THE CYBER INSURANCE INDUSTRY▊
A sector file: the product that promised to absorb cyber risk, examined at the exact moment the biggest claims in its history arrived.
- ENTITY
- A market, not a company — carriers, Lloyd's syndicates, and reinsurers underwriting "cyber" FACT
- OPERATION
- Risk transfer for a fee — U.S. cyber premiums were about $3.6 billion in 2018 per the NAIC, and climbing fast ATTRIBUTED
- EVENT
- NOTPETYA, JUNE 2017 — the largest claims the product had ever seen met the "act of war" exclusion FACT
- PATTERN
- Per industry estimates cited by CM-Alliance, around 27% of cyber claims are not honoured or only partially paid due to exclusions ATTRIBUTED
- DISPOSITION
- Merck v. Ace American: New Jersey courts held the war exclusion inapplicable; upheld on appeal; settled at the eleventh hour before the state supreme court, January 2024 ADJUDICATED
Here is a species that feeds on uncertainty in both directions — selling certainty to the insured, and reserving uncertainty for itself in the policy language, where the exclusions live.
Representative body: Lloyd's of London (
@LloydsofLondon). From Market Bulletin Y5381, the sector's own explanation for mandating state-backed cyber-attack exclusions:
"…losses have the potential to greatly exceed what the insurance market is able to absorb." —
Lloyd's Market Bulletin Y5381 (PDF)
A taxonomy note. This drawer holds no single animal — it holds a niche. Companies come and go from it; the incentive structure is the organism. The file therefore names companies only where the public record already does: a docket, a denial letter quoted in court, a market bulletin.
The question the file poses is the one every buyer should ask before the premium clears: when the worst thing actually happens, does this product pay? NotPetya was the experiment. The results, both sides of them, are below.
the drama timeline
ACT I — THE WORM AND THE LETTER (2017–2018)
June 2017: malware built for Ukraine escapes into every network with a Ukrainian tax-software dependency. The claims arrive. Then the letters do.
-
JUN 2017
NotPetya
NotPetya, widely attributed by Western governments to the Russian military, wrecks corporate networks worldwide. Merck's damages reach ~$1.4 billion; Mondelez estimates more than $100 million. Both file claims under all-risk property policies covering destruction of data and software.
-
JUN 1 2018
"Hostile or warlike action"
Zurich's written rejection cites Exclusion B.2(a): losses from "hostile or warlike action in time of peace or war" by a government or its agents. Most of Merck's ~30 insurers and reinsurers take the same position on ~$700 million in claims. The clause dates, in spirit, to an era when war arrived by ship.
Note the tension the sector built for itself: the same attribution that governments issued to condemn the attack became the insurers' exhibit A for not paying for it.
ACT II — THE COURTS (2019–2024)
Two food-and-pharma giants versus their own insurers, litigating whether a worm is a war. One case settles quietly. The other largely wins, twice, then settles on the courthouse steps.
-
JAN 2022
Merck wins the argument
A New Jersey court rules the warfare exemption did not apply to Merck's NotPetya losses — the $1.4 billion ruling. The decision is upheld on appeal in 2023.
-
NOV 2022
Mondelez and Zurich settle — no precedent
Mondelez and Zurich settle confidentially, mid-trial posture, leaving — as CSO Online put it — no legal precedent behind. The war-exclusion question stays half-answered for everyone else's policy.
-
JAN 2024
The eleventh-hour settlement
With oral arguments about to begin at the New Jersey Supreme Court, Merck and its remaining insurers reach what Bloomberg Law called an "11th-hour" settlement. Merck's two court wins stand; the sector never gets its highest-court test.
Scoreboard, such as it is: the insured largely won everywhere the question was actually decided — and the industry made sure it would never be decided again, which is Act III.
ACT III — THE REWRITE (AUG 2022–MAR 2023)
Losing an argument in court is expensive. Rewriting the policy so the argument can't recur is cheap. Watch the sector choose.
