Skip to main content
Category: Policy Exclusions

Unencrypted Device Exclusion

Also known as: Encryption Exclusion, Lost or Stolen Device Encryption Exclusion
Simply put

An unencrypted device exclusion is a clause in a cyber insurance policy that removes or limits coverage for losses arising from a device that was not encrypted at the time of an incident, such as a lost or stolen laptop or portable drive. Encryption is the process of encoding information so that only authorized persons can read it, and it is commonly used to protect confidential or legally protected data. Whether such an exclusion applies to a given claim depends on the specific policy wording, so an affected loss may or may not be covered.

Formal definition

An unencrypted device exclusion is a policy provision that operates to bar or restrict indemnity where a loss event involves a device on which encryption controls were absent, disabled, or improperly configured at the time of the event. In practice a device may be treated as unencrypted where an encryption-on policy has not been applied, where a management or reporting agent shows the device as not encrypted, or where encryption was intentionally excluded from certain assets (for example external drives excluded from full-disk encryption via administrative policy). The exclusion is conditional and its reach turns on the precise wording, applicable endorsements, and any conditions precedent regarding security controls; it may be framed as an outright exclusion, a coverage condition, or a warranty. Its application can bear on both first-party heads of loss (such as the insured's own data restoration or breach response costs) and third-party liability (such as privacy claims following unauthorized disclosure of data on the device), but the effect in each case depends on the specific policy. This entry does not address any particular insurer form or the technical adequacy of any specific encryption standard; note that terms such as 'unencrypted' and the threshold for approved encryption are defined variably across standards bodies and vendor tooling.

Why it matters

An unencrypted device exclusion can determine whether an otherwise valid claim is paid at all. Lost and stolen devices remain a common source of data exposure, and encryption is widely regarded as a baseline control for protecting confidential and legally protected data. Where a policy contains this exclusion, an insured that suffers a breach involving an unencrypted laptop or portable drive may find that both its own response costs and any liability to affected individuals fall outside coverage. Because the clause can be drafted as an outright exclusion, a coverage condition, or a warranty, the difference in wording can be the difference between full indemnity and no recovery.

The practical difficulty is that whether a device is treated as 'encrypted' is not always straightforward. Management tooling may report a device as 'not encrypted' where an encryption-on policy has been deployed but not yet applied, and reporting agents that fail to check in can misrepresent an encrypted device as unencrypted. Organizations may also deliberately exclude certain assets, such as external drives, from full-disk encryption through administrative policy. Each of these situations can create a gap between the insured's understanding of its own control posture and the state an insurer relies on when applying the exclusion.

Because the threshold for 'approved' or adequate encryption is defined variably across standards bodies and vendor tooling, disputes can arise over whether a control that was technically present satisfied the policy. This makes the exclusion a point of genuine attention for anyone relying on cyber insurance as part of risk transfer, particularly given that insurance does not reduce the likelihood of a device being lost or stolen and does not by itself constitute a resilience or data-protection program.

Who it's relevant to

Risk managers and insurance buyers
Risk managers relying on cyber insurance as a form of risk transfer should identify whether their policy contains an unencrypted device exclusion and understand whether it is drafted as an exclusion, a condition, or a warranty. Because insurance does not reduce the likelihood of a device being lost or stolen, this clause is a point at which expected recovery can quietly disappear, and its presence should inform how the organization prioritizes encryption as a mitigation control alongside its coverage.
CISOs and security teams
Security leaders should be aware that a device's reported encryption status can diverge from its actual state, for example, where an encryption-on policy has been deployed but not yet applied, where a reporting agent fails to check in, or where assets such as external drives are deliberately excluded from full-disk encryption. These discrepancies can affect how an insurer applies the exclusion, so accurate encryption inventory and reporting matter beyond their security value.
Underwriters and brokers
Underwriters use encryption-related exclusions, conditions, and warranties to manage exposure tied to lost or stolen devices, while brokers must explain to insureds how each drafting approach affects coverage and what evidence of encryption may be required at claim time. Both should account for the fact that 'unencrypted' and approved-encryption thresholds are defined variably across standards and tooling, which is a recognized source of dispute.
Legal and compliance professionals
Legal and compliance teams should assess how the exclusion interacts with data-protection obligations, since a device involved in a breach may trigger notification duties regardless of coverage. They should also scrutinize the precise wording and any conditions precedent, because whether an affected loss is covered depends on the specific policy language and applicable jurisdiction.

Inside Unencrypted Device Exclusion

Exclusionary trigger
An unencrypted device exclusion is a policy provision that typically bars or limits coverage for losses arising from the loss, theft, or compromise of a device (such as a laptop, mobile phone, portable drive, or backup media) that was not encrypted at the time of the incident. Whether it applies depends on the specific wording, and some forms limit the bar only to losses caused by the lack of encryption rather than all losses involving the device.
Scope of affected coverage
The exclusion can affect both first-party coverages (for example, the insured's own data restoration or business interruption costs tied to the lost device) and third-party coverages (for example, privacy liability or regulatory defense arising from unauthorized access to personal data on the device). The exact reach depends on how the endorsement is drafted and which coverage parts it references.
Definition of encryption
Policies may or may not define what qualifies as encryption, including standards, algorithms, or the state of the device (at rest versus in transit). Absent a clear definition, disputes can arise over whether partial encryption, weak encryption, or an unlocked-but-encrypted device satisfies the requirement. The meaning is not standardized across insurer forms.
Relationship to conditions and warranties
Encryption obligations may appear as an exclusion, as a condition precedent, or as a warranty in the application or policy. These are legally distinct mechanisms with different consequences for coverage, so the label and placement of the requirement matters when assessing its effect.
Interaction with other exclusions
An unencrypted device exclusion may overlap or interact with failure-to-maintain-standards exclusions and with representations made in the application about security controls. How these provisions combine is subject to the specific wording and applicable jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Unencrypted Device Exclusion.

