Skip to main content
Category: Policy Exclusions

Hostile Act Exclusion

Also known as: Hostile Acts Exclusion, War Exclusion Clause, War and Hostile Action Exclusion, Hostile or Warlike Action Exclusion
Simply put

A hostile act exclusion is a provision in an insurance policy that removes coverage for losses caused by war or warlike actions between nations or comparable actors. It exists because insurers have historically treated damage from such conflict as outside the scope of what they are willing to cover. Whether a particular loss falls within this exclusion depends heavily on the specific policy wording and how terms like 'hostile' and 'warlike' are interpreted.

Formal definition

The hostile act exclusion (often appearing as, or alongside, the war exclusion clause) is a longstanding exclusionary provision found in property, general liability, and increasingly cyber-related insurance forms that bars recovery for loss or damage proximately caused by war or 'hostile or warlike' action between sovereign or quasi-sovereign parties. Its rationale rests on insurers' traditional inability to price and absorb catastrophic, correlated losses arising from armed conflict. Application turns on the specific policy language and jurisdictional interpretation, including whether cyber operations attributed to state or state-sponsored actors qualify as 'hostile or warlike' acts, an area of active dispute given the historical framing of these exclusions around traditional armed conflict. Scope boundaries, the meaning of 'hostile' versus 'warlike,' and attribution requirements are not uniformly defined across insurer forms and have been the subject of contested litigation. This entry describes the exclusion as a coverage-limiting term and does not assert how any particular claim would be resolved.

Why it matters

The hostile act exclusion sits at the center of one of the most consequential coverage disputes in modern insurance: whether losses from state-sponsored cyber operations fall inside or outside the reach of a clause originally written with traditional armed conflict in mind. For insureds, the difference is stark. A single exclusion applied broadly can convert what a policyholder assumed was a covered cyber event into an uninsured catastrophe, while a narrow reading preserves the protection the buyer believed they had purchased. Because these exclusions have been standard in property and general liability forms for decades, they were not necessarily drafted with cyber incidents in view, which is precisely why their application to cyber claims is contested.

The stakes are heightened by the correlated, catastrophic nature of the losses insurers seek to exclude. The traditional rationale for the exclusion rests on insurers' inability to price and absorb the accumulated damage that armed conflict between nations can produce simultaneously across many insureds. When a cyber operation is attributed to a state or state-sponsored actor, insurers may argue that the same accumulation concern applies, while policyholders may argue that the historical framing of 'hostile or warlike' action was directed at conventional warfare rather than digital operations. This tension has produced litigation, including disputes arising from the Merck coverage matter, in which courts have examined whether the words 'hostile' and 'warlike' extend to cyber events.

For anyone relying on cyber insurance as a component of risk transfer, the exclusion is a reminder that coverage is conditional on wording. Insurance does not reduce the likelihood of a state-sponsored attack and does not by itself constitute resilience; an exclusion that removes coverage for the very scenario an organization most fears can leave a substantial gap that must be understood before an incident, not discovered after one.

Who it's relevant to

Risk managers
Risk managers evaluating cyber and property programs need to identify where a hostile act or war exclusion sits, how broadly it is worded, and whether any cyber-specific carve-backs or affirmative endorsements narrow it. Because insurance is only one part of a risk strategy, they should treat this exclusion as a potential gap in risk transfer that may need to be addressed through negotiated wording, mitigation, or accepted retention rather than assumed away.
Insurance brokers and underwriters
Brokers must place and explain forms where the scope of 'hostile or warlike' action and any attribution standard directly affect what the client is buying, and should flag the unsettled state of the law rather than represent outcomes as certain. Underwriters use the exclusion to manage exposure to correlated, catastrophic conflict-driven losses, and must weigh how their form's language will be interpreted, an area where forms and court readings are not uniform.
Chief information security officers
CISOs should understand that even strong security controls do not change how an exclusion is written or applied. If an organization faces credible risk from state-sponsored actors, the exclusion may bar recovery for exactly that scenario, which makes it important to coordinate with risk and legal colleagues so that security investment and insurance expectations are aligned rather than assumed to overlap.
Legal and compliance professionals
Legal and compliance teams engage directly with the contested interpretation of these clauses, including disputes such as the Merck coverage matter, where courts have examined whether 'hostile' and 'warlike' reach cyber events. They should focus on precise policy wording, attribution requirements, and jurisdictional differences, recognizing that scope boundaries have been the subject of contested litigation and are not settled uniformly.

Inside Hostile Act Exclusion

War and Warlike Operations Language
The core of most hostile act exclusions bars coverage for loss arising from war, invasion, insurrection, or warlike operations by sovereign or quasi-sovereign forces. The precise scope depends on the specific wording, and formulations vary materially across insurer forms.
Hostile or Warlike Action Trigger
Language addressing action by a military, naval, or air force, or by an agent of a government, sovereign, or other authority. Whether an act qualifies as 'hostile' or 'warlike' is frequently contested and turns on facts, wording, and jurisdiction rather than any single fixed definition.
State-Attribution Element
Many formulations require, or are argued to require, that the act be attributable to a nation-state or state-sponsored actor. Attribution in cyber contexts is technically and evidentiarily difficult, which is a central point of dispute in applying the exclusion to cyber events.
Cyber-Specific Carve-Backs or Endorsements
Some policies attempt to clarify how the exclusion applies to cyber operations through endorsements or carve-backs, potentially narrowing or expanding the exclusion. Whether such wording exists and what it says is entirely form-specific and must be read in the individual policy.
Scope Across First- and Third-Party Coverage
A hostile act exclusion, where applicable, can operate against both first-party losses (such as business interruption or data restoration) and third-party coverages (such as liability claims), depending on how the exclusion is positioned within the policy and its stated wording.

