03

Silent Cyber: from Gray Zone to Explicit Clause

Revisiting the Lloyd's LMA 21-042 directive and its implications for Property & Casualty reinsurance treaties

Silent CyberLloyd'sTreatyFinancial LinesMay 29, 2026

1. The Silence That Costs Billions

For several decades, non-life insurance policies were written in a world where the digital economy did not yet exist or was not perceived as a source of tangible losses. A property insurance policy covered physical damage caused by fire, explosion, weather events or theft; a professional liability policy covered errors and omissions in the conduct of an activity. Neither mentioned the word "cyber," simply because the question did not arise.

It is precisely this drafting legacy that created what the market calls silent cyber, or non-affirmative cyber: the set of cyber risk exposures embedded in classic policies without being explicitly named, priced, or, in the majority of cases, intentionally covered by the insurer. The contract's silence on the cyber question does not mean that coverage is excluded; in many legal systems, and particularly under English law, the absence of explicit exclusion can be interpreted as implicit inclusion. It is this contractual void that constitutes the very essence of the problem.

Operational definition Silent cyber refers to any exposure to cyber risk lodged in an insurance policy that contains neither an explicit affirmation clause of cyber coverage nor an explicit exclusion of it. The insurer therefore does not know, at the time of underwriting, whether or not they cover cyber; the policyholder, symmetrically, does not know whether they benefit from it. This bilateral uncertainty zone is both a prudential problem and a systematic litigation driver in the event of a loss.

The quantification of the global market's silent cyber exposure is, by nature, difficult to perform precisely, since by definition it is not tracked in insurers' underwriting systems. The most rigorous estimates, published by the Cambridge Centre for Risk Studies and cited by Lloyd's in its market publications, placed the overall non-life market's exposure to silent cyber at between 100 and 300 billion dollars in annual premiums at risk in 2019, of which an unknown but potentially very significant fraction carried unintentional cyber exposure.1

2. NotPetya as a Revelation: When the Gray Zone Becomes a Liability

The Attack That Changed Insurance Law

Before June 2017, silent cyber was a technical discussion topic in actuarial and legal circles of the London market. After NotPetya, it became an industrial emergency. The attack, attributed by the American, British and European governments to the Russian military intelligence service (GRU), propagated via the Ukrainian accounting software M.E.Doc and infected tens of thousands of systems belonging to companies operating in Ukraine before spreading globally through the internal networks of major multinational groups.2

Among the victims were names with no direct connection to Ukraine: food manufacturer Mondelez (estimated losses of 180 million dollars), pharmaceutical group Merck (870 million dollars), shipping company Maersk (300 million dollars) or Saint-Gobain (80 million euros). All had taken out property or assets insurance policies. None of these policies mentioned cyber.

$10B
estimated total
economic losses
from NotPetya
$870M
claim filed by
Merck alone
with its insurers
~40%
of NotPetya losses
initially refused
via "act of war" clause
2023
year of settlement
of the Merck litigation,
six years after the attack

The "Act of War" Clause: A Shield That Cracked

The insurers who had covered these companies via property policies massively invoked the "act of war" or "hostilities" exclusion clauses present in virtually all non-life policies since the early twentieth century. These clauses, designed to exclude physical destruction caused by armed conflicts between states, obviously addressed a very different context from the cyberattacks of the late 2010s. Zurich Insurance, Mondelez's main insurer, refused to indemnify by invoking this exclusion. The dispute was settled out of court in 2022 under undisclosed terms.3

The Merck case was even more resounding. The New Jersey trial court ruled in January 2022 that the "act of war" exclusion could not apply to a cyberattack, on the grounds that the hostility exclusion clauses written in the twentieth century targeted acts of kinetic hostility between nations, not cyber operations. This decision, confirmed on appeal in May 2023, compelled Merck's insurers to pay the full 1.4 billion dollars claimed, an amount far exceeding the premium received.4

These two cases outlined the contours of a structural problem. On one side, insurers who had underwritten industrial risks without ever intending to cover cyber and who found themselves exposed to massive losses. On the other, good-faith policyholders who had paid premiums for years and who discovered, at the time of the loss, that the boundary between coverage and exclusion was entirely dependent on the outcome of judicial litigation. This uncertainty was unsustainable for both parties.

