Affirmative Cyber Coverage
Affirmative cyber coverage refers to insurance policy language that explicitly states whether cyber-related losses are covered or excluded, rather than leaving the question unaddressed. It stands in contrast to 'silent cyber,' where cyber exposures may be unintentionally contained within traditional property and liability policies that do not clearly speak to those risks. The purpose is to give both policyholders and insurers clarity about what is and is not covered when a cyber event occurs.
Affirmative cyber coverage denotes insurance policy wording that expressly grants or excludes coverage for cyber-related losses, providing certainty of intent for both carriers and policyholders. It is defined in opposition to silent (or non-affirmative) cyber, which describes potential cyber exposures embedded within traditional property and liability policies that do not explicitly address cyber perils. The distinction gained prominence after Lloyd's mandated in July 2019 that policies be clear on whether coverage is provided for losses caused by a cyber event. Whether a given cyber loss is ultimately covered still depends on the specific policy wording, endorsements, exclusions, and conditions; affirmative coverage establishes that cyber is deliberately addressed but does not by itself determine the breadth of protection. Affirmative coverage may appear within standalone cyber policies (spanning first-party losses and third-party liability) or as explicit grants or exclusions added to traditional lines, subject to the specific form.
Why it matters
The distinction between affirmative and silent cyber coverage addresses a fundamental problem in risk transfer: uncertainty about whether a cyber loss will actually be paid. When traditional property and liability policies do not explicitly speak to cyber perils, both policyholders and insurers can be exposed to disputes over whether an event triggers coverage. This 'silent cyber' ambiguity creates the risk that a policyholder assumes protection that was never priced or intended, while insurers face aggregation exposure they never deliberately underwrote. Affirmative coverage exists to remove that ambiguity by stating expressly whether cyber-related losses are covered or excluded.
The issue gained regulatory momentum when Lloyd's mandated in July 2019 that policies be clear on whether coverage is provided for losses caused by a cyber event. For risk managers and brokers, this shift means that relying on the possibility of a silent-cyber recovery under a legacy policy form is an increasingly unreliable strategy; the market has moved toward explicit treatment of cyber, whether through affirmative grants or through express exclusions on traditional lines. Understanding which of a program's policies affirmatively address cyber, and which exclude it, is essential to identifying coverage gaps.
It is important to recognize the limits of what affirmative coverage guarantees. Establishing that a policy deliberately addresses cyber does not by itself determine how broad the protection is. Whether a specific loss is ultimately covered still turns on the policy wording, endorsements, exclusions, and conditions. Affirmative coverage resolves the question of intent, not the question of scope, and it does nothing to reduce the likelihood of a cyber incident occurring.
Who it's relevant to
Inside Affirmative Cyber Coverage
Common questions
Answers to the questions practitioners most commonly ask about Affirmative Cyber Coverage.