12

Lloyd's Retreat from Hybrid War Risk

The war exclusion rested on an identifiable war. Hybrid war erases declaration, attribution, boundaries and the kinetic character, making the exclusion almost inapplicable. From NotPetya to Lloyd's retreat, how to insure a risk designed to remain without an author.

ReinsuranceCyber RiskSystemic RiskInsurabilitySeptember 4, 2026
$10bn
Global damage caused by NotPetya in 2017, of which $1.4bn for the Merck group alone
31 March 2023
Effective date of the Lloyd's exclusion of state-backed cyber-attacks in standalone cyber policies
$3.5tn
Global economic loss of a systemic cyber-attack on a payments system, over five years (Lloyd's)
11
Undersea cables damaged in the Baltic Sea since the start of 2024, with no established attribution

I.War, the Historical Frontier of Insurability

The fundamental risk par excellence

Of all the exclusions a contract of insurance contains, that of war is the oldest and the most stable. It dates back to the great conflicts of the twentieth century and has never been seriously questioned, for war embodies what insurance theory calls fundamental risk, as opposed to particular risk. An isolated fire strikes one insured without touching the others, and risk pooling works fully. War, on the contrary, strikes a very large number of insureds simultaneously, destroys entire classes of assets, escapes any stable statistical law and results from a deliberate human will that no insurer can control or foresee. No premium could finance such an accumulation of correlated losses, and that is why war has always been held to be structurally uninsurable1.

Four properties that made the exclusion workable

If the war exclusion functioned so well for a century, it is not only because war was serious, it is because war was identifiable. Classical war possessed four properties that made it possible to say, without too much hesitation, whether a loss arose from war or not. It was declared, or at least openly assumed by a state. It was attributable, the belligerent being known and claiming its acts. It was bounded, in space by fronts and in time by a beginning and an end. It was finally kinetic, made of explosives, armor and troops, leaving indisputable physical traces. These four properties made the exclusion an applicable clause, because the question of whether a loss resulted from war admitted an answer. It is precisely this answer that hybrid war renders unfindable.

II.Hybrid War, or the Dissolution of the Categories

A war that stays below the threshold

Hybrid war, sometimes called gray-zone conflict, designates the set of operations that remain short of open conflict while imposing considerable costs and uncertainty on the adversary. It is waged through cyber-attacks, sabotage of infrastructure, jamming of navigation signals, disinformation, by any means that wounds without crossing the formal threshold of war. Since the start of 2024, at least eleven undersea communication and power cables have been damaged in the Baltic Sea, and informal NATO sources point to a significant share of transatlantic cables affected by suspicious causes2. These attacks, conducted by means of a shadow fleet of ships under flags of convenience dragging their anchors along the seabed, illustrate a deliberately ambiguous strategy, of low cost and high reward.

The four properties erased

The stake for insurance is that hybrid war methodically erases the four properties on which the exclusion rested. It is not declared, since it stays below the threshold of assumed conflict. It is not attributable, its authors resorting to intermediaries, ships under third-country flags, criminal or diaspora groups, to blur responsibility. It is not bounded, for a cyber operation spreads without borders and a cable sabotage produces chain effects far beyond its target. It is not kinetic, often leaving only a line of code or an anchor that one may say was dragged by accident. The episode of the ship seized and then released by Sweden in early 2025, for want of being able to prove intent, sums up this indeterminacy3. The founding question of the exclusion, does this loss arise from war, then becomes a question without a certain answer.

From crime to war, a continuum

To these four erasures is added a more insidious confusion, the one that blurs the line between criminality, espionage and war. Ransomware offers the clearest example of this murky zone. An attack may be carried out by a criminal group acting for profit, but tolerated, sheltered or steered by a state that finds a strategic interest in it. Should it then be treated as an act of delinquency, covered by the cyber policy, or as a state operation that an exclusion carves out. Reality presents itself less as a clean boundary than as a continuum, where each attack blends varying degrees of pecuniary motive and state interest. Yet the exclusion presupposes a binary cut, the attack is state-backed or it is not, where the phenomenon is by nature gradual. This mismatch between the binary logic of the clause and the continuous nature of the threat is one of the deepest sources of coverage uncertainty.

