Hostile Act Exclusion
A hostile act exclusion is a provision in an insurance policy that removes coverage for losses caused by war or warlike actions between nations or comparable actors. It exists because insurers have historically treated damage from such conflict as outside the scope of what they are willing to cover. Whether a particular loss falls within this exclusion depends heavily on the specific policy wording and how terms like 'hostile' and 'warlike' are interpreted.
The hostile act exclusion (often appearing as, or alongside, the war exclusion clause) is a longstanding exclusionary provision found in property, general liability, and increasingly cyber-related insurance forms that bars recovery for loss or damage proximately caused by war or 'hostile or warlike' action between sovereign or quasi-sovereign parties. Its rationale rests on insurers' traditional inability to price and absorb catastrophic, correlated losses arising from armed conflict. Application turns on the specific policy language and jurisdictional interpretation, including whether cyber operations attributed to state or state-sponsored actors qualify as 'hostile or warlike' acts, an area of active dispute given the historical framing of these exclusions around traditional armed conflict. Scope boundaries, the meaning of 'hostile' versus 'warlike,' and attribution requirements are not uniformly defined across insurer forms and have been the subject of contested litigation. This entry describes the exclusion as a coverage-limiting term and does not assert how any particular claim would be resolved.
Why it matters
The hostile act exclusion sits at the center of one of the most consequential coverage disputes in modern insurance: whether losses from state-sponsored cyber operations fall inside or outside the reach of a clause originally written with traditional armed conflict in mind. For insureds, the difference is stark. A single exclusion applied broadly can convert what a policyholder assumed was a covered cyber event into an uninsured catastrophe, while a narrow reading preserves the protection the buyer believed they had purchased. Because these exclusions have been standard in property and general liability forms for decades, they were not necessarily drafted with cyber incidents in view, which is precisely why their application to cyber claims is contested.
The stakes are heightened by the correlated, catastrophic nature of the losses insurers seek to exclude. The traditional rationale for the exclusion rests on insurers' inability to price and absorb the accumulated damage that armed conflict between nations can produce simultaneously across many insureds. When a cyber operation is attributed to a state or state-sponsored actor, insurers may argue that the same accumulation concern applies, while policyholders may argue that the historical framing of 'hostile or warlike' action was directed at conventional warfare rather than digital operations. This tension has produced litigation, including disputes arising from the Merck coverage matter, in which courts have examined whether the words 'hostile' and 'warlike' extend to cyber events.
For anyone relying on cyber insurance as a component of risk transfer, the exclusion is a reminder that coverage is conditional on wording. Insurance does not reduce the likelihood of a state-sponsored attack and does not by itself constitute resilience; an exclusion that removes coverage for the very scenario an organization most fears can leave a substantial gap that must be understood before an incident, not discovered after one.
Who it's relevant to
Inside Hostile Act Exclusion
Common questions
Answers to the questions practitioners most commonly ask about Hostile Act Exclusion.
