The war exclusion rested on an identifiable war. Hybrid war erases declaration, attribution, boundaries and the kinetic character, making the exclusion almost inapplicable. From NotPetya to Lloyd's retreat, how to insure a risk designed to remain without an author.
Of all the exclusions a contract of insurance contains, that of war is the oldest and the most stable. It dates back to the great conflicts of the twentieth century and has never been seriously questioned, for war embodies what insurance theory calls fundamental risk, as opposed to particular risk. An isolated fire strikes one insured without touching the others, and risk pooling works fully. War, on the contrary, strikes a very large number of insureds simultaneously, destroys entire classes of assets, escapes any stable statistical law and results from a deliberate human will that no insurer can control or foresee. No premium could finance such an accumulation of correlated losses, and that is why war has always been held to be structurally uninsurable1.
If the war exclusion functioned so well for a century, it is not only because war was serious, it is because war was identifiable. Classical war possessed four properties that made it possible to say, without too much hesitation, whether a loss arose from war or not. It was declared, or at least openly assumed by a state. It was attributable, the belligerent being known and claiming its acts. It was bounded, in space by fronts and in time by a beginning and an end. It was finally kinetic, made of explosives, armor and troops, leaving indisputable physical traces. These four properties made the exclusion an applicable clause, because the question of whether a loss resulted from war admitted an answer. It is precisely this answer that hybrid war renders unfindable.
Hybrid war, sometimes called gray-zone conflict, designates the set of operations that remain short of open conflict while imposing considerable costs and uncertainty on the adversary. It is waged through cyber-attacks, sabotage of infrastructure, jamming of navigation signals, disinformation, by any means that wounds without crossing the formal threshold of war. Since the start of 2024, at least eleven undersea communication and power cables have been damaged in the Baltic Sea, and informal NATO sources point to a significant share of transatlantic cables affected by suspicious causes2. These attacks, conducted by means of a shadow fleet of ships under flags of convenience dragging their anchors along the seabed, illustrate a deliberately ambiguous strategy, of low cost and high reward.
The stake for insurance is that hybrid war methodically erases the four properties on which the exclusion rested. It is not declared, since it stays below the threshold of assumed conflict. It is not attributable, its authors resorting to intermediaries, ships under third-country flags, criminal or diaspora groups, to blur responsibility. It is not bounded, for a cyber operation spreads without borders and a cable sabotage produces chain effects far beyond its target. It is not kinetic, often leaving only a line of code or an anchor that one may say was dragged by accident. The episode of the ship seized and then released by Sweden in early 2025, for want of being able to prove intent, sums up this indeterminacy3. The founding question of the exclusion, does this loss arise from war, then becomes a question without a certain answer.
To these four erasures is added a more insidious confusion, the one that blurs the line between criminality, espionage and war. Ransomware offers the clearest example of this murky zone. An attack may be carried out by a criminal group acting for profit, but tolerated, sheltered or steered by a state that finds a strategic interest in it. Should it then be treated as an act of delinquency, covered by the cyber policy, or as a state operation that an exclusion carves out. Reality presents itself less as a clean boundary than as a continuum, where each attack blends varying degrees of pecuniary motive and state interest. Yet the exclusion presupposes a binary cut, the attack is state-backed or it is not, where the phenomenon is by nature gradual. This mismatch between the binary logic of the clause and the continuous nature of the threat is one of the deepest sources of coverage uncertainty.
This dissolution is not an abstraction, it has already cost billions and nearly destabilized the market. On 27 June 2017, on the eve of Ukraine's national day, a malware named NotPetya, introduced through the update of a Ukrainian accounting software, spread to more than sixty countries within hours, causing around ten billion dollars of global damage4. The United States attributed it in 2018 to Russian military intelligence, and US justice indicted six GRU officers in 2020. The pharmaceutical group Merck lost around 1.4 billion dollars, the Mondelez group more than one hundred million, the carrier Maersk, which handles nearly a fifth of world trade, between two hundred and fifty and three hundred million. A weapon designed to strike Ukraine had overflowed onto the world economy, exposing insurers who had never priced such a risk.
