Use of a computer system by, at the direction of, or under the control of a sovereign state to disrupt, deny, degrade, manipulate or destroy information in a computer system.
A cyber operation, within the meaning of the LMA cyber war clauses (LMA 5564 to 5567), refers to the use of a computer system by, at the direction of, or under the control of a sovereign state to disrupt, deny access to, or degrade the functionality of a computer system, and/or to copy, remove, manipulate, deny access to or destroy information in such a system. This definition is deliberately broad: it covers destructive attacks, espionage and sabotage alike. The state element is central: it distinguishes the cyber operation covered by these clauses from ordinary cybercrime (ransomware, fraud), which does not constitute a cyber operation within the LMA sense. The burden of proving attribution to a state rests on the parties according to the modalities set out in the attribution clause. In clauses without attribution (B versions), ordinary contract law applies. The cyber operation is the nodal concept around which the entire cyber war exclusion regime turns: depending on the chosen clause (LMA 5564 to 5567), its mere occurrence may suffice to trigger exclusion (5564) or may only trigger exclusion under certain conditions of intensity or war context (5565, 5566, 5567).
In 2017, NotPetya was officially attributed to Russia's GRU by several Western governments. Its deployment via the EternalBlue mechanism and automatic propagation make it a state-backed cyber operation within the LMA sense, which led insurers to invoke war and cyber exclusion clauses in the resulting claims.
cyber operation, opération cyber étatique, state-backed cyber operation, cyberopération