3. The London Market's Response: From Bulletin Y5258 to the LMA 21-042 Directive

The Initial Wake-up Call: Bulletin Y5258

Lloyd's of London was the first insurance market to assess the problem systematically and impose a normative response on its syndicates. In January 2019, Lloyd's published market bulletin Y5258, the first binding text imposing on syndicates operating in the London market an explicit action on silent cyber in their portfolios.5 The bulletin formulates a simple principle, though complex in its execution: all policies underwritten by Lloyd's syndicates must, starting from the deadlines set by class of risk, either explicitly affirm that cyber is covered, or explicitly exclude it. Contractual neutrality, that is, silence, is no longer an acceptable option.

The timetable imposed by Y5258 is progressive. Property policies with physical damage coverage must comply with the new requirement from January 1, 2020; all other non-life insurance classes, by January 1, 2021 at the latest. The priority accorded to property policies is not arbitrary: it is precisely there that silent cyber exposure is financially heaviest, due to business interruption guarantees whose losses can reach considerable amounts.

June 2017 NotPetya attack. First massive disputes between insurers and policyholders over the scope of property policies.
January 2019 Lloyd's publishes bulletin Y5258: obligation to affirm or exclude cyber in all Lloyd's syndicates' treaties and policies.
January 2020 First Y5258 deadline: mandatory compliance for physical damage property policies.
January 2021 Second deadline: extension to all non-life classes. Publication by LMA of implementing directive 21-042 and associated model clauses.
January 2022 New Jersey court judgment in the Merck case: the "act of war" exclusion does not apply to state-sponsored cyberattacks. Lloyd's approach validated by the judicial outcome.
July 2024 CrowdStrike reveals a new gap: cyber exclusion clauses drafted around the notion of malicious act do not cover losses of non-intentional origin.

The LMA 21-042 Directive: Operationalizing the Principle

If Y5258 establishes the principle, it is the LMA 21-042 directive, published by the Lloyd's Market Association during the first quarter of 2021, that provides its technical operationalization. The LMA is the body representing underwriting syndicates in the London market and publishing the standardized model clauses used by the market. Directive 21-042 supports the compliance of all non-life classes by providing underwriters with a framework of pre-drafted clauses, legally validated and adapted to the various contractual situations encountered in practice.6

The directive explicitly distinguishes three situations in which an underwriter may find themselves facing a non-cyber risk. The first is pure exclusion: the underwriter decides that the policy will cover no loss whose principal or contributing cause is a cyber event, whatever its nature. The second is partial affirmation: the underwriter agrees to cover certain limitatively defined cyber consequences, while excluding others. The third, rarer but existing, is full affirmation: the underwriter decides to explicitly include the entirety of cyber risk in the policy, with adapted pricing and risk analysis. The directive specifies that the second option, partial affirmation, is the one requiring the most drafting vigilance, as the definition of included and excluded perimeters entirely determines coverage quality.

4. The Architecture of Clauses: Between Legal Precision and Residual Ambiguity Risk

LMA Exclusion Clauses: NMA 2914, LMA 9340 and Their Variants

The London market has a corpus of standardized clauses, the most commonly used for cyber exclusion being clause NMA 2914 (known as CL 380 in its maritime version), whose origins date to the 1990s and which has been progressively revised, and clause LMA 9340, more recent and more precisely drafted to cover cyberattacks in the contemporary sense.7 Both clauses rest on an identical mechanism: they exclude from the guarantee losses whose proximate or distal cause is a cyber event, defined as any malicious use of a computer system, network or electronic device.

