Back to glossaryCyber

Silent cyber (non-affirmative cyber)

Cyber exposure implicitly embedded in a traditional policy that neither explicitly mentions nor excludes cyber.

Definition

Silent cyber refers to the cyber exposure implicitly embedded in traditional insurance policies, whether property, general liability or business interruption, that were drafted before cyber was treated as a distinct peril and whose wordings neither mention nor exclude it. Such a policy can therefore be triggered by a loss of cyber origin that neither the insurer nor the policyholder had priced. The problem is twofold for the insurer, who carries an unmeasured and therefore unreserved exposure, together with an accumulation risk, since a single cyber event can trigger simultaneous claims across multiple lines of business. The market response, led by Lloyd's from 2019 onward, was to require every policy to state its position on cyber, either by including and pricing it, known as affirmative cyber, or by excluding it unambiguously. Silent cyber is therefore not a form of cover but a contractual gap that regulation and underwriting guidelines seek to close. The boundary remains contested in litigation, because classifying a loss as cyber often requires establishing the primary technical cause of the damage, an exercise that is rarely straightforward.

Example

During the 2017 NotPetya attack, companies such as Mondelez sought to claim under their conventional all-risk property policy, which made no mention of cyber. The Mondelez v. Zurich litigation crystallized the issue, with the insurer invoking a war exclusion while the policyholder disputed its application to a cyberattack.

Related terms
Related articles
Also known as

cyber silencieux, cyber non affirmatif, non-affirmative cyber