Few provisions in a cyber insurance policy generate more confusion — or more litigation — than the war exclusion. For most of the history of property and casualty insurance, the war exclusion was a technical provision that the vast majority of policyholders never needed to think about. Unless your business was physically located in an active war zone, the war exclusion was unlikely to affect your coverage.

Cyber insurance has changed that calculation entirely. In a world where nation-state actors conduct cyberattacks against foreign businesses and governments routinely, where destructive malware deployed as a geopolitical weapon can reach private companies thousands of miles from any kinetic conflict, and where attribution of an attack to a state-sponsored actor is often disputed and sometimes unknowable, the war exclusion has become one of the most consequential clauses in a cyber policy. Understanding what it says, what it means, and how courts have interpreted it is essential for any business owner who takes cyber insurance seriously.

What the War Exclusion Is and Why It Exists

Insurance policies have contained war exclusions for well over a century. The fundamental logic is straightforward: the losses caused by war are too large, too unpredictable, and too correlated across policyholders to be insurable through private insurance markets. When a nation goes to war, the resulting destruction does not follow normal statistical patterns. Losses are not independent of one another — they are concentrated in specific geographic areas, industries, or populations, and their total scale can dwarf anything that actuarial models based on ordinary experience would predict.

The typical war exclusion in a traditional property insurance policy excludes coverage for loss or damage caused by or resulting from war, whether declared or undeclared, civil war, insurrection, rebellion, or revolution. Some policies extend this exclusion to government action taken in connection with military operations. The purpose is to keep private insurers from becoming involuntary guarantors of losses that result from geopolitical decisions that no policyholder or insurer can control.

In the pre-digital era, applying the war exclusion was relatively straightforward. A building destroyed by a military strike was clearly a war loss. A ship sunk by a naval vessel was clearly a war loss. These events were physical, observable, and obviously connected to armed conflict between states. The geographic and contextual connection to war was usually evident from the facts.

Why the War Exclusion Doesn’t Translate Cleanly to Cyber

The digital world breaks nearly every assumption that makes the traditional war exclusion workable. Nation-state cyberattacks are invisible, they cross borders instantaneously, they can be designed to affect a specific target or to spread indiscriminately across global networks, and their attribution to a specific state actor is often contested, uncertain, and based on intelligence assessments rather than observable facts.

A business in New Jersey can be affected by a cyberattack launched from Russia or China without any kinetic military action occurring anywhere near it. The attack may have been launched by a government agency, a government-contracted criminal group, or a freelance criminal group working for its own reasons but using tools similar to those used by state actors. The malware used in the attack may be identical to malware used by nation-states and also available to ordinary criminals, making attribution to a state actor technically uncertain even for sophisticated investigators.

This ambiguity creates a profound problem for the war exclusion. If the exclusion applies whenever an attack can be attributed to a nation-state, then a large and growing category of cyber threats falls outside the coverage that businesses pay substantial premiums to obtain. If the exclusion does not apply to nation-state cyber attacks, then insurers face exposure to correlated, potentially catastrophic losses whenever a nation-state decides to conduct offensive cyber operations — a sovereign decision that private insurers have no ability to predict or influence.

The NotPetya Litigation

The collision between the war exclusion and cyber insurance came to a head in litigation arising from the NotPetya malware attack of June 2017. NotPetya was a destructive malware that initially spread through a compromised Ukrainian accounting software update, then propagated across corporate networks with extraordinary speed, destroying data on every system it reached. Unlike ransomware, which encrypts data in exchange for payment, NotPetya simply destroyed data with no mechanism for recovery. It caused an estimated ten billion dollars in damages globally — making it the most destructive cyberattack in history at the time.

The US, UK, and other governments attributed NotPetya to the Russian military intelligence agency GRU, deployed as part of Russia’s ongoing conflict with Ukraine. However, because NotPetya spread through interconnected corporate networks without regard to borders, it devastated major multinational companies that had no connection to Ukraine or to Russian-Ukrainian hostilities. The Danish shipping giant Maersk estimated losses of up to 300 million dollars. The pharmaceutical company Merck estimated losses of 870 million dollars. The food and consumer goods company Mondelez estimated losses of 180 million dollars. Numerous other companies suffered significant losses.

