Traditional war exclusions were written for physical conflict. Cyber risk created a harder question: what happens when malicious code launched or supported by a government damages thousands of organizations across many countries, including companies that were not the intended target?
This is not theoretical. Cyber attacks can spread rapidly through common software, managed-service providers, cloud infrastructure and global networks. The potential for correlated losses is one reason insurers and reinsurers worry about cyber accumulation—the possibility that one event triggers claims across a huge portfolio at the same time.
Why Lloyd’s changed its cyber requirements
Lloyd’s Market Bulletin Y5381, dated August 16, 2022, set requirements for state-backed cyber-attack exclusions in standalone cyber-attack policies. Lloyd’s said cyber losses can create systemic exposures that syndicates may struggle to manage, citing the ability of harmful code to spread and society’s critical dependence on IT infrastructure. The requirement applied from March 31, 2023 at inception or renewal.
The bulletin followed earlier Lloyd’s work requiring policies to be clear about whether cyber coverage was affirmatively included or excluded. The important buyer lesson is transparency: a modern cyber policy should not leave major cyber-war exposure to vague assumptions.
“War exclusion” can mean several different things
| Concept | Question for the policy |
|---|---|
| Traditional war | Does the exclusion apply to declared/undeclared war, invasion or military action? |
| State-backed cyber attack | How does the form define state backing, sponsorship or control? |
| Major detrimental impact | Does the exclusion depend on the attack materially impairing a state’s ability to function or security capability? |
| Attribution | Who decides that a state was responsible, and what evidence can be used? |
| Infrastructure/systemic loss | Are critical infrastructure failures or widespread events separately limited? |
Attribution is one of the hardest issues
A ransomware note does not usually identify a government sponsor. Security researchers, intelligence agencies, governments and vendors can disagree or take months to reach an assessment. Policy wording therefore matters enormously: some exclusions describe how attribution can be established, what happens when attribution is uncertain and whether an insurer can rely on an official government position.
Risk managers should not stop at the phrase “war exclusion.” Ask what evidence triggers it and whether the policy has a process for contested attribution.
State-backed does not always mean “targeted at you”
A company can be collateral damage. An attack aimed at another country’s infrastructure may spread through software dependencies or global networks and affect businesses elsewhere. Whether that loss is excluded depends on how the policy defines the cyber operation and its connection to the state-backed event.
How systemic cyber risk differs from an ordinary breach
A phishing incident affecting one company is relatively contained. A vulnerability in a widely used cloud platform or software update can affect thousands of insureds simultaneously. That aggregation is closer to catastrophe risk in property insurance and can challenge the amount of capital available to pay losses.
For the underlying coverages, see our small-business cyber insurance checklist, our guide to network security vs. privacy liability and our explanation of cyber business interruption.
What a buyer should request from the broker
- The complete exclusion endorsement. Do not rely on a quote summary.
- Definition of state-backed cyber attack. Look for the threshold between criminal activity and government-linked activity.
- Attribution clause. Understand who can determine responsibility and how disputes are handled.
- Any write-back. Some structures preserve limited coverage for particular events even when broader state-backed losses are excluded.
- Systemic-event sublimits. Widespread cloud, infrastructure or software events may have separate treatment.
- Territorial effect. Check whether the policy distinguishes impacts inside and outside the state involved.
Do not assume “nation-state attack” is automatically uncovered
Coverage depends on the wording. A policy may distinguish between espionage, cyber terrorism, state-backed operations that fall below a severe-impact threshold and attacks that materially impair a state’s functions or security. Different insurers and markets have developed different clauses. The correct answer comes from the policy form, not the attacker label used in a news headline.
Retentions and sublimits can matter even when the exclusion does not
A loss that remains covered still has to pass through the policy’s retention, waiting period and applicable sublimits. Our cyber retention, deductible and sublimit guide explains those financial mechanics. A buyer can have coverage in principle but still face a large retained loss.
Scenario testing is more useful than asking “Am I covered?”
Ask the broker and insurer to walk through concrete scenarios: ransomware attributed to a criminal group with suspected government ties; malware that escapes from a geopolitical conflict; a cloud outage tied to a hostile state; destructive code affecting your company in a neutral country; an event with no official attribution. Request written explanations where possible and compare the answers among competing policies.
Cyber war exclusions and reinsurance
Primary cyber insurers also buy reinsurance. If state-backed or systemic events are difficult to model, reinsurers may restrict capacity, require clearer exclusions or price the aggregation risk differently. This is one reason contract wording evolves quickly. A cyber form that was competitive two years ago may not reflect current market approaches.
Frequently asked questions
Does Lloyd’s Y5381 apply to every cyber insurer worldwide?
No. It is a Lloyd’s requirement for relevant business written by Lloyd’s syndicates. Other insurers and jurisdictions can use different forms and rules.
Are all attacks by nation-state-linked groups excluded?
Not automatically. The policy’s state-backed attack definition, attribution mechanism and any write-backs determine the result.
Why is attribution important to insurance?
An exclusion tied to state responsibility cannot be applied sensibly without a process for deciding whether a state was behind or supporting the attack.
Can a cyber policy cover ordinary ransomware but exclude a systemic state-backed event?
Yes. Modern wordings can differentiate ordinary cybercrime from specified catastrophic or state-backed events. Review the actual endorsement.
Sources and further reading
Reviewed October 5, 2026. This guide distinguishes Lloyd’s market requirements from general law. Cyber exclusions are highly wording-specific and should be reviewed with qualified insurance and legal advisers.
