Revisiting the Lloyd's LMA 21-042 directive and its implications for Property & Casualty reinsurance treaties
For several decades, non-life insurance policies were written in a world where the digital economy did not yet exist or was not perceived as a source of tangible losses. A property insurance policy covered physical damage caused by fire, explosion, weather events or theft; a professional liability policy covered errors and omissions in the conduct of an activity. Neither mentioned the word "cyber," simply because the question did not arise.
It is precisely this drafting legacy that created what the market calls silent cyber, or non-affirmative cyber: the set of cyber risk exposures embedded in classic policies without being explicitly named, priced, or, in the majority of cases, intentionally covered by the insurer. The contract's silence on the cyber question does not mean that coverage is excluded; in many legal systems, and particularly under English law, the absence of explicit exclusion can be interpreted as implicit inclusion. It is this contractual void that constitutes the very essence of the problem.
The quantification of the global market's silent cyber exposure is, by nature, difficult to perform precisely, since by definition it is not tracked in insurers' underwriting systems. The most rigorous estimates, published by the Cambridge Centre for Risk Studies and cited by Lloyd's in its market publications, placed the overall non-life market's exposure to silent cyber at between 100 and 300 billion dollars in annual premiums at risk in 2019, of which an unknown but potentially very significant fraction carried unintentional cyber exposure.1
Before June 2017, silent cyber was a technical discussion topic in actuarial and legal circles of the London market. After NotPetya, it became an industrial emergency. The attack, attributed by the American, British and European governments to the Russian military intelligence service (GRU), propagated via the Ukrainian accounting software M.E.Doc and infected tens of thousands of systems belonging to companies operating in Ukraine before spreading globally through the internal networks of major multinational groups.2
Among the victims were names with no direct connection to Ukraine: food manufacturer Mondelez (estimated losses of 180 million dollars), pharmaceutical group Merck (870 million dollars), shipping company Maersk (300 million dollars) or Saint-Gobain (80 million euros). All had taken out property or assets insurance policies. None of these policies mentioned cyber.
The insurers who had covered these companies via property policies massively invoked the "act of war" or "hostilities" exclusion clauses present in virtually all non-life policies since the early twentieth century. These clauses, designed to exclude physical destruction caused by armed conflicts between states, obviously addressed a very different context from the cyberattacks of the late 2010s. Zurich Insurance, Mondelez's main insurer, refused to indemnify by invoking this exclusion. The dispute was settled out of court in 2022 under undisclosed terms.3
The Merck case was even more resounding. The New Jersey trial court ruled in January 2022 that the "act of war" exclusion could not apply to a cyberattack, on the grounds that the hostility exclusion clauses written in the twentieth century targeted acts of kinetic hostility between nations, not cyber operations. This decision, confirmed on appeal in May 2023, compelled Merck's insurers to pay the full 1.4 billion dollars claimed, an amount far exceeding the premium received.4
These two cases outlined the contours of a structural problem. On one side, insurers who had underwritten industrial risks without ever intending to cover cyber and who found themselves exposed to massive losses. On the other, good-faith policyholders who had paid premiums for years and who discovered, at the time of the loss, that the boundary between coverage and exclusion was entirely dependent on the outcome of judicial litigation. This uncertainty was unsustainable for both parties.
Lloyd's of London was the first insurance market to assess the problem systematically and impose a normative response on its syndicates. In January 2019, Lloyd's published market bulletin Y5258, the first binding text imposing on syndicates operating in the London market an explicit action on silent cyber in their portfolios.5 The bulletin formulates a simple principle, though complex in its execution: all policies underwritten by Lloyd's syndicates must, starting from the deadlines set by class of risk, either explicitly affirm that cyber is covered, or explicitly exclude it. Contractual neutrality, that is, silence, is no longer an acceptable option.