The LMA 9340 clause presents a significant drafting advantage over its predecessors in that it precisely defines the terms "cyberattack" and "cyber incident," thereby avoiding the ambiguities of interpretation that had fueled litigation around "war and hostilities" clauses in the NotPetya cases. It also incorporates an explicit list of types of events covered by the exclusion, which considerably reduces the surface of potential litigation.

LMA 9341, a variant of the foregoing, goes further by excluding not only malicious cyberattacks but also non-malicious computer system failures, what one might call "accidental cyber." This extension is precisely what would have allowed insurers to defend themselves more easily against CrowdStrike-type losses, had the clause been systematically adopted. Yet in 2024, only a minority of property policies outside the Lloyd's market had incorporated this extended wording.

The Structural Limit of Malicious Exclusion Clauses Most cyber clauses drafted between 2019 and 2023 were built around the notion of malice, meaning they only exclude or affirm losses caused by an intentionally hostile act. This construction reflected the historical reality of cyber losses, dominated by ransomware and state-sponsored attacks. The CrowdStrike event of July 2024, whose origin is an accidental software failure without a malicious actor, revealed that this malice criterion created a new gray zone for large-scale losses of non-intentional origin.

The Challenge of Causal Proportionality in Mixed Losses

Beyond the choice of clause, the concrete implementation of the affirmation or exclusion principle runs into a causality problem in losses that combine a cyber and a physical component. Consider a concrete example: an attack on the industrial control system (SCADA) of a chemical plant causes an explosion and fire resulting in significant physical damage and business interruption losses. The proximate cause of the loss is physical (the explosion). The initial cause is cyber (the attack on the SCADA). Depending on whether the retained clause refers to the proximate cause or the efficient cause of the event, coverage applies or not.

This problem of causal proportionality is far from anecdotal. In practice it concerns an entire range of sectors where computer systems drive physical processes, including industry, energy, transportation, healthcare and urban infrastructure. LMA 21-042 recommends explicitly indicating in the retained clause whether it is the proximate or efficient cause that determines coverage application, but this recommendation has not been universally followed by underwriters.8

5. Implications for Property & Casualty Reinsurance Treaties

Risk Propagation Through the Reinsurance Chain

Silent cyber is not a problem that stops at the relationship between the direct insurer and their policyholder. It propagates mechanically through the reinsurance chain, sometimes invisibly, all the way to reinsurers who were never aware of the existence of a cyber exposure in the portfolio they accept under treaty. This propagation takes two main forms depending on the type of treaty involved.

In a quota share treaty (pro-rata), the reinsurer shares a fixed proportion of each premium and each loss in the ceded portfolio. If the direct insurer's portfolio contains an untracked silent cyber exposure, the reinsurer takes it on at their quota share level without having modeled or priced it. The risk is therefore directly linked to the quality of information transmitted by the cedant in the risk bordereaux, which prior to 2021 rarely mentioned the presence or absence of cyber exposure in individual risks.

In an excess of loss (XL) treaty, the situation is different but potentially more dangerous. The reinsurer does not share small losses but commits to indemnifying the cedant beyond a given retention. A systemic cyber event, such as NotPetya or CrowdStrike, generates numerous simultaneous losses that can collectively exceed the retention by amounts very difficult to anticipate if the reinsurer had not modeled the cyber accumulation in their cedant's portfolio. It is precisely this accumulation scenario in property XL treaties that constitutes the prudential nightmare of reinsurers since 2017.

Back-to-Back Alignment: An Unfinished Task

One of the most complex challenges posed by the LMA 21-042 directive for reinsurers is that of contractual coherence between direct policies and reinsurance treaties, what the jargon calls back-to-back coverage. Ideally, if the direct insurer has excluded cyber from their property policies, their reinsurance treaty should contain the same exclusion, and vice versa. Yet in market reality, this coherence is not automatic.

