Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Does Your Terrorism Policy Cover What You Think It Does?Policy Exclusions
5 min readFor Business Continuity Managers

Does Your Terrorism Policy Cover What You Think It Does?

The Terrorism Risk Insurance Act (TRIA) backstop isn't a substitute for a complete terrorism risk assessment. It's a federal reimbursement mechanism that only activates after you've already paid claims under your private policies. If those policies exclude the peril or cap coverage below your actual exposure, TRIA won't fill the gap.

This checklist helps you verify that your terrorism insurance actually protects what you need it to protect, not just what your broker said you bought three years ago.

What This Checklist Covers

You'll audit your existing terrorism coverage across property, business interruption, workers' compensation, and liability programs. Each item requires a specific deliverable or verification step. The goal is a documented record showing where coverage exists, where it doesn't, and what exclusions could block a claim even when TRIA certification occurs.

This isn't about whether TRIA gets reauthorized. The House passed the TRIA Program Reauthorization Act of 2026 by a 373-15 vote, and the program has never paid a claim since its creation after September 11. The real question is whether your underlying policies would respond to the terrorism scenarios your organization actually faces, including cyberterrorism, infrastructure disruption, and lone-actor violence.

Prerequisites

Before you start, gather these documents:

  • Current declarations pages for all commercial property, general liability, workers' compensation, and Stand-Alone Cyber Policy contracts
  • Any terrorism endorsements or separate terrorism insurance policies
  • Lender agreements or financing covenants that reference terrorism coverage requirements
  • Your organization's business continuity plan, specifically sections identifying critical infrastructure dependencies
  • Last year's underwriting questionnaires for property and cyber policies

You'll also need access to someone who can explain what "certified act of terrorism" means under your specific policy language. Don't assume it matches the TRIA statutory definition.

Checklist Items

1. Verify terrorism coverage is affirmatively included, not just available.

Pull each policy's terrorism section. Confirm coverage wasn't declined at renewal. Many policies include terrorism within the base premium for certain lines, but others require you to opt in. Look for a signed endorsement or declarations page line item showing terrorism coverage with specific limits.

2. Document the per-occurrence limit for terrorism on each policy.

Write down the dollar figure. Compare it to your property values, revenue at risk, and potential business interruption losses. Limits should match or exceed your property schedule values and a 12-month business interruption projection.

3. Confirm whether cyberterrorism falls under your cyber policy or your property policy.

Treasury guidance includes cyber liability among TRIA-eligible lines, but your cyber policy may exclude acts of terrorism entirely, or your property policy may exclude cyber perils. A cyberattack that takes down your payment systems could fall into neither bucket. Get explicit confirmation from your insurer(s) in writing about which policy responds to a state-sponsored cyberattack certified as terrorism.

4. Identify any nuclear, biological, chemical, or radiological (NBCR) exclusions.

These exclusions appear in many commercial property forms and would block coverage even if TRIA certification occurs. NBCR events could produce some of the largest terrorism losses, yet your private policy may cap or eliminate coverage before the federal backstop applies. Create a schedule showing which policies contain NBCR exclusions and what your residual exposure is.

5. Review whether your workers' compensation policy includes terrorism coverage automatically.

Most workers' compensation policies include terrorism without a separate charge, but confirm this in writing. If your workforce is concentrated in high-profile locations or near critical infrastructure, document whether your limits adequately cover a mass-casualty event. A memo from your workers' comp carrier confirming terrorism is covered and stating the per-occurrence limit is ideal.

6. Check if your lender or lessor requires terrorism coverage and at what limit.

Financing agreements often mandate terrorism insurance as a condition of underwriting. If you've let coverage lapse or reduced limits, you may be in breach. A compliance matrix showing each lender's terrorism requirement and your current policy limit, with no gaps, is essential.

7. Map your Contingent Business Interruption exposures to terrorism scenarios.

If your revenue depends on a supplier, utility, or transportation hub, a terrorism event that doesn't damage your property could still trigger a business interruption claim. Verify whether your policy's contingent coverage extends to certified terrorism. List your top five contingent dependencies and confirm that terrorism-related disruption at those sites would trigger coverage.

8. Confirm how "certification" works under your policy's terrorism definition.

TRIA requires the Secretary of the Treasury, in concurrence with the Secretary of State and Attorney General, to certify an event. But your policy may use different language or impose additional conditions. Compare your policy's terrorism definition with the TRIA statutory definition, highlighting any differences.

9. Document any sub-limits or separate deductibles that apply to terrorism claims.

Some policies apply a separate, higher deductible for terrorism or cap certain coverages (like business interruption) below the main policy limit. Create a table showing your standard deductible, your terrorism deductible, and any sub-limits that would reduce your recovery.

10. Verify that your broker has reviewed your terrorism coverage in the last 12 months.

If no one has walked through these questions with you recently, you're relying on assumptions. Since no TRIA claims have ever been paid, many businesses assume the risk is remote or already fully covered. Meeting notes or an email from your broker summarizing your current terrorism limits, exclusions, and any recommended changes are crucial.

Common Mistakes

Assuming TRIA creates coverage where none exists. The federal backstop only reimburses insurers after they've paid claims under valid policies. If your policy excludes the peril, TRIA doesn't override that exclusion.

Treating terrorism as a single risk. Domestic terrorism, cyberterrorism, and infrastructure attacks each trigger different policy sections and exclusions. Assess all three.

Ignoring attribution challenges in cyberterrorism scenarios. A cyberattack must still satisfy TRIA's statutory definition and certification process. Attribution to a terrorist group isn't automatic, and delays could complicate claims.

Relying on outdated coverage elected years ago. Your exposure changes as you add locations, grow revenue, and adopt new technologies. Your terrorism limits should change with it.

Next Steps

Once you've completed this checklist, you'll have a documented record of your terrorism coverage and any gaps. Share it with your executive team, your lender, and your business continuity planning group.

If you found gaps, your broker can request quotes for higher limits, separate terrorism policies, or endorsements that close specific exclusions. If you found that cyberterrorism isn't clearly covered, consider whether a Stand-Alone Cyber Policy with affirmative terrorism coverage makes sense.

Don't wait for reauthorization debates or a near-miss event to discover you're underinsured. The federal backstop exists, but it only works if your private policies do their job first.

Terrorism Risk Insurance Program

Application Security Isn’t Optional Anymore.

You Might Also Like