Back to glossaryCyber

Cyber act

Malicious act using a computer system to cause harm, as opposed to an unintentional cyber incident. Central term in LMA 5400 and 5401 property clauses.

Definition

In LMA property clause terminology (LMA 5400 and 5401), a cyber act refers to a malicious act involving the use of a computer system to cause harm. This distinction between a cyber act (malicious) and a cyber incident (non-malicious or accidental) is fundamental to applying the write-back in LMA 5400. LMA 5400 excludes all losses linked to a cyber act, but reinstates physical damage caused by fire or explosion resulting from a non-malicious cyber incident. LMA 5401 excludes both without exception. The boundary between the two notions can be fine: a misconfiguration that causes a fire is a cyber incident; an intentional attack that provokes the same fire is a cyber act. In practice, establishing intent is often the central issue in claims handling. These concepts are distinct from the state-backed cyber operation notion used in the cyber war clauses (LMA 5564 to 5567).

Example

A hacker takes control of the temperature regulation system of a server room and causes overheating that triggers a fire. This is a cyber act: malicious intent is established. The fire would not be covered under LMA 5400. If the overheating had resulted from an unintentional software fault, it would be a cyber incident, and the physical fire damage would be covered under the LMA 5400 write-back.

Related terms
Related articles
Also known as

cyber act, malicious cyber act, acte cyber malveillant, acte informatique malveillant