III.NotPetya, the Precedent That Triggered Everything

A weapon of war that overflows the battlefield

This dissolution is not an abstraction, it has already cost billions and nearly destabilized the market. On 27 June 2017, on the eve of Ukraine's national day, a malware named NotPetya, introduced through the update of a Ukrainian accounting software, spread to more than sixty countries within hours, causing around ten billion dollars of global damage4. The United States attributed it in 2018 to Russian military intelligence, and US justice indicted six GRU officers in 2020. The pharmaceutical group Merck lost around 1.4 billion dollars, the Mondelez group more than one hundred million, the carrier Maersk, which handles nearly a fifth of world trade, between two hundred and fifty and three hundred million. A weapon designed to strike Ukraine had overflowed onto the world economy, exposing insurers who had never priced such a risk.

The paralysis of Maersk concretely illustrates this overflow. Within hours, the shipping group saw almost all of its computer systems go dark across the world, forcing its port terminals to a halt and disrupting a notable fraction of global maritime trade, even though the company had no connection with the Ukrainian conflict. This uncontrolled propagation effect is the signature of cyber war risk, for a cyber weapon, unlike a missile, knows no bounded target and spreads blindly through interconnected software chains. The war loss, once confined to a theater of operations, thus becomes planetary, and it is this absence of boundary that forbids any classical pooling.

The ruling that sounded the alarm

Merck claimed indemnification under its all-risks property policies, endowed with 1.75 billion dollars of coverage, and its eight insurers, among which were Lloyd's syndicates, refused to pay nearly 700 million by invoking the exclusion of hostile or warlike acts5. In January 2022, the Superior Court of New Jersey ruled against them, holding that this exclusion, drafted for classical armed conflict, could not target a cyber-attack, and that the insured could not reasonably expect it to carve out such a loss. The court of appeal upheld this reasoning in 2023, characterizing NotPetya as a non-military cyber-attack directed against an accounting software provider, and not a hostile or warlike act within the meaning of the clause. The insurers finally settled in early 2024 to avoid an unfavourable precedent imposing itself on the whole market.

THE LESSON OF THE MERCK PRECEDENT
The NotPetya case revealed a disturbing truth. War exclusions inherited from the kinetic era, written for tanks and bombardments, do not apply to a digital attack in the eyes of the judges. As long as the clause does not explicitly mention cyber and attribution, the ambiguity benefits the policyholder, and the insurer finds itself covering, without having intended or priced it, an accumulation of losses of state origin. The market understood that it could no longer rely on clauses conceived for another war.

IV.Lloyd's Response, Redrawing the Frontier

The exclusion of state-backed cyber-attacks

The response of the London market matched the alarm. Through its market bulletin Y5381 of 16 August 2022, Lloyd's required that, from 31 March 2023, every standalone cyber policy contain a clause excluding losses resulting from a state-backed cyber-attack6. The clause had to carve out losses arising from war, declared or not, in the absence of a separate war exclusion, as well as state-backed cyber-attacks liable to significantly impair the functioning of a state or its security capabilities, and rest on a robust attribution mechanism. This directive was not a mere drafting precaution, it expressed a deeper fear, that of systemic accumulation.

The dread of the systemic loss

The figure that haunts underwriters is known. According to a modeling conducted by Lloyd's with the Cambridge Centre for Risk Studies, a cyber-attack on a major payments system could cost the world economy up to 3,500 billion dollars over five years, of which 1,100 billion for the United States alone, where the global cyber insurance market amounted to only around 9 billion dollars in premiums9. This dizzying disproportion, between a potential loss of several thousand billion and an insurance capacity of a few billion, explains the retreat. To frame the risk, the Lloyd's Market Association published a series of model clauses, whose gradation reveals the difficulty of the exercise7.