When these companies sought coverage under their property and casualty insurance policies, insurers denied coverage by invoking the war exclusion. The resulting litigation produced some of the most significant cyber insurance coverage decisions to date. In New Jersey, Merck argued that its all-risk property policy covered the NotPetya losses because the war exclusion applied only to traditional armed conflict and not to cyberattacks, even nation-state ones. In 2023, a New Jersey appellate court ruled in Merck’s favor, holding that the war exclusion in Merck’s policy did not apply because it was written in language that contemplated traditional kinetic warfare, and the insurer had not specifically excluded cyber warfare or nation-state cyber attacks. The court found that a business buying property insurance had a reasonable expectation of coverage for a cyberattack, and that expectation would not be defeated by an exclusion written decades before cyber warfare existed.

The Mondelez litigation raised similar issues. Zurich Insurance sought to apply the war exclusion to Mondelez’s NotPetya losses, but the parties ultimately reached a settlement after years of litigation. The Lloyd’s of London syndicate that insured Merck’s international operations litigated the issue separately with similar results. These cases sent a strong signal to the insurance industry that old-form war exclusions written in traditional language would not reliably exclude cyber warfare losses, prompting insurers to rewrite their exclusions with cyber warfare specifically in mind.

How Insurers Responded: New Hostile Nation-State Exclusions

In the years following the NotPetya litigation, insurers revised their policy language to address cyber warfare more explicitly. Rather than relying on traditional war exclusion language that courts had found inapplicable to cyber incidents, many insurers began using exclusions specifically drafted for the cyber context.

The new exclusions typically exclude coverage for cyber incidents that are part of a war, whether declared or not, or that are carried out by or on behalf of a nation or government. Some versions use the phrase hostile or warlike action. Others use terms like state-sponsored attack or attack carried out by a government entity. The common thread is an attempt to capture nation-state cyber operations within the exclusion without relying on the traditional armed conflict framing that failed in the NotPetya cases.

These new exclusions are not uniform. Different insurers use different language, and the precise wording matters enormously for coverage purposes. An exclusion that applies only to attacks carried out by a nation-state may be interpreted differently from one that applies to attacks carried out by a nation-state or by a person acting on behalf of or in connection with a nation-state. The second formulation is broader and could potentially exclude attacks by criminal groups that happen to use tools developed by state actors, even if those groups are not actually working for any government.

The Attribution Problem

Every version of a war or nation-state exclusion depends on the ability to attribute an attack to a state actor, and attribution in the cyber context is a deeply difficult problem. Unlike a military strike, which leaves physical evidence and is typically acknowledged or at least identifiable as state action, a cyberattack can be designed to obscure its origins. Attackers use infrastructure in multiple countries, employ techniques borrowed from other actors, and deliberately create false flags intended to point attribution toward the wrong party.

Government attribution — the official public statements by the US or allied governments naming a state actor — is useful but not conclusive for insurance purposes. Government attribution is typically a diplomatic or geopolitical act as much as a technical finding. It reflects intelligence assessments that may be based on classified information that is never disclosed publicly, that may be subject to analytical uncertainty, and that may be influenced by policy objectives rather than purely by evidentiary standards. A government attribution is not a judicial finding, and different courts may give it different weight.

For the business seeking coverage, the attribution problem creates a perverse dynamic: the insurer invokes the nation-state exclusion and points to government attribution or public reporting suggesting state sponsorship, while the policyholder argues that attribution is uncertain and that the exclusion requires more definitive proof. Courts have not yet established a clear standard for how definitive attribution must be to trigger a nation-state exclusion. This uncertainty makes coverage disputes over war exclusions inherently unpredictable and expensive to litigate.

Lloyd’s of London’s 2023 Cyber War Exclusion Mandates

In 2022, Lloyd’s of London issued a bulletin requiring that all standalone cyber insurance policies written through the Lloyd’s market include specific exclusions for losses arising from war and cyber operations between nation-states. This requirement took effect for policies incepting on or after March 31, 2023. Because Lloyd’s syndicates write a very significant share of the global cyber insurance market — and many US policies are placed through Lloyd’s or involve Lloyd’s-market reinsurance — this mandate had substantial impact on cyber policies worldwide.

Lloyd’s provided four model exclusion clauses that syndicates could use, ranging from relatively narrow exclusions focused on declared war between major powers to broader exclusions encompassing nation-state cyber operations and retaliatory cyberattacks. The mandate required that any compliant exclusion include at a minimum an exclusion for losses arising from a cyber operation that forms part of a war between states, and a provision giving the insurer the ability to exclude coverage where attribution of an attack to a state actor is plausible, even if not conclusively established.

