Independent research · As at 28 July 2026

Sneaky terms explained

The clauses that quietly shrink your cyber cover — what they say, why they bite, who uses them, and what to push back on before you sign. Every claim about a specific insurer links to a public wording, PDS, court case or reputable commentary.

On this page

  1. War & state-sponsored-actor exclusions
  2. Security-control warranties & condition precedents
  3. "Failure to maintain" exclusions
  4. Betterment clauses
  5. Mandatory insurer response panels
  6. Short notification windows
  7. Sub-limits on ransomware, social engineering & BEC
  8. Co-insurance on extortion & catastrophe
  9. "Direct loss" wording traps
  10. Retroactive dates & known circumstances
  11. Dishonesty carve-outs
  12. Aggregation clauses

1. War & state-sponsored-actor exclusions

Lloyd's marketBeazleyZurich (property)Chubb/ACE (property)

What it says. Cyber policies have always excluded "war". Since Lloyd's Market Bulletin Y5381 (August 2022) required all Lloyd's standalone cyber policies to exclude state-backed cyber attacks, the market has standardised on the LMA cyber war clauses (LMA5564–LMA5567 and A/B variants). The broadest (LMA5564) can exclude any state-sponsored attack; the most common (LMA5567 family) excludes attacks causing "major detrimental impact" to an "impacted state" — see this 2026 market update on LMA5567A/B. Beazley's War and Cyber War Exclusion defines "cyber war" as digital force between states, with a carve-back for victims not physically located in the impacted state.

Why it bites. A large share of serious ransomware and destructive attacks have some state nexus (NotPetya was attributed to Russia). Attribution is contestable, slow, and largely in the insurer's hands. If your insurer argues the actor was state-backed, your headline limit can evaporate exactly when the whole market is hit at once.

Real disputes. Mondelez v Zurich: Zurich initially refused a ~US$100m NotPetya claim under a property policy's "hostile or warlike action" exclusion; settled confidentially with no precedent set. Merck v ACE American: New Jersey courts held the war exclusion covered only real-world physical warfare before a 2024 settlement of the US$1.4bn NotPetya claim. Those wins for policyholders are precisely why insurers rewrote the exclusions with the LMA cyber-specific wordings.
What to negotiate. Refuse blanket state-actor exclusions (LMA5564-style). Prefer LMA5567A/B-type wordings with a high "impacted state" threshold, a carve-back for collateral-damage victims outside the impacted state, clear attribution mechanics (who decides, on what evidence, who bears the burden), and cover that continues while attribution is disputed.

2. MFA & security-control warranties / condition precedents

TravelersCommon across the market

What it says. Proposal forms and endorsements ask you to confirm controls — MFA on remote and privileged access, EDR, offline backups, patching cadence. Some policies elevate these to warranties or conditions precedent: if the control wasn't in place (or lapses), there is no cover, and the insurer may seek to void the policy entirely for misrepresentation.

Why it bites. The application is filled in by someone who may not know that MFA covers the firewall but not the server fleet. "We have MFA" is treated as enterprise-wide fact. After a breach, forensics hands the insurer the evidence.

Real dispute. Travelers v International Control Services (2022): after a ransomware event, Travelers discovered MFA protected only the firewall, not servers or other assets, and sued to rescind the whole policy for misrepresentation. ICS consented to rescission — the policy was void, as if it never existed. Broker analysis: Lockton on Travelers v ICS.

Australian angle. Section 54 of the Insurance Contracts Act 1984 (Cth) stops insurers refusing claims for acts/omissions that didn't cause the loss — a real shield against technical breaches of ongoing conditions. It does not protect against pre-contractual misrepresentation on the proposal form, so answer application questions with the same care as a prospectus.

What to negotiate. Have the person who actually runs your controls sign off the application. Ask for warranties to be softened to "to the best of the insured's knowledge", scoped to named systems, and for a severability clause so one wrong answer doesn't void the whole policy. Document your control state at inception.

3. "Failure to maintain" security exclusions

CNA/Columbia CasualtyLegacy wordings

What it says. An exclusion for loss arising from failure to "continuously implement" the procedures and risk controls described in your application — sometimes titled "Failure to Follow Minimum Required Practices".

Why it bites. Every breach involves some control failing; that's what a breach is. Read literally, this exclusion can swallow the whole policy. It converts your application answers into a permanent, continuously-audited promise.