The gradation of the LMA exclusions, from the policyholder's view
LMA5564, total exclusionExcludes any state-backed cyber-attack · unused in practice
Intermediate clauses (5565, 5566)Exclusion tied to the impairment of the state
LMA5567, the most widespreadExcludes only on major impact to the host state
B versions, without attributionSet aside by bulletin Y5381

This gradation shows that Lloyd's did not seek to exclude every state-backed cyber-attack, which the broadest clause would have allowed but which the market does not use, but only the most devastating, those that strike a state in its functioning. A later bulletin, Y5433, refined this apparatus in 2024 without relaxing it, extending its scope to multi-line policies and requiring, in order to cover a cyber-attack carried out within a conventional war, a distinct and explicit grant of coverage8. The market thus redrew, clause by clause, the frontier of what it agrees to bear.

This movement constitutes a second front, after that of silent cyber. The London market had first sought, through the so-called affirmative cyber clauses, to drive cyber risk out of the traditional policies that covered it without naming it, a subject already treated in this series12. The exclusion of state-backed war takes this logic one step further, by addressing not ordinary cyber but its most catastrophic fringe, that of state origin. In both cases, the approach is the same, to turn an implicit and unpriced exposure into an explicit and delimited guarantee, even at the price of carving out the share deemed too heavy. The management of hybrid war risk is therefore part of a wider effort of clarification, by which the market tries to regain control of what it actually insures.

V.The Impasse of Attribution

To exclude is to name a culprit

This whole construction rests on a fragile premise, namely that one will be able to say, when the time comes, that an attack indeed emanates from a state. Yet attribution is the most difficult operation in the entire cyber field, and hybrid war is precisely designed to make it impossible. The clauses retain as the primary factor the attribution issued by the government of the state where the affected system is located, but governments publicly attribute only rare attacks, out of reluctance to disclose their sources and out of fear of diplomatic repercussions10. Failing that, the clauses fall back on an objectively reasonable inference, a formula that transfers to the insurer and the insured the burden of a characterization that the states themselves evade.

This mechanism places the insurer in a singular, almost sovereign position. By arrogating to itself the right to decide that an attack emanates from a state, for want of governmental attribution, it sets itself up as judge of an eminently political question, one that engages relations between nations and that foreign offices handle with extreme caution. A London underwriter would thus have to settle, in order to refuse an indemnity, what a foreign ministry refrains from publicly asserting. This confusion of roles, where the insurance technician is called upon to make a geopolitical judgment, weakens the clause as much as it exposes the insurer to interminable disputes, each attribution becoming a field of litigation.

The gap between the loss and its attribution

To this is added a ruinous temporal gap. NotPetya was officially attributed to Russia only in 2018, nearly a year after the events, and the indictment of the responsible officers took three years. How can a loss be settled whose characterization, and therefore coverage, depends on an attribution that may never come, or only years later. The deniability that defines hybrid war is not a side effect, it is its principal weapon, and it is also what disarms the exclusion. By refusing to declare itself, the adversary deprives the insurer of the fact on which the whole clause rested. The cable sabotages in the Baltic, where one still hesitates to distinguish the act of war from mere maritime negligence, show this impasse at work in real time.

ONE CANNOT EXCLUDE WHAT ONE CANNOT NAME
The exclusion of state war presupposes that the state origin of the attack can be established. But hybrid war has made the indeterminacy of its origin its very principle of operation. The insurer is therefore faced with a clause whose condition of application, attribution, is precisely what the adversary works to render undemonstrable. The exclusion does not remove uncertainty, it shifts it toward the question, without reliable answer, of who struck.

VI.Toward a Public Backstop and the Limit of the Insurable

The precedent of terrorism

If hybrid war exceeds the market's capacity, the question becomes who will bear the burden. The history of insurance offers an illuminating precedent, that of terrorism. After waves of attacks that became uninsurable by the market alone, several states put in place public or mixed last-resort schemes, Pool Re in the United Kingdom, the TRIA program in the United States, GAREAT in France, through which the public authority takes on the catastrophic share of the risk that insurers cannot absorb11. These mechanisms rest on a simple idea, certain risks are too correlated and too massive for private pooling, and only the community can be their insurer of last resort.

