Skip to content
Security Notes

Cyber insurance: what gets excluded when you claim

By Elias Lankinen11 min read

I have thorough sourcing and five verified images. Writing the post now.

The $1.4 billion argument over what counts as war

In the summer of 2017, a piece of malware called NotPetya tore through Merck's network in about 90 seconds. The pharmaceutical giant lost roughly 40,000 computers. Vaccine production stalled. When the accountants finished totting up the damage, the bill came to about $1.4 billion, according to Bloomberg Law. Merck had insurance for exactly this kind of catastrophe: an all-risks property program with $1.75 billion in limits sitting above a $150 million deductible. So it filed a claim. Its insurers said no. Eight of them, disputing roughly $700 million of the total, invoked a clause that had been sitting quietly in property policies since the era of naval blockades and artillery barrages: the war exclusion. NotPetya, they argued, was an act of war by the Russian government, and war is not covered.

Source: Wikimedia Commons
Source: Wikimedia Commons

That fight, and the seven years of litigation it produced, is the sharpest illustration of a truth most buyers of cyber insurance never confront until it is too late: the policy is not a promise to pay. It is a promise to pay unless, and the exclusions doing the work behind that "unless" are where the real coverage is decided. Here is what actually gets excluded when you claim, and why.

Cyber insurance is a young market still writing its own rules

Cyber is not like fire or flood, where insurers have a century of loss data. The product is barely two decades old, the threats mutate monthly, and a single incident can hit thousands of policyholders at once. That combination, as broker Reed Smith notes, leaves carriers writing exclusions faster and broader than in almost any other line of insurance. The scale of the payouts has also shifted. The US market's direct written premiums actually fell 7.11% to $9.14 billion in 2024, the first decline in the market's history, while the combined loss ratio dropped to around 47%, a third straight profitable year. Profitable years are precisely when insurers refine the fine print, because they can afford to be choosy about what they cover next time. A word of caution on the numbers that follow. Some of the most-quoted denial statistics come from security vendors rather than regulators, and they blur very different outcomes together. When you read that a large share of claims "close without payment," that figure sweeps in claims below the deductible, claims the policyholder withdrew, and claims resolved with free incident-response help. Outright denial on an exclusion is a smaller, harder-to-measure slice. Treat precise percentages as directional, not gospel.

The war exclusion: the clause that nearly swallowed cyber

The war exclusion is the oldest and most consequential trapdoor. Its logic is straightforward: insurers price ordinary risk, and the ruinous, correlated losses of warfare are meant to be borne by states, not the private market. The language in Merck's policies barred coverage for loss caused by "hostile or warlike action in time of peace or war" by "any government or sovereign power." The problem is attribution. NotPetya was not an ordinary crime. In February 2018 the White House press secretary called it "the most destructive and costly cyber-attack in history" and pinned it on the Russian military, as Axios reported; nine governments jointly attributed it to GRU unit 74455, the group known as Sandworm. Total worldwide damage ran to an estimated $10 billion. If any cyberattack was going to qualify as warlike action by a sovereign power, this was the one.

Source: Wikimedia Commons
Source: Wikimedia Commons

And yet Merck won. In January 2022 a New Jersey trial court ruled the exclusion did not apply, and in May 2023 an appellate panel agreed, finding the insurers "did not demonstrate that the NotPetya attack was a 'hostile' or 'warlike' action." The reasoning was almost literal: the exclusion, as written, contemplated military action, armies and weapons, and insurers had never updated the wording for a world where a state fires code instead of shells. A policyholder reading that clause would reasonably understand it to mean traditional warfare. The insurers, having drafted the ambiguity, had to eat it. The New Jersey Supreme Court agreed to hear the case, and then, days before oral argument in January 2024, the parties settled on confidential terms. So the highest-court precedent everyone wanted never arrived. What the market took from Merck was not "war exclusions don't work" but "our war exclusions are written for the wrong century."

