Bricking Coverage
Bricking coverage is an optional feature in some cyber insurance policies that helps pay to replace or restore physical devices that a cyberattack has rendered unusable, effectively turning them into a 'brick.' It addresses situations where hardware such as computers or connected devices no longer functions after an attack, sometimes because the device's low-level software (firmware) has been corrupted. Whether any given loss is covered depends on the specific policy wording, endorsements, and exclusions.
Bricking coverage is a first-party cyber insurance enhancement, typically added by endorsement, that responds to the cost of replacing or restoring physical devices rendered inoperable as a result of a covered cyber event. 'Bricking' refers to a device becoming unusable, in some cases through corruption of the firmware or other low-level software on which the device depends to function. Coverage commonly extends to the cost of replacing hardware that cannot be restored, and may address a range of affected devices, but the scope, sublimits, and applicable conditions and exclusions vary by insurer form and specific policy wording. This coverage is distinct from third-party liability coverages and from data restoration coverage, and it does not by itself reduce the likelihood of an attack; it is a risk-transfer mechanism, not a resilience control. The precise triggers and whether firmware corruption, failed updates, or other causes fall within scope depend on the individual policy language.
Why it matters
Standard cyber insurance has historically focused on intangible losses such as data restoration, business interruption, and liability to affected third parties. Bricking coverage addresses a gap that these coverages may leave open: the physical hardware itself. When a cyberattack renders a device permanently unusable, sometimes by corrupting the firmware or other low-level software on which it depends to function, the affected organization may face the cost of replacing that hardware outright. Without a specific grant of coverage for this exposure, an insured could find that its policy responds to the lost data or the operational downtime but not to the cost of the physical devices that have been turned into 'bricks.'
The relevance of this coverage has grown as organizations depend on larger populations of connected devices, any of which could be affected by an attack. The cost implications are a function of how many devices are involved and whether they can be restored or must be replaced entirely, though the actual financial impact in any given event depends on the circumstances and is not something that can be generalized. Because bricking coverage is typically offered by endorsement rather than as a standard part of the base form, whether an organization carries it at all is a deliberate purchasing decision that risk managers and brokers must weigh.
It is important to keep this coverage in perspective as a risk-transfer mechanism. Bricking coverage does not reduce the likelihood that an attack will occur, and it is not a substitute for resilience measures such as maintaining spare hardware, tested recovery procedures, or firmware integrity controls. It helps pay for a loss after the fact; it does not prevent the loss. Whether any specific bricking event is covered depends on the policy wording, applicable sublimits, conditions, and exclusions.
Who it's relevant to
Inside Bricking Coverage
Common questions
Answers to the questions practitioners most commonly ask about Bricking Coverage.