Skip to main content
Category: Policy Exclusions

Critical Infrastructure Exclusion

Also known as: Critical National Infrastructure Exclusion, Infrastructure Exclusion
Simply put

A critical infrastructure exclusion is a clause in a cyber insurance policy that removes coverage for losses caused by the failure of large-scale public systems that society depends on, such as electrical, satellite, or utility services. If your business suffers a loss because one of these outside systems went down, the policy will commonly not pay for it. It does not reduce the chance of such an event occurring; it only defines what the insurer will and will not cover.

Formal definition

A critical infrastructure exclusion is an exclusionary provision in a cyber insurance policy that carves out losses arising from the failure or disruption of critical (often national) infrastructure external to the insured, commonly including electrical or power grid failure, utility service disruption, satellite failure, and similar large-scale systems. Critical infrastructure in this context refers to the physical or virtual systems and assets so vital that their incapacity or destruction would have a debilitating impact on societal functions such as energy, healthcare, transportation, and water. The exclusion can operate against both first-party recovery (for example, business interruption traceable to an upstream infrastructure failure) and third-party liability, but its precise reach depends on the specific policy wording, defined terms, endorsements, and how the excluded infrastructure is enumerated; some forms list specific systems while others use broader language. Whether a given loss is barred is therefore conditional and subject to the interaction of this exclusion with related exclusions (such as war or systemic-event provisions), conditions precedent, and applicable jurisdiction. This exclusion is a coverage-scope concept and is distinct from critical infrastructure protection (CIP) or resilience programs, which address reducing the likelihood or impact of such failures rather than allocating financial risk.

Why it matters

Modern businesses depend on external systems they neither own nor control, including power grids, telecommunications networks, satellite services, and water and utility providers. When one of these large-scale systems fails, the resulting downtime can cascade into significant losses for organizations far downstream. A critical infrastructure exclusion determines whether a cyber policy responds to those losses, and in many forms it commonly removes coverage for losses traceable to the failure of such external systems. For an insured, this means a business interruption that feels squarely within the spirit of cyber cover may nonetheless fall outside the policy's scope.

The exclusion matters because it can operate at the point of greatest financial stress. First-party losses such as business interruption arising from an upstream power or utility failure, as well as third-party liability, may both be affected depending on wording. Because these events are, by nature, large-scale and potentially systemic, they can coincide with other restrictive provisions such as war or systemic-event exclusions, compounding the uncertainty over whether a claim will be paid. Risk managers who assume broad protection can be surprised to find that a dependency outside their perimeter is precisely what the insurer has carved out.

Crucially, this exclusion is a coverage-scope concept and does nothing to reduce the likelihood or impact of an infrastructure failure. It should not be confused with critical infrastructure protection or resilience planning, which address the operational side of the risk. An organization that relies on insurance alone to manage infrastructure dependency risk may find itself both exposed operationally and unpaid contractually, underscoring why risk transfer and risk mitigation must be evaluated together rather than treated as substitutes.

Who it's relevant to

Risk Managers
Risk managers need to understand where their organization depends on external infrastructure such as power, telecommunications, satellite, and utility services, and whether losses flowing from those dependencies are excluded. Because the exclusion allocates financial risk rather than reducing it, they should evaluate this alongside resilience and continuity measures rather than assuming insurance closes the gap.
Insurance Brokers and Underwriters
Brokers must identify how a given form enumerates or broadly describes excluded infrastructure and explain to clients that coverage is conditional on the specific wording. Underwriters use the exclusion to manage exposure to large-scale, potentially systemic events, and both parties should be alert to how it interacts with war and systemic-event provisions when assessing scope.
Chief Information Security Officers
CISOs should recognize the distinction between this coverage-scope exclusion and critical infrastructure protection or resilience programs, which address reducing the likelihood or impact of failures. Understanding what the policy will not pay for can inform how much investment goes into mitigating external dependency risk operationally.
Resilience and Business Continuity Planners
Because the exclusion may bar recovery for business interruption traceable to upstream infrastructure failure, continuity planners should map external system dependencies and design mitigation, redundancy, and recovery capabilities that do not rely on insurance to absorb these events.
Legal and Compliance Professionals
Legal and compliance teams should scrutinize how the exclusion is drafted, how it interacts with related exclusions and conditions precedent, and how it may be interpreted differently across jurisdictions. Tracing the causal chain of a loss against the precise language is central to assessing whether a claim is likely to be barred.

