THE CYBER INSURANCE INDUSTRY

A sector file: the product that promised to absorb cyber risk, examined at the exact moment the biggest claims in its history arrived.

ENTITY
A market, not a company — carriers, Lloyd's syndicates, and reinsurers underwriting "cyber" FACT
OPERATION
Risk transfer for a fee — U.S. cyber premiums were about $3.6 billion in 2018 per the NAIC, and climbing fast ATTRIBUTED
EVENT
NOTPETYA, JUNE 2017 — the largest claims the product had ever seen met the "act of war" exclusion FACT
PATTERN
Per industry estimates cited by CM-Alliance, around 27% of cyber claims are not honoured or only partially paid due to exclusions ATTRIBUTED
DISPOSITION
Merck v. Ace American: New Jersey courts held the war exclusion inapplicable; upheld on appeal; settled at the eleventh hour before the state supreme court, January 2024 ADJUDICATED

Here is a species that feeds on uncertainty in both directions — selling certainty to the insured, and reserving uncertainty for itself in the policy language, where the exclusions live.

Representative body: Lloyd's of London (@LloydsofLondon). From Market Bulletin Y5381, the sector's own explanation for mandating state-backed cyber-attack exclusions: "…losses have the potential to greatly exceed what the insurance market is able to absorb."Lloyd's Market Bulletin Y5381 (PDF)

A taxonomy note. This drawer holds no single animal — it holds a niche. Companies come and go from it; the incentive structure is the organism. The file therefore names companies only where the public record already does: a docket, a denial letter quoted in court, a market bulletin.

The question the file poses is the one every buyer should ask before the premium clears: when the worst thing actually happens, does this product pay? NotPetya was the experiment. The results, both sides of them, are below.

the drama timeline

ACT I — THE WORM AND THE LETTER (2017–2018)

June 2017: malware built for Ukraine escapes into every network with a Ukrainian tax-software dependency. The claims arrive. Then the letters do.

  1. JUN 2017

    NotPetya

    NotPetya, widely attributed by Western governments to the Russian military, wrecks corporate networks worldwide. Merck's damages reach ~$1.4 billion; Mondelez estimates more than $100 million. Both file claims under all-risk property policies covering destruction of data and software.

  2. JUN 1 2018

    "Hostile or warlike action"

    Zurich's written rejection cites Exclusion B.2(a): losses from "hostile or warlike action in time of peace or war" by a government or its agents. Most of Merck's ~30 insurers and reinsurers take the same position on ~$700 million in claims. The clause dates, in spirit, to an era when war arrived by ship.

    Note the tension the sector built for itself: the same attribution that governments issued to condemn the attack became the insurers' exhibit A for not paying for it.

ACT II — THE COURTS (2019–2024)

Two food-and-pharma giants versus their own insurers, litigating whether a worm is a war. One case settles quietly. The other largely wins, twice, then settles on the courthouse steps.

  1. JAN 2022

    Merck wins the argument

    A New Jersey court rules the warfare exemption did not apply to Merck's NotPetya losses — the $1.4 billion ruling. The decision is upheld on appeal in 2023.

  2. NOV 2022

    Mondelez and Zurich settle — no precedent

    Mondelez and Zurich settle confidentially, mid-trial posture, leaving — as CSO Online put it — no legal precedent behind. The war-exclusion question stays half-answered for everyone else's policy.

  3. JAN 2024

    The eleventh-hour settlement

    With oral arguments about to begin at the New Jersey Supreme Court, Merck and its remaining insurers reach what Bloomberg Law called an "11th-hour" settlement. Merck's two court wins stand; the sector never gets its highest-court test.

    Scoreboard, such as it is: the insured largely won everywhere the question was actually decided — and the industry made sure it would never be decided again, which is Act III.

ACT III — THE REWRITE (AUG 2022–MAR 2023)

Losing an argument in court is expensive. Rewriting the policy so the argument can't recur is cheap. Watch the sector choose.

  1. AUG 16 2022

    Lloyd's Market Bulletin Y5381

    Lloyd's requires state-backed cyber-attack exclusions in all standalone cyber policies at inception or renewal from March 31, 2023. The bulletin's stated logic: hostile actors can disseminate attacks easily, harmful code spreads, and "losses have the potential to greatly exceed what the insurance market is able to absorb." The clause that had just lost in New Jersey returns — clarified, broadened, and mandatory.

ACT IV — THE FLOOR (THE DEFENSE'S ACT)

The same underwriting caution that denies claims also, verifiably, hardened the world's networks. The defense gets its own act, because it earned one.

  1. 2021–PRESENT

    The questionnaire becomes the audit

    Per Marsh, the world's largest insurance broker: insurers took "a much more cautious stance — requiring specific cybersecurity controls and placing insurability at stake," with certain controls now "a minimum requirement for insurers." In practice, the renewal questionnaire pushed multifactor authentication, endpoint detection, and tested backups into networks that had shrugged off a decade of conference keynotes — because this time the coverage depended on it.

