Back to glossaryCyber

Cyber incident

Disruption or failure of a computer system of non-malicious origin, as opposed to an intentional cyber act. The LMA 5400 write-back covers physical damage resulting from such an incident.

Definition

The cyber incident, in the context of LMA property clauses (LMA 5400), refers to a disruption or failure of a computer system resulting from a non-malicious cause: human error, software bug, hardware failure, faulty update or natural event affecting systems. It contrasts with the cyber act, which implies malicious intent. This distinction determines the scope of the write-back in LMA 5400: only physical damage (fire, explosion) resulting from a non-malicious cyber incident is reinstated into property coverage. Damage resulting from a malicious cyber act remains excluded. In practice, post-loss qualification is often difficult and is the subject of forensic investigations. The cyber incident must not be confused with the cyber operation concept in the cyber war clauses, which requires a state dimension.

Example

In 2018, a software update error at TSMC (semiconductor manufacturer) paralyzed entire production lines for several days, causing a USD 170 million loss. This is a non-malicious cyber incident. Under LMA 5400, any resulting physical damage would potentially have benefited from the fire/explosion write-back.

Related terms
Related articles
Also known as

cyber incident, incident informatique, défaillance cyber, cyber failure