Real dispute. Columbia Casualty v Cottage Health (2015): after a 32,500-record breach, the insurer sued its own insured to claw back what it had paid, citing failures to patch and re-assess security under the minimum-practices exclusion. The case was dismissed on procedural grounds (mandatory ADR), leaving the exclusion untested — and still in circulation.
What to negotiate. Strike it, or narrow it to specific named controls with a materiality and causation link ("to the extent the failure directly caused the loss"). In Australia, s54 helps where the lapse didn't cause the loss — but don't rely on litigation as your control.

4. Betterment clauses

Market-wide

What it says. The insurer pays to restore systems and data to their state immediately before the incident — not to a better one. Anything beyond like-for-like is "betterment" and excluded. See Simmons & Simmons on reinstatement, betterment and exclusions.

Why it bites. After ransomware you cannot responsibly rebuild the same vulnerable environment, and often you literally can't (the old OS version is end-of-life). The upgrade you're forced to make is the part the insurer won't pay for. Disputes over what counts as "betterment" delay settlement while you're bleeding downtime.

What to negotiate. Ask for a betterment carve-back or "improved security" allowance (some wordings cover required upgrades where like-for-like restoration is impossible or would leave the vulnerability in place). At minimum, agree in writing during the claim which rebuild costs are accepted before you spend.

5. Mandatory insurer response panels & consent clauses

Market-wideCFC (in-house)Coalition (in-house)

What it says. You must use the insurer's panel of incident responders, lawyers and negotiators — or obtain prior written consent before incurring any costs. Costs incurred without consent may not be covered. See Alliant on the claims process and Lockton's cyber claims guide.

Why it bites. At 2am on day zero, your own retained IR firm knows your environment; the panel firm doesn't. Engage yours first and you may be paying for it yourself. Panel professionals are also repeat players for the insurer, which matters when coverage questions arise mid-incident. Insurers like CFC (35+ in-house cyber responders serving Australia from Brisbane) make the in-house model a selling point — which is fine, as long as you chose it deliberately.

What to negotiate. Get your preferred IR firm, forensics provider and law firm endorsed onto the policy before binding. Confirm the emergency-costs carve-out (most wordings allow reasonable costs in the first 48–72 hours without consent — check yours) and the hotline SLA.

6. Short notification windows as conditions precedent

Market-wide

What it says. Notify "as soon as practicable", "immediately", or within a fixed number of days of discovering an incident or circumstance — often expressed as a condition precedent to cover. See claims-readiness commentary.

Why it bites. In a real incident nobody is thinking about the PDS. IT triages quietly for a week, then legal finds the policy required notice within 72 hours. In hard markets, late notice is one of the most common grounds for reservation of rights.

Australian angle. s54 ICA again softens the blow where the delay didn't prejudice the insurer — but "claims made and notified" mechanics and prejudice arguments still generate disputes. Don't plan to litigate your way back in.

What to negotiate. "As soon as practicable after the [risk manager / general counsel] becomes aware" is far safer than flat-day deadlines — knowledge should sit with named senior roles, not any employee. Put the insurer's hotline in your incident-response plan and rehearse it.

7. Sub-limits on ransomware, social engineering & BEC

EmergenceQBEMarket-wide

What it says. A $5m policy is not $5m for everything. Cyber crime / social engineering / funds-transfer fraud is routinely sub-limited (sometimes to $100k–$250k), ransomware payments may be sub-limited, and some crime cover is an optional extension you must buy. In Australia, Emergence's Cyber Event Protection wording (CEP-005.1) treats Criminal Financial Loss as an optional section; QBE's QCyberProtect lists social engineering fraud as a distinct cover part. Insurers also apply sub-limits or exclusions at renewal when security gaps are found (AU market commentary).

Why it bites. BEC/payment-redirection fraud is the most common way Australian SMEs actually lose money, and it's exactly the loss most likely to be sub-limited or sitting in an optional section you didn't buy. Buyers discover the sub-limit at claim time.

What to negotiate. Get a schedule of every sub-limit next to your realistic loss scenarios. Push social engineering / cybercrime sub-limits up (they're often negotiable for evidence of payment controls like call-back verification). Confirm whether ransomware payments, negotiation costs and BI all sit at full limit.

