Skip to main content
Category: Policy Exclusions

State-Backed Cyber-Attack Exclusion

Also known as: State-Sponsored Cyber-Attack Exclusion, Cyber War Exclusion, Nation-Backed Cyberattack Exclusion
Simply put

A state-backed cyber-attack exclusion is a clause in a cyber insurance policy that removes coverage for losses caused by cyber-attacks attributed to a nation-state or entities acting on its behalf. In broad terms, it is designed to carve out large-scale or catastrophic attacks tied to government actors, particularly those linked to warlike activity. Whether a given attack falls within the exclusion depends on the specific wording of the clause and how the attack is attributed.

Formal definition

An exclusionary provision, associated with model wordings introduced through the Lloyd's market for cyber policies incepting from March 2023, that restricts cover for losses arising from a 'state backed cyber-attack.' According to the evidence, at a minimum such an exclusion is intended to exclude losses arising from a war (whether declared or not) and losses arising from state backed cyber-attacks that (a) significantly impair the ability of a state to function or (b) significantly impair the security capabilities of a state. Application turns heavily on the specific policy wording, including the definitions of 'state backed' and 'war,' the attribution mechanism used to determine state involvement, and any endorsements or narrowing language negotiated for a particular risk; the evidence indicates several distinct market wordings exist rather than a single uniform clause. Note that the precise operative language, attribution standards, and scope may vary between insurer forms and were not fully reproduced in the available evidence.

Why it matters

Cyber-attacks attributed to nation-states or actors operating on their behalf can produce losses on a scale that insurers treat as potentially catastrophic and difficult to aggregate. State-backed cyber-attack exclusions exist because insurers seek to carve out this category of loss, particularly attacks tied to warlike activity or those that significantly impair a state's ability to function or its security capabilities, from cover that was priced and reserved for more conventional cyber events. For the insured, the practical consequence is that a serious incident could fall outside coverage precisely when losses are largest, so understanding where the exclusion begins and ends is central to assessing what protection a policy actually provides.

The stakes are heightened by the fact that these exclusions are not uniform. The evidence indicates that model wordings were introduced through the Lloyd's market for cyber policies incepting from March 2023, but that several distinct market wordings exist rather than a single standard clause. Whether a given attack is excluded depends heavily on how terms such as 'state backed' and 'war' are defined in the specific policy, and on the attribution mechanism the wording relies on to establish state involvement. Two insureds facing similar incidents could see different coverage outcomes based solely on differences in their policy language.

Attribution is the crux of the uncertainty. Determining that an attack was 'state backed' can be technically and politically contested, and the standard by which attribution is decided, and who decides it, varies between forms and was not fully reproduced in the available evidence. This means an exclusion's real-world effect cannot be judged from its existence alone; it turns on the operative wording, the attribution standard, and the specific facts of an incident. Buyers and their advisers should treat coverage for state-linked events as conditional and clause-dependent rather than assumed.

Who it's relevant to

Risk managers and insurance buyers
For those procuring cover, the exclusion defines a potential gap between the losses an organization faces and the losses its policy will respond to. Buyers should scrutinize how 'state backed' and 'war' are defined, understand the attribution mechanism in their specific wording, and consider whether any narrowing endorsements are available or appropriate for their risk profile. Because the exclusion can bite hardest in the most severe scenarios, it is a central factor in evaluating whether the policy meets the organization's risk transfer objectives.
Brokers and underwriters
Brokers must be able to explain that these clauses are not standardized and that several distinct market wordings exist, so comparing forms on the basis of price or headline cover alone can mislead clients. Underwriters apply the exclusion as part of managing aggregation and catastrophic exposure and rely on its definitions and attribution provisions to delineate the boundary of the risk they are accepting. Both sides need clarity on the operative language, which the available evidence notes may vary between insurer forms.
Legal and compliance professionals
Coverage disputes involving these exclusions are likely to focus on definitional and attribution questions, whether an attack was 'state backed,' whether it meets thresholds such as significantly impairing a state's ability to function or its security capabilities, and who bears the burden of establishing attribution. Legal advisers reviewing policy wordings should flag ambiguity in these definitions and note that outcomes may differ across forms and jurisdictions, since the precise attribution standards and scope were not fully reproduced in the available evidence.
CISOs and resilience planners
The exclusion is a reminder that insurance is risk transfer, not risk mitigation, and that a policy may not respond to a catastrophic state-linked event. It does not reduce the likelihood of an attack or substitute for controls, incident response, and business continuity planning. Resilience leaders should factor the possibility of uninsured state-backed loss into their planning assumptions rather than treating insurance as a guaranteed backstop for nation-state scenarios.

