PRIV-07 Privacy, Cyber & AI Security Program Operations State law (varies)
Cyber Insurance: Coverage Triggers, Exclusions, and Claim Disputes
A cyber tower is many small policies stapled together, and the fights are predictable. This brief maps the coverage grants, the four denial theories that recur, and the notice steps that protect a claim.
Briefing in 60 seconds
- Cyber policies are claims-made and modular; each insuring agreement has its own trigger, retention, and sublimit, so a covered incident can still be mostly uninsured.
- War and hostile-act exclusions drove the NotPetya litigation, and standalone cyber policies have since been rewritten with state-backed-attack exclusions that remain largely untested.
- Applications and security warranties become coverage conditions; an inaccurate answer about multifactor authentication or backups is a common rescission and denial theory.
- Social-engineering and funds-transfer fraud typically sit under low sublimits, which is where insureds most often discover the tower does not match the loss.
Controlling variables
- Contract terms
- Which insuring agreements were purchased, their individual sublimits and retentions, and whether the wording is a broad-form manuscript policy or a restrictive standard form.
- Timing
- Whether the claim was first made and reported inside the policy period, and whether the incident postdates the retroactive date on a claims-made form.
- Documents
- The application, security questionnaire, and any warranty endorsement, since answers given at binding are read as conditions when the carrier reviews the loss.
- Facts
- Whether the loss arose from an outside intrusion, an employee deceived into transferring funds, or a vendor's system, each of which routes to different coverage parts.
- Jurisdiction
- Which state's law governs interpretation, since rules on ambiguity, reasonable expectations, and the duty to defend differ enough to change outcomes on identical wording.
General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.
A cyber policy is not one coverage. It is a stack of separate insuring agreements — breach response, business interruption, extortion, liability, funds transfer, regulatory defense — each with its own trigger, its own retention, and frequently its own sublimit. An incident can fall squarely inside the policy's subject matter and still leave most of the loss uninsured because it landed in the coverage part that carries a low sublimit.
Disputes cluster in four places: what the policy calls a covered event, whether an exclusion for war or infrastructure failure applies, whether the insured kept the security controls it described at binding, and whether the loss fits the narrow definitions in the crime-adjacent coverages.
What the tower actually pays for
| Coverage part | What it funds | Where it strains |
|---|---|---|
| Incident response / breach costs | Forensics, legal, notification, call center, credit monitoring, public relations. | Panel requirements. Using off-panel counsel or forensics without consent can reduce or eliminate reimbursement. |
| Business interruption | Lost net income and extra expense during a covered outage. | Waiting periods measured in hours, proof of loss against a projected baseline, and whether restoration delay caused by choice rather than necessity counts. |
| Contingent business interruption | Loss caused by an outage at a vendor or supplier. | Whether the vendor is a scheduled or unscheduled provider, and whether cloud outages are excluded as infrastructure failure. |
| Cyber extortion | Ransom, negotiation, and recovery costs. | Consent requirements before payment, sanctions conditions, and sublimits far below the full policy limit. |
| Privacy and network security liability | Third-party claims, defense costs, and settlements. | Exclusions for statutory privacy claims and for violations of laws governing the collection of information. |
| Regulatory defense and penalties | Investigations, defense, and fines where insurable. | Insurability of penalties varies by state, and consent-decree compliance costs are frequently outside the grant. |
| Funds transfer and social engineering | Money sent to a criminal after a fraudulent instruction. | Modest sublimits, callback-verification conditions, and definitional fights over whether the transfer was a direct loss caused by computer fraud. |
Two structural features matter before any exclusion is reached. Nearly all cyber policies are claims-made and reported, so a claim made during the policy period but reported after it can fall outside coverage entirely, and losses tied to conduct predating a retroactive date are excluded regardless of when discovered. And the "each incident" retention applies per coverage part, which means a single event can carry several retentions.
War, hostile acts, and infrastructure
The most consequential coverage litigation of the past decade grew from a single 2017 wiper campaign that spread globally through accounting software. Carriers denied large property and all-risk claims on the ground that the malware was an act of war or a hostile act by a sovereign, and insureds argued the exclusion had always been understood to require armed conflict. A New Jersey appellate court in 2023 ruled for the insured in the most prominent of those cases, reasoning that the traditional war exclusion did not clearly extend to a cyberattack absent language saying so; the matter resolved before the state's highest court decided it, and a parallel case settled as well. The result is that the leading precedent is persuasive rather than nationally settled.
The market responded by rewriting the wording. Standalone cyber policies now commonly carry state-backed cyberattack exclusions with attribution mechanics — who decides that a state sponsored the attack, on what evidence, and whether the insured can contest it. Those provisions have not been meaningfully tested in U.S. courts as of mid-2026, so an organization relying on the older case law is relying on wording its current policy may no longer contain. Read the operative exclusion, not the headline.
Infrastructure exclusions sit beside them and are quieter but broader in practice. Language excluding failure of utilities, satellites, or the internet itself can be read to reach cloud outages, which is exactly the exposure contingent business interruption was purchased to cover. Where the business depends on two or three providers, name them and negotiate the carve-back rather than assuming the grant swallows the exclusion.
Read the endorsements first: the base form is negotiable and often generous. The denial almost always lives in an endorsement added at binding or renewal, which is where the war, infrastructure, warranty, and sublimit changes are made.