Inside Critical Infrastructure Exclusion

Scope of Excluded Infrastructure
The exclusion typically identifies categories of critical infrastructure whose failure or disruption falls outside coverage. Depending on the specific wording, this may reference systems such as power grids, telecommunications networks, water utilities, or other services on which the insured depends but does not control. What qualifies as 'critical infrastructure' can be defined differently across insurer forms and jurisdictions, so the precise list in the policy language governs.
Dependency and Causation Language
Many versions of this exclusion turn on whether a loss arises from the failure of external infrastructure rather than the insured's own systems. The wording may address direct dependence (the insured relies on the infrastructure) and how proximate cause is assessed. Whether a given loss is captured depends heavily on how causation is drafted and interpreted, subject to the specific wording.
Interaction with War and Hostile Act Exclusions
Critical infrastructure exclusions sometimes overlap with war, cyber-terrorism, or hostile-act exclusions, particularly where infrastructure disruption is alleged to result from state-sponsored or geopolitical activity. These are distinct exclusions that may apply separately or together, and their interplay is determined by the policy's combined wording and any endorsements.
Affected Coverage Types
The exclusion can bear on both first-party coverages (such as the insured's own business interruption or contingent business interruption arising from an upstream infrastructure outage) and third-party liability coverages. How it applies to each is not uniform and depends on the coverage grant it is attached to and the specific policy language.
Exceptions, Carve-Backs, and Endorsements
Some policies narrow the exclusion through carve-backs or endorsements that restore coverage for defined scenarios, sublimit affected exposures, or add waiting periods. The presence and breadth of any such carve-back is a matter of negotiation and the individual policy wording rather than a market standard.

Common questions

Answers to the questions practitioners most commonly ask about Critical Infrastructure Exclusion.

Does a critical infrastructure exclusion only apply to losses suffered by infrastructure operators themselves?
No. This is a common misconception. The exclusion is typically framed around the cause or source of a loss rather than the identity of the insured. In many policies it is worded to exclude losses arising from disruption to external infrastructure the insured depends on, such as power, telecommunications, or upstream network providers, regardless of whether the insured operates any infrastructure itself. Whether it applies to a given claim depends on the specific wording, the defined scope of 'infrastructure,' and how the causal link to the loss is drafted.
Is a critical infrastructure exclusion the same as a war or hostile act exclusion?
Not necessarily, though they are sometimes confused and can overlap. A critical infrastructure exclusion generally addresses losses stemming from failure or disruption of essential services or systems, which may be triggered by non-hostile causes such as accidental outages or cascading technical failures. A war or hostile act exclusion addresses losses attributable to armed conflict or state-sponsored hostile action. Some incidents, such as an attack on a power grid, could implicate both. Because these exclusions are drafted separately and vary between insurer forms, you should read each on its own terms rather than assuming one subsumes the other.
How can we tell whether a business interruption loss from a third-party outage would fall within this exclusion?
This requires reading the exclusion alongside the coverage grant, subject to the specific wording. Look at how 'critical infrastructure' or the excluded services are defined, whether the exclusion reaches dependent or contingent business interruption arising from external providers, and how proximate cause is treated. A loss triggered by an upstream telecommunications or power failure may be excluded in many forms, but coverage can turn on endorsements, carve-backs, and the causal chain the insurer accepts. Because this is a first-party coverage question, confirm how the business interruption insuring agreement and any waiting period interact with the exclusion.
What should we look for when reviewing this exclusion during placement or renewal?
Review the definition of infrastructure and whether it is enumerated or open-ended, since broad or ambiguous definitions expand the exclusion's reach. Check for carve-backs that preserve coverage for specified scenarios, and note any interaction with dependent business interruption, system failure, or cyber extortion coverages. Compare the wording across competing insurer forms, as this exclusion is not standardized. Clarify how it aligns with war, cyber operation, and infrastructure-related exclusions to avoid gaps or overlapping denials. Involve coverage counsel where the language is ambiguous.
Can a critical infrastructure exclusion be narrowed or negotiated?
In some markets and depending on the risk, insurers may agree to narrow the exclusion, add carve-backs, or provide affirmative coverage for certain dependency scenarios, sometimes subject to a sublimit. Availability of such changes varies by insurer appetite, the insured's risk profile, and market conditions, and there is genuine disagreement among underwriters and brokers about how far these exclusions should extend. Any negotiated language should be documented in the policy through endorsement rather than relied upon through correspondence, and confirmed against the final wording.
How does this exclusion affect our resilience and continuity planning?
Because insurance is a risk-transfer mechanism and does not reduce the likelihood of an outage, an exclusion that may leave infrastructure-dependency losses uninsured is a reason to strengthen mitigation. This includes identifying single points of dependency on power, telecommunications, and upstream providers, and reflecting them in business continuity and disaster recovery planning through measures such as redundancy and defined recovery objectives. Treat any residual exposure the exclusion leaves as retained risk to be managed through resilience and, where appropriate, risk acceptance, rather than assuming the policy will respond.

