Threshold defined in LMA cyber war clauses beyond which a state-backed cyber operation is considered to have had a major detrimental impact on a sovereign state.
The impacted state is a key concept introduced by the LMA 5565, 5566 and 5567 clause families to delimit the scope of state-backed cyber operations that trigger the exclusion. A state becomes an impacted state when a cyber operation has had a major detrimental impact either on the functioning of that state through disruption to the availability, integrity or delivery of an essential service (financial institutions, health services, utility services), or on the security or defense of that state. This dual criterion, essential services on one side and security or defense on the other, establishes a threshold of systemic criticality: a state-backed cyberattack triggers the exclusion only if it reaches this intensity. Below this threshold, non-systemic state-backed cyber operations remain covered within the policy limit, subject to other exclusions. The concept is deliberately broad and open to interpretation, particularly on what constitutes a major impact or where the line falls between disruption of an essential service and an ordinary sectoral incident. LMA 5565 additionally introduces a cap on residual coverage, absent from 5566 and 5567. The 5567B guard-rail variant specifies that a state cannot be qualified as impacted when the cyber operation solely affects the insured, thereby protecting the isolated target.
A state-backed cyberattack paralyzes for 72 hours the interbank clearing system of a small EU member state, making transfers impossible. Financial institutions constitute an essential service under LMA definitions. This state becomes an impacted state. Insureds whose systems are located in that state see their claims excluded under LMA 5566 and 5567 (but not the bystanding write-back under 5567A for systems located outside that state).
impacted state, état impacté, seuil d'impact systémique