Inside State-Backed Cyber-Attack Exclusion

War exclusion lineage
State-backed cyber-attack exclusions typically evolve from traditional war and hostile-act exclusions found across many insurance lines. Insurers adapted this longstanding concept to address losses arising from cyber operations conducted by, on behalf of, or attributable to a nation-state, rather than relying solely on legacy war wording that predates cyber risk.
Attribution mechanism
A central element is how the policy determines that an attack is state-backed. Wording varies: some clauses reference formal attribution by a government or authoritative body, others allow the insurer to rely on objective evidence, and some leave attribution to be established by the parties. Because reliable, timely attribution of cyber-attacks is technically and politically difficult, this component is often the most contested part of the exclusion.
Scope of excluded acts
The exclusion defines which activities fall within it, for example, cyber operations amounting to war, operations occurring during declared or undeclared hostilities, or operations that significantly impair a state's functioning. The precise language determines whether a given incident is captured, and definitions differ materially across insurer forms.
Carve-backs and exceptions
Some exclusions include carve-backs that preserve cover for certain scenarios, such as bystanding or collateral impact on an insured not directly targeted, or attacks below a defined threshold of severity. The presence, wording, and conditions of any carve-back strongly affect how much protection remains.
Coverage lines affected
The exclusion can apply to both first-party cover (such as the insured's own business interruption or data restoration costs) and third-party cover (such as liability to others), depending on the policy. Whether a specific loss is excluded is subject to the specific wording and any endorsements, and should not be assumed uniform across coverage sections.
Burden of proof and conditions
Policies commonly address which party must establish that the exclusion applies and what evidentiary standard is used. This procedural component interacts with jurisdiction and applicable law, and can determine the practical outcome of a disputed claim even where the substantive wording is similar.

Common questions

Answers to the questions practitioners most commonly ask about State-Backed Cyber-Attack Exclusion.

