Skip to main content
Category: Policy Exclusions

War Exclusion

Also known as: War Exclusion Clause, Hostile Acts Exclusion, War Risk Exclusion
Simply put

A war exclusion is a provision found in nearly all insurance policies that removes coverage for losses arising from war or warlike actions. In cyber insurance, this can extend to cyber operations that form part of a war, meaning certain losses tied to state-backed or wartime activity may not be paid even if the loss would otherwise be covered. Whether a particular loss falls within the exclusion depends heavily on the specific wording of the clause and the circumstances of the incident.

Formal definition

The war exclusion is a policy provision, present in nearly all insurance policies, that excludes loss arising out of war or warlike actions. These exclusions are typically broad in scope, and reported wordings encompass concepts ranging from 'war' and 'insurrection' to 'military action, whether war is declared or not,' and, in the cyber context, cyber operations that are part of war. Traditionally the exclusion has addressed warlike acts between sovereign states, though wording varies materially across insurer forms and endorsements. As an exclusion, it operates to remove coverage that would otherwise attach; its application is subject to the specific policy wording, applicable endorsements, and the attribution and factual context of the incident. Note that certain regulatory regimes constrain how war-related exclusions may be applied to specific coverages, for example, restrictions on excluding death or disability resulting from war or act of war in some lines, so scope can differ by jurisdiction. This entry addresses the exclusion as a coverage-limiting term and does not evaluate whether any particular cyber incident constitutes 'war' for exclusionary purposes, which remains contested and fact-dependent.

Why it matters

The war exclusion determines whether a loss that would otherwise be covered is actually paid, and in the cyber context this question has become one of the most consequential and contested areas of coverage. Because reported wordings are broad, reaching concepts from "war" and "insurrection" to "military action, whether war is declared or not", and because some cyber policy exclusions now expressly reach cyber operations that are part of war, an insured could suffer a significant cyber loss and find that recovery turns entirely on how the exclusion is worded and how the incident is characterized. This makes the clause a central concern rather than boilerplate to be skimmed past.

Who it's relevant to

Risk managers and insureds
For those buying coverage, the war exclusion defines a boundary of what a policy will and will not pay. Because outcomes depend heavily on wording and on how an incident is characterized, risk managers should review the exact exclusion language, any endorsements that modify it, and how the clause treats state-backed or wartime cyber activity, rather than assuming a broadly worded cyber policy responds to every loss.
Brokers and underwriters
Brokers must be able to compare exclusion wordings across insurer forms, since these vary materially and can produce different results for the same event. Underwriters set the scope of the exclusion and any carve-backs. Both should recognize that whether a given cyber incident falls within the exclusion is fact-dependent and contested, and should avoid representing coverage outcomes as certain.
Legal and compliance professionals
Because scope can differ by jurisdiction, including regulatory constraints on excluding war or act of war for certain coverages such as death or disability in some lines, legal and compliance teams should assess how applicable regimes limit or shape the exclusion's application. They are also positioned to advise on the attribution and characterization questions that determine whether the clause is triggered.
Resilience and incident response planners
The war exclusion is a coverage term, not a resilience control, and it does not reduce the likelihood or severity of a cyber incident. Planners should understand that a loss falling within the exclusion may go unpaid, which is a reason to treat insurance as risk transfer that operates alongside, not in place of, mitigation, continuity, and recovery capabilities.

Inside War Exclusion

Traditional/Hostile Acts Language
Core wording that excludes loss arising from war, whether declared or undeclared, invasion, hostilities, and similar armed conflict between states. Originally drafted with kinetic conflict in mind, its application to cyber events is contested and depends heavily on the specific policy wording and jurisdiction.
Hostile or Warlike Action by a Nation-State
A component often invoked in cyber contexts, addressing acts by or on behalf of a government, sovereign power, or its agents. The central interpretive difficulty is attribution: establishing that a given cyber incident was carried out by, or at the direction of, a nation-state actor to a standard the exclusion requires.
Cyber Operation / State-Backed Attack Carve-Outs
Some insurers have introduced wording specifically addressing state-backed cyber operations, sometimes distinguishing between attacks that impair essential state functions and those with narrower effects. The precise triggers and definitions vary by insurer form and are not standardized across the market.
Attribution Standard
The evidentiary basis the insurer must meet to apply the exclusion, such as reliance on government attribution, reasonable inference, or other criteria stated in the wording. How attribution is defined and who bears the burden materially affects whether a claim is denied.
Collateral or Spillover Damage Provisions
Language addressing losses suffered by parties not directly targeted, for example where malware intended for one target spreads more broadly. Whether such losses fall inside or outside the exclusion is a recognized area of dispute and depends on the specific wording.
Interaction with Coverage Grants
The exclusion operates against both first-party coverages (such as business interruption and data restoration) and third-party coverages (such as privacy liability). Its effect depends on how it is drafted relative to each grant, applicable endorsements, and any conditions precedent.

Common questions

Answers to the questions practitioners most commonly ask about War Exclusion.

