Cyber

Accidental cyber

Cyber event caused by unintentional software or hardware failure, as opposed to malicious cyber resulting from a deliberate attack.

Definition

Accidental cyber refers to large-scale IT losses or outages resulting from human error, software bugs or hardware failures without hostile intent. The July 2024 CrowdStrike event, which took 8.5 million Windows systems offline via a defective update, is the paradigmatic example. The distinction is central to insurance: most cyber exclusion clauses drafted between 2019 and 2023 targeted only malicious cyber (cyberattack, intentional hostile act), leaving exposure to accidental systemic events unaddressed. LMA 9341 and clause revisions underway since 2025 aim to cover the full spectrum, including accidental cyber. The insurance stakes are significant: an accidental event simultaneously affecting a major cloud provider could exceed insured losses from a conventional malicious event.

Example

The defective CrowdStrike Channel File 291 update in July 2024: no malicious intent, no attacker, but 8.5 million systems simultaneously in BSoD and an estimated 5.4 to 10 billion dollars in insured losses: a purely accidental event that most cyber exclusion clauses then in force did not allow insurers to deny.

Related terms
Related articles
Also known as

cyber non malveillant, technology failure, défaillance informatique généralisée, non-malicious cyber