Does a state-backed cyber-attack exclusion mean any attack traced to another country is automatically uncovered?
No. A state-backed or state-sponsored exclusion does not operate as a blanket denial for anything with a foreign origin. Whether the exclusion applies depends on the specific wording, which typically sets conditions such as attribution requirements, the involvement of a nation-state or those acting on its behalf, and sometimes a defined level of impact. Many attacks originate abroad or use foreign infrastructure without meeting the definitional threshold of state backing in the policy. The exclusion is conditional and must be read against its defined terms, any carve-backs, and the applicable jurisdiction rather than assumed to bar all cross-border incidents.
Is a state-backed cyber-attack exclusion the same as a traditional war exclusion?
Not necessarily. Although both concern hostile acts by or on behalf of states, they are distinct clauses that can appear separately or together in a policy. Traditional war exclusions were drafted with kinetic conflict in mind, and questions have arisen about how well that language maps onto cyber events. State-backed cyber-attack exclusions are generally more recent formulations intended to address attribution and nation-state involvement specifically in a cyber context. The scope, defined terms, attribution mechanisms, and any exceptions differ by form, so the two should not be treated as interchangeable; the operative language of each clause governs.
How is attribution to a nation-state typically established under this exclusion?
The method depends on the specific wording. Some forms reference attribution by a government body of the state in which the affected system is located or where the insured operates, while others may allow the insurer to make a reasonable determination based on available evidence when a government has not formally attributed the attack. Because formal government attribution can be slow, incomplete, or absent, the attribution mechanism is often a point of negotiation and potential dispute. Insureds should identify precisely who decides, on what evidentiary standard, and what happens if attribution is contested or unresolved, subject to the policy language and jurisdiction.
What should an insured review in the wording before relying on cyber coverage against this exclusion?
Read the exclusion together with its definitions and any carve-backs. Key items typically include how 'state-backed,' 'cyber operation,' or similar terms are defined; whether there is a distinction between attacks during a state of armed conflict and those outside it; whether widespread or systemic events are separately addressed; the attribution mechanism and who invokes it; and any write-backs that preserve coverage in specified circumstances. It is also worth checking how this exclusion interacts with any separate war exclusion and with sublimits or conditions elsewhere in the form. Comparing forms across markets can reveal materially different scope.
How does this exclusion affect first-party versus third-party cyber coverage?
Where it applies, a state-backed exclusion can potentially reach both first-party losses (such as business interruption, data restoration, and cyber extortion costs) and third-party liabilities (such as privacy claims and regulatory defense), depending on how the clause is positioned in the policy and whether it is drafted to apply policy-wide or to specific coverage sections. The practical effect on each category turns on the specific wording. Insureds and brokers should confirm which insuring agreements the exclusion modifies rather than assuming uniform application across all coverages.
Can an insured mitigate the coverage gap created by this exclusion?
Options depend on the market and the individual account. Approaches discussed in practice include negotiating narrower wording or carve-backs, seeking clarity on the attribution standard, and confirming how systemic-event language operates. It is important to recognize that insurance is a risk-transfer tool and does not reduce the likelihood of a nation-state incident; an exclusion narrows the transfer available, so residual exposure may need to be addressed through risk acceptance or through mitigation and resilience measures rather than through coverage alone. Availability and terms of any alternative or supplementary coverage vary by insurer and jurisdiction, and no specific product outcome should be assumed.

Common misconceptions

A state-backed cyber-attack exclusion means any attack traced to a foreign hacker is automatically uninsured.
The exclusion generally turns on whether an attack is attributable to a nation-state under the policy's defined attribution mechanism, not merely on the attacker's location or nationality. Criminal activity by individuals or groups without sufficient state nexus is typically outside the exclusion, though whether coverage responds still depends on the specific wording, attribution standard, and other terms.
All state-backed cyber exclusions are worded the same way, so the effect is consistent across the market.
Wording varies materially between insurer forms in how they define state backing, how attribution is established, which coverage lines are affected, and whether carve-backs apply. Two policies described as excluding state-backed attacks can produce very different outcomes for the same incident, subject to the specific wording and jurisdiction.
The exclusion is purely an insurance issue and has no bearing on an organization's resilience planning.
Insurance is a risk-transfer mechanism, not a substitute for risk mitigation or resilience. Where a state-backed attack falls within an exclusion, the insured may bear the loss regardless of its recovery capabilities, which makes understanding the exclusion relevant to how much residual risk an organization is knowingly accepting and how it invests in mitigation and continuity.

Best practices

Read the full exclusion wording alongside definitions, conditions, and endorsements rather than relying on a summary label, and identify exactly how the policy defines state backing and establishes attribution.
Map which coverage sections the exclusion applies to, distinguishing first-party losses (such as business interruption and data restoration) from third-party liability, since the exclusion may operate differently across them.
Examine any carve-backs or exceptions closely to understand what protection remains, and confirm the conditions and thresholds that must be met for those carve-backs to apply.
Clarify with the broker or insurer which party bears the burden of proving the exclusion applies, the evidentiary standard used, and how attribution disputes would be handled under the governing jurisdiction.
Treat the exclusion as a driver of retained risk and address the gap through risk mitigation, business continuity, and disaster recovery planning rather than assuming insurance will respond.
Compare exclusion wording across competing quotes and at each renewal, since terms vary between insurer forms and can change, and document the residual risk being accepted.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide