Cyber exclusions in non-cyber policies
Category: Cyber and technology risk · Reviewed by the Apex broking team · Last reviewed 2026-08-22 · ~4 min read
Category: Cyber and technology risk
Also known as: silent cyber, non-affirmative cyber, cyber write-back, affirmative cyber cover
Related concepts: cyber exclusion in PI, cyber insurance, terrorism exclusion
The problem
Traditional property, liability, marine and specialty wordings were drafted long before cyber attack was a mainstream cause of loss. They were not silent because anyone had decided cyber should be covered; they were silent because the question had not been asked. That left insurers with unpriced accumulation risk and left buyers unable to say, before a loss, whether an event such as ransomware halting a production line would be met under the property section, the business interruption section, a standalone cyber policy, or nothing at all.
The market response
Lloyd’s Market Bulletin Y5258, issued in 2019, required that all policies be clear on whether cover is provided for losses caused by a cyber event, so that managing agents either exclude cyber loss or provide affirmative cover for it. Market Bulletin Y5277, issued on 29 January 2020, set out the phased timetable for the remaining classes. First-party property damage came first, from 1 January 2020. A second phase from 1 July 2020 covered classes including accident and health, contingency, space, political risks, crime and property. A third phase from 1 January 2021 brought in aviation, cargo and the liability classes, including directors and officers, employers’ liability, marine liability and professional indemnity. A fourth phase from 1 July 2021 dealt with marine excess of loss, casualty treaty and remaining classes.
Although those requirements were addressed to Lloyd’s managing agents, the effect ran across the whole UK market, because company-market insurers and reinsurers were working through the same accumulation problem at the same time.
What the exclusions look like
There is no single wording, and that is the point. In broad terms you will meet three families. An absolute cyber exclusion removes all loss, damage, liability or expense directly or indirectly caused by or contributed to by a cyber act or cyber incident. A partial exclusion excludes cyber causes but writes back ensuing physical damage from a listed peril such as fire or explosion, so that a cyber attack which starts a fire is still a property claim. A definitional exclusion works by confirming that electronic data is not tangible property and that loss of use, corruption or reduction in functionality of data is not physical damage, which removes cyber loss from the insuring clause rather than from an exclusion list.
Alongside these, most policies now define the terms — cyber act, cyber incident, computer system, data — and the definitions do at least as much work as the exclusion itself.
State-backed attacks
The market then addressed a narrower question inside standalone cyber cover. Lloyd’s Market Bulletin Y5381, dated 16 August 2022, required all standalone cyber-attack policies falling within risk codes CY and CZ to contain a suitable clause excluding liability for losses arising from state-backed cyber-attacks, at inception or renewal from 31 March 2023. The bulletin required such clauses, as a minimum, to exclude losses arising from a war whether declared or not if the policy did not have a separate war exclusion; to exclude losses arising from state-backed cyber-attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state; to set out whether cover excluded computer systems located outside any state affected; and to set out a robust basis on which the parties agree how any state-backed cyber-attack will be attributed to one or more states.
The result is that the standalone cyber market, which is where affirmative cover was pushed, itself carries a defined war and state-attack boundary. Buyers who assumed that moving cyber exposure out of the property tower and into a cyber policy eliminated the question will find it has been relocated rather than removed.
Where the gaps sit
Four gaps recur. Between a property policy that excludes cyber causes and a cyber policy that covers data and network interruption but not physical damage. Between a liability policy that excludes cyber and a cyber policy whose third-party section is limited to privacy and network security liability. Between a professional indemnity policy and a cyber policy where a client’s loss flows from both a professional failing and a security failing — the boundary discussed in PI versus cyber insurance. And between the war and state-attack wordings in the cyber policy and the terrorism and war wordings elsewhere in the programme.
What to check
Ask for the cyber exclusion wording from every policy in the programme, not just the cyber policy, and lay them side by side. Confirm whether any physical damage write-back exists and which perils it names. Confirm how each policy treats data. Confirm the state-backed attack wording in the cyber policy and how attribution is decided. Then map a small number of realistic scenarios — ransomware halting operations, a supplier outage, a destructive attack causing plant damage — against the whole programme rather than one policy at a time. That mapping exercise is where the value is; the individual wordings rarely surprise anyone once they are read together.
Frequently asked questions
Does my property policy cover a cyber attack?
Modern wordings say so one way or the other. Most exclude cyber causes, some write back ensuing physical damage from named perils such as fire or explosion. The exclusion and its definitions have to be read together.
What did Lloyd’s require about state-backed cyber attacks?
Market Bulletin Y5381 of 16 August 2022 required standalone cyber-attack policies in risk codes CY and CZ, at inception or renewal from 31 March 2023, to exclude state-backed cyber-attacks that significantly impair a state’s ability to function or its security capabilities, and to set out how attribution would be decided.
Does buying standalone cyber close the gap?
It closes the silence, not necessarily the gap. Standalone cyber carries its own war and state-attack boundary, and its own treatment of physical damage, so the programme still has to be read as a whole.
Related entries
- Cyber exclusion in PI policies
- PI vs cyber insurance boundary
- Cyber insurance
- PI cyber extension explained
- Terrorism exclusion
- Cyber governance and insurance
This entry is part of the Apex Insurance Wiki. Position stated as at August 2026. Last reviewed 2026-08-22. Next review: 2027-02-22. It is general insurance information, not legal advice, and not regulated advice on a specific policy.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
