorsement language, not on the cyber events (Phelps Dunbar).

Practical implications — Five questions for every sublimit endorsement. Which endorsement creates a limit below the headline number? Which insuring agreement does it say it modifies, in those words? Per claim, per event, or once for the policy year? Does it say "regardless of the number of" claims, incidents, transfers, or payments? If your cyber is a tower, a primary with excess layers above it, do the excess layers follow the primary's sublimits? The follow-form clause answers that. It is the excess policy's promise to track the primary's terms.

So what?

Put the two endorsements side by side. HSB's cap said "solely with respect to the coverage afforded under this endorsement." Obsidian's said the maximum "under each Insuring Agreement, regardless of the number of" incidents. One reached for the insuring agreement and missed. The other named it, then shut the door on splitting a loss into pieces to buy a second limit.

For a regional carrier buying cyber, the vendor-payment loss is the one you will have. The coverage that responds is typically social engineering or funds transfer fraud, and it often carries a sublimit well below the cyber aggregate. Written the Perry way, money moving twice does not buy a second $250,000. The sublimit is one maximum for all cyber-crime loss under that insuring agreement. It sits inside the policy aggregate.

The control that stops this loss is older than the policy: a call to the vendor on the number already in your file, before the first wire, whenever payment instructions change. In our experience it is also the first control the underwriter asks about before moving the sublimit.

The LION POV

Here's how we're advising clients:

  • Make every sublimit name its insuring agreement. If the endorsement caps "the coverage afforded under this endorsement," ask the underwriter which coverage that is. On a negotiated program, have coverage counsel redline it before you bind.
  • Read the aggregate words before the dollar figure. "All," "maximum," "regardless of the number of," "during the policy period." Those words decide whether $250,000 is per event or per year.
  • Bring the controls, then ask for the limit. Underwriters move social engineering sublimits on controls before price: callback verification on any change to payment details, dual authorization above a set amount, the procedure written down. With those on the application, ask what a higher sublimit costs. If the answer is no, ask for per-event wording instead of aggregate.

After CiCi, expect corrected endorsements that name the insuring agreement and say "regardless of the number of." Narrower wording, same price. Compare it to what you have. Price it. Do not initial it.

LION reads bound cyber policies, endorsement by endorsement, for FI clients before renewal. Grab 30 minutes with Flip and bring the policy.


You are on both sides of this page

Both policies came through cyber programs.

CiCi's notice of the attack went to At-Bay Insurance Services, which the court record identifies as HSB's agent for receiving claims. CiCi's briefing calls At-Bay HSB's managing general agent, or MGA, the firm that runs a program on a carrier's paper. It ties CiCi's bad-faith counts in part to At-Bay's claim handling. Perry's policy was sold through Cowbell Cyber and issued on Obsidian Specialty's paper, in Obsidian's name.

That is much of the middle market. A program builds the form and the endorsement library. A carrier supplies the paper. Claim counsel later defends the wording in court. HSB's endorsement was written by people who do that for a living, and a federal judge found it capped nothing. The same test applies beyond cyber. Sublimit endorsements sit on property, casualty and professional forms too.

(sources: CiCi Enterprises, LP v. HSB Specialty Insurance Co., No. 3:23-cv-2155-L (N.D. Tex. Feb. 23, 2026); Perry & Perry Builders, Inc. v. Cowbell Cyber, Inc., et al., No. 6:25-cv-00106 (W.D. Tex. Mar. 9, 2026))

So what?

As a carrier or MGA, the wording is already on policies in force. This cannot wait for renewal. Pull the three sublimit endorsements your program attaches most often and identify the insuring agreement each one modifies. If the answer depends on inference rather than words on the page, bring in coverage counsel this month. For an MGA, read the capacity agreement next to the endorsement. It says whose problem an unclear endorsement becomes.

As an insured, ask which program produced the policy, and whether anyone has mapped every sublimit endorsement to an insuring agreement since the program was built.


What LION is seeing in financial institution (FI) lines

On the renewals we are seeing, cyber is soft for banks and investment managers. It is flatter for carriers and MGAs. Spend that room on the sublimit wording, not the rate. A rate cut on a policy with a $250,000 aggregate social engineering cap is a discount on limits you will never reach.


