Cyber attacks have become one of the most significant operational risks facing commercial enterprises. Ransomware attacks, data breaches, distributed denial-of-service attacks, and nation-state-sponsored intrusions can disable critical systems, disrupt supply chains, and prevent businesses from meeting their contractual obligations for days or weeks at a time. As cyber incidents have grown in frequency and severity, a natural question has emerged in commercial contract law: can a cyber attack qualify as a force majeure event that excuses a party from its contractual obligations?

The answer is complicated, and courts are still working through the implications. Unlike natural disasters or government shutdowns, cyber attacks raise questions about foreseeability, preventability, and causal chain that don’t arise in traditional force majeure analysis. The outcome of any given cyber force majeure argument depends heavily on the specific language of the contract, the nature of the attack, the affected party’s security practices, and the jurisdiction where the dispute is heard. This article explains where the law currently stands and what business owners should do to address cyber risk in their contracts.

Why Cyber Attacks Are Different from Traditional Force Majeure Events

Traditional force majeure events — hurricanes, earthquakes, wars — share several characteristics that make them intuitively fitting force majeure candidates. They are genuinely external to any individual party’s operations, they are not preventable through reasonable operational measures, and they affect a broad range of parties simultaneously rather than a single targeted entity. Courts and contracting parties have accepted these events as force majeure for centuries because they clearly fall within the concept of ‘superior force’ that the doctrine was designed to address.

Cyber attacks share some of these characteristics but not others. Sophisticated attacks by nation-state actors or organized criminal groups can be genuinely beyond any individual organization’s ability to prevent, regardless of the security measures they take. Other attacks succeed because the victim organization failed to implement basic security controls — unpatched systems, weak passwords, inadequate access controls — that the industry treats as standard practice. The spectrum from genuinely unpreventable to clearly negligent creates significant analytical complexity that traditional force majeure doctrine wasn’t designed to handle.

Foreseeability is another dimension that distinguishes cyber attacks from traditional force majeure events. Hurricanes strike particular geographic areas in predictable seasons; a business located outside a hurricane zone may legitimately claim it didn’t foresee a hurricane affecting its operations. By contrast, cyber attacks are a pervasive, well-publicized risk that affects businesses across all industries and geographies. Courts considering whether a cyber attack was ‘unforeseeable’ — as required for force majeure and related common law doctrines — have noted that cyber risk is now a well-recognized operational risk that sophisticated businesses should plan for.

Attribution and the distinction between ‘acts of God’ and ‘acts of man’ add further complexity. Natural disasters and pandemics are events that no person caused. Cyber attacks are intentional acts committed by identifiable, if often difficult-to-catch, actors. Some force majeure clauses explicitly limit coverage to ‘acts of God’ in ways that courts may interpret to exclude attacks caused by human actors. The presence of human agency on the attacking side cuts against the classic force majeure characterization, even when the victim had no control over and no means of preventing the attack.

How Courts Have Approached the Question

Reported litigation specifically addressing cyber attacks as force majeure events remains relatively limited, but the cases that have emerged suggest a few clear patterns. Courts have been most receptive to cyber force majeure arguments when: the attack was a sophisticated nation-state or advanced persistent threat attack that could not reasonably have been prevented; the attack specifically targeted and disrupted the systems directly necessary for contractual performance; the affected party had implemented industry-standard security measures prior to the attack; and the force majeure clause expressly included cyber attacks, malicious computer intrusions, or similar events as qualifying triggers.

Courts have been least receptive when: the attack succeeded because of basic security failures that reasonable operational practices would have prevented; the affected party had received prior warnings or had known vulnerabilities that remained unaddressed; the force majeure clause didn’t expressly include cyber attacks and the court applied a narrow interpretation of catch-all language; or the affected party could have maintained or restored performance through business continuity capabilities that it failed to develop or maintain.

A significant case arose in the context of the NotPetya malware attack of 2017, which was attributed to Russian military intelligence and caused billions of dollars in damage to multinational companies whose operations were disrupted for weeks. The Mondelez International v. Zurich American Insurance case, while primarily an insurance coverage dispute rather than a contract force majeure case, raised similar analytical questions about whether a nation-state cyber attack constitutes an ‘act of war’ or an ‘unforeseeable event’ and has influenced how lawyers and courts think about cyber attack classification more broadly. The insurance context is different from the contract context, but the underlying analytical framework has relevance to both.

Commercial parties who have tried to invoke force majeure based on cyber attacks in contract disputes have generally been more successful when they could point to specific contract language covering cyber events, when they could document the attack’s connection to a specific external actor (such as a foreign government), and when they could demonstrate that their security practices met or exceeded industry standards. The combination of express contractual coverage, documented external attribution, and demonstrated reasonable security practices creates the strongest factual basis for a cyber force majeure argument.

The Role of Security Standards in Force Majeure Analysis

Courts evaluating cyber force majeure claims have incorporated security standard analysis in a way that doesn’t appear in traditional force majeure doctrine. For a natural disaster, courts don’t ask whether the affected party had reasonable disaster prevention measures in place. For a cyber attack, courts effectively do ask this question, because cyber risk is a known operational risk that reasonable businesses are expected to address through appropriate security controls.

