Malicious act using a computer system to cause harm, as opposed to an unintentional cyber incident. Central term in LMA 5400 and 5401 property clauses.
In LMA property clause terminology (LMA 5400 and 5401), a cyber act refers to a malicious act involving the use of a computer system to cause harm. This distinction between a cyber act (malicious) and a cyber incident (non-malicious or accidental) is fundamental to applying the write-back in LMA 5400. LMA 5400 excludes all losses linked to a cyber act, but reinstates physical damage caused by fire or explosion resulting from a non-malicious cyber incident. LMA 5401 excludes both without exception. The boundary between the two notions can be fine: a misconfiguration that causes a fire is a cyber incident; an intentional attack that provokes the same fire is a cyber act. In practice, establishing intent is often the central issue in claims handling. These concepts are distinct from the state-backed cyber operation notion used in the cyber war clauses (LMA 5564 to 5567).
A hacker takes control of the temperature regulation system of a server room and causes overheating that triggers a fire. This is a cyber act: malicious intent is established. The fire would not be covered under LMA 5400. If the overheating had resulted from an unintentional software fault, it would be a cyber incident, and the physical fire damage would be covered under the LMA 5400 write-back.
cyber act, malicious cyber act, acte cyber malveillant, acte informatique malveillant