The application is a coverage document
Underwriting questionnaires now ask granular control questions: multifactor authentication on remote access and privileged accounts, endpoint detection coverage, patch cadence, offline or immutable backups, email filtering, segmentation. Those answers do three things. They price the risk. They are incorporated into the policy by reference. And in many programs they reappear as a warranty endorsement or a condition precedent, so that a control described at binding but absent at the time of loss becomes the carrier's cleanest denial.
The related theory is the failure-to-maintain-security exclusion, which removes coverage where the insured did not maintain the standards it represented. A 2015 federal case involving a healthcare provider's exposed server is the frequently cited example, and the exclusion has since become standard. The defense is not argument. It is evidence: control inventories, configuration exports, and audit records dated before the incident showing the represented state was the actual state.
- The questionnaire was completed by the wrong person. A procurement or finance signatory answers "yes" to controls deployed only in part. Have the security owner sign off on every technical answer and keep the supporting evidence with the application.
- Partial deployment described as complete. Multifactor authentication covering the corporate domain but not the legacy VPN is the most common example, and it is the exact gap attackers use.
- Late notice. Notice conditions run from awareness of a circumstance that could give rise to a claim, not from the lawsuit. Waiting for certainty is the routine way claims are forfeited.
- Off-panel vendors. Retaining preferred counsel or a familiar forensic firm without consent can leave the insured funding the response it insured, a sequencing trap detailed in data-breach response, privilege, and notification.
- Statutory privacy exclusion. Many forms exclude claims under statutes governing the collection of information, which can reach the biometric class actions described in biometric privacy laws. Ask specifically whether that exclusion is present.
- Contract mismatch. Customer agreements promise indemnity broader than the policy funds, or name the customer as an additional insured on a policy that does not permit it. Reconcile the commitments to the tower before signing, not after a claim.
Preserving the claim while responding to the incident
- Hour 0 to 24 — notice and consent
Give notice under every potentially applicable policy, including the crime and errors-and-omissions towers, not just the cyber form. Request consent for counsel and forensics in writing. Notice is cheap; a coverage argument about late notice is not.
- Day 1 — separate the ledgers
Open cost codes that mirror the coverage parts on the day the response starts. Reconstructing which invoices were response versus remediation, months later, is where recoveries are lost.
- Day 1 to 7 — protect privilege and coverage together
Insurers ask for the forensic report. Sharing it can affect a privileged investigation posture, so negotiate a common-interest arrangement or an agreed summary rather than forwarding the full report reflexively.
- Week 1 to 4 — build the interruption proof
Business interruption is proved with a pre-incident baseline. Capture order volumes, transaction counts, and staffing as they stood before the outage while the data is still retrievable.
- Ongoing — preserve the record
A litigation hold covering incident and coverage material should issue early, because coverage litigation runs on the same documents as the underlying claim.
- On a reservation of rights — read it as a roadmap
A reservation letter names the provisions the carrier is preserving. It is the earliest reliable statement of the denial theory, and it should drive what evidence the insured assembles next.
Where the insured is a public company, the incident may carry a separate disclosure track governed by materiality rather than by the policy; the current framework is administered by the SEC and runs on its own clock. For extortion events, carrier consent interacts with sanctions screening and federal reporting expectations set out at CISA's ransomware resources — the payment analysis is covered in ransomware response and the legality of paying.
Questions the desk gets
Does cyber insurance cover a ransom payment?
Usually yes in principle, under the extortion agreement, and usually subject to a sublimit and a consent condition. Two limits matter more than the wording. Carriers condition payment on sanctions screening, and no policy funds a payment that would itself be unlawful. And the ransom is frequently the smallest number in the event — restoration, interruption, and notification costs typically dwarf it and sit under different agreements with different retentions.
An employee wired funds after a spoofed email. Is that a cyber claim?
It may be, but the coverage is narrow and the fights are definitional. Carriers argue that a voluntary transfer by an authorized employee is not a direct loss caused by computer fraud. Federal appellate decisions have gone both ways on similar facts, so the answer turns on the wording and the governing law. Check whether a social-engineering endorsement was purchased, what its sublimit is, and whether it conditions coverage on callback verification that was actually performed.
Will the carrier pay to improve our security after the incident?
Generally not. Policies fund restoration to the pre-incident state, not betterment. That line is fought over constantly because the practical way to restore service is often to rebuild on a hardened platform. Document the distinction contemporaneously — what was necessary to restore operations versus what was an upgrade the organization chose to make — because the allocation cannot be reconstructed persuasively after the fact.
Should our vendors carry their own cyber policies?
Yes, and the requirement should be specific: limits, coverage parts, retroactive date, and evidence of renewal, rather than a generic certificate reference. Also address subrogation, since a waiver of subrogation in a service agreement can cut off the recovery your own carrier would otherwise pursue. The broader insurance-clause mechanics are covered in commercial insurance clauses and additional insureds.
What to do next
Pull the policy and build a one-page map: each insuring agreement, its limit, its sublimit, its retention, and its waiting period. Most organizations have never seen their own tower summarized that way, and the exercise usually surfaces at least one sublimit that does not match a real exposure — extortion, funds transfer, or contingent interruption being the usual candidates.
Then reconcile the security questionnaire against reality before renewal, and keep dated evidence for each control claimed. Mapping the program to the NIST Cybersecurity Framework gives underwriters a structure they recognize and gives you a record if a warranty is later challenged; the FTC's security guidance and CISA supply the baseline expectations. Finally, decide now who gives notice and who holds authority to consent to vendors, because both decisions are made in the first day of an incident. Related material sits on the Privacy, Cyber & AI desk.
Sources
Atlas Research Desk
ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.