Lloyd's redraws the line

The insurers' answer was to rewrite the clause so it could never be read narrowly again. The push came from Lloyd's of London, the centuries-old insurance marketplace whose syndicates set much of the tone for the global market. In late 2021 the Lloyd's Market Association published a suite of model war-exclusion clauses (numbered LMA5564 through 5567) built specifically for cyber, and in a 2022 bulletin Lloyd's told its syndicates that from 31 March 2023 every standalone cyber policy written in the market must exclude state-backed cyberattacks. The new clauses do two things the old ones did not. First, they exclude not just "war" but state-backed operations that "significantly impair" a state's ability to function or its security, even absent a declared war. Second, and more strikingly, they hand insurers a rule for the attribution problem that tripped them up in Merck. Under one model clause, the primary factor in deciding whether an attack was state-backed is any attribution made by the government of the country where the affected computer system sits. In practice: if Washington blames Moscow for the attack that hit your US servers, that government statement can be enough for your insurer to invoke the exclusion, whether or not the attribution ever gets tested in court. This is a genuine tightening, and it is contested. Critics argue it makes coverage hostage to geopolitics, that attribution is slow, uncertain, and politically motivated, and that a business hit by ransomware has no way to know at purchase time whether a future government statement will void its claim. That debate is unresolved, and the exact wording varies from insurer to insurer. The one safe generalisation is that the post-2023 war exclusion is far harder for a policyholder to defeat than the one Merck beat.

"You said you had multi-factor authentication"

If war exclusions are the dramatic denials, the quiet ones are far more common, and they hinge on something you did rather than something a foreign state did. When you apply for cyber cover, you fill out a questionnaire attesting to your security controls: do you use multi-factor authentication (MFA, the second login step, a code or app prompt, that stops a stolen password from being enough), do you patch promptly, do you back up offline. Those answers are not box-ticking. They are representations the insurer relies on to price and issue the policy, and getting them wrong can void everything. The case that put this on every broker's slide deck is Travelers v. International Control Services. An electronics manufacturer, ICS, attested on its application that it used MFA for email, remote access, and all endpoints. After a ransomware attack in May 2022, Travelers investigated and found MFA was configured only on the firewall; the servers the attackers actually hit had none. Travelers sued to rescind the policy, and ICS consented to rescission in August 2022. Rescission is worse than a denied claim. The word means the policy is treated as void from inception, as if it never existed. Premiums get returned, and every dollar of the loss falls back on the company. There is no argument about whether this particular incident was covered, because there is no policy left to argue about. The lesson landing across the market is that an inaccurate application answer, even an honest mistake by someone who did not know the servers were unprotected, can hand the insurer a clean exit.

Failure to maintain: the promise that never expires

Closely related, and easy to confuse, is the "failure to maintain" exclusion. Misrepresentation is about what you said at the start. Failure to maintain is about what you kept doing afterward. Many policies exclude losses arising from the insured's failure to keep the security standards it represented, or to follow reasonable practices, for the whole policy period, not just the day you signed. The practical bite is that the obligation is live throughout the year. If your team disables MFA on a legacy application in month four to keep an old system running, and the breach comes through that door in month seven, the insurer can point to the gap. Industry write-ups consistently rank missing or lapsed MFA as the single most common thread in denied cyber claims, though, again, the precise percentages vary by who is counting and how. The underlying mechanism is not in doubt: the controls you attest to are a continuing condition of coverage, and the moment you fall below them you have handed the carrier a reason to look elsewhere. There is a real fairness debate buried here. Security is messy; every large organisation runs some unpatched system somewhere. A broadly worded failure-to-maintain clause can, in principle, let an insurer find some lapse in almost any breached company, because a company that had perfect security would not have been breached. Courts have not fully resolved how strictly these clauses can be read, and well-advised buyers now negotiate to narrow them, so that only a material failure directly causing the loss counts.