For US businesses, the practical effect of the Lloyd’s mandate is that cyber policies written through Lloyd’s-market syndicates now contain specific, updated war exclusion language that is more likely to exclude nation-state cyber incidents than the old-form language that courts rejected in the NotPetya cases. If your policy is placed through the London market or includes Lloyd’s coverage, you should review the specific exclusion language carefully.

How to Evaluate Your Policy for War Exclusion Language

Reviewing the war exclusion in your cyber policy requires careful attention to several specific issues. The exact language of the exclusion matters more than its heading or its general description. Two policies that both claim to contain a war exclusion may have very different scope depending on the precise words used.

First, identify whether the war exclusion appears in your policy as a standalone provision or as part of a broader exclusion for government actions, hostile acts, or similar concepts. Some policies combine war, terrorism, and government action exclusions in a single clause, which can create ambiguity about which specific events are excluded.

Second, examine whether the exclusion contains any cyber-specific language or whether it is written in traditional terms that predate the cyber context. Old-form language that refers only to armed forces, military operations, or physical destruction may be subject to the same arguments that succeeded in the NotPetya cases. Updated language that specifically refers to cyberattacks, computer systems, or malicious code may be much more difficult to challenge.

Third, look for attribution provisions. Some modern cyber war exclusions include provisions addressing how attribution is to be determined — whether the insurer can invoke the exclusion based on its own assessment, whether government attribution is required, or whether some other standard applies. These provisions directly affect whether the exclusion can be applied in practice.

Fourth, look for any carve-backs. A carve-back is a provision that restores coverage for certain types of losses that would otherwise fall within the exclusion. Carve-backs for losses to domestic infrastructure, for collateral damage to businesses not targeted by the state actor, or for incidents where attribution is not clearly established have been negotiated in some policies. The availability of carve-backs depends on the insurer and the market conditions at the time of renewal.

Negotiating War Exclusion Carve-Backs

The ability to negotiate carve-backs to the war exclusion depends heavily on the current state of the cyber insurance market, your company’s specific risk profile, and the insurer’s appetite for the particular exposure you are seeking to cover. In a hard market where cyber insurance is expensive and supply is limited, insurers have less incentive to offer favorable carve-backs. In a more competitive market, there is more room for negotiation.

The most commonly negotiated carve-back is sometimes called the collateral damage carve-back. The theory is that a business that was not the intended target of a nation-state cyber operation should not have its coverage eliminated simply because its systems were affected by malware that spread beyond its intended targets. The NotPetya companies were collateral damage victims of an attack directed at Ukraine — they had no involvement in the geopolitical conflict and no ability to protect themselves against it. A collateral damage carve-back would preserve coverage for businesses in that position.

Another type of carve-back addresses the attribution uncertainty problem by providing that the war exclusion only applies where attribution to a state actor has been conclusively established, rather than merely alleged or suggested. This carve-back preserves coverage in cases where attribution is disputed, which is most cases.

Working with a sophisticated insurance broker who regularly handles large cyber placements and who understands the current state of negotiations in the market is essential to achieving meaningful carve-backs. Retail brokers who are not specialists in cyber insurance may not be aware of what is achievable through negotiation, and may not have relationships with the underwriters who have authority to offer non-standard terms.

What Cyber Policies Covering Acts of War Look Like

Some specialty insurers and war risk markets offer cyber coverage that specifically includes acts of war — the coverage that standard cyber policies typically exclude. These products are designed for businesses that face elevated nation-state cyber risk because of their industry, their government contracts, their geographic footprint, or the sensitivity of the data they hold.

Cyber war coverage can be structured as a standalone policy or as an endorsement to an existing cyber policy. It typically covers losses resulting from cyberattacks carried out by or on behalf of nation-states, including both targeted attacks and collateral damage from broader cyber operations. Premiums are higher than for standard cyber coverage, and coverage terms may be more restrictive in other respects to compensate for the additional exposure.

For most small and mid-sized businesses, the purchase of dedicated cyber war coverage is not currently standard practice. The more important step is to understand clearly what your standard cyber policy covers and what it excludes with respect to nation-state attacks, so that you can assess your actual risk exposure and decide whether additional coverage is warranted.

The war exclusion in cyber insurance is ultimately a reflection of an unresolved tension between the private insurance industry’s capacity constraints and the geopolitical realities of the modern world. Nation-state cyber operations are a permanent feature of the threat landscape, and businesses cannot avoid exposure to them simply by maintaining strong security controls. Working with experienced legal and insurance counsel to understand your policy’s war exclusion, negotiate the best possible terms at renewal, and plan for the possibility of a coverage dispute is the most practical approach available to US businesses today.