The timetable imposed by Y5258 is progressive. Property policies with physical damage coverage must comply with the new requirement from January 1, 2020; all other non-life insurance classes, by January 1, 2021 at the latest. The priority accorded to property policies is not arbitrary: it is precisely there that silent cyber exposure is financially heaviest, due to business interruption guarantees whose losses can reach considerable amounts.
If Y5258 establishes the principle, it is the LMA 21-042 directive, published by the Lloyd's Market Association during the first quarter of 2021, that provides its technical operationalization. The LMA is the body representing underwriting syndicates in the London market and publishing the standardized model clauses used by the market. Directive 21-042 supports the compliance of all non-life classes by providing underwriters with a framework of pre-drafted clauses, legally validated and adapted to the various contractual situations encountered in practice.6
The directive explicitly distinguishes three situations in which an underwriter may find themselves facing a non-cyber risk. The first is pure exclusion: the underwriter decides that the policy will cover no loss whose principal or contributing cause is a cyber event, whatever its nature. The second is partial affirmation: the underwriter agrees to cover certain limitatively defined cyber consequences, while excluding others. The third, rarer but existing, is full affirmation: the underwriter decides to explicitly include the entirety of cyber risk in the policy, with adapted pricing and risk analysis. The directive specifies that the second option, partial affirmation, is the one requiring the most drafting vigilance, as the definition of included and excluded perimeters entirely determines coverage quality.
The London market has a corpus of standardized clauses, the most commonly used for cyber exclusion being clause NMA 2914 (known as CL 380 in its maritime version), whose origins date to the 1990s and which has been progressively revised, and clause LMA 9340, more recent and more precisely drafted to cover cyberattacks in the contemporary sense.7 Both clauses rest on an identical mechanism: they exclude from the guarantee losses whose proximate or distal cause is a cyber event, defined as any malicious use of a computer system, network or electronic device.
The LMA 9340 clause presents a significant drafting advantage over its predecessors in that it precisely defines the terms "cyberattack" and "cyber incident," thereby avoiding the ambiguities of interpretation that had fueled litigation around "war and hostilities" clauses in the NotPetya cases. It also incorporates an explicit list of types of events covered by the exclusion, which considerably reduces the surface of potential litigation.
LMA 9341, a variant of the foregoing, goes further by excluding not only malicious cyberattacks but also non-malicious computer system failures, what one might call "accidental cyber." This extension is precisely what would have allowed insurers to defend themselves more easily against CrowdStrike-type losses, had the clause been systematically adopted. Yet in 2024, only a minority of property policies outside the Lloyd's market had incorporated this extended wording.
Beyond the choice of clause, the concrete implementation of the affirmation or exclusion principle runs into a causality problem in losses that combine a cyber and a physical component. Consider a concrete example: an attack on the industrial control system (SCADA) of a chemical plant causes an explosion and fire resulting in significant physical damage and business interruption losses. The proximate cause of the loss is physical (the explosion). The initial cause is cyber (the attack on the SCADA). Depending on whether the retained clause refers to the proximate cause or the efficient cause of the event, coverage applies or not.
This problem of causal proportionality is far from anecdotal. In practice it concerns an entire range of sectors where computer systems drive physical processes, including industry, energy, transportation, healthcare and urban infrastructure. LMA 21-042 recommends explicitly indicating in the retained clause whether it is the proximate or efficient cause that determines coverage application, but this recommendation has not been universally followed by underwriters.8
Silent cyber is not a problem that stops at the relationship between the direct insurer and their policyholder. It propagates mechanically through the reinsurance chain, sometimes invisibly, all the way to reinsurers who were never aware of the existence of a cyber exposure in the portfolio they accept under treaty. This propagation takes two main forms depending on the type of treaty involved.
In a quota share treaty (pro-rata), the reinsurer shares a fixed proportion of each premium and each loss in the ceded portfolio. If the direct insurer's portfolio contains an untracked silent cyber exposure, the reinsurer takes it on at their quota share level without having modeled or priced it. The risk is therefore directly linked to the quality of information transmitted by the cedant in the risk bordereaux, which prior to 2021 rarely mentioned the presence or absence of cyber exposure in individual risks.