    Credit where the record supports it: the underwriting form has arguably done more for baseline security adoption than any compliance regime the industry ever mocked.

both sides, on the record

The coverage delta. Around 27% of claims not honoured or only partially paid due to exclusions, per industry estimates cited by CM-Alliance — the product's perceived and actual coverage are different documents [8].

The war that wasn't. The sector's flagship denials — Merck, Mondelez — leaned on a clause written for armies, and the only courts to rule on it said it didn't apply [2] [3] [5].

The loop. ProPublica documented ransoms paid over recoverable backups because payment was cheaper; Wosar: "keeping ransomware alive today" — premiums in, ransoms out, attackers funded, demand up [6].

Solvency is the product. A systemic state-backed event could exceed "what the insurance market is able to absorb" — Lloyd's said so in the bulletin itself. An insurer that pays everything once pays nobody twice, and Carnegie's analysis argued the real defect was ambiguity, which the rewrite at least fixed up front [1] [7].

The system self-corrected. Merck won in court, twice, and was paid by settlement; the war exclusion as applied to spillover cyberattacks effectively died in New Jersey. The adjudicated record cuts against the sector — and the sector complied with it [2].

The floor got raised. Controls are now a condition of insurability — Marsh's words: "requiring specific cybersecurity controls and placing insurability at stake." And on ransoms, regulators told ProPublica that payment often minimizes the insured's total loss and restores operations fastest — the insurer's duty is to the client's balance sheet, not to the ecosystem [9] [6].

YOU DECIDE

Scoped to the sector, never to a villain — there isn't one, which is rather the point. The dates make the argument: coverage sold before the exclusion was tested; denial when it was; the exclusion broadened after the courts read it narrowly. All of it lawful, all of it disclosed in policy language, all of it on the record above.

Weigh both costly signals honestly. The insured that fought — Merck — won everywhere the question was decided. And the same industry that wrote the exclusions also forced multifactor authentication on more networks than twenty years of security evangelism managed. The product is neither the scam its angriest critics describe nor the safety net its brochures imply. It is a contract, and the exclusions are the contract.

The archive does not judge. It reads the policy language, including the fine print.

evidence locker

PRIMARY & ADJUDICATED RECORD

  1. Lloyd's of London — Market Bulletin Y5381, "State backed cyber-attack exclusions" (Aug 16, 2022) FACT — the mandatory rewrite, in the market's own words. assets.lloyds.com/media/…/Y5381 Market Bulletin - Cyber-attack exclusions.pdf
  2. The Record — "Merck settles with insurers who denied $700 million NotPetya claim" (Jan 2024) ADJUDICATED — the ruling, the appellate affirmance, and the eleventh-hour settlement. therecord.media/merck-insurance-settlement-notpetya
  3. CSO Online — "Mondelez and Zurich's NotPetya settlement leaves behind no legal precedent" (Nov 2022) ATTRIBUTED csoonline.com/article/574013/…

PRESS & ANALYSIS

  1. Brookings — "How the NotPetya attack is reshaping cyber insurance" ATTRIBUTED — the denial letter's exclusion language and the market stakes. brookings.edu/articles/how-the-notpetya-attack-is-reshaping-cyber-insurance/
  2. Bloomberg via Insurance Journal — "Was It an Act of War? That's Merck Cyber Attack's $1.3 Billion Insurance Question" (Dec 2019) ATTRIBUTED — the ~30 insurers, the NAIC premium figure, the stakes. insurancejournal.com/news/national/2019/12/03/550039.htm
  3. ProPublica — "The Extortion Economy: How Insurance Companies Are Fueling a Rise in Ransomware Attacks" (2019) ATTRIBUTED — the loop thesis, the Wosar quote, and the regulators' counterpoint. propublica.org/article/the-extortion-economy-…
  4. Carnegie Endowment — "War, Terrorism, and Catastrophe in Cyber Insurance: Understanding and Reforming Exclusions" (2020) ATTRIBUTED — the scholarly case that the exclusions were ambiguous and needed reform. carnegieendowment.org/research/2020/10/…
  5. CM-Alliance — "Why Do Cyber Insurance Claims Get Rejected?" (Sep 2023) ATTRIBUTED — the ~27% not-honoured-or-partially-paid estimate, cited to industry figures. cm-alliance.com/cybersecurity-blog/why-do-cyber-insurance-claims-get-rejected
  6. Marsh — "Cyber resilience: 12 key controls to strengthen your security" SELF-PUBLISHED — the broker's own statement that controls are now a minimum requirement for insurability; the defense's floor-raising card. marsh.com/en/services/cyber-risk/insights/cyber-resilience-twelve-key-controls-…
The standard. This is a sector file: no single company is its subject, and no company on it is accused of wrongdoing. The denials and their language are quoted from the parties' own letters as reproduced in the cited reporting; the Merck outcome is stated as adjudicated (two court wins, then a settlement); the Mondelez settlement is stated as precedent-free because it was. The feedback-loop thesis is ProPublica's and Wosar's, attributed. The defense — solvency logic, the courts' correction being honored, and the demonstrably raised security floor — is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.