Common questions

Answers to the questions practitioners most commonly ask about Hostile Act Exclusion.

Does a hostile act exclusion only apply to declared wars between nations?
No. This is a common misconception. While the exclusion originates from traditional war-risk language, many cyber policy wordings extend the concept beyond formally declared war between sovereign states to include hostilities, warlike operations, and in some forms actions by state-sponsored or nation-backed actors. Whether an incident falls within the exclusion depends on the specific wording, any carve-backs or endorsements, and how terms like 'hostile,' 'warlike,' or 'state-sponsored' are defined in the policy. Because cyber attacks are frequently difficult to attribute, the practical reach of such an exclusion is often contested rather than automatically limited to conventional armed conflict.
If my policy has a hostile act exclusion, does that mean any attack traced to a foreign country is automatically uncovered?
Not necessarily. Attribution to a foreign source is not the same as satisfying the exclusion's wording, and the two should not be conflated. The exclusion typically requires that the loss arise from conduct meeting the policy's definition of a hostile or warlike act, which may involve questions of attribution, the actor's relationship to a state, and the nature of the act. Establishing those elements can be evidentiarily difficult, and the burden and standard of proof, subject to the specific wording and jurisdiction, may rest with the insurer. Some policies also include carve-backs that preserve cover for certain cyber operations even where a state nexus is alleged. Whether a given claim is excluded turns on the precise language, any endorsements, and the facts, rather than on attribution alone.
How can I tell whether a specific hostile act exclusion is broad or narrow?
Read the operative wording alongside any definitions, exceptions, and carve-backs, rather than relying on the clause heading. Points to examine typically include how 'hostile,' 'warlike,' and 'state-sponsored' or 'cyber operation' are defined; whether attribution standards or evidentiary requirements are specified; whether the exclusion is subject to carve-backs that restore cover for particular scenarios; and whether it applies to both first-party losses (such as business interruption or data restoration) and third-party liabilities. Where wording is ambiguous, it is reasonable to seek clarification from the broker or underwriter and to compare the language against other market forms.
What documentation should we keep to support a claim that might face a hostile act exclusion?
Because disputes often center on the nature and origin of an attack, contemporaneous incident records can be relevant. These may include forensic reports, indicators of compromise, timelines of detection and response, and any attribution analysis from internal teams or external responders. Keeping records that show the impact on your own operations (relevant to first-party claims) separately from records relevant to third-party exposures can help, since the exclusion may apply differently across coverage sections. The value of any specific document depends on the policy wording and the facts; this general guidance does not substitute for advice from coverage counsel or your broker on a particular matter.
Should we ask our broker about negotiating carve-backs to a hostile act exclusion at renewal?
Discussing the scope of the exclusion with your broker is a reasonable part of renewal preparation. Areas often explored include whether carve-backs can preserve cover for defined cyber scenarios, how attribution language is framed, and which party bears the burden of proving the exclusion applies. Availability of any given amendment depends on the insurer, the market, and your risk profile, and terms differ across forms; there is genuine variation and disagreement among underwriters and brokers about how these clauses should be structured. Understand what remains excluded after any negotiation, and treat the exclusion as one factor in your overall risk-transfer strategy rather than something insurance alone resolves.
How does a hostile act exclusion fit into our broader resilience planning?
Insurance is a risk-transfer mechanism and does not reduce the likelihood of an attack or by itself constitute resilience. A hostile act exclusion represents a scenario where transfer may not respond, which makes it relevant to risk acceptance and mitigation decisions. Where such an exclusion could leave a material gap, it is prudent to consider mitigation controls and continuity and recovery planning, including your recovery time and recovery point objectives, incident response, and crisis management arrangements, so the organization is not relying solely on a coverage that may be contested or unavailable for a given event. The exclusion should inform, not replace, these resilience measures.

Common misconceptions

A cyberattack traced to a foreign government is automatically excluded as a hostile act.
Application is not automatic. Whether the exclusion bites depends on the specific wording, whether the event meets the policy's definition of a hostile or warlike act, the strength and standard of attribution, any cyber-specific endorsements, and jurisdictional interpretation. These are frequently contested and outcomes vary.
The hostile act exclusion and a general nation-state or infrastructure exclusion are the same thing.
These are distinct clauses that may coexist in a policy with different triggers and scope. A hostile act or war exclusion focuses on warlike or state action, while separate exclusions may address critical infrastructure or other perils. Each must be read on its own wording, and one applying does not mean another does.
If the hostile act exclusion applies, the insured has no risk-management options left.
Insurance is only one form of risk transfer and does not by itself reduce the likelihood of an incident. Where coverage is uncertain due to this exclusion, mitigation, resilience planning, and negotiated policy wording remain relevant. Coverage gaps are a reason to strengthen non-insurance controls, not evidence that nothing further can be done.

Best practices

Read the exact hostile act and war exclusion wording in each policy, including any cyber-specific endorsements or carve-backs, rather than relying on a general understanding of what 'war' exclusions typically say.
Ask the underwriter or broker how the exclusion is intended to interact with cyber events, and confirm what attribution standard, if any, the insurer would apply before declining a claim.
Map the exclusion against both first-party coverages (such as business interruption and data restoration) and third-party coverages (such as liability), since the same clause may affect them differently depending on placement and wording.
Where feasible, negotiate clarifying language or endorsements at renewal to reduce ambiguity about how state-attributed cyber incidents are treated, recognizing that available wording is form- and market-dependent.
Treat any residual coverage uncertainty from this exclusion as a driver for stronger risk mitigation and resilience measures, since insurance does not reduce incident likelihood and is not a substitute for continuity and recovery capability.
Involve legal or coverage counsel when assessing potential state-sponsored incidents, as attribution, wording interpretation, and jurisdiction can materially change whether the exclusion applies.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.