State-Backed Cyber-Attack Exclusion
A state-backed cyber-attack exclusion is a clause in a cyber insurance policy that removes coverage for losses caused by cyber-attacks attributed to a nation-state or entities acting on its behalf. In broad terms, it is designed to carve out large-scale or catastrophic attacks tied to government actors, particularly those linked to warlike activity. Whether a given attack falls within the exclusion depends on the specific wording of the clause and how the attack is attributed.
An exclusionary provision, associated with model wordings introduced through the Lloyd's market for cyber policies incepting from March 2023, that restricts cover for losses arising from a 'state backed cyber-attack.' According to the evidence, at a minimum such an exclusion is intended to exclude losses arising from a war (whether declared or not) and losses arising from state backed cyber-attacks that (a) significantly impair the ability of a state to function or (b) significantly impair the security capabilities of a state. Application turns heavily on the specific policy wording, including the definitions of 'state backed' and 'war,' the attribution mechanism used to determine state involvement, and any endorsements or narrowing language negotiated for a particular risk; the evidence indicates several distinct market wordings exist rather than a single uniform clause. Note that the precise operative language, attribution standards, and scope may vary between insurer forms and were not fully reproduced in the available evidence.
Why it matters
Cyber-attacks attributed to nation-states or actors operating on their behalf can produce losses on a scale that insurers treat as potentially catastrophic and difficult to aggregate. State-backed cyber-attack exclusions exist because insurers seek to carve out this category of loss, particularly attacks tied to warlike activity or those that significantly impair a state's ability to function or its security capabilities, from cover that was priced and reserved for more conventional cyber events. For the insured, the practical consequence is that a serious incident could fall outside coverage precisely when losses are largest, so understanding where the exclusion begins and ends is central to assessing what protection a policy actually provides.
The stakes are heightened by the fact that these exclusions are not uniform. The evidence indicates that model wordings were introduced through the Lloyd's market for cyber policies incepting from March 2023, but that several distinct market wordings exist rather than a single standard clause. Whether a given attack is excluded depends heavily on how terms such as 'state backed' and 'war' are defined in the specific policy, and on the attribution mechanism the wording relies on to establish state involvement. Two insureds facing similar incidents could see different coverage outcomes based solely on differences in their policy language.
Attribution is the crux of the uncertainty. Determining that an attack was 'state backed' can be technically and politically contested, and the standard by which attribution is decided, and who decides it, varies between forms and was not fully reproduced in the available evidence. This means an exclusion's real-world effect cannot be judged from its existence alone; it turns on the operative wording, the attribution standard, and the specific facts of an incident. Buyers and their advisers should treat coverage for state-linked events as conditional and clause-dependent rather than assumed.
Who it's relevant to
Inside State-Backed Cyber-Attack Exclusion
Common questions
Answers to the questions practitioners most commonly ask about State-Backed Cyber-Attack Exclusion.