In an excess of loss (XL) treaty, the situation is different but potentially more dangerous. The reinsurer does not share small losses but commits to indemnifying the cedant beyond a given retention. A systemic cyber event, such as NotPetya or CrowdStrike, generates numerous simultaneous losses that can collectively exceed the retention by amounts very difficult to anticipate if the reinsurer had not modeled the cyber accumulation in their cedant's portfolio. It is precisely this accumulation scenario in property XL treaties that constitutes the prudential nightmare of reinsurers since 2017.
One of the most complex challenges posed by the LMA 21-042 directive for reinsurers is that of contractual coherence between direct policies and reinsurance treaties, what the jargon calls back-to-back coverage. Ideally, if the direct insurer has excluded cyber from their property policies, their reinsurance treaty should contain the same exclusion, and vice versa. Yet in market reality, this coherence is not automatic.
Several factors explain this gap. First, the renewal dates of direct policies and reinsurance treaties often do not coincide, creating time windows during which the direct policy has been updated but the treaty has not yet been. Second, multi-year treaties, common in certain segments of property reinsurance, locked in terms drafted before the LMA 21-042 directive came into force and can only be modified at contractual maturity. Third, and this is perhaps the most structural problem, the information transmitted by cedants to reinsurers on the actual composition of their portfolio was insufficiently granular to allow reinsurers to assess the residual silent cyber exposure in the portfolios they accepted.9
The implementation of LMA 21-042 had tangible effects on the pricing and conditions of property reinsurance treaties from the 2022 and 2023 renewals onward. Reinsurers began requiring cedants to provide a compliance declaration attesting that the ceded portfolio meets LMA 21-042 requirements. Some reinsurers inserted into treaty conditions termination or rate modification clauses in the event of cedant non-compliance.
On the pricing side, the clarification of the cyber perimeter in direct policies had a paradoxical effect on property reinsurance premiums. On one hand, the reduction in uncertainty about the coverage perimeter decreased the uncertainty loading that reinsurers implicitly applied to their rates. On the other, the explicit recognition that certain property policies now affirmed cyber coverage led some reinsurers to increase their premiums for treaty tranches likely to be hit by a systemic accumulation event, particularly the high-tower tranches of catastrophe XL programs.
The LMA 21-042 directive and the Y5258 bulletin requirements are binding for syndicates operating in the Lloyd's market. They do not, however, apply to continental European markets, American insurers, Asian markets or Bermuda. This regulatory asymmetry has created arbitrage opportunities: insurers operating outside the Lloyd's regulatory framework were able to continue underwriting non-life risks without explicit cyber affirmation or exclusion, capturing premiums that London syndicates could no longer accept without compliance.
Continental regulators, including EIOPA at the European level and the ACPR in France, published between 2021 and 2023 recommendations in the same direction as Lloyd's, but in the form of non-binding guidance rather than enforceable regulatory requirements. The Solvency II Directive does not, as of this date, contain any specific provision imposing on European insurers the same contractual clarity required by Lloyd's.10 This deficit of international regulatory convergence remains one of the major blind spots in the fight against silent cyber at the global scale.
LMA 21-042 compliance has progressed rapidly for large industrial risks, where underwriters and brokers have the legal and technical resources needed to revise contracts. It is much slower in the small and medium enterprise segment, where multi-risk business policies are often standardized products distributed through banking networks or generalist brokers who do not master the subtleties of cyber clauses. In this segment, residual silent cyber remains significant and poorly quantified in 2026, several years after the LMA framework came into force.
