Critical Infrastructure Exclusion
A critical infrastructure exclusion is a clause in a cyber insurance policy that removes coverage for losses caused by the failure of large-scale public systems that society depends on, such as electrical, satellite, or utility services. If your business suffers a loss because one of these outside systems went down, the policy will commonly not pay for it. It does not reduce the chance of such an event occurring; it only defines what the insurer will and will not cover.
A critical infrastructure exclusion is an exclusionary provision in a cyber insurance policy that carves out losses arising from the failure or disruption of critical (often national) infrastructure external to the insured, commonly including electrical or power grid failure, utility service disruption, satellite failure, and similar large-scale systems. Critical infrastructure in this context refers to the physical or virtual systems and assets so vital that their incapacity or destruction would have a debilitating impact on societal functions such as energy, healthcare, transportation, and water. The exclusion can operate against both first-party recovery (for example, business interruption traceable to an upstream infrastructure failure) and third-party liability, but its precise reach depends on the specific policy wording, defined terms, endorsements, and how the excluded infrastructure is enumerated; some forms list specific systems while others use broader language. Whether a given loss is barred is therefore conditional and subject to the interaction of this exclusion with related exclusions (such as war or systemic-event provisions), conditions precedent, and applicable jurisdiction. This exclusion is a coverage-scope concept and is distinct from critical infrastructure protection (CIP) or resilience programs, which address reducing the likelihood or impact of such failures rather than allocating financial risk.
Why it matters
Modern businesses depend on external systems they neither own nor control, including power grids, telecommunications networks, satellite services, and water and utility providers. When one of these large-scale systems fails, the resulting downtime can cascade into significant losses for organizations far downstream. A critical infrastructure exclusion determines whether a cyber policy responds to those losses, and in many forms it commonly removes coverage for losses traceable to the failure of such external systems. For an insured, this means a business interruption that feels squarely within the spirit of cyber cover may nonetheless fall outside the policy's scope.
The exclusion matters because it can operate at the point of greatest financial stress. First-party losses such as business interruption arising from an upstream power or utility failure, as well as third-party liability, may both be affected depending on wording. Because these events are, by nature, large-scale and potentially systemic, they can coincide with other restrictive provisions such as war or systemic-event exclusions, compounding the uncertainty over whether a claim will be paid. Risk managers who assume broad protection can be surprised to find that a dependency outside their perimeter is precisely what the insurer has carved out.
Crucially, this exclusion is a coverage-scope concept and does nothing to reduce the likelihood or impact of an infrastructure failure. It should not be confused with critical infrastructure protection or resilience planning, which address the operational side of the risk. An organization that relies on insurance alone to manage infrastructure dependency risk may find itself both exposed operationally and unpaid contractually, underscoring why risk transfer and risk mitigation must be evaluated together rather than treated as substitutes.
Who it's relevant to
Inside Critical Infrastructure Exclusion
Common questions
Answers to the questions practitioners most commonly ask about Critical Infrastructure Exclusion.