This security standard analysis introduces an element of comparative fault into what is usually a binary force majeure inquiry. A business that suffered a ransomware attack because an employee clicked on a phishing email and the business had no email filtering, no security awareness training, and no endpoint protection faces a much harder force majeure argument than a business that suffered a sophisticated supply chain attack despite implementing comprehensive security controls, regular penetration testing, and employee training. The security measures in place at the time of the attack are relevant to whether the attack was ‘beyond the party’s reasonable control,’ which is the standard most force majeure clauses apply.

Practical implication: if cyber attacks are a relevant risk in your business, the security posture you maintain has implications not just for your insurance coverage and regulatory compliance but for your ability to invoke force majeure in a contract dispute. Businesses that maintain documented, industry-standard security controls are in a better position to argue that a successful attack was beyond their reasonable control. Businesses with known security gaps face the argument that better controls would have prevented the attack, undermining the force majeure claim.

Drafting Contracts to Address Cyber Attacks

The clearest way to address whether cyber attacks qualify as force majeure is to include them expressly in the force majeure clause. Modern contract drafting increasingly includes language along the lines of: ‘significant cyber attacks, ransomware events, or malicious intrusions into information systems that prevent or materially hinder performance, provided that the affected party had implemented commercially reasonable security measures prior to the attack.’ This formulation both includes cyber attacks as qualifying events and builds in the security standard condition that courts are applying anyway.

The caveat about commercially reasonable security measures is important. Including cyber attacks in force majeure without any security standard condition could create a perverse incentive to underinvest in security, since a successful attack would excuse performance regardless of how preventable it was. Conditioning the force majeure protection on reasonable security measures ensures that the protection applies to sophisticated attacks against well-defended organizations rather than to attacks that succeeded because of easily correctable negligence.

Define what constitutes a qualifying cyber event carefully. Not every cyber incident justifies a force majeure invocation. A brief service outage caused by a denial-of-service attack that is resolved within hours is different from a ransomware attack that encrypts your entire operational infrastructure and takes weeks to remediate. Consider specifying minimum thresholds for what constitutes a qualifying cyber event — for example, requiring that the incident result in a system outage of more than 24 hours, or that it affect systems directly necessary for contractual performance, rather than allowing any cyber incident to trigger the protection.

Address business continuity obligations in relation to force majeure. If a party has a contractual obligation to maintain a business continuity plan and disaster recovery capability, those obligations are relevant to whether a cyber attack should excuse performance. A party who is contractually required to maintain backup systems and disaster recovery procedures, but fails to do so, should not be able to invoke force majeure based on a cyber attack that their own BCP failures made more impactful. Aligning force majeure provisions with business continuity obligations creates a coherent framework for addressing cyber risk contractually.

Insurance Considerations for Cyber Force Majeure

Cyber insurance has become an important part of managing the risks that cyber attacks create, and it interacts in important ways with force majeure analysis. Cyber liability policies typically cover first-party losses from cyber attacks — including business interruption losses, data recovery costs, and incident response expenses — as well as third-party claims arising from data breaches. Business interruption coverage in cyber policies is designed precisely for the scenario where a cyber attack prevents normal operations.

From a force majeure perspective, cyber insurance doesn’t change whether a cyber attack qualifies as a force majeure event under your contracts. But it affects the practical consequences significantly. A business with comprehensive cyber insurance coverage may be able to recover business interruption losses from its insurer even in situations where the force majeure doctrine wouldn’t excuse the contractual obligation, providing a financial backstop that reduces the stakes of the force majeure analysis. Businesses without cyber insurance or with inadequate coverage face much higher net exposure when cyber attacks disrupt performance.

Cyber insurers have increasingly built security standard requirements into their policies, requiring policyholders to maintain specific controls as a condition of coverage. The controls required by cyber insurers — multi-factor authentication, endpoint detection, regular backups, security awareness training — are largely the same controls that courts consider when evaluating whether a cyber attack was preventable. Maintaining the security standards required by your cyber insurer thus serves double duty: it keeps your insurance coverage in force and it strengthens your force majeure argument if a successful attack nonetheless occurs.

Practical Takeaways

Update your force majeure clauses to expressly address cyber attacks. Given the frequency and severity of cyber incidents, relying on generic force majeure language or catch-all provisions to cover cyber attacks creates unnecessary legal uncertainty. Express coverage, with appropriate conditions about security standards, provides both parties with clearer expectations and reduces the risk of expensive disputes about whether the clause applies.

Invest in cybersecurity not just as an operational matter but as a legal protection strategy. The better your documented security posture, the stronger your force majeure argument if a cyber attack occurs. Maintain documentation of your security controls, penetration testing, employee training, and incident response capabilities. This documentation will be relevant if you ever need to argue that a successful attack was genuinely beyond your control despite reasonable preventive measures.

Review your cyber insurance coverage alongside your contract force majeure provisions. Identify where the insurance coverage ends and the contractual exposure begins, and determine whether the gap is acceptable or requires additional insurance or contractual protection. A cyber attack that exceeds your insurance coverage and that you cannot excuse through force majeure creates an uncovered liability exposure that should factor into your business risk assessment.

See Also