Several factors explain this gap. First, the renewal dates of direct policies and reinsurance treaties often do not coincide, creating time windows during which the direct policy has been updated but the treaty has not yet been. Second, multi-year treaties, common in certain segments of property reinsurance, locked in terms drafted before the LMA 21-042 directive came into force and can only be modified at contractual maturity. Third, and this is perhaps the most structural problem, the information transmitted by cedants to reinsurers on the actual composition of their portfolio was insufficiently granular to allow reinsurers to assess the residual silent cyber exposure in the portfolios they accepted.9

The Multi-Year Treaty Problem A significant proportion of property reinsurance treaties have three-to-five year terms, concluded before 2019. These treaties, unamended, continue to transfer silent cyber risk to reinsurers under conditions that no longer reflect either regulatory requirements or the current understanding of risk. Bringing these long-term treaties into compliance can only be achieved through endorsement or at maturity, leaving residual exposures that reinsurers struggle to precisely quantify.

Impact on Pricing and Treaty Conditions Post-2021

The implementation of LMA 21-042 had tangible effects on the pricing and conditions of property reinsurance treaties from the 2022 and 2023 renewals onward. Reinsurers began requiring cedants to provide a compliance declaration attesting that the ceded portfolio meets LMA 21-042 requirements. Some reinsurers inserted into treaty conditions termination or rate modification clauses in the event of cedant non-compliance.

On the pricing side, the clarification of the cyber perimeter in direct policies had a paradoxical effect on property reinsurance premiums. On one hand, the reduction in uncertainty about the coverage perimeter decreased the uncertainty loading that reinsurers implicitly applied to their rates. On the other, the explicit recognition that certain property policies now affirmed cyber coverage led some reinsurers to increase their premiums for treaty tranches likely to be hit by a systemic accumulation event, particularly the high-tower tranches of catastrophe XL programs.

6. What Remains Unresolved: The 2026 Horizon

International Divergence as a Regulatory Arbitrage Vector

The LMA 21-042 directive and the Y5258 bulletin requirements are binding for syndicates operating in the Lloyd's market. They do not, however, apply to continental European markets, American insurers, Asian markets or Bermuda. This regulatory asymmetry has created arbitrage opportunities: insurers operating outside the Lloyd's regulatory framework were able to continue underwriting non-life risks without explicit cyber affirmation or exclusion, capturing premiums that London syndicates could no longer accept without compliance.

Continental regulators, including EIOPA at the European level and the ACPR in France, published between 2021 and 2023 recommendations in the same direction as Lloyd's, but in the form of non-binding guidance rather than enforceable regulatory requirements. The Solvency II Directive does not, as of this date, contain any specific provision imposing on European insurers the same contractual clarity required by Lloyd's.10 This deficit of international regulatory convergence remains one of the major blind spots in the fight against silent cyber at the global scale.

Small and Medium Enterprises: A Market Largely Behind

LMA 21-042 compliance has progressed rapidly for large industrial risks, where underwriters and brokers have the legal and technical resources needed to revise contracts. It is much slower in the small and medium enterprise segment, where multi-risk business policies are often standardized products distributed through banking networks or generalist brokers who do not master the subtleties of cyber clauses. In this segment, residual silent cyber remains significant and poorly quantified in 2026, several years after the LMA framework came into force.

CrowdStrike and the Third Gray Zone: Non-Malicious Cyber

The CrowdStrike event of July 2024 opened a new chapter in the history of silent cyber. Having resolved, at least partially, the gray zone between "covered" and "excluded" through LMA 21-042, the market finds itself confronted with a second gray zone, the one opposing "malicious cyber" to "accidental cyber." Most exclusion clauses drafted between 2019 and 2023 exclude losses resulting from a cyberattack, that is, an intentional and hostile act. They do not exclude, or not explicitly, losses resulting from an accidental large-scale software failure, even if it simultaneously affects millions of systems.

