What Cyber Insurance Does NOT Cover: Exclusions Explained

by Vitaly GLUSHNEV

What Cyber Insurance Does NOT Cover: Exclusions Explained

Every cyber insurance article tells you what the policy covers. Almost none tell you where it stops. Yet the gaps are where the painful surprises live, and they surface at the worst moment: during a claim. Here are the exclusions and limits that matter most, and how to read a policy so they do not catch you.

The war exclusion: the big one

Every cyber policy contains a war exclusion. In the Ryskly catalog of 682 products across 57 countries, war exclusions appear in 100% of policy wordings. The question is not whether your policy has one, but how it is worded, because the difference decided the largest cyber insurance dispute in history.

In 2017 the NotPetya malware, widely attributed to a state actor, wrecked systems at hundreds of companies worldwide. Pharmaceutical giant Merck claimed 1.4 billion under its insurance. The insurers invoked the war exclusion: state actor, hence "hostile or warlike action". Courts ultimately sided with Merck, reasoning that a traditional war exclusion written for armies and missiles does not automatically stretch to malware hitting a civilian company in peacetime.

The industry response was new, explicit cyber war language. Modern wordings (led by Lloyd's requirements from 2023 onward) spell out what counts as state-backed cyber operations and when cover stops. When you compare policies, this is worth a direct question to the broker: how does this wording treat state-attributed attacks that hit businesses as collateral damage? The answers differ meaningfully between products.

Social engineering: covered less often than you think

Here is the gap that hits small and mid-sized businesses most often. An employee receives a convincing email from a "supplier" with new bank details. Finance pays. The money is gone. Is it covered?

Frequently not. Classic cyber policies cover damage to and from your systems. Money you voluntarily transferred, even under deception, is a different category: cyber crime or funds transfer fraud cover. In our catalog, only 49% of products include it. The other half of the market leaves the most common real-world loss uncovered by default.

Where it is included, watch the sub-limit. A policy with a 1 million overall limit may cap social engineering losses at 100,000 or 250,000. Given that invoice fraud routinely reaches six figures, the sub-limit is the number that matters.

Your own broken promises

The application you fill in becomes part of the contract. If you declared MFA on all remote access and forensics show the attacker walked in through a VPN account without MFA, expect a reduced payout or a denied claim. Some policies go further with explicit conditions: cover applies only if the declared controls were actually in place at the time of the incident.

Related exclusions in many wordings:

  • Unpatched known vulnerabilities. Some policies exclude or reduce cover for incidents exploiting vulnerabilities left unpatched beyond a defined window.
  • End-of-life systems. Running an OS or software past its support date can void cover for incidents involving it.
  • Prior known incidents. Anything you knew about before the policy started is excluded. Discovering a breach and then buying insurance does not work.

Fines and penalties: it depends where you are

After a data breach, regulators may fine you. Whether insurance can pay that fine is not up to the insurer, it is up to the law of your country. In some jurisdictions regulatory fines are insurable, in others insuring them is against public policy. Policies handle this with the phrase "where insurable by law", which sounds reassuring and guarantees nothing in your specific country. If GDPR-type fines are a real concern, ask the broker directly how the wording plays out in your jurisdiction, and note that even where fines are excluded, defense costs and the costs of dealing with the investigation are usually covered.

The quieter gaps worth knowing

Betterment. The policy restores your systems to their pre-incident state. It does not pay for the security upgrade you should have had. Some modern products soften this, but the default is restoration, not improvement.

Reputation and lost future customers. Business interruption cover pays for income lost during the outage and a defined recovery period. Customers who quietly left afterward are your loss.

Hardware. Pure cyber policies traditionally cover data and software. Physically destroyed equipment (bricked firmware, burned-out components) may need separate or extended cover.

Acts of insiders at the top. Fraud by rank-and-file employees is generally covered. Fraud by directors and owners is generally not.

Infrastructure failures. A general internet, power or telecom outage that takes your business down is typically excluded; it is not an attack on you. Cloud provider outages sit in between: some policies offer contingent business interruption for named providers, many do not.

How to read a policy for exclusions in 20 minutes

  1. Find the exclusions section and read it before the coverage section. It is shorter and more honest.
  2. Find every sub-limit in the schedule. The headline limit means little if key covers are capped at a tenth of it.
  3. Search the wording for "war", "terrorism" and "state" and see how cyber operations are defined.
  4. Check for conditions tied to your declared controls (MFA, backups, patching windows).
  5. Ask the broker to show you, in writing, whether social engineering losses are covered and up to what amount.

Twenty minutes with the wording beats any marketing brochure. And if you want to see how products differ on these dimensions before talking to a broker, our comparison table tracks cyber crime cover, incident response and more across 682 products.

FAQ

Are ransomware payments covered?
Usually yes, where paying is legal, and always within limits and conditions (insurer consent, negotiation through their response team). Some markets and sanctions regimes prohibit payment to certain actors, which overrides any policy.

Is there any way to cover state-sponsored attacks?
You cannot buy cover for actual war. For state-attributed attacks hitting businesses as bystanders, modern wordings differ: some carve back cover explicitly, some do not. This is a comparison point between products, not a given.

Do exclusions differ much between countries?
The war exclusion is universal. Regulatory fine insurability, data protection specifics and cyber crime cover vary a lot by market, which is why comparing products within your own country matters more than reading global averages.

What is the single most important exclusion to check for a small business?
Social engineering. It is the most frequent real loss, and with only 49% of products covering it, the odds that a randomly chosen policy leaves it out are basically a coin flip.