The paralysis of Maersk concretely illustrates this overflow. Within hours, the shipping group saw almost all of its computer systems go dark across the world, forcing its port terminals to a halt and disrupting a notable fraction of global maritime trade, even though the company had no connection with the Ukrainian conflict. This uncontrolled propagation effect is the signature of cyber war risk, for a cyber weapon, unlike a missile, knows no bounded target and spreads blindly through interconnected software chains. The war loss, once confined to a theater of operations, thus becomes planetary, and it is this absence of boundary that forbids any classical pooling.
Merck claimed indemnification under its all-risks property policies, endowed with 1.75 billion dollars of coverage, and its eight insurers, among which were Lloyd's syndicates, refused to pay nearly 700 million by invoking the exclusion of hostile or warlike acts5. In January 2022, the Superior Court of New Jersey ruled against them, holding that this exclusion, drafted for classical armed conflict, could not target a cyber-attack, and that the insured could not reasonably expect it to carve out such a loss. The court of appeal upheld this reasoning in 2023, characterizing NotPetya as a non-military cyber-attack directed against an accounting software provider, and not a hostile or warlike act within the meaning of the clause. The insurers finally settled in early 2024 to avoid an unfavourable precedent imposing itself on the whole market.
The response of the London market matched the alarm. Through its market bulletin Y5381 of 16 August 2022, Lloyd's required that, from 31 March 2023, every standalone cyber policy contain a clause excluding losses resulting from a state-backed cyber-attack6. The clause had to carve out losses arising from war, declared or not, in the absence of a separate war exclusion, as well as state-backed cyber-attacks liable to significantly impair the functioning of a state or its security capabilities, and rest on a robust attribution mechanism. This directive was not a mere drafting precaution, it expressed a deeper fear, that of systemic accumulation.
The figure that haunts underwriters is known. According to a modeling conducted by Lloyd's with the Cambridge Centre for Risk Studies, a cyber-attack on a major payments system could cost the world economy up to 3,500 billion dollars over five years, of which 1,100 billion for the United States alone, where the global cyber insurance market amounted to only around 9 billion dollars in premiums9. This dizzying disproportion, between a potential loss of several thousand billion and an insurance capacity of a few billion, explains the retreat. To frame the risk, the Lloyd's Market Association published a series of model clauses, whose gradation reveals the difficulty of the exercise7.
This gradation shows that Lloyd's did not seek to exclude every state-backed cyber-attack, which the broadest clause would have allowed but which the market does not use, but only the most devastating, those that strike a state in its functioning. A later bulletin, Y5433, refined this apparatus in 2024 without relaxing it, extending its scope to multi-line policies and requiring, in order to cover a cyber-attack carried out within a conventional war, a distinct and explicit grant of coverage8. The market thus redrew, clause by clause, the frontier of what it agrees to bear.
This movement constitutes a second front, after that of silent cyber. The London market had first sought, through the so-called affirmative cyber clauses, to drive cyber risk out of the traditional policies that covered it without naming it, a subject already treated in this series12. The exclusion of state-backed war takes this logic one step further, by addressing not ordinary cyber but its most catastrophic fringe, that of state origin. In both cases, the approach is the same, to turn an implicit and unpriced exposure into an explicit and delimited guarantee, even at the price of carving out the share deemed too heavy. The management of hybrid war risk is therefore part of a wider effort of clarification, by which the market tries to regain control of what it actually insures.
This whole construction rests on a fragile premise, namely that one will be able to say, when the time comes, that an attack indeed emanates from a state. Yet attribution is the most difficult operation in the entire cyber field, and hybrid war is precisely designed to make it impossible. The clauses retain as the primary factor the attribution issued by the government of the state where the affected system is located, but governments publicly attribute only rare attacks, out of reluctance to disclose their sources and out of fear of diplomatic repercussions10. Failing that, the clauses fall back on an objectively reasonable inference, a formula that transfers to the insurer and the insured the burden of a characterization that the states themselves evade.