8. Co-insurance on extortion payments & catastrophic events

BeazleyMarket-wide on extortion

What it says. You bear a fixed percentage of the loss on top of your excess — commonly seen on cyber extortion (e.g. insurer pays 50–80% of a ransom) and now on systemic events: Beazley's catastrophic cyber approach applies a 50% sub-limit of indemnity for defined remote-probability cyber catastrophes.

Why it bites. Co-insurance kicks in exactly when losses are largest. A 50% share of a systemic-event loss can exceed your entire annual security budget, and buyers frequently miss the percentage because it sits in an endorsement, not the schedule.

What to negotiate. Ask directly: "Is there any co-insurance percentage anywhere in this policy — extortion, widespread events, anything?" Trade a higher excess for removal of co-insurance where possible; a known fixed excess is plannable, an open-ended percentage is not.

9. "Direct loss" wording traps (crime policies masquerading as cyber cover)

ChubbCrime/ECC policies generally

What it says. Electronic and computer crime policies cover "direct financial loss resulting directly from" defined events. Courts read "direct" narrowly — twice over.

Real dispute. Inchcape Australia v Chubb Insurance Australia [2022] FCA 883: after ransomware encrypted servers and destroyed backups, the Federal Court held the crime policy's "direct financial loss" covered essentially the cost of replacing destroyed data — not incident response, forensics, hardware or the other recovery costs Inchcape chose to incur. Commentary: Herbert Smith Freehills, "Dedicated cyber insurance or bust — lessons from Inchcape".

Why it bites. Plenty of Australian businesses think their crime policy, management liability wording or ISR extension "does cyber". Inchcape shows the gap: the operational costs that dominate a real ransomware recovery were not "direct" loss.

What to negotiate. Buy a dedicated standalone cyber policy for incident response, BI and recovery costs; use crime policies for what they're for (theft of funds). Map each realistic loss scenario to the specific insuring clause you'd claim under — if you can't, neither can your broker at claim time.

10. Retroactive dates & known-circumstance exclusions

Market-wide

What it says. No cover for incidents originating before the retroactive date (often your first inception date with that insurer), or arising from circumstances known — or that "ought reasonably" to have been known — before inception.

Why it bites. Attackers commonly dwell in networks for months. If the intrusion began before your retro date, or a pentest report flagged the hole last year, the insurer has an argument the whole event predates the policy. Switching insurers can silently reset your retro date and open a gap.

What to negotiate. Ask for "full retroactive cover" or the earliest possible retro date, and preserve continuity when switching insurers. Notify circumstances (not just claims) before renewal so they attach to the expiring policy.

11. Dishonesty & criminal-act carve-outs

Market-wide

What it says. No cover for loss arising from dishonest, fraudulent, criminal or malicious acts of the insured — often extending to "any" director, officer or employee, with cover for innocent insureds varying widely.

Why it bites. Insider incidents are a material share of breaches. Broad wording ("any employee" rather than "any director acting with intent") can strip cover from the innocent company because one staff member acted dishonestly — the very event you wanted insured.

What to negotiate. Limit the carve-out to acts of senior management/directors, require a final adjudication (not mere allegation) before the exclusion applies, and include an innocent-insured / severability clause.

12. Aggregation & related-events clauses

Market-wide

What it says. All claims "arising from, based upon or attributable to" the same originating cause, or a "series of related" events, are treated as one claim — one limit, one excess.

Why it bites. It cuts both ways, and the insurer chooses the direction after the fact. Multiple attacks exploiting the same vulnerability across a year can be aggregated into a single limit; conversely, one incident might be split into multiple "claims" each bearing its own excess. Systemic events (a supply-chain compromise hitting you three ways) are where this clause decides whether you have $5m or $15m of cover.

What to negotiate. Understand the aggregation language before binding, run your worst-case scenario through it, and consider reinstatement-of-limit options for a second unrelated event in the same period.
Disclaimer. This page is general information only — not legal or financial advice, and not a recommendation to buy or avoid any insurance product. Policy wordings differ between insurers, products, versions and endorsements, and change frequently; the linked documents may have been superseded. Always check the current PDS and full policy wording for any product you are considering and obtain advice from a licensed insurance broker or lawyer about your specific circumstances. Content current as at 28 July 2026.