Back to glossaryCyber

Bystanding cyber asset

A computer system of the insured or its service providers located outside an impacted state but affected by the collateral effects of a state-backed cyber operation.

Definition

The bystanding cyber asset concept, as used in LMA 5567 clauses, refers to a computer system belonging to the insured or its third-party service providers that is not physically located in a state impacted by a state-backed cyber operation, but that nonetheless suffers damage or disruption through propagation or network dependency effects. The central question for the insurer is whether the exclusion linked to the impacted state also applies to these peripheral assets. LMA 5567A answers in the negative: paragraph 1.3 does not apply to systems outside the impacted zone, which constitutes the bystanding write-back, a mechanism that preserves cover for an insured whose assets are located abroad or in the cloud but affected indirectly. The Hamilton variant reverses this logic by rewriting paragraph 1.3 to exclude those third-party assets as well, bringing effective cover close to LMA 5566 level. This doctrinal point is one of the most debated on the cyber market, as it determines the real value of the policy for multinational or heavily cloud-dependent companies.

Example

A French bank whose processing systems are hosted by an Irish cloud provider suffers disruptions during a state-backed cyberattack targeting Ukrainian financial infrastructure. Its systems are not located in Ukraine (the impacted state) but are indirectly affected. Under LMA 5567A, the bystanding write-back preserves cover. Under the Hamilton variant, the exclusion also applies to those third-party assets.

Related terms
Related articles
Also known as

actif cyber collatéral, write-back bystanding, bystanding