This mechanism places the insurer in a singular, almost sovereign position. By arrogating to itself the right to decide that an attack emanates from a state, for want of governmental attribution, it sets itself up as judge of an eminently political question, one that engages relations between nations and that foreign offices handle with extreme caution. A London underwriter would thus have to settle, in order to refuse an indemnity, what a foreign ministry refrains from publicly asserting. This confusion of roles, where the insurance technician is called upon to make a geopolitical judgment, weakens the clause as much as it exposes the insurer to interminable disputes, each attribution becoming a field of litigation.
To this is added a ruinous temporal gap. NotPetya was officially attributed to Russia only in 2018, nearly a year after the events, and the indictment of the responsible officers took three years. How can a loss be settled whose characterization, and therefore coverage, depends on an attribution that may never come, or only years later. The deniability that defines hybrid war is not a side effect, it is its principal weapon, and it is also what disarms the exclusion. By refusing to declare itself, the adversary deprives the insurer of the fact on which the whole clause rested. The cable sabotages in the Baltic, where one still hesitates to distinguish the act of war from mere maritime negligence, show this impasse at work in real time.
If hybrid war exceeds the market's capacity, the question becomes who will bear the burden. The history of insurance offers an illuminating precedent, that of terrorism. After waves of attacks that became uninsurable by the market alone, several states put in place public or mixed last-resort schemes, Pool Re in the United Kingdom, the TRIA program in the United States, GAREAT in France, through which the public authority takes on the catastrophic share of the risk that insurers cannot absorb11. These mechanisms rest on a simple idea, certain risks are too correlated and too massive for private pooling, and only the community can be their insurer of last resort.
An identical debate has opened for catastrophic cyber. The idea of a federal public backstop, which would intervene after the most devastating attacks, has been raised as far as the American national cybersecurity strategy, but it is only at the stage of exploration11. This question extends a recurring motif of this series, already encountered in relation to climate risk and catastrophe bonds, that of recourse to public support for the uninsurable share of a risk that has become too large. Lloyd's retreat from hybrid war is, in this perspective, neither an abdication nor an admission of powerlessness, but the lucid delimitation of the place where private insurability stops and where collective solidarity must take over.
Such a backstop would nonetheless run into the same obstacle as the exclusion it would complete. For a public scheme to be triggered, the event that activates it must be defined, and any definition of a catastrophic cyber war runs once again into attribution and characterization. A backstop that is too broad would amount to subsidizing the imprudence of the least protected organizations, creating moral hazard, while one that is too narrow would leave without relief the victims of an attack whose state origin remained undemonstrable. The design of public support for cyber risk therefore does not make the central difficulty disappear, it shifts it from the insurance policy to the law, without resolving it.
At the close of this analysis, a deeper truth emerges about the very nature of insurance. The frontier of the insurable has always coincided with the frontier of the knowable, for one prices only what one can measure, and one indemnifies only what one can characterize. Classical war, however terrible, remained knowable, and its exclusion workable. Hybrid war is entirely built to be unknowable, undeclared to escape the law of war, unattributable to escape responsibility, ambiguous to escape characterization. By withdrawing from this terrain, the market is not fleeing a risk too heavy, it is acknowledging that it cannot insure ambiguity itself. The real question of the years to come is therefore not whether one will learn to draft exclusions better, but who will bear a risk whose author has made indeterminacy his strategy, and how far a society can leave without a guarantor the share of war that now hides beneath the appearances of peace.
How an endpoint update becomes a global single point of failure and rewrites reinsurers' cyber PML models
Revisiting the Lloyd's LMA 21-042 directive and its implications for Property & Casualty reinsurance treaties
Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.
A power grid goes dark, a hospital freezes under a ransom. Crime, disaster, or act of war. On the answer hangs everything, because if it is crime your policy pays, and if it is war it does not. And those who launched the attack have arranged that no one can tell.
One morning, a letter tells you your home will not be reinsured. You have done nothing wrong, your house has not changed. What has changed is that chance, the thing all insurance rests on, has quietly left your postcode.
One analysis with every new publication, on insurance, reinsurance, cyber and AI. No account, no noise.
No spam, one-click unsubscribe, no data ever sold.