Skip to main content

Cyber Insurance in 2026: Coverage Gaps, Exclusion Clauses, and What CISOs Need to Negotiate Before the Claim

9 min read
CISO Daily
Cyber Insurance in 2026: Coverage Gaps, Exclusion Clauses, and What CISOs Need to Negotiate Before the Claim

The cyber insurance market has passed through its period of acute pricing volatility. After years in which premiums increased 30–60% annually and many organisations found coverage increasingly unaffordable or unavailable, the market entered a relative stabilisation period in 2024-2025. Capacity has returned, pricing has moderated, and the range of available policies has expanded.

What has not stabilised is the complexity of what policies actually cover. Underwriters have spent the past several years tightening exclusion language in response to large losses. The result is a market where coverage gaps are more numerous and more consequential than they were five years ago, and where the gap between what a policyholder assumes they have and what their policy actually provides is widest.

For CISOs, the practical task is threefold: understand where your current policy’s coverage is likely to fail, identify the organisational risk that remains with the business regardless of insurance, and prepare board-level communication that accurately represents the residual exposure.

The War Exclusion: Still the Most Contested Gap

The war exclusion — which denies coverage for losses attributable to acts of war — has been a feature of insurance policy language for decades. Its application to cyber incidents became contentious following the NotPetya ransomware attack in 2017, which several major insurers attempted to invoke the war exclusion against, on the basis that NotPetya was a Russian state-sponsored destructive attack against Ukraine that caused collateral damage to international businesses.

Lloyd’s of London published guidance in 2023 mandating that cyber policies issued in the Lloyd’s market include explicit state-backed cyberattack exclusions. The specific language varies by syndicate and policy, but the common elements are:

  • Attacks attributed to states or state-backed actors may be excluded
  • Attribution is determined by the insurer, not by a court, government, or agreed external authority
  • Exclusions may apply even to collateral damage (organisations not the intended target of a state-backed attack)
  • War exclusion provisions may also apply to acts of cyber warfare between states that affect third-party infrastructure

The practical implication: If your organisation is hit by ransomware that is subsequently attributed to a state-sponsored group — a category that now includes substantial commercial ransomware activity from North Korea, Russia-linked criminal groups with documented government relationships, and Iran-nexus operators — the insurer has a potential basis for invoking the exclusion.

This is not theoretical. Multiple organisations have faced exclusion arguments on this basis. Some have succeeded in claiming; others have not. The outcome depends on the specific policy language, the nature and timing of attribution, and the jurisdiction.

What to negotiate: Require policies to specify the attribution standard — who makes the determination, on what evidence, and what the policy position is for incidents where attribution is disputed or evolves after the claim. Some policies now offer “hostile state-actor event” coverage as an add-on, with sublimits, that provides certainty where the base policy creates ambiguity.

Ransomware Sublimits: When 50% of Your Coverage Disappears

Ransomware sublimits apply a lower cap to ransomware-specific losses within a broader cyber policy. A policy with a £10M limit and a 50% ransomware sublimit pays a maximum of £5M for ransomware-related losses, regardless of the actual loss quantum.

Sublimits for ransomware became common as ransomware losses dominated insurer loss ratios in 2022-2023. They are now standard across the market for most organisations above a certain risk profile. The sublimit percentage varies: 50% is common; some policies apply 25% sublimits for organisations assessed as high-ransomware-risk (healthcare, manufacturing, education).

The compounding effect: Ransomware sublimits often interact with other policy provisions to further reduce effective cover:

  • Business interruption coverage may have a separate waiting period and sublimit
  • Regulatory defence costs (responding to ICO investigations, mandatory data breach notifications) may be counted against the same sublimit as direct ransomware response costs
  • The sublimit may be gross of deductible — meaning if your deductible is £500K and your sublimit is £5M, your effective insurance cover for ransomware is £4.5M before sub-limits within that for specific cost categories

For the board: Present cyber insurance as providing defined cover for a defined scenario, not as a backstop against all cyber losses. A material ransomware event at a mid-sized UK enterprise will commonly generate response costs of £3-8M (incident response, legal, notification, PR, remediation) before any ransom payment. If the sublimit provides £3M of cover and the deductible absorbs £500K of that, the residual insurance contribution to a £6M incident is less than half.

Systemic Event Exclusions

Beyond war exclusions, insurers have introduced systemic event exclusions that limit coverage for incidents affecting multiple policyholders simultaneously. The concern is that a single infrastructure event — a major cloud provider outage caused by a cyberattack, or a widely-deployed security product turning into an attack vector — could generate correlated losses across thousands of policies simultaneously, creating an insolvency-level event for underwriters.

