How the major cyber underwriters compare on the terms that actually decide whether a claim gets paid. Scored 1–5 shields per criterion from publicly available wordings, PDS documents, court cases and reputable commentary.
Each underwriter is scored 1–5 shields (5 = most buyer-friendly) on five criteria. Scores are our editorial opinion based on the public documents linked in the notes column and on our Sneaky Terms research. They are not a statement about any insurer's solvency, service quality or any individual policy — wordings vary enormously by product, market segment, broker facility and endorsement, and the policy you are offered may differ from anything we reviewed. Where public evidence was thin we score conservatively at 3 and say so.
Clarity of wording — plain-language drafting, defined terms, ease of finding sub-limits and conditions.
Breadth of exclusions — how much the war/state-actor, systemic and infrastructure exclusions take away (narrower = higher score).
Warranty strictness — how harshly security-control questions are converted into warranties or conditions precedent.
Sub-limit & co-insurance generosity — how much of the headline limit is really available for ransomware, cybercrime/BEC and systemic events.
Claims & disputes track record — publicly reported coverage disputes and litigation posture (fewer buyer-hostile disputes = higher score).
| Underwriter | Clarity | Exclusion breadth | Warranty strictness | Sub-limits / co-insurance | Claims record | Notes & sources |
|---|---|---|---|---|---|---|
| Beazley (Lloyd's) | 🛡🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡 | 🛡🛡🛡🛡 | Unusually transparent about its war/cyber-war exclusion (with non-impacted-state carve-back), but pioneered 50% co-insurance on defined catastrophic cyber events — check that endorsement carefully. |
| Chubb | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡 | Strong global cyber franchise (AU product), but litigated "direct loss" narrowly and won in Inchcape [2022] FCA 883 (a crime policy — buy their dedicated cyber wording, not crime cover, for cyber). ACE (now Chubb) fought Merck's NotPetya claim for years before the 2024 settlement. |
| Coalition | 🛡🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | Modern, readable wording (UK Cyber & Tech 3.0) and in-house IR. Trade-off: active security monitoring feeds underwriting — control lapses discovered by their scanning can affect renewal terms; treat security questions as continuously live. |
| CFC | 🛡🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡🛡 | Plain-English policy wording, large AU presence with 35+ in-house responders in Brisbane and up to $25m capacity. In-house IR is good but effectively a built-in panel — endorse your own vendors if you want them. |
| Emergence (AU) | 🛡🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡 | 🛡🛡🛡 | Australian cyber specialist; CEP-005.1 wording is accessible and recently improved — but Criminal Financial Loss (BEC/social engineering) is an optional section: if you didn't buy it, your most likely loss isn't covered. |
| AIG (CyberEdge) | 🛡🛡 | 🛡🛡🛡 | 🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | Comprehensive but complex modular wording; detailed ransomware supplementary questionnaires raise misrepresentation stakes. Historically co-insurance/sub-limit options used to manage ransomware exposure — read the schedule line by line. |
| Zurich | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡 | Fought the Mondelez NotPetya claim under a property policy's war exclusion before settling. Its standalone cyber wordings are conventional; the lesson is about how aggressively war exclusions may be run when losses are systemic. |
| Allianz | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | Limited public dispute history in cyber; conventional corporate wordings. Scored neutral pending better public evidence. |
| AXA XL | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | Major global cyber capacity provider; wordings vary by market. Scored neutral pending better public evidence. |
| QBE (AU) | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | QCyberProtect includes extortion and social-engineering cover parts — confirm each part's sub-limit on your schedule rather than assuming full limit. |
| Lloyd's market wordings | 🛡🛡🛡 | 🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | All Lloyd's standalone cyber must carry a state-backed attack exclusion (Bulletin Y5381) via the LMA clause suite. Which variant (LMA5564 vs LMA5567A/B) matters more than which syndicate. |
| Marsh / Aon panel facilities | 🛡🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | 🛡🛡🛡 | Broker-arranged facilities (e.g. Marsh Cyber ECHO-type products) typically pre-negotiate improved, standardised wordings across panel insurers — often a good baseline, but the underlying insurers' exclusions (incl. LMA war clauses) still flow through. Ask your broker for the facility wording vs open-market comparison. |
🛡 = 1 (buyer-hostile) … 🛡🛡🛡🛡🛡 = 5 (buyer-friendly). A "3" often means "insufficient public evidence to differentiate", not "average product". No insurer paid for, reviewed or influenced these scores.