A community bank with $500 million in assets opens on a Monday morning. Tellers log in to the core banking system. Nothing loads. The mobile app shows a maintenance screen. ACH files are not processing. Wire transfers are stuck.
The bank’s IT director calls the core platform provider. The answer: a ransomware attack hit the vendor’s data center over the weekend. Systems are down. No timeline for restoration.
The bank’s own systems are unaffected. Its firewalls held. Its backups are intact. But none of that matters, because every transaction the bank processes runs through that vendor’s platform.
By Wednesday, the bank is still down. Branch staff are handling deposits manually. Commercial loan closings are postponed. The bank is losing fee income, paying overtime, and fielding calls from regulators. The estimated financial impact: $1.8 million in lost income and extra expenses over five days.
The bank files a claim under its cyber policy. Dependent business interruption coverage. $5 million limit on the declarations page.
The adjuster comes back with a number: $1 million. That is the sublimit for dependent BI. The $5 million applies to the bank’s own systems. The vendor outage falls under a carve-out buried on page 34.
This Is Not Hypothetical
In August 2025, Marquis Software Solutions, a fintech vendor serving more than 700 banks and credit unions, was hit by ransomware. The Akira group exploited an access control vulnerability in a SonicWall firewall. Customer records for more than 823,000 individuals were exposed across dozens of institutions. The banks themselves were not breached. Their own security held. But they depended on Marquis for data analytics, compliance reporting, and customer relationship tools. When Marquis went down, those functions went with it.
In May 2025, a planned infrastructure upgrade at Fiserv went wrong and knocked out online banking, Zelle, ACH processing, and direct deposits for dozens of banks, including Bank of America and Capital One. It was resolved in about 12 hours. In late 2023, a ransomware attack hit Ongoing Operations, a Trellance-owned disaster recovery unit that markets itself as the provider keeping credit unions running when nothing else works. The business-continuity vendor went down. About 60 credit unions lost access to systems for days.
Examiner Attention Is Already Here
After the Marquis breach, vendor concentration became the top examiner concern in cybersecurity conversations with community banks. Regulators are now asking whether insurance programs respond when critical vendors fail.
Your examiner asks about vendor risk. Your insurer sublimits it. Nobody is checking whether the coverage matches the dependency.
The Dependency Nobody Prices Correctly
A community bank’s core processor (Jack Henry, Fiserv, FIS, CSI, Corelation) touches every function: deposits, lending, wires, online banking, regulatory reporting. These platforms are not interchangeable. Switching core vendors takes 12 to 18 months. When one goes down, the bank does not switch to a backup. The bank waits.
In five consecutive bank reviews, dependent BI coverage ranged from $100,000 to not purchased at all. The best-positioned program carried a $1 million sublimit. A multi-day core platform outage can generate $1.5 million to $2.5 million in losses. The sublimit covers 40 to 65 cents on the dollar.
Calculate what a day of downtime costs your bank: lost income, staff overtime, manual workarounds, customer impact. Then compare that number to your sublimit. Most banks I talk to have not done that math.
What the Policy Says (and What It Means)
Dependent business interruption coverage isn’t straightforward. It includes conditions that determine whether a vendor outage triggers coverage at all.
Four Questions That Determine Whether Your Vendor Outage Is Covered
No Other Policy Picks This Up
The D&O policy does not cover this. No claim against directors. The fidelity bond does not cover this. No fraud occurred. The bank’s single most critical operational dependency sits under the weakest coverage on the program, and there is no second policy behind it.
What to Check at Your Next Renewal
Your bank cannot operate without its core platform. One vendor, no substitute, 12 to 18 months to switch. The insurance should reflect that dependency. In most cases, it does not.
Vendor concentration is one of five incident types where coverage breaks down across all three bank policies. I map the full picture in Five Common Cyber Incidents, Three Policies, and the Gaps Between Them.
Find out whether your dependent BI trigger covers a vendor outage that was not a cyberattack. Get in touch.