-
AUG 16 2022
Lloyd's Market Bulletin Y5381
Lloyd's requires state-backed cyber-attack exclusions in all standalone cyber policies at inception or renewal from March 31, 2023. The bulletin's stated logic: hostile actors can disseminate attacks easily, harmful code spreads, and "losses have the potential to greatly exceed what the insurance market is able to absorb." The clause that had just lost in New Jersey returns — clarified, broadened, and mandatory.
ACT IV — THE FLOOR (THE DEFENSE'S ACT)
The same underwriting caution that denies claims also, verifiably, hardened the world's networks. The defense gets its own act, because it earned one.
-
2021–PRESENT
The questionnaire becomes the audit
Per Marsh, the world's largest insurance broker: insurers took "a much more cautious stance — requiring specific cybersecurity controls and placing insurability at stake," with certain controls now "a minimum requirement for insurers." In practice, the renewal questionnaire pushed multifactor authentication, endpoint detection, and tested backups into networks that had shrugged off a decade of conference keynotes — because this time the coverage depended on it.
Credit where the record supports it: the underwriting form has arguably done more for baseline security adoption than any compliance regime the industry ever mocked.
both sides, on the record
The coverage delta. Around 27% of claims not honoured or only partially paid due to exclusions, per industry estimates cited by CM-Alliance — the product's perceived and actual coverage are different documents [8].
The war that wasn't. The sector's flagship denials — Merck, Mondelez — leaned on a clause written for armies, and the only courts to rule on it said it didn't apply [2] [3] [5].
The loop. ProPublica documented ransoms paid over recoverable backups because payment was cheaper; Wosar: "keeping ransomware alive today" — premiums in, ransoms out, attackers funded, demand up [6].
Solvency is the product. A systemic state-backed event could exceed "what the insurance market is able to absorb" — Lloyd's said so in the bulletin itself. An insurer that pays everything once pays nobody twice, and Carnegie's analysis argued the real defect was ambiguity, which the rewrite at least fixed up front [1] [7].
The system self-corrected. Merck won in court, twice, and was paid by settlement; the war exclusion as applied to spillover cyberattacks effectively died in New Jersey. The adjudicated record cuts against the sector — and the sector complied with it [2].
The floor got raised. Controls are now a condition of insurability — Marsh's words: "requiring specific cybersecurity controls and placing insurability at stake." And on ransoms, regulators told ProPublica that payment often minimizes the insured's total loss and restores operations fastest — the insurer's duty is to the client's balance sheet, not to the ecosystem [9] [6].
YOU DECIDE
Scoped to the sector, never to a villain — there isn't one, which is rather the point. The dates make the argument: coverage sold before the exclusion was tested; denial when it was; the exclusion broadened after the courts read it narrowly. All of it lawful, all of it disclosed in policy language, all of it on the record above.
Weigh both costly signals honestly. The insured that fought — Merck — won everywhere the question was decided. And the same industry that wrote the exclusions also forced multifactor authentication on more networks than twenty years of security evangelism managed. The product is neither the scam its angriest critics describe nor the safety net its brochures imply. It is a contract, and the exclusions are the contract.
The archive does not judge. It reads the policy language, including the fine print.
evidence locker
PRIMARY & ADJUDICATED RECORD
PRESS & ANALYSIS
ProPublica — "The Extortion Economy: How Insurance Companies Are Fueling a Rise in Ransomware Attacks" (2019) ATTRIBUTED — the loop thesis, the Wosar quote, and the regulators' counterpoint.
propublica.org/article/the-extortion-economy-…
Carnegie Endowment — "War, Terrorism, and Catastrophe in Cyber Insurance: Understanding and Reforming Exclusions" (2020) ATTRIBUTED — the scholarly case that the exclusions were ambiguous and needed reform.
carnegieendowment.org/research/2020/10/…
The standard. This is a sector file: no single company is its subject, and no company on it is accused of wrongdoing. The denials and their language are quoted from the parties' own letters as reproduced in the cited reporting; the Merck outcome is stated as adjudicated (two court wins, then a settlement); the Mondelez settlement is stated as precedent-free because it was. The feedback-loop thesis is ProPublica's and Wosar's, attributed. The defense — solvency logic, the courts' correction being honored, and the demonstrably raised security floor — is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.