Does the war exclusion only apply to declared wars between nations?
No. This is a common misconception. Many war exclusion clauses are drafted to reach beyond formally declared war to encompass hostile acts, warlike operations, and in some wordings state-sponsored or state-attributed cyber activity, whether or not war is formally declared. Whether a given event falls within the exclusion depends on the specific wording, including how terms such as 'hostile,' 'warlike,' or 'sovereign' are defined, and how attribution is established. Some forms narrow the exclusion and others broaden it, so the presence of a war exclusion does not by itself tell you which events are excluded without reading the operative language.
If my policy has a war exclusion, does that mean all nation-state cyberattacks are automatically excluded?
Not necessarily. It is a mistake to assume any attack linked to a nation-state falls outside coverage. The reach of a war exclusion depends on the exact wording, any cyber-specific carve-backs or exceptions, how attribution must be demonstrated, and the burden of proof, which typically rests with the insurer asserting the exclusion. Some forms include exceptions that preserve coverage for certain cyber operations, or limit the exclusion to attacks meeting defined thresholds. Whether a particular state-linked incident is excluded is a wording-and-facts question rather than an automatic outcome, and reasonable underwriters and brokers disagree about how these clauses apply to ambiguous events.
How can I tell how broadly my war exclusion is written?
Review the operative language with a broker or coverage counsel and identify how the clause defines its triggering terms, whether it addresses cyber operations specifically, and whether it contains any carve-backs or exceptions that restore coverage. Note how attribution is to be determined and on whom the burden falls. Because these clauses vary substantially across insurer forms and are not standardized, the only reliable way to assess breadth is to read the specific wording and any related endorsements rather than relying on the general label 'war exclusion.'
What questions should I raise at renewal about the war exclusion?
Consider asking how the exclusion defines hostile or warlike acts, whether it addresses cyber events and state attribution explicitly, what mechanism or evidence governs attribution, on whom the burden of proof sits, and whether any carve-backs preserve coverage for specified scenarios. Ask how the wording interacts with any separate infrastructure or systemic-event exclusions, since these can overlap. Because wordings differ between insurers and can change between renewal cycles, comparing the current and proposed language is prudent.
How does the war exclusion interact with other exclusions in a cyber policy?
A war exclusion may operate alongside other exclusions, such as infrastructure exclusions or failure-to-maintain-standards provisions, and the same incident could potentially implicate more than one. The interaction depends on how each clause is worded and how they are read together within the policy. Because an insurer may assert multiple grounds for declining a claim, it is worth understanding not only the war exclusion in isolation but how it fits with the broader exclusion set and any conditions precedent. Coverage counsel can help assess how these provisions combine for a given fact pattern.
Since attribution of cyberattacks is often disputed, how does that affect application of the war exclusion?
Attribution is frequently uncertain and contested, which is central to how a war exclusion operates in practice. The relevant questions are what standard of attribution the wording requires, what evidence is acceptable, and which party bears the burden of establishing that the exclusion applies, which typically falls to the insurer asserting it. Because technical attribution can be ambiguous and may rely on government or third-party assessments, disputes can arise over whether the threshold is met. This uncertainty is a recognized area of disagreement, and the specific wording determines how it is resolved for a particular claim.

Common misconceptions

The war exclusion only applies to conventional, kinetic warfare and cannot affect a cyber claim.
Insurers have sought to apply war and hostile-acts language to cyber incidents attributed to nation-states, and some forms now include wording drafted specifically for state-backed cyber operations. Whether it applies to a given cyber loss is subject to the specific policy wording and jurisdiction rather than being categorically inapplicable.
If a government publicly blames a country for an attack, the exclusion automatically applies.
Application depends on the attribution standard set out in the wording and on which party bears the burden of proof. A public statement does not by itself satisfy every policy's requirements, and the sufficiency of attribution evidence is a frequent point of dispute.
The war exclusion is standardized, so all cyber policies treat state-sponsored attacks the same way.
War and cyber-operation exclusion language varies across insurer forms, with differing definitions, triggers, and carve-outs. Two policies can reach opposite outcomes on the same incident depending on their specific wording, endorsements, and the governing jurisdiction.

Best practices

Read the exact war and hostile-acts wording in each policy, including any state-backed cyber operation language, and do not assume market-wide uniformity across insurer forms.
Identify the attribution standard the exclusion relies on and determine which party bears the burden of proof, since this materially affects claim outcomes.
Assess how the exclusion interacts with each coverage grant separately, distinguishing first-party losses (such as business interruption and data restoration) from third-party liability (such as privacy and regulatory claims).
Clarify how spillover or collateral damage is treated, particularly for malware not specifically targeting the insured, and negotiate carve-backs where feasible.
Do not treat cyber insurance as a substitute for resilience; the exclusion can leave state-attributed losses uninsured, so pair coverage with mitigation, continuity, and recovery planning.
Engage broker and legal review of exclusion wording before binding, and document how disputed terms and jurisdictional differences could affect a potential claim.
Promotional banner for the Penetration Report Template Kit