How UK Cyber Insurers Differ on War Exclusions
Why war exclusions became the cyber market’s hardest problem
War exclusions are as old as insurance: losses from war between states are considered uninsurable at commercial premiums, and every class excludes them. Cyber strained this settlement because state-linked hacking rarely looks like war. Malware attributed to state actors has repeatedly caused massive losses to ordinary businesses far from any battlefield, and litigation over whether traditional war exclusions caught such losses exposed how poorly drafted the old language was for cyber. The market’s response was to write cyber-specific war and state-backed-attack language — and it is in that new language that insurers now differ.
The Lloyd’s requirements and the market shift
The pivotal intervention came from Lloyd’s of London, which mandated that from 2023 standalone cyber policies written in the market must include suitable clauses excluding losses arising from war, and clearly excluding losses from state-backed cyber attacks that significantly impair the ability of a state to function (or its security capabilities). Lloyd’s required the clauses to be legally reviewed and robust, but did not prescribe a single wording — so a family of model clauses and insurer-specific variants emerged, differing in scope and mechanics. Company-market insurers outside Lloyd’s were not bound by the mandate, but the direction of travel spread widely. The practical consequence for buyers: “war exclusion” now labels a range of meaningfully different clauses, and the label alone tells you little.
The attribution problem: who decides it was a state?
A state-backed-attack exclusion only bites if the attack can be attributed to a state — and attribution in cyberspace is genuinely hard. Wordings answer the question differently. Some give primary weight to whether the government of the affected state formally attributes the attack to another state; some allow the insurer to establish attribution by inference from objectively reasonable evidence where governments stay silent; and they differ on who bears the burden of proof and what happens during the (potentially long) period before attribution is settled — including whether the insurer must pay in the interim. For a policyholder, the attribution mechanics decide how easily an insurer can invoke the exclusion, which makes them one of the most important paragraphs in the clause.
Infrastructure vs target: whose loss is excluded?
A second axis is the relationship between the attack’s target and your loss. Some clauses focus on attacks that impair a state’s essential services — power, water, financial systems, communications — and exclude losses flowing from such attacks even for businesses that were mere collateral damage. Others draw a distinction the buyer should look for: a carve-back preserving cover where the insured’s own systems were not the target, or where the insured was affected only as bystander to an attack on infrastructure elsewhere. Whether you are covered when a state-backed attack on someone else’s infrastructure knocks out your operations is exactly the kind of question two wordings can answer in opposite ways.
Systemic events vs targeted attacks
Beneath the war language sits a broader concern: systemic risk. Insurers can absorb one company’s ransomware incident; a single event simultaneously hitting thousands of insureds threatens the pool itself. Some of the drafting choices in modern war clauses — the focus on attacks impairing state function, on essential infrastructure, on widespread effects — are really systemic-risk controls. Related mechanisms appear elsewhere in cyber wordings too: exclusions or sub-limits for widespread events, and infrastructure exclusions for failures of power or telecommunications networks. When you assess a cyber policy, read the war clause together with these neighbouring provisions; the total systemic carve-out is what matters, not any single clause.
What to check in a cyber wording
Five checks give a fast read on any cyber war clause. First, scope: does it exclude only war-like state action, or state-backed cyber operations generally? Second, attribution: who decides, on what evidence, who bears the burden, and is the insurer obliged to pay pending attribution? Third, the bystander question: is there a carve-back where you were not the target? Fourth, essential infrastructure: how is it defined, and does the exclusion reach losses from infrastructure attacks outside your own state? Fifth, interaction: what do the neighbouring widespread-event and infrastructure clauses take away that the war clause leaves? A broker comparing wordings across the market can score these side by side before you buy.
Frequently asked questions
Do all cyber insurance policies exclude war?
Yes — war exclusions are universal across commercial insurance. What varies in cyber is how each wording treats state-backed cyber attacks short of declared war: the scope of the exclusion, how attribution to a state is established, and whether bystander losses are carved back.
What did Lloyd’s change about cyber war exclusions?
From 2023, Lloyd’s required standalone cyber policies in its market to include robust clauses excluding losses from war and from state-backed cyber attacks that significantly impair a state’s ability to function. It mandated the requirement, not a single wording, so clause language still varies between insurers.
How is a cyber attack attributed to a state?
Wordings differ. Some lean on formal attribution by the government of the affected state; others let the insurer infer attribution from objectively reasonable evidence. Clauses also differ on the burden of proof and on whether claims are paid while attribution remains unresolved.
Am I covered if a state-backed attack on infrastructure hits my business?
It depends entirely on the wording. Some clauses exclude losses flowing from attacks on essential services even for bystanders; others carve back cover where your systems were not the target. This is one of the sharpest differences between current cyber wordings, so check yours specifically.
What else limits systemic cyber losses besides the war exclusion?
Look for widespread-event exclusions or sub-limits and for infrastructure exclusions covering failures of power or telecoms networks. Read these alongside the war clause: the combined effect of all three defines how a policy responds to a large, multi-victim event.
Two quotes are rarely comparing like with like.
Send us your current cyber schedule and wording and we’ll review how it handles war and state-backed-attack exclusions — no obligation. Or call us on 0117 325 0027.
Start a cyber proposal →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952).
