Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. After NotPetya in 2017, a food manufacturer sought to trigger its all-risks property policy, which said nothing about cyber. Its insurer invoked a war exclusion. What did that litigation crystallise?
That a policy silent on cyber still opens an argument about whether it responds
Silent cyber is the cyber exposure implicitly contained in traditional policies, property, liability or business interruption, written before cyber was treated as a distinct risk, and whose wordings neither mention nor exclude it. The litigation that followed NotPetya shows exactly what that produces: neither insurer nor insured could rely on any text addressing the question, so the argument moved onto a clause drafted for something else, the war exclusion. The point to retain is not who was right, it is that silence protects nobody: it amounts to neither cover nor exclusion, it amounts to a lawsuit. The problem is twofold for the insurer, carrying an unmeasured and therefore unreserved exposure, plus accumulation risk, since one event can trigger simultaneous claims across several lines. That is the finding that led the Lloyd's market, from 2019, to require every policy to take a position.
Glossary entry · silent-cyber2. An affirmative cyber cover differs from a silent policy by what it puts in writing. What exactly does the insurer gain from a contract that takes a position?
The ability to measure and reserve its real exposure
Affirmative cyber is cover explicitly provided, described and priced, as against silent cyber where the exposure is neither mentioned nor excluded. An affirmative cover names the events covered, attacks on systems, data breaches, extortion, business interruption of digital origin, and names the exclusions, sub-limits and trigger conditions as well. What the insurer gains is not a reduction in risk, and that is the misreading to discard: the number of attacks does not fall because a contract is better drafted. What it gains is measurement. A named exposure can be counted, reserved, aggregated at portfolio level and ceded to reinsurers; a silent exposure can do none of that, and surfaces at claim time. The move to affirmative cover, driven by prudential authorities and by Lloyd's from 2019, aimed at precisely this, and the insured gains in turn a legal certainty no silence ever offered.
Glossary entry · affirmation-cyber3. On 19 July 2024, a defective CrowdStrike update takes 8.5 million Windows systems offline, with no attacker and no hostile intent. Insurers find that their cyber exclusion clauses, drafted between 2019 and 2023, do not allow them to deny the claims. Why?
Those clauses targeted cyberattack and intentional hostile acts, neither of which was present
The first wave of clarification, that of 2019, resolved silence on malicious cyber and left it untouched everywhere else. Drafting of that generation describes a trigger: cyberattack, unauthorised access, intentional hostile act. CrowdStrike presents none of these, which is not a matter of qualification but the very nature of the event: a defective configuration file, pushed by the vendor itself through an entirely legitimate channel, onto machines nobody had broken into. The trigger not being met, the exclusion does not bite, and the cover responds. The lesson reaches past the case: an exclusion is read on its trigger, not on its heading, and the word cyber in a clause title says nothing about what it actually excludes. That finding fed the revisions underway since 2025, LMA 9341 among them, which seek to address the whole spectrum rather than the malicious side alone. The three other answers invent rules that do not exist: neither the number of insureds struck, nor the existence of a recourse against a third party, nor any approval regime neutralises an exclusion clause.
Glossary entry · cyber-accidentel4. Two identical fires destroy two server rooms. The first comes from overheating caused by an intruder who took control of the temperature regulation; the second, from a software fault in that same regulation. Both property policies carry LMA 5400. What decides the cover?
Whether malicious intent is established, which separates a cyber act from a cyber incident
LMA 5400 excludes loss connected to a cyber act, meaning a malicious act carried out through a computer system, then reinstates by write-back the physical fire or explosion damage resulting from a non-malicious cyber incident. Two physically identical losses therefore meet opposite fates, and the only thing separating them is intent. That singularity is worth holding on to, because it shifts the centre of gravity of the claim: the question is no longer to value damage, it is to establish a fact on which technical expertise speaks poorly. Forensic analysis reads logs, command sequences and access traces, and can often say what happened without being able to say why; the intrusion may be old, the manipulation may look like maintenance work, and the burden of proof becomes the real issue in the file. LMA 5401, which excludes both cases without exception, buys legal certainty at the price of cover, and the choice between the two wordings is made with open eyes. The other answers introduce criteria the text does not carry: the LMA 5400 write-back turns neither on a threshold, nor on the victim's sector, nor on any special occurrence rule.
Glossary entry · cyber-act5. In 2018, a software update error at TSMC halts several production lines and costs 170 million dollars, almost entirely in lost output. The property policy carries LMA 5400 and its fire and explosion write-back. What does that write-back cover here?
Nothing, for want of any fire or explosion physical damage to reinstate
A write-back is read twice: on what it qualifies, and on what it gives back. The first reading is favourable here, since the TSMC event is indeed a non-malicious cyber incident, an update error with no attacker. The second closes the door: what LMA 5400 reinstates is physical damage caused by fire or explosion, and the TSMC loss contains none. The 170 million is output not produced, a financial loss the reinstatement never addresses. Clearing the first step therefore says nothing about the outcome, and conflating the two readings is the classic error on this clause. The lesson reaches much further: in most industrial cyber losses the dominant head is not physical damage but a stoppage, which makes a write-back tied to fire and explosion considerably narrower than it looks. It is also worth noting that cover for this loss, where it exists, will come from elsewhere, from a business interruption cover whose trigger does not require physical damage, and how those two contracts fit together is precisely the subject of program coordination.
Glossary entry · cyber-incident6. In 2018, after two consecutive loss-making years, Lloyd's launched Decile 10 and required a remediation plan for the worst ten per cent of each syndicate's lines. One syndicate then finds that its property policies mention cyber neither to include it nor to exclude it. Why is that an underwriting problem, and not merely a drafting one?
Because the syndicate carries an exposure it has neither priced nor counted in its accumulations
Silent cyber is not a stylistic imprecision, it is an exposure with no counter. A policy that says nothing about cyber does not stop covering it: it leaves to a court, and therefore to the outcome of litigation, the question of whether the damage falls within the general definition of insured perils. From the insurer's side, that exposure is invisible everywhere it looks: it is not in the premium, since no rating element addresses it; it is not in the accumulation returns, since nothing allows it to be flagged; it is not in the reinsurance cessions, since one does not cede what one has not identified. Decile 10 did not create the cyber rule, it created the setting: when the Corporation forces a loss-making syndicate to explain where its losses come from, an exposure no system measures becomes impossible to defend. The 2019 market bulletin, which required every policy to state its position on cyber one way or the other, comes out of that sequence. The three other answers assume silence produces a settled legal effect, favouring one side or the other: that is exactly what silence does not do, and it is the whole difficulty.
Glossary entry · decile-10-lloyds