The clauses that quietly shrink your cyber cover — what they say, why they bite, who uses them, and what to push back on before you sign. Every claim about a specific insurer links to a public wording, PDS, court case or reputable commentary.
What it says. Cyber policies have always excluded "war". Since Lloyd's Market Bulletin Y5381 (August 2022) required all Lloyd's standalone cyber policies to exclude state-backed cyber attacks, the market has standardised on the LMA cyber war clauses (LMA5564–LMA5567 and A/B variants). The broadest (LMA5564) can exclude any state-sponsored attack; the most common (LMA5567 family) excludes attacks causing "major detrimental impact" to an "impacted state" — see this 2026 market update on LMA5567A/B. Beazley's War and Cyber War Exclusion defines "cyber war" as digital force between states, with a carve-back for victims not physically located in the impacted state.
Why it bites. A large share of serious ransomware and destructive attacks have some state nexus (NotPetya was attributed to Russia). Attribution is contestable, slow, and largely in the insurer's hands. If your insurer argues the actor was state-backed, your headline limit can evaporate exactly when the whole market is hit at once.
What it says. Proposal forms and endorsements ask you to confirm controls — MFA on remote and privileged access, EDR, offline backups, patching cadence. Some policies elevate these to warranties or conditions precedent: if the control wasn't in place (or lapses), there is no cover, and the insurer may seek to void the policy entirely for misrepresentation.
Why it bites. The application is filled in by someone who may not know that MFA covers the firewall but not the server fleet. "We have MFA" is treated as enterprise-wide fact. After a breach, forensics hands the insurer the evidence.
Australian angle. Section 54 of the Insurance Contracts Act 1984 (Cth) stops insurers refusing claims for acts/omissions that didn't cause the loss — a real shield against technical breaches of ongoing conditions. It does not protect against pre-contractual misrepresentation on the proposal form, so answer application questions with the same care as a prospectus.
What it says. An exclusion for loss arising from failure to "continuously implement" the procedures and risk controls described in your application — sometimes titled "Failure to Follow Minimum Required Practices".
Why it bites. Every breach involves some control failing; that's what a breach is. Read literally, this exclusion can swallow the whole policy. It converts your application answers into a permanent, continuously-audited promise.
What it says. The insurer pays to restore systems and data to their state immediately before the incident — not to a better one. Anything beyond like-for-like is "betterment" and excluded. See Simmons & Simmons on reinstatement, betterment and exclusions.
Why it bites. After ransomware you cannot responsibly rebuild the same vulnerable environment, and often you literally can't (the old OS version is end-of-life). The upgrade you're forced to make is the part the insurer won't pay for. Disputes over what counts as "betterment" delay settlement while you're bleeding downtime.
What it says. You must use the insurer's panel of incident responders, lawyers and negotiators — or obtain prior written consent before incurring any costs. Costs incurred without consent may not be covered. See Alliant on the claims process and Lockton's cyber claims guide.
Why it bites. At 2am on day zero, your own retained IR firm knows your environment; the panel firm doesn't. Engage yours first and you may be paying for it yourself. Panel professionals are also repeat players for the insurer, which matters when coverage questions arise mid-incident. Insurers like CFC (35+ in-house cyber responders serving Australia from Brisbane) make the in-house model a selling point — which is fine, as long as you chose it deliberately.
What it says. Notify "as soon as practicable", "immediately", or within a fixed number of days of discovering an incident or circumstance — often expressed as a condition precedent to cover. See claims-readiness commentary.
Why it bites. In a real incident nobody is thinking about the PDS. IT triages quietly for a week, then legal finds the policy required notice within 72 hours. In hard markets, late notice is one of the most common grounds for reservation of rights.
Australian angle. s54 ICA again softens the blow where the delay didn't prejudice the insurer — but "claims made and notified" mechanics and prejudice arguments still generate disputes. Don't plan to litigate your way back in.
What it says. A $5m policy is not $5m for everything. Cyber crime / social engineering / funds-transfer fraud is routinely sub-limited (sometimes to $100k–$250k), ransomware payments may be sub-limited, and some crime cover is an optional extension you must buy. In Australia, Emergence's Cyber Event Protection wording (CEP-005.1) treats Criminal Financial Loss as an optional section; QBE's QCyberProtect lists social engineering fraud as a distinct cover part. Insurers also apply sub-limits or exclusions at renewal when security gaps are found (AU market commentary).
Why it bites. BEC/payment-redirection fraud is the most common way Australian SMEs actually lose money, and it's exactly the loss most likely to be sub-limited or sitting in an optional section you didn't buy. Buyers discover the sub-limit at claim time.
What it says. You bear a fixed percentage of the loss on top of your excess — commonly seen on cyber extortion (e.g. insurer pays 50–80% of a ransom) and now on systemic events: Beazley's catastrophic cyber approach applies a 50% sub-limit of indemnity for defined remote-probability cyber catastrophes.
Why it bites. Co-insurance kicks in exactly when losses are largest. A 50% share of a systemic-event loss can exceed your entire annual security budget, and buyers frequently miss the percentage because it sits in an endorsement, not the schedule.
What it says. Electronic and computer crime policies cover "direct financial loss resulting directly from" defined events. Courts read "direct" narrowly — twice over.
Why it bites. Plenty of Australian businesses think their crime policy, management liability wording or ISR extension "does cyber". Inchcape shows the gap: the operational costs that dominate a real ransomware recovery were not "direct" loss.
What it says. No cover for incidents originating before the retroactive date (often your first inception date with that insurer), or arising from circumstances known — or that "ought reasonably" to have been known — before inception.
Why it bites. Attackers commonly dwell in networks for months. If the intrusion began before your retro date, or a pentest report flagged the hole last year, the insurer has an argument the whole event predates the policy. Switching insurers can silently reset your retro date and open a gap.
What it says. No cover for loss arising from dishonest, fraudulent, criminal or malicious acts of the insured — often extending to "any" director, officer or employee, with cover for innocent insureds varying widely.
Why it bites. Insider incidents are a material share of breaches. Broad wording ("any employee" rather than "any director acting with intent") can strip cover from the innocent company because one staff member acted dishonestly — the very event you wanted insured.
What it says. All claims "arising from, based upon or attributable to" the same originating cause, or a "series of related" events, are treated as one claim — one limit, one excess.
Why it bites. It cuts both ways, and the insurer chooses the direction after the fact. Multiple attacks exploiting the same vulnerability across a year can be aggregated into a single limit; conversely, one incident might be split into multiple "claims" each bearing its own excess. Systemic events (a supply-chain compromise hitting you three ways) are where this clause decides whether you have $5m or $15m of cover.