Systemic event exclusions take several forms:

  • Infrastructure provider exclusions: Attacks affecting named providers (AWS, Azure, GCP, major CDNs) that cause losses to the policyholder through the provider’s disruption may be excluded or sublimited
  • Dependency network exclusions: Losses caused by compromise of a third-party supplier in the policyholder’s dependency chain
  • Critical infrastructure exclusions: Losses arising from attacks on critical national infrastructure that affect the policyholder’s operations

The CrowdStrike Falcon sensor update incident in July 2024 — which caused system crashes across millions of Windows machines globally — tested systemic exclusion language across the market. Outcomes varied significantly by policy wording. Organisations with business interruption claims faced different results depending on whether their policy required a “malicious act” as the trigger for coverage, or covered operational IT outages more broadly.

What to negotiate: Understand which of your key dependencies fall within systemic exclusion language. For each exclusion, quantify the residual exposure: what is your maximum daily revenue exposure if your primary cloud provider is unavailable for 24-72 hours due to a cyberattack? That number should be reflected either in negotiated coverage or in explicit board risk acceptance.

The Underwriting Information Your Policy Depends On

Insurers condition cyber cover on representations about the organisation’s security posture made during the application process. Material misrepresentation — whether intentional or through administrative error — can void coverage at claim time.

The representations that generate the most claim disputes:

MFA deployment: Nearly all cyber policies now require MFA on remote access and privileged accounts as a condition of coverage. An attack that exploits a VPN or RDP service without MFA — even if MFA is deployed across 95% of the environment — can trigger a misrepresentation defence if the policy application stated MFA was deployed universally.

EDR coverage: Policies frequently require endpoint detection and response tooling deployed across all endpoints. Coverage gaps — unmanaged devices, contractor endpoints, legacy systems excluded from EDR — create representation exposure.

Backup isolation: Policies typically require offline or immutable backups. A ransomware attack that encrypts both production and backup environments will be scrutinised against the backup representation.

Action for CISOs: The security posture information submitted to underwriters should be accurate and current. Do not leave underwriting submissions to procurement or finance teams without technical review. If the actual security state differs from the representation (as it frequently does in large organisations), note the discrepancy during renewal and resolve it either through corrected representations or specific coverage endorsements for the gap.

What to Tell the Board

Boards often misunderstand cyber insurance as providing comprehensive cover for cyber risk. The accurate framing:

Cyber insurance transfers a defined subset of cyber risk, under defined conditions, up to defined limits. The uninsured residual includes: losses above policy limits, losses within exclusion categories (war, systemic events), losses arising from misrepresentation of security posture, and losses in categories with sublimits that don’t cover the actual loss quantum.

The board-relevant question is not “do we have cyber insurance?” but “what is our uninsured cyber risk exposure, and have we accepted it explicitly?”

A practical framework for that conversation:

  1. Maximum credible loss scenario: What does a full ransomware encryption event cost, including response, remediation, regulatory exposure, and revenue impact? Use a FAIR-based quantification or a tabletop-derived estimate.

  2. Policy cover under that scenario: Walk through the coverage waterfall — deductible, sublimits, exclusions — and determine the net insurance contribution to that scenario.

  3. Residual exposure: The gap between the maximum credible loss and the expected insurance contribution is the risk the business is retaining, whether or not it has been explicitly accepted.

  4. Risk treatment options: Higher sublimits are available at additional premium. Self-insurance reserves or captive structures can address residual exposure. Security investment reduces the probability of the maximum credible loss scenario.

The CISO’s role in this conversation is to provide the technical grounding for the loss scenario estimates and the honest assessment of what the current security posture means for the probability of each scenario. The board decision about what residual exposure to accept is a governance decision, not a security one — but it requires the CISO to ensure the inputs are accurate.

Checklist for Cyber Insurance Review

  • Read the war exclusion language and identify the attribution standard
  • Identify all sublimits and the cost categories they cover
  • Verify that the underwriting representations accurately reflect current security posture
  • Quantify the gap between the maximum credible loss and the maximum insurance payout
  • Identify which critical dependencies fall within systemic event exclusions
  • Confirm that incident response and legal counsel on the insurer’s approved panel are already retained or known
  • Verify that the claim notification procedure is documented and the CISO, legal, and finance teams know it

The annual insurance renewal is the right time for this review. Waiting until a claim is in progress to understand policy coverage is the most expensive way to learn what you actually have.