The ransom you may not be allowed to pay

Even when your policy plainly covers ransomware, a different body of law can override it. In the United States, the Treasury's Office of Foreign Assets Control (OFAC) administers sanctions, and paying money to a sanctioned person or group is illegal regardless of the reason. Many prolific ransomware crews are, or are linked to, sanctioned entities. Evil Corp, the group behind the Dridex banking malware, was sanctioned in December 2019, for instance. In September 2021, OFAC issued an updated advisory spelling out that companies facilitating ransom payments, and it named cyber insurers, financial institutions, and incident-response firms explicitly, may be violating sanctions law even when acting on a victim's behalf. Crucially, the advisory states that having insurance coverage available to reimburse a ransom is no protection from sanctions liability. OFAC's rules impose strict liability, meaning you can be penalised even if you had no idea the recipient was sanctioned. So the coverage can exist on paper and still be unusable in practice. If the attacker turns out to be sanctioned, your insurer cannot lawfully reimburse the payment, and you cannot lawfully make it. The advisory does offer a lever: OFAC treats prompt reporting to law enforcement and cooperation as significant mitigating factors, which is part of why insurers now route ransomware victims through specialist counsel before a single coin moves. The payment clause in your policy, in other words, comes with a silent condition, that the counterparty is legally payable, that no underwriter writes in bold.

When everyone is hit at once

The newest frontier of exclusion is not about your conduct or a foreign army. It is about correlation. Insurers price on the assumption that losses are largely independent: your office fire does not cause mine. Cyber breaks that assumption. A flaw in one widely used platform can down thousands of businesses in the same hour, producing a single loss event the size of a natural disaster. Insurers call this accumulation risk, and it is the thing that keeps their capital models awake at night. The demonstration came on 19 July 2024, when a faulty update to CrowdStrike's Falcon security software, a logic error in a single configuration file, sent millions of Windows machines into the blue screen of death. Airlines grounded flights, hospitals postponed procedures, and the losses across large companies ran into the billions of dollars. Notably, it was not even an attack; it was a botched patch. But it showed insurers exactly how one third-party dependency could trigger claims from their entire book at once. The response has been a wave of "widespread event" and "systemic risk" language: exclusions and sublimits (caps that pay only a fraction of your limit) for losses tied to failures of shared infrastructure, major cloud outages, or software used across the whole economy. The irony is uncomfortable. The incidents most likely to hurt you are increasingly the ones your policy is most carefully engineered not to cover, precisely because they would hurt everyone at once.

What to watch

The pattern across all of this is a market maturing by subtraction. Every headline loss, NotPetya, the ransomware wave, CrowdStrike, teaches insurers where their words were too loose, and the next policy generation closes the gap. Coverage narrows not through a single dramatic clause but through the steady accretion of definitions, conditions, and carve-outs that only reveal their shape when you file. For a buyer, the useful shift in mindset is to stop reading the insuring agreement, the part that lists what is covered, as the answer, and start reading the exclusions, definitions, and application questions as the real contract. The questions worth asking before you sign are unglamorous: How is a "state-backed" attack defined and who decides? Does the failure-to-maintain clause require that my lapse actually caused the loss? What is the sublimit on a widespread event, and what counts as one? Is anything I attested to on the application still true today? The open question hanging over the whole market is whether cyber coverage can keep narrowing without becoming something customers no longer value. An insurer that excludes state attacks, systemic events, and any lapse in security controls has excluded a large share of how catastrophic cyber losses actually happen. At some point the product has to answer the question Merck asked in 2017 and spent seven years litigating: when the worst thing occurs, is this a promise to pay, or a well-drafted way to say no?

Sources

  1. Bloomberg Law, Merck's $1.4 Billion Insurance Win Splits Cyber From 'Act of War', 2024
  2. Insurance Journal, Merck Settles Coverage Dispute With Insurers Over War Exclusion in NotPetya Attack, 2024
  3. Cybersecurity Dive, Merck reaches settlement in closely watched NotPetya insurance case, 2024
  4. Axios, White House confirms NotPetya malware was Russian military operation, 2018
  5. Clifford Chance, Lloyd's cyber war exclusion, 2023
  6. King & Wood Mallesons, Lloyd's of London announces cyber-attack insurance exclusions for "state backed cyber-attack", 2022
  7. Lockton, Travelers v. ICS underscores need to respond carefully to cyber insurance application questions, 2022
  8. Reed Smith, Navigating common exclusions in cyber policies, 2023
  9. American Hospital Association, U.S. Treasury Department: Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments, 2021
  10. Astra Security, 64 Cyber Insurance Claims Statistics 2026, 2026
  11. DeepStrike, Cyber Insurance Claims Statistics 2025: What the Data Reveals About Denials and Risk, 2025
  12. Insurance Thought Leadership, Cyber Insurance Exclusions to Expect in 2026, 2026