This gap creates a situation symmetrical to that of the original silent cyber: insurers who sincerely believed they had excluded cyber risk from their property policies via a clause targeting malice discover they remain potentially exposed to large-scale accidental cyber events. The market began to respond to this problem in 2025, in particular through the revision of LMA clauses to incorporate broader wording targeting any "widespread IT failure" regardless of its origin, but this update is still far from universal.11

Towards a Third Generation of Cyber Clauses

The normative history of silent cyber follows a logic of successive iterations in response to events that each time reveal a gap the previous generation of clauses had not anticipated. The first generation of clauses, inherited from the twentieth century, ignored cyber entirely. The second generation, stemming from LMA 21-042 and the LMA 9340-9341 clauses, resolved the problem of malicious cyber but left open the problem of accidental cyber. The third generation, currently under construction in 2025-2026, seeks to cover the full spectrum of systemic cyber events, whether intentional or not, while preserving the capacity of non-cyber insurers to underwrite physical risks without taking on unintentional cyber exposure.

This third generation will also need to resolve the question of coverage of physical consequences of cyberattacks on industrial systems, a subject that neither first nor second generation clauses have addressed satisfactorily. The cyber insurance market is still young; it has approximately twenty-five years of commercial existence compared to several centuries for maritime or fire insurance. It is likely that the next fifteen years will see as many normative developments as the past fifteen, as the digitalization of the physical economy continues to blur the boundaries between tangible and intangible risk.


Sources and references

1. Cambridge Centre for Risk Studies, University of Cambridge Judge Business School, Cyber risk outlook, 2019; Lloyd's of London, Realistic Disaster Scenarios for Cyber, 2020 edition.

2. White House Press Secretary, statement of February 15, 2018 attributing NotPetya to the Russian GRU; UK National Cyber Security Centre, joint statement, same date.

3. Mondelez International Inc. v. Zurich American Insurance Company, Circuit Court of Cook County, Illinois; out-of-court settlement announced October 2022.

4. Merck & Co. v. Ace American Insurance Company et al., Superior Court of New Jersey, Appellate Division, judgment of May 13, 2023. Indemnity amount: 1.4 billion dollars.

5. Lloyd's of London, Market Bulletin Y5258, Cyber risk and the Lloyd's market, January 10, 2019.

6. Lloyd's Market Association, Cyber guidance and model clauses, bulletin LMA 21-042, first quarter 2021.

7. Lloyd's Market Association, clause LMA 9340 (Cyber Attack Exclusion Clause) and LMA 9341 (Cyber and Data Exclusion); NMA 2914 (Electronic Data Endorsement A) and NMA 2915 (Electronic Data Endorsement B).

8. LMA Technical Committee, Cyber affirmation and exclusion: guidance on proximate and efficient cause, technical note, 2021.

9. Swiss Re Institute, Closing the silent cyber protection gap, sigma 3/2022.

10. EIOPA, Understanding cyber underwriting risk, thematic report, December 2023; ACPR Banque de France, Cyber risk in the insurance sector, analysis and synthesis no. 130, 2021.

11. Lloyd's Market Association, 2025 market notes on the revision of LMA 9340 and 9341 clauses to incorporate large-scale non-malicious cyber events.

Related articles
09

The Financial Lines Market Post-Covid

Since 2018, the financial lines market has offered the purest textbook case of the underwriting cycle. A cleansing of supply collided with the fear of a wave of Covid-related claims to produce the most brutal hard market of the century.

Financial LinesD&O
Read →
07

Solvency II Tested by Cyber Risk

Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.

Solvency IICyber Risk
Read →
05

Ransomware as a Financial Asset

Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.

CyberRansomware
Read →
Editorials you might enjoy
HS06

Why bosses insure themselves against their own decisions

A leader makes a decision, a merger, a launch, a restructuring. It fails, the shareholders lose money and sue them, personally. Their house, their savings are on the line. And yet they sleep soundly, because an insurance exists that covers them against the consequences of their own judgment.

Financial LinesFinance
Read →
HS05

NIS2, the directive no one has read but that binds you anyway

A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.

LawCyber
Read →