The question of the cyber backstop

An identical debate has opened for catastrophic cyber. The idea of a federal public backstop, which would intervene after the most devastating attacks, has been raised as far as the American national cybersecurity strategy, but it is only at the stage of exploration11. This question extends a recurring motif of this series, already encountered in relation to climate risk and catastrophe bonds, that of recourse to public support for the uninsurable share of a risk that has become too large. Lloyd's retreat from hybrid war is, in this perspective, neither an abdication nor an admission of powerlessness, but the lucid delimitation of the place where private insurability stops and where collective solidarity must take over.

Such a backstop would nonetheless run into the same obstacle as the exclusion it would complete. For a public scheme to be triggered, the event that activates it must be defined, and any definition of a catastrophic cyber war runs once again into attribution and characterization. A backstop that is too broad would amount to subsidizing the imprudence of the least protected organizations, creating moral hazard, while one that is too narrow would leave without relief the victims of an attack whose state origin remained undemonstrable. The design of public support for cyber risk therefore does not make the central difficulty disappear, it shifts it from the insurance policy to the law, without resolving it.

A PUBLIC BACKSTOP DOES NOT ABOLISH AMBIGUITY
Transferring the uninsurable share of hybrid war to the public authority does not dissolve the problem of attribution, it changes its recipient. The state will in turn have to decide, and at the same moment of uncertainty, whether an attack arises from war. The question the insurer could not settle, the community will not settle more easily, for it is inscribed in the very nature of a threat designed to remain without an author.

Insuring the knowable, not the ambiguous

At the close of this analysis, a deeper truth emerges about the very nature of insurance. The frontier of the insurable has always coincided with the frontier of the knowable, for one prices only what one can measure, and one indemnifies only what one can characterize. Classical war, however terrible, remained knowable, and its exclusion workable. Hybrid war is entirely built to be unknowable, undeclared to escape the law of war, unattributable to escape responsibility, ambiguous to escape characterization. By withdrawing from this terrain, the market is not fleeing a risk too heavy, it is acknowledging that it cannot insure ambiguity itself. The real question of the years to come is therefore not whether one will learn to draft exclusions better, but who will bear a risk whose author has made indeterminacy his strategy, and how far a society can leave without a guarantor the share of war that now hides beneath the appearances of peace.