The Bottom Line

Two courts, one number, opposite results.

The cap that failed pointed at itself. The cap that held pointed at the insuring agreement and closed the counting argument in advance. Both policies came through programs. Neither ruling describes a pre-loss review that mapped the sublimit to its insuring agreement. The first public readings came in court.

The cyber limit on your declarations page is a number. The sublimit endorsement is the page that decides whether you ever see it. If you issue policies, it is also the page your claims department cites next.

Three for your board on Monday

  1. Get the bound cyber policy, every endorsement, in issuance order. For each sublimit, name the insuring agreement it says it changes. Do not accept the specimen form or an endorsement title as the answer.
  2. Name the loss most likely to happen. Vendor-payment fraud, ransomware, cloud outage. Then the insuring agreement and the sublimit that apply. Per event, per claim, or the maximum for the policy period? Is the callback procedure for changed payment instructions written down and tested?
  3. If we issue policies, test our own wording. Pull the three most-used sublimit endorsements. For each, the insuring agreement it modifies, who last reviewed it, and when.

If the honest answer to any of those three is "I'd have to check," that's the conversation to have before renewal, not after a claim. Book a confidential conversation or reply to this email.


Next Friday, Part 3 of The Endorsement Audit: capacity and retention. New Jersey's Supreme Court on a director who loses coverage on the overlap between two roles, Delaware's on defense costs that do not count toward the self-insured retention, and the one-page checklist of every endorsement to pull before renewal.


LION has published a structured review of the five most common D&O program gaps: the D&O Contract Vigilance Blueprint, a five-day email course available to clients and subscribers preparing for renewal.

  • The policy mistakes we see most often when reviewing D&O programs
  • Where your personal assets sit when the company can't indemnify you

Want it? Just reply to this email with the word "blueprint" and I'll sign you up.

Thank you for reading today's edition.

Stay Covered Everybody,

-FLIP

P.S. Want to share this edition? Copy the link below:

https://lionspecialty.kit.com/posts/a-250k-ransomware-cap-failed-in-dallas-a-250k-wire-fraud-cap-held-in-waco-one-endorsement-named-the-coverage-one-didn-t

And if this was forwarded to you, subscribe here: https://lionspecialty.kit.com/

P.P.S. Nothing in this briefing constitutes legal advice. These are the opinions of the founder. It's market intelligence designed to help you ask better questions of your advisors and make sharper decisions at your next insurance renewal.


You're receiving this because you subscribed to the LION Specialty Boardroom Brief.
Unsubscribe  ·  Update your preferences

LION Specialty

Everything you need to know to navigate the financial institution insurance market in ≈ 5 minutes per week. Delivered on Fridays.

Read more from LION Specialty
Kaiser bought a $95M D&O tower and collected $1M. One endorsement did it. And a federal judge just took away the carriers' first argument.

Skim time: 5 minutes · Listening time: 7 minutes. Prefer to listen? Flip reads this week's Brief here. Kaiser Permanente is one of the largest health systems in the country. In January it settled a False Claims Act case with the Justice Department for more than half a billion dollars. It had bought a $95 million directors and officers (D&O) tower for exactly this kind of claim. The carriers paid $1 million. Not because the claim wasn't covered. The primary carrier said it was. The reason was...

90 pages on who grades your carrier's bonds. 4 days to erase 2 years of CA privacy claims. And old fashioned underwriting discipline turns a loss into $57.7M.

Skim time: 5 minutes · Listening time: 6.6 minutes. Prefer to listen? Flip reads this week's Brief here. Ninety pages of comment letters crossed my desk this week. On a Wednesday night. My wife asked what could possibly be in there. The price of your carrier's balance sheet. Fitch, KBRA, and S&P Global wrote to state regulators. So did the American Council of Life Insurers, two investor and analyst associations, and one policy institute. The same complaint runs through all of them in...

Skim time: 5 minutes · Listening time: 6.5 minutes. Prefer to listen? Flip reads this week's Brief here. The future of brokerage looks like a team of AI agents with job descriptions, working on platforms like Grok Bot and Buzz. On those platforms a digital worker gets its own login and its own queue, and everything it does leaves a trail. A licensed human still signs everything that matters. I believe that enough to be running a small agent pilot in my own shop right now. Twenty-five years in...