FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Cyber and technology risk

Cyber exclusions in non-cyber policies

Category: Cyber and technology risk · Reviewed by the Apex broking team · Last reviewed 2026-08-22 · ~4 min read

In short: “Silent” or non-affirmative cyber describes cover for cyber-related loss that a property, liability or marine policy neither clearly grants nor clearly excludes. Since 2019 the London market has systematically removed that ambiguity, so a modern non-cyber policy will normally either exclude cyber loss outright or grant a defined write-back — and the difference between the two is where most coverage gaps now live.

Category: Cyber and technology risk
Also known as: silent cyber, non-affirmative cyber, cyber write-back, affirmative cyber cover
Related concepts: cyber exclusion in PI, cyber insurance, terrorism exclusion

The problem

Traditional property, liability, marine and specialty wordings were drafted long before cyber attack was a mainstream cause of loss. They were not silent because anyone had decided cyber should be covered; they were silent because the question had not been asked. That left insurers with unpriced accumulation risk and left buyers unable to say, before a loss, whether an event such as ransomware halting a production line would be met under the property section, the business interruption section, a standalone cyber policy, or nothing at all.

The market response

Lloyd’s Market Bulletin Y5258, issued in 2019, required that all policies be clear on whether cover is provided for losses caused by a cyber event, so that managing agents either exclude cyber loss or provide affirmative cover for it. Market Bulletin Y5277, issued on 29 January 2020, set out the phased timetable for the remaining classes. First-party property damage came first, from 1 January 2020. A second phase from 1 July 2020 covered classes including accident and health, contingency, space, political risks, crime and property. A third phase from 1 January 2021 brought in aviation, cargo and the liability classes, including directors and officers, employers’ liability, marine liability and professional indemnity. A fourth phase from 1 July 2021 dealt with marine excess of loss, casualty treaty and remaining classes.

Although those requirements were addressed to Lloyd’s managing agents, the effect ran across the whole UK market, because company-market insurers and reinsurers were working through the same accumulation problem at the same time.

What the exclusions look like

There is no single wording, and that is the point. In broad terms you will meet three families. An absolute cyber exclusion removes all loss, damage, liability or expense directly or indirectly caused by or contributed to by a cyber act or cyber incident. A partial exclusion excludes cyber causes but writes back ensuing physical damage from a listed peril such as fire or explosion, so that a cyber attack which starts a fire is still a property claim. A definitional exclusion works by confirming that electronic data is not tangible property and that loss of use, corruption or reduction in functionality of data is not physical damage, which removes cyber loss from the insuring clause rather than from an exclusion list.

Alongside these, most policies now define the terms — cyber act, cyber incident, computer system, data — and the definitions do at least as much work as the exclusion itself.

State-backed attacks

The market then addressed a narrower question inside standalone cyber cover. Lloyd’s Market Bulletin Y5381, dated 16 August 2022, required all standalone cyber-attack policies falling within risk codes CY and CZ to contain a suitable clause excluding liability for losses arising from state-backed cyber-attacks, at inception or renewal from 31 March 2023. The bulletin required such clauses, as a minimum, to exclude losses arising from a war whether declared or not if the policy did not have a separate war exclusion; to exclude losses arising from state-backed cyber-attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state; to set out whether cover excluded computer systems located outside any state affected; and to set out a robust basis on which the parties agree how any state-backed cyber-attack will be attributed to one or more states.

The result is that the standalone cyber market, which is where affirmative cover was pushed, itself carries a defined war and state-attack boundary. Buyers who assumed that moving cyber exposure out of the property tower and into a cyber policy eliminated the question will find it has been relocated rather than removed.

Where the gaps sit

Four gaps recur. Between a property policy that excludes cyber causes and a cyber policy that covers data and network interruption but not physical damage. Between a liability policy that excludes cyber and a cyber policy whose third-party section is limited to privacy and network security liability. Between a professional indemnity policy and a cyber policy where a client’s loss flows from both a professional failing and a security failing — the boundary discussed in PI versus cyber insurance. And between the war and state-attack wordings in the cyber policy and the terrorism and war wordings elsewhere in the programme.

What to check

Ask for the cyber exclusion wording from every policy in the programme, not just the cyber policy, and lay them side by side. Confirm whether any physical damage write-back exists and which perils it names. Confirm how each policy treats data. Confirm the state-backed attack wording in the cyber policy and how attribution is decided. Then map a small number of realistic scenarios — ransomware halting operations, a supplier outage, a destructive attack causing plant damage — against the whole programme rather than one policy at a time. That mapping exercise is where the value is; the individual wordings rarely surprise anyone once they are read together.

Frequently asked questions

Does my property policy cover a cyber attack?

Modern wordings say so one way or the other. Most exclude cyber causes, some write back ensuing physical damage from named perils such as fire or explosion. The exclusion and its definitions have to be read together.

What did Lloyd’s require about state-backed cyber attacks?

Market Bulletin Y5381 of 16 August 2022 required standalone cyber-attack policies in risk codes CY and CZ, at inception or renewal from 31 March 2023, to exclude state-backed cyber-attacks that significantly impair a state’s ability to function or its security capabilities, and to set out how attribution would be decided.

Does buying standalone cyber close the gap?

It closes the silence, not necessarily the gap. Standalone cyber carries its own war and state-attack boundary, and its own treatment of physical damage, so the programme still has to be read as a whole.

Related entries


This entry is part of the Apex Insurance Wiki. Position stated as at August 2026. Last reviewed 2026-08-22. Next review: 2027-02-22. It is general insurance information, not legal advice, and not regulated advice on a specific policy.

Map the cyber scenarios across the whole programme
Silent cyber is gone. What replaced it is a set of boundaries that only make sense read side by side. Bristol-based, FCA-regulated, wordings first.
Call 0117 325 0027  info@apexinsurancebrokers.co.uk

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.

Want a broker to look at your commercial cover?
If you have your renewal pack, Statement of Fact or schedule, send it over and we’ll come back with options — no forms to fill in. Arranging cover for the first time? That works too. Or call 0117 325 0027.
Start a commercial quote →
Larger or multi-site risk? We’ll come and see you.
Get a quote →