June 2017 NotPetya causes around $10bn of global damage, attributed the following year to Russian military intelligence.
January 2022 The Superior Court of New Jersey sets aside the war exclusion in the Merck case, deemed inapplicable to a cyber-attack.
August 2022 Lloyd's publishes bulletin Y5381 mandating the exclusion of state-backed cyber-attacks in standalone cyber policies.
31 March 2023 Entry into force of the exclusion, resting on the LMA model clauses and their attribution mechanism.
October 2023 Lloyd's puts the impact of a systemic cyber-attack on a payments system at $3.5tn over five years.
Since 2024 A multiplication of undersea cable sabotages in the Baltic, with no established attribution, illustrating hybrid war.
SOURCES AND REFERENCES
  1. On war as fundamental risk, as opposed to particular risk, and on the antiquity of the war exclusion inherited from the conflicts of the twentieth century, classical insurance literature; the correlated, catastrophic, non-diversifiable and deliberate character of war risk, rendering it structurally uninsurable.
  2. Truman National Security Project, CEPA and GLOBSEC, analyses of hybrid war and gray-zone operations remaining short of open conflict; since the start of 2024, at least eleven undersea cables damaged in the Baltic Sea, a significant share of transatlantic cables affected according to informal NATO sources; shadow fleet, flags of convenience, diaspora and criminal proxies, Sino-Russian coordination; around one thousand instances of Russian vessels loitering; jamming of navigation signals.
  3. Baltic Sea cable incidents, November 2024, BCS East-West and C-Lion1 near the Chinese vessel Yi Peng 3; Christmas Day 2024, Estlink 2 and four telecommunications cables near the shadow-fleet vessel Eagle S; Balticconnector in 2023 by the vessel Newnew Polar Bear; Taiwan cables in early 2025; seizure and release by Sweden of the vessel Vezhen in February 2025, the damage having been deemed accidental.
  4. NotPetya, 27 June 2017, introduced through the update of a Ukrainian accounting software and spread to more than sixty countries, around $10bn of global damage; public US attribution to Russia's GRU in 2018, indictment of six officers in October 2020; losses of Maersk between $250m and $300m, of Mondelez more than $100m, of FedEx's TNT subsidiary around $400m.
  5. Merck v. ACE American and others, eight insurers including Lloyd's syndicates, all-risks property policies with $1.75bn of coverage and a $150m deductible, around $700m disputed; Superior Court of New Jersey, Judge Thomas J. Walsh, 13 January 2022; New Jersey court of appeal, May 2023, characterizing NotPetya as a non-military cyber-attack and setting aside the exclusion of hostile or warlike acts; settlement in early 2024 on undisclosed terms.
  6. Lloyd's, market bulletin Y5381 of 16 August 2022, effective 31 March 2023; obligation for every standalone cyber policy, risk codes CY and CZ, to exclude state-backed cyber-attacks; exclusion of war losses, declared or not, in the absence of a separate exclusion, of cyber-attacks significantly impairing the functioning or security of a state, and requirement of a robust attribution mechanism.
  7. Lloyd's Market Association model clauses, LMA5564 to LMA5567, published on 25 November 2021 and revised in January 2023; A versions incorporating attribution and compliant, B versions non-compliant without prior agreement; gradation from the broadest clause, LMA5564 excluding any state-backed cyber-attack but unused, to the most widespread, LMA5567, excluding only on a major impact to the state where the insured assets are located.
  8. Lloyd's, market bulletin Y5433, 2024; clauses ranked by type and phased in since 31 October 2023; extension to multi-line policies containing a cyber section; no relaxation of the approach; from 1 January 2025, coverage of cyber-attacks carried out within a conventional war made subject to a distinct and explicit grant of coverage.
  9. Lloyd's and Cambridge Centre for Risk Studies, systemic risk scenario, October 2023; global economic loss of $3.5tn over five years on a weighted average, between $2.3tn and $16tn depending on severity, of which $1.1tn for the United States, $470bn for China and $200bn for Japan; global cyber insurance market estimated at around $9.2bn in premiums in 2022; more than a fifth of the world's cyber premium placed at Lloyd's.
  10. On attribution as the central difficulty, Guy Carpenter and law-firm analyses of war exclusions applied to cyber operations; primary attribution by the government of the state where the affected system is located, rarity of public attributions out of reluctance to disclose sources and fear of reprisals, subsidiary mechanism of objectively reasonable inference.
  11. On public or mixed last-resort schemes facing catastrophic risks, Pool Re in the United Kingdom, the TRIA program in the United States and GAREAT in France for terrorism; debate on a public backstop for catastrophic cyber raised in the American national cybersecurity strategy at the stage of exploration; on recourse to public support for the uninsurable share, see articles 05 and 06 of this series, AlgoPolis.
  12. On silent cyber and the move to affirmative coverage, as well as on the LMA 21-042 clauses, see article 03 of this series, AlgoPolis; on systemic accumulation risk, see article 02; on catastrophe bonds applied to cyber, see article 29 forthcoming.
Related articles
02

CrowdStrike and Systemic Accumulation Risk

How an endpoint update becomes a global single point of failure and rewrites reinsurers' cyber PML models

ReinsuranceAccumulation
Read →
03

Silent Cyber: from Gray Zone to Explicit Clause

Revisiting the Lloyd's LMA 21-042 directive and its implications for Property & Casualty reinsurance treaties

Silent CyberLloyd's
Read →
05

Ransomware as a Financial Asset

Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.

CyberRansomware
Read →
Editorials you might enjoy
HS09

When insuring war becomes impossible

A power grid goes dark, a hospital freezes under a ransom. Crime, disaster, or act of war. On the answer hangs everything, because if it is crime your policy pays, and if it is war it does not. And those who launched the attack have arranged that no one can tell.

ReinsuranceCyber Risk
Read →
HS02

Why your insurer no longer wants your house

One morning, a letter tells you your home will not be reinsured. You have done nothing wrong, your house has not changed. What has changed is that chance, the thing all insurance rests on, has quietly left your postcode.

Climate RiskInsurability
Read →
Stay informed

Follow the research

One analysis with every new publication, on insurance, reinsurance, cyber and AI. No account, no noise.

No spam, one-click unsubscribe, no data ever sold.