Unencrypted Device Exclusion
An unencrypted device exclusion is a clause in a cyber insurance policy that removes or limits coverage for losses arising from a device that was not encrypted at the time of an incident, such as a lost or stolen laptop or portable drive. Encryption is the process of encoding information so that only authorized persons can read it, and it is commonly used to protect confidential or legally protected data. Whether such an exclusion applies to a given claim depends on the specific policy wording, so an affected loss may or may not be covered.
An unencrypted device exclusion is a policy provision that operates to bar or restrict indemnity where a loss event involves a device on which encryption controls were absent, disabled, or improperly configured at the time of the event. In practice a device may be treated as unencrypted where an encryption-on policy has not been applied, where a management or reporting agent shows the device as not encrypted, or where encryption was intentionally excluded from certain assets (for example external drives excluded from full-disk encryption via administrative policy). The exclusion is conditional and its reach turns on the precise wording, applicable endorsements, and any conditions precedent regarding security controls; it may be framed as an outright exclusion, a coverage condition, or a warranty. Its application can bear on both first-party heads of loss (such as the insured's own data restoration or breach response costs) and third-party liability (such as privacy claims following unauthorized disclosure of data on the device), but the effect in each case depends on the specific policy. This entry does not address any particular insurer form or the technical adequacy of any specific encryption standard; note that terms such as 'unencrypted' and the threshold for approved encryption are defined variably across standards bodies and vendor tooling.
Why it matters
An unencrypted device exclusion can determine whether an otherwise valid claim is paid at all. Lost and stolen devices remain a common source of data exposure, and encryption is widely regarded as a baseline control for protecting confidential and legally protected data. Where a policy contains this exclusion, an insured that suffers a breach involving an unencrypted laptop or portable drive may find that both its own response costs and any liability to affected individuals fall outside coverage. Because the clause can be drafted as an outright exclusion, a coverage condition, or a warranty, the difference in wording can be the difference between full indemnity and no recovery.
The practical difficulty is that whether a device is treated as 'encrypted' is not always straightforward. Management tooling may report a device as 'not encrypted' where an encryption-on policy has been deployed but not yet applied, and reporting agents that fail to check in can misrepresent an encrypted device as unencrypted. Organizations may also deliberately exclude certain assets, such as external drives, from full-disk encryption through administrative policy. Each of these situations can create a gap between the insured's understanding of its own control posture and the state an insurer relies on when applying the exclusion.
Because the threshold for 'approved' or adequate encryption is defined variably across standards bodies and vendor tooling, disputes can arise over whether a control that was technically present satisfied the policy. This makes the exclusion a point of genuine attention for anyone relying on cyber insurance as part of risk transfer, particularly given that insurance does not reduce the likelihood of a device being lost or stolen and does not by itself constitute a resilience or data-protection program.
Who it's relevant to
Inside Unencrypted Device Exclusion
Common questions
Answers to the questions practitioners most commonly ask about Unencrypted Device Exclusion.