Many risk managers view terrorism risk insurance as a settled issue. The Terrorism Risk Insurance Act (TRIA) has been around since 2002, reauthorized regularly, with its mechanics largely unchanged. However, as the Senate approves an extension through 2034 and the House suggests changes to the certification threshold, this complacency could be costly.
These myths persist because TRIA has operated in the background for so long that few practitioners have experienced an actual certification scenario. The program's stability has led to assumptions that don't align with policy language or the operational reality of coverage triggers. Here's what you need to know.
Myth 1: Any Large-Scale Attack Automatically Qualifies as Terrorism Under TRIA
Reality: Certification requires a formal determination by the Treasury Secretary, with the Secretary of State and the Attorney General's concurrence. The event must meet three criteria: it involves violence or danger to human life, property, or infrastructure; it's committed by someone acting on behalf of a foreign entity; and it's intended to intimidate civilians or influence government policy.
The House bill proposes raising the insured loss threshold from $5 million to $10 million, effective in 2029. This change creates a new floor for losses that even enter the certification discussion. If your exposure is between $5 million and $10 million, you'll face a coverage gap starting in 2029 unless your terrorism endorsements address it.
Certification isn't automatic. Treasury has discretion. While the act of violence might be clear, attributing it to a foreign interest often isn't. If you're relying on TRIA as your primary terrorism backstop, plan for the weeks or months when attribution remains unclear.
Myth 2: TRIA Covers All Terrorism, Including Domestic Actors
Reality: TRIA requires foreign involvement. An act by a domestic individual or group, no matter how destructive, doesn't qualify. This limitation affects your coverage structure.
Stand-alone cyber policies often include cyber extortion coverage, but if the extortion is linked to a physical terrorism event, check if your property and casualty policies exclude domestic terrorism. Many commercial policies do. If you assume TRIA fills all terrorism gaps, you're mistaken. Domestic terrorism requires separate coverage, which is often expensive or unavailable in high-risk sectors.
When reviewing your program, map out scenarios by actor type. Foreign state-backed? TRIA applies if certified. Foreign non-state actor? TRIA applies if certified. Domestic actor? You're on your own unless you've purchased specific domestic terrorism coverage.
Myth 3: The Certification Process Is Quick and Transparent
Reality: Treasury has 90 days to make a certification determination, and historically, the process has been opaque. The House bill requires Treasury to provide notice during the certification process, which would be an improvement, but this hasn't been reconciled with the Senate's reauthorization yet.
For your team, don't wait for certification to activate your response. Business Interruption Coverage and Contingent Business Interruption both start accruing losses immediately. Delaying recovery efforts pending certification lets the clock run on your deductible and potentially your policy limits.
Your incident response plan should include a parallel track: operate as if you'll need to self-fund the response while documenting everything for a potential TRIA claim. This documentation includes loss estimates, attribution evidence, and communications with law enforcement. If certification comes through months later, you'll need a clean record to support your claim.
Myth 4: TRIA Eliminates the Need for Standalone Terrorism Coverage
Reality: TRIA is a federal backstop, not a comprehensive solution. Insurers set their own retention levels, which can be substantial. TRIA only kicks in after the industry aggregate retention is met, and the federal share phases in gradually.
If you're in a high-risk industry or location, your insurer's appetite for terrorism risk might be limited regardless of TRIA. You might face sub-limits, higher deductibles, or outright exclusions for certain attack vectors. Cyber terrorism, in particular, sits in a gray zone. If a foreign actor uses ransomware to disrupt critical infrastructure, is that a TRIA-eligible event? Maybe, but certification would depend on the physical damage and the Treasury's interpretation of "dangerous to property or infrastructure."
Don't assume your property policy's terrorism coverage is identical to your cyber policy's terrorism coverage. Read both. Look for gaps in the attack vectors covered, the loss types included, and the certification requirements.
Myth 5: The Extension to 2034 Means Stability and No Further Changes
Reality: The House and Senate bills still need reconciliation. The $10 million threshold and the Treasury notification requirement are on the table, and both would change how you structure your program.
The terrorism risk landscape is shifting. State-sponsored cyber operations, attacks on supply chains, and hybrid physical-cyber events don't fit neatly into TRIA's 2002 framework. The program was designed for another September 11th, not for a coordinated ransomware campaign against hospitals or a supply chain attack that cascades into physical infrastructure failures.
As the bills move toward reconciliation, watch for how the final language treats cyber-physical attacks. If your organization operates critical infrastructure, you need to know whether a cyber event that causes physical damage would meet TRIA's criteria. The answer isn't clear, and the ambiguity creates risk.
What to Do Instead
Start by pulling your current terrorism coverage from every policy in your program: property, casualty, cyber, and any specialty lines. Map the definitions. Do they all use the same language? Do they all require TRIA certification, or do some provide coverage regardless?
Next, model your exposure under the new $10 million threshold. If you're close to that line, decide whether to increase limits, lower deductibles, or accept the gap. For most mid-market companies, $10 million is a significant loss but not catastrophic. For critical infrastructure operators, it might be a single day of downtime.
Finally, update your incident response plan to account for certification uncertainty. Who's responsible for tracking the Treasury's determination? Who's documenting losses in real time? Who's coordinating with your broker to preserve your claim rights while you're still responding to the event?
TRIA has been stable for two decades, but stability doesn't mean simplicity. The program's reauthorization is a chance to pressure-test your assumptions and close gaps before you need the coverage.