Does an unencrypted device exclusion mean any breach involving a lost or stolen device is automatically denied?
No. The exclusion typically applies only where the loss arises from a device that was unencrypted at the time of the incident, and even then its reach depends on the specific wording. Many losses in a breach event stem from causes unrelated to device encryption, and those may still be covered subject to other policy terms, exclusions, and conditions. Whether a particular claim is barred turns on the causal link the policy requires between the unencrypted device and the loss, so the exclusion is conditional rather than a blanket denial.
Is encrypting devices a substitute for having cyber insurance, since encryption seems to remove the exposure the exclusion addresses?
No. Encryption is a risk mitigation control that reduces the likelihood or impact of certain losses, while insurance is a risk transfer mechanism that responds to losses after they occur. Encrypting devices may help you avoid triggering this particular exclusion, but it does not address the many other loss scenarios a cyber policy may respond to, and it does not by itself constitute resilience. The two serve different functions and are generally complementary rather than interchangeable.
How can we tell whether our policy contains an unencrypted device exclusion and how broadly it applies?
Review the policy form and any endorsements for exclusionary language referencing encryption, portable devices, or lost or stolen hardware, and read it alongside the definitions and conditions sections. Pay attention to the causal wording, such as whether the exclusion applies to losses 'arising from,' 'directly resulting from,' or 'to the extent caused by' an unencrypted device, because that phrasing materially affects scope. Because wording varies across insurers and forms, a broker or coverage counsel can help interpret how a specific version would apply to your exposures.
What can an organization do to reduce the risk that this exclusion is invoked?
Common approaches include implementing and documenting encryption across in-scope devices, maintaining asset inventories that record encryption status, and enforcing encryption through technical controls rather than relying on policy alone. Keeping evidence of these measures can be relevant if an insurer questions the encryption state of a device at the time of a loss. Whether such steps prevent the exclusion from applying still depends on the exclusion's wording and the facts of the incident, so mitigation efforts reduce but do not eliminate the risk.
How does this exclusion interact with failure-to-maintain-standards exclusions?
Both are conditional provisions that can limit coverage where the insured did not uphold specified security measures, but they operate on different premises. An unencrypted device exclusion focuses specifically on the encryption state of a device, whereas a failure-to-maintain-standards exclusion addresses broader adherence to stated controls or representations. Depending on the wording, a single incident could potentially implicate one, both, or neither. How they overlap or apply cumulatively depends on the specific language of each provision and the facts, so the two should be read together rather than in isolation.
Does the exclusion affect first-party and third-party coverages differently?
It can, depending on how the exclusion is drafted and where it sits in the policy. Some exclusions are written to apply across all coverage parts, potentially affecting first-party items such as data restoration or business interruption as well as third-party items such as privacy liability and regulatory defense. Others may be scoped more narrowly. To understand which coverages are affected, check whether the exclusion is a general exclusion or attached to a specific coverage grant, and review it against the wording of each part.

Common misconceptions

If any device involved in an incident was unencrypted, the entire claim is automatically denied.
Application depends on the specific wording. Some exclusions bar only the portion of loss attributable to the lack of encryption on the affected device, while others are broader. Whether it applies to a given claim also turns on facts, the definition of encryption used, and jurisdiction, so the outcome is conditional rather than automatic.
Encrypting devices is a compliance formality that satisfies the insurer and also makes the organization resilient.
Encryption is a security control that mitigates certain risks; satisfying an exclusion's requirement is a coverage matter, not a measure of resilience. Meeting the encryption condition does not by itself reduce incident likelihood across other vectors, restore data, or constitute business continuity or disaster recovery capability. Risk transfer through insurance and risk mitigation through controls remain distinct.
The exclusion means the same thing across all cyber policies.
Wording is not standardized. Insurers may draft the provision as an exclusion, condition, or warranty, may define encryption differently or not at all, and may scope it to different coverage parts. What the provision covers and excludes must be read from the specific form and endorsements.

Best practices

Read the exclusion's exact wording to determine whether it bars all loss involving an unencrypted device or only loss caused by the absence of encryption, and identify which first-party and third-party coverage parts it touches.
Check whether the policy defines encryption and, if it does not, seek clarification or a definition endorsement to avoid disputes over partial, weak, or at-rest-versus-in-transit encryption.
Confirm whether the encryption requirement is drafted as an exclusion, a condition precedent, or a warranty, since each carries different consequences for coverage, and involve legal or compliance review as needed.
Verify that representations about encryption made in the application are accurate and consistent with actual practice, given the interaction between this exclusion and failure-to-maintain-standards or misrepresentation provisions.
Maintain and evidence an encryption program for portable and mobile devices and backup media as a risk-mitigation measure, recognizing that doing so addresses this exclusion but does not substitute for broader resilience planning.
Assess coverage implications alongside jurisdiction, since how such provisions are interpreted may vary, and document the analysis so risk transfer decisions reflect the conditional nature of the coverage.
Promotional banner for the Penetration Report Template Kit