Common misconceptions

The critical infrastructure exclusion only removes coverage for the infrastructure operators themselves, so an ordinary insured that merely depends on those services is unaffected.
Depending on the wording, the exclusion can reach losses suffered by dependent insureds, for example, business interruption or contingent business interruption stemming from an upstream utility or telecom outage, not only losses of the infrastructure operator. Whether a dependent insured's loss is excluded is subject to the specific dependency and causation language in the policy.
Having cyber insurance means infrastructure-related outages are covered because that is what the policy is for.
Insurance is a risk-transfer mechanism, and this exclusion is one of several conditions that can limit what is transferred. It does not reduce the likelihood of an infrastructure failure and is not a substitute for resilience measures. Coverage for any infrastructure-linked loss depends on the exclusion's wording, applicable carve-backs, other exclusions, and jurisdiction.
The critical infrastructure exclusion and the war exclusion are the same thing.
They are distinct provisions. A critical infrastructure exclusion addresses loss connected to failure or disruption of defined infrastructure regardless of cause, while a war or hostile-act exclusion addresses loss arising from armed conflict or comparable acts. They can overlap where infrastructure disruption is attributed to hostile action, but each applies according to its own wording.

Best practices

Read the exclusion against the definition of 'critical infrastructure' used in your specific policy, and confirm exactly which categories of systems and services are captured rather than assuming a market-standard scope.
Map your organization's key dependencies on external infrastructure (power, telecommunications, cloud, water, and similar) and test each against the exclusion and any contingent business interruption grant to identify potential coverage gaps.
Examine how the exclusion interacts with war, hostile-act, and cyber-terrorism exclusions, since overlapping wording can compound to remove coverage for infrastructure disruptions attributed to geopolitical causes.
Negotiate carve-backs, sublimits, or endorsements where feasible, and document precisely which scenarios any restored coverage does and does not address, subject to the final policy wording.
Distinguish this risk-transfer question from resilience: maintain business continuity and disaster recovery arrangements for infrastructure outages, since the exclusion means insurance may not respond and does not lower the likelihood of an event.
Involve brokers, coverage counsel, and technical resilience staff together when interpreting the exclusion, and confirm how the relevant jurisdiction approaches causation and dependency for excluded infrastructure losses.
Promotional banner for the Pentest Readiness checklist download