The CrowdStrike event of July 2024 opened a new chapter in the history of silent cyber. Having resolved, at least partially, the gray zone between "covered" and "excluded" through LMA 21-042, the market finds itself confronted with a second gray zone, the one opposing "malicious cyber" to "accidental cyber." Most exclusion clauses drafted between 2019 and 2023 exclude losses resulting from a cyberattack, that is, an intentional and hostile act. They do not exclude, or not explicitly, losses resulting from an accidental large-scale software failure, even if it simultaneously affects millions of systems.
This gap creates a situation symmetrical to that of the original silent cyber: insurers who sincerely believed they had excluded cyber risk from their property policies via a clause targeting malice discover they remain potentially exposed to large-scale accidental cyber events. The market began to respond to this problem in 2025, in particular through the revision of LMA clauses to incorporate broader wording targeting any "widespread IT failure" regardless of its origin, but this update is still far from universal.11
The normative history of silent cyber follows a logic of successive iterations in response to events that each time reveal a gap the previous generation of clauses had not anticipated. The first generation of clauses, inherited from the twentieth century, ignored cyber entirely. The second generation, stemming from LMA 21-042 and the LMA 9340-9341 clauses, resolved the problem of malicious cyber but left open the problem of accidental cyber. The third generation, currently under construction in 2025-2026, seeks to cover the full spectrum of systemic cyber events, whether intentional or not, while preserving the capacity of non-cyber insurers to underwrite physical risks without taking on unintentional cyber exposure.
This third generation will also need to resolve the question of coverage of physical consequences of cyberattacks on industrial systems, a subject that neither first nor second generation clauses have addressed satisfactorily. The cyber insurance market is still young; it has approximately twenty-five years of commercial existence compared to several centuries for maritime or fire insurance. It is likely that the next fifteen years will see as many normative developments as the past fifteen, as the digitalization of the physical economy continues to blur the boundaries between tangible and intangible risk.
1. Cambridge Centre for Risk Studies, University of Cambridge Judge Business School, Cyber risk outlook, 2019; Lloyd's of London, Realistic Disaster Scenarios for Cyber, 2020 edition.
2. White House Press Secretary, statement of February 15, 2018 attributing NotPetya to the Russian GRU; UK National Cyber Security Centre, joint statement, same date.
3. Mondelez International Inc. v. Zurich American Insurance Company, Circuit Court of Cook County, Illinois; out-of-court settlement announced October 2022.
4. Merck & Co. v. Ace American Insurance Company et al., Superior Court of New Jersey, Appellate Division, judgment of May 13, 2023. Indemnity amount: 1.4 billion dollars.
5. Lloyd's of London, Market Bulletin Y5258, Cyber risk and the Lloyd's market, January 10, 2019.
6. Lloyd's Market Association, Cyber guidance and model clauses, bulletin LMA 21-042, first quarter 2021.
7. Lloyd's Market Association, clause LMA 9340 (Cyber Attack Exclusion Clause) and LMA 9341 (Cyber and Data Exclusion); NMA 2914 (Electronic Data Endorsement A) and NMA 2915 (Electronic Data Endorsement B).
8. LMA Technical Committee, Cyber affirmation and exclusion: guidance on proximate and efficient cause, technical note, 2021.
9. Swiss Re Institute, Closing the silent cyber protection gap, sigma 3/2022.
10. EIOPA, Understanding cyber underwriting risk, thematic report, December 2023; ACPR Banque de France, Cyber risk in the insurance sector, analysis and synthesis no. 130, 2021.
11. Lloyd's Market Association, 2025 market notes on the revision of LMA 9340 and 9341 clauses to incorporate large-scale non-malicious cyber events.
Since 2018, the financial lines market has offered the purest textbook case of the underwriting cycle. A cleansing of supply collided with the fear of a wave of Covid-related claims to produce the most brutal hard market of the century.
Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.
Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.
A leader makes a decision, a merger, a launch, a restructuring. It fails, the shareholders lose money and sue them, personally. Their house, their savings are on the line. And yet they sleep soundly, because an insurance exists that covers them against the consequences of their own judgment.
A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.