Cyber & Insurance Technology

Cyber Insurance Bricking and Betterment Coverage: When Hardware Replacement or Upgrades May Be Covered

A deep guide to bricking, hardware replacement, data restoration and betterment provisions in cyber insurance, including policy limits and claim documentation.

Server hardware in a data center illustrating cyber insurance bricking, restoration and hardware replacement
Photo: panumas nikhomkhai / Pexels
Short answer: “Bricking” coverage can pay to repair or replace hardware that becomes unusable because of a covered cyber event, while “betterment” coverage can sometimes contribute toward upgraded replacement technology when restoring the exact pre-loss configuration is impractical. Neither benefit should be assumed to exist in every cyber policy. Definitions, sublimits, retentions, consent requirements and property-damage exclusions vary widely.

Cyber insurance began largely as protection for data breaches, privacy liability and digital incident response. Modern cyber losses can be more physical. Malware can corrupt firmware, ransomware can disable servers and industrial devices, and restoring an old technology stack may require replacing equipment that is no longer supported.

That creates two related claim questions. First, does the policy pay when a cyber event permanently disables hardware even if there is no traditional fire or impact damage? Second, if replacement technology is newer or better than the old system, will the policy treat the improvement as uncovered “betterment”?

What “bricking” means in cyber insurance

In cyber coverage discussions, bricking generally refers to hardware that is rendered nonfunctional by a cyber event and cannot reasonably be restored to service. The device may still physically exist, but its firmware, operating environment or essential digital function has been damaged so severely that replacement is necessary.

Some modern cyber products affirmatively include hardware replacement for bricked devices. AXIS, for example, publicly describes its ACI cyber product as covering replacement of bricked hardware and allowing a stated amount of betterment. That is an example of available market wording—not evidence that every policy offers the same feature.

Why property-damage exclusions matter

Cyber policies often contain exclusions or limitations for tangible property damage because traditional property insurance historically handled physical assets. At the same time, traditional property policies can contain cyber exclusions or restrictions. Bricking endorsements or affirmative hardware wording are designed to reduce that gray area.

A business should therefore ask two questions instead of one:

  1. Does the cyber policy affirmatively cover hardware rendered unusable by a covered security event?
  2. If not, does any property, equipment breakdown or technology policy respond?

Betterment: restoring versus improving

Insurance is generally designed to indemnify a covered loss rather than finance unrelated upgrades. In technology claims, however, exact replacement can be impossible. A five-year-old server model may no longer be sold; an unsupported operating system may not be safely reinstallable; or the replacement platform may require more current hardware.

Betterment wording can allow some incremental improvement cost when it is necessary or specifically covered. WTW’s cyber insurance overview notes that policies traditionally restrict improvements beyond the pre-loss state, while negotiated wording may allow limited betterment when the original component or software can no longer be obtained. Again, the policy wording controls.

Claim cost Possible coverage question What to document
Reinstalling software from clean backups Data restoration / digital asset restoration Forensic findings, backup records, labor invoices
Replacing a server made unusable by malware Bricking / hardware replacement Technical proof the hardware cannot reasonably be restored
Buying a newer server because the old model is unavailable Betterment or nearest equivalent Vendor quote showing why like-for-like replacement is unavailable
Voluntary capacity expansion during recovery May exceed covered restoration Separate upgrade costs from loss-driven costs

How to avoid mixing recovery with an IT transformation project

After a major incident, management often wants to rebuild “the right way” rather than recreate the vulnerable environment. That may be sensible operationally, but the claim should distinguish covered restoration from strategic modernization.

Create a cost ledger with at least three columns: pre-loss restoration, necessary substitute/obsolescence cost, and elective improvement. If the policy provides a betterment allowance, the claim team can apply the wording to the second and third categories more cleanly.

Consent and vendor requirements still matter

Even broad cyber coverage can include requirements to notify the insurer promptly, use approved vendors or obtain consent before incurring certain costs. A company that signs a large hardware replacement contract before reviewing the policy can create an avoidable coverage dispute.

Our first 24 hours of a cyber claim guide explains why notice and evidence preservation matter. The data breach response guide covers forensics, legal and notification costs, while cyber retentions and sublimits explains how a separate limit can restrict an otherwise covered cost.

A realistic scenario

A ransomware event corrupts firmware on 40 specialized endpoint devices. The devices cannot be reliably reimaged. The manufacturer no longer sells that model, and the nearest replacement has better specifications. The insured’s claim now has at least four layers: incident response, data restoration, business interruption and hardware replacement. The adjuster may also need to determine whether the difference between old and new equipment is covered betterment, necessary equivalent replacement or an elective upgrade.

Questions to ask when comparing cyber policies

  • Is bricking or hardware replacement expressly included?
  • Does it have a separate sublimit?
  • What event must cause the hardware failure?
  • Are operational technology and industrial devices included?
  • How does the policy define data restoration and digital assets?
  • Is betterment covered, capped or excluded?
  • Are prior consent or panel-vendor requirements imposed?
  • Does the same retention apply across restoration, bricking and business interruption?

Frequently asked questions

Does every cyber policy cover damaged hardware?

No. Hardware and tangible property can be excluded or covered only through specific wording or endorsements.

Is bricking the same as ordinary equipment breakdown?

No. Bricking refers to loss of hardware functionality caused by a cyber event. Equipment breakdown coverage has its own triggers and exclusions.

What is betterment in a cyber claim?

It is the portion of restoration or replacement that leaves the insured with technology better than the pre-loss state. Some policies exclude it; others allow limited betterment.

Can I replace everything with newer equipment after ransomware?

You can make business decisions, but whether the insurer pays depends on the policy and whether the cost is necessary restoration, covered betterment or an elective upgrade.

Reviewed October 6, 2026. Bricking and betterment are not standardized benefits. Compare actual policy language, endorsements, sublimits and consent conditions.

Written by

insurer724