Editorial opinion · As at 28 July 2026

Underwriter ratings

How the major cyber underwriters compare on the terms that actually decide whether a claim gets paid. Scored 1–5 shields per criterion from publicly available wordings, PDS documents, court cases and reputable commentary.

Methodology

Each underwriter is scored 1–5 shields (5 = most buyer-friendly) on five criteria. Scores are our editorial opinion based on the public documents linked in the notes column and on our Sneaky Terms research. They are not a statement about any insurer's solvency, service quality or any individual policy — wordings vary enormously by product, market segment, broker facility and endorsement, and the policy you are offered may differ from anything we reviewed. Where public evidence was thin we score conservatively at 3 and say so.

Criteria

Clarity of wording — plain-language drafting, defined terms, ease of finding sub-limits and conditions.
Breadth of exclusions — how much the war/state-actor, systemic and infrastructure exclusions take away (narrower = higher score).
Warranty strictness — how harshly security-control questions are converted into warranties or conditions precedent.
Sub-limit & co-insurance generosity — how much of the headline limit is really available for ransomware, cybercrime/BEC and systemic events.
Claims & disputes track record — publicly reported coverage disputes and litigation posture (fewer buyer-hostile disputes = higher score).

Comparison — as at 28 July 2026

UnderwriterClarityExclusion breadthWarranty strictnessSub-limits / co-insuranceClaims recordNotes & sources
Beazley (Lloyd's)🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Unusually transparent about its war/cyber-war exclusion (with non-impacted-state carve-back), but pioneered 50% co-insurance on defined catastrophic cyber events — check that endorsement carefully.
Chubb🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Strong global cyber franchise (AU product), but litigated "direct loss" narrowly and won in Inchcape [2022] FCA 883 (a crime policy — buy their dedicated cyber wording, not crime cover, for cyber). ACE (now Chubb) fought Merck's NotPetya claim for years before the 2024 settlement.
Coalition🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Modern, readable wording (UK Cyber & Tech 3.0) and in-house IR. Trade-off: active security monitoring feeds underwriting — control lapses discovered by their scanning can affect renewal terms; treat security questions as continuously live.
CFC🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Plain-English policy wording, large AU presence with 35+ in-house responders in Brisbane and up to $25m capacity. In-house IR is good but effectively a built-in panel — endorse your own vendors if you want them.
Emergence (AU)🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Australian cyber specialist; CEP-005.1 wording is accessible and recently improved — but Criminal Financial Loss (BEC/social engineering) is an optional section: if you didn't buy it, your most likely loss isn't covered.
AIG (CyberEdge)🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Comprehensive but complex modular wording; detailed ransomware supplementary questionnaires raise misrepresentation stakes. Historically co-insurance/sub-limit options used to manage ransomware exposure — read the schedule line by line.
Zurich🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Fought the Mondelez NotPetya claim under a property policy's war exclusion before settling. Its standalone cyber wordings are conventional; the lesson is about how aggressively war exclusions may be run when losses are systemic.
Allianz🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Limited public dispute history in cyber; conventional corporate wordings. Scored neutral pending better public evidence.
AXA XL🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Major global cyber capacity provider; wordings vary by market. Scored neutral pending better public evidence.
QBE (AU)🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡QCyberProtect includes extortion and social-engineering cover parts — confirm each part's sub-limit on your schedule rather than assuming full limit.
Lloyd's market wordings🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡All Lloyd's standalone cyber must carry a state-backed attack exclusion (Bulletin Y5381) via the LMA clause suite. Which variant (LMA5564 vs LMA5567A/B) matters more than which syndicate.
Marsh / Aon panel facilities🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡🛡Broker-arranged facilities (e.g. Marsh Cyber ECHO-type products) typically pre-negotiate improved, standardised wordings across panel insurers — often a good baseline, but the underlying insurers' exclusions (incl. LMA war clauses) still flow through. Ask your broker for the facility wording vs open-market comparison.

🛡 = 1 (buyer-hostile) … 🛡🛡🛡🛡🛡 = 5 (buyer-friendly). A "3" often means "insufficient public evidence to differentiate", not "average product". No insurer paid for, reviewed or influenced these scores.

Disclaimer. These ratings are editorial opinion for general information only — not legal or financial advice, not a product recommendation, and not a rating of any insurer's financial strength or claims-paying ability. They reflect only the specific public documents linked, which may be outdated or unrepresentative of the product you are offered. Wordings change constantly; always obtain and read the current PDS and full policy wording, and get advice from a licensed insurance broker or adviser for your circumstances. Australian readers: general advice only, prepared without regard to your objectives, financial situation or needs. As at 28 July 2026.