Drive-by Compromise
Drive-by compromise is a type of cyberattack in which malicious code is delivered to a victim's system simply by visiting a compromised or malicious website, often without the user needing to click or download anything. Attackers typically inject harmful code into a legitimate website so that scripts run automatically when a visitor's browser loads the page. This is a security threat concept, not an insurance coverage term; whether losses arising from such an attack are insurable depends entirely on the specific policy wording.
Drive-by Compromise (MITRE ATT&CK Technique T1189) is an initial-access technique in which an adversary gains access to a system through a user's normal web browsing. In a typical sequence, an adversary injects malicious code (for example, scripts) into a legitimate but compromised website; when a targeted user visits the site, the scripts execute automatically to deliver a payload. When the compromised site is chosen to target a specific population of visitors, the activity is commonly described as a strategic web compromise or watering hole attack. This entry describes an adversary technique for framing threat and control discussions; it is distinct from any insurance coverage trigger, and it does not by itself indicate whether resulting first-party or third-party losses would be covered under a given cyber policy.
Why it matters
Drive-by compromise matters because it undermines a common assumption that users must actively click, download, or open an attachment to be infected. Malicious code can execute automatically when a browser loads a compromised page, meaning that ordinary web browsing by employees can become an initial-access vector. This has direct implications for organizational resilience: it raises the importance of browser patching, script controls, network segmentation, and endpoint monitoring, none of which are insurance measures but rather risk-mitigation controls intended to reduce the likelihood of a successful intrusion.
For insurance and risk-transfer purposes, the technique itself is not a coverage trigger. Whether losses flowing from a drive-by compromise, such as first-party costs (for example business interruption, data restoration, or cyber extortion) or third-party liabilities (for example privacy claims or regulatory defense), would be covered depends entirely on the specific policy wording, applicable endorsements, exclusions, and conditions precedent. Some cyber policies impose conditions relating to the maintenance of security standards or patching; an intrusion that exploits an unpatched browser could, subject to the specific wording and jurisdiction, raise questions under a failure-to-maintain-standards exclusion or similar condition. These are wording-dependent questions, not automatic outcomes.
The distinction is important for risk managers and underwriters evaluating exposure. Because strategic web compromise (watering hole) variants can be aimed at a specific population of visitors, the technique can be used in targeted campaigns against particular sectors or organizations. Recognizing the technique helps in framing control discussions and in assessing the adequacy of an organization's mitigation posture, but it does not by itself resolve how any resulting loss would be treated under a given cyber policy.
Who it's relevant to
Inside Drive-by Compromise
Common questions
Answers to the questions practitioners most commonly ask about Drive-by Compromise.
