What Cyber Insurance Does Not Cover (and the Exclusions That Matter)

Cyber insurance generally does not cover incidents you knew about before the policy began, bodily injury or property damage, widespread infrastructure outages, upgrades beyond what you had, contractual penalties, or acts of war. Many claims also fail on conditions rather than exclusions: an inaccurate security answer on the application, missed notice deadlines, or hiring vendors without the insurer's consent.

By Trella Commercial · Updated October 3, 2026

The short version

  • Standard exclusions remove incidents that began before the policy, physical injury and damage, outages of the power grid or internet backbone, war, and system upgrades.
  • The exclusions that vary most between insurers are the ones to compare: wrongful collection of data, unencrypted devices, failure to maintain security, and state-sponsored attacks.
  • Conditions deny claims too. Inaccurate application answers, late notice to the insurer, and spending money without consent are common problems.
  • Some losses fall between policies. Stolen funds, employee theft, and physical damage may belong to a crime or property policy, not cyber.
  • Coverage you did not buy is not "excluded," but it is still missing. Dependent business interruption, system failure, and social engineering are often optional.

Exclusions found in almost every cyber policy

ExclusionWhat it removesWhy it exists
Prior knowledge and prior actsIncidents you knew about, or that began before the retroactive dateInsurance covers unknown future events, not existing problems
Bodily injury and property damagePhysical injuries and damage to tangible propertyThese belong to general liability and property policies
Infrastructure failureOutages of power, internet, telecommunications, or other utilities not under your controlLosses across whole regions could not be priced
War and hostile actsLosses from war, and in many forms, cyberattacks attributed to a nation stateCatastrophic and correlated across policyholders
BettermentUpgrading systems beyond what you had before the incidentCoverage restores you; it does not improve you
Contractual liabilityPenalties or obligations you agreed to in a contract, beyond what the law would impose anywayYou cannot transfer a promise you made to the insurer without its agreement
Intentional actsDishonest or criminal acts by the business's owners or executivesYou cannot insure your own wrongdoing; innocent insureds are often protected
Fines uninsurable by lawPenalties a state does not allow to be insuredPublic policy; insurability of fines varies by state
Intellectual propertyPatent infringement and theft of trade secretsUsually a separate specialty risk
Government seizureSystems seized or shut down by government orderNot a fortuitous loss

Exclusions that vary from insurer to insurer

These are where two policies with the same limit can perform very differently.

Wrongful collection and tracking technology

Many privacy claims do not involve a hacker at all. They allege that a business collected or shared data without proper consent, through website tracking pixels, session replay tools, or biometric data. Some cyber policies exclude these "wrongful collection" claims or limit them to a small sublimit. For Washington businesses that collect health-related data, this matters under the My Health My Data Act.

Failure to maintain security

Some policies exclude or reduce coverage if the business failed to maintain security measures it described on the application, such as multifactor authentication or patching. Others address the same issue through the application itself. Either way, the controls you claim must actually be in place.

Unencrypted devices

A few policies exclude or limit breaches involving unencrypted laptops or portable media. Encryption also matters legally: under Washington's breach law, properly encrypted data generally does not trigger notice at all unless the key is also taken.

Unsupported software

Some insurers exclude or reduce coverage for incidents that exploit software the vendor no longer supports with security updates, or apply a coinsurance penalty.

Widespread events and state-sponsored attacks

War exclusions have been rewritten across the market in recent years, and many now address cyberattacks attributed to a nation state, sometimes with exceptions for a business that is collateral damage. Some insurers also limit coverage for "widespread events" that hit many policyholders at once. The wording here differs a great deal; read it rather than assuming.

Prior incidents and retroactive dates

When you switch cyber insurers, the new policy may set a retroactive date of its start, excluding incidents that began earlier but are discovered later. Attackers often sit inside a network for weeks before they are found, so matching your prior retroactive date, when possible, is worth asking for.

Conditions that deny claims

An exclusion removes a type of loss. A condition is something you must do. Breaking a condition can cost you coverage for a loss the policy would otherwise pay.

ConditionWhat goes wrongHow to avoid it
Accurate applicationThe application said multifactor authentication was in place for email and remote access; it was notAnswer from fact, and fix gaps before applying
Prompt noticeThe business waited weeks to tell the insurer while its IT provider tried to fix thingsCall the breach hotline as soon as you suspect an incident
Consent for costsThe business hired its own forensic firm and lawyer without approvalUse the insurer's panel or get written consent first
CooperationLogs were deleted or systems wiped before forensicsPreserve evidence until the investigators say otherwise
Ransom approvalThe business paid the attacker directlyNever pay or negotiate without the insurer
Verification proceduresA payment change was not confirmed by phone, as the social engineering coverage requiredBuild call-back verification into your payment process

Losses that fall between policies

LossUsually belongs toNotes
Money stolen by an employeeCrime (employee dishonesty)Cyber policies generally do not cover employee theft
Wire sent because of a fake invoiceCyber (social engineering) or crimeCoordinate the two so the loss is not caught between them, and check both sublimits
Server destroyed in an office firePropertyCyber covers data, not physical damage
Laptop stolen from a carProperty or inland marine for the device; cyber for any breach it causesTwo claims, two policies
Customer injured by a hacked connected deviceGeneral liability, possibly with gapsBodily injury is excluded from most cyber policies
Mistakes in software you sell or IT services you provideTechnology errors and omissionsOften combined with cyber on one form for tech businesses

Common gaps that are not exclusions

Some of the most painful surprises are coverages that were never purchased:

  • Dependent business interruption: lost income when a vendor's systems go down
  • System failure: outages from accidental errors or bad updates, with no attacker
  • Social engineering: employees tricked into sending money
  • Invoice manipulation: customers paying fake invoices sent from your hacked email
  • Reputational harm: income lost to customers who leave after a breach

See what cyber insurance covers for how each one works.

Common questions

Why would a cyber insurance claim be denied?

The most common reasons are an exclusion that applies (such as prior knowledge or infrastructure failure), a breached condition (such as an inaccurate security answer on the application or late notice), or a loss the policy never covered (such as wire fraud without social engineering coverage).

Does cyber insurance cover state-sponsored cyberattacks?

It depends on the war exclusion. Many current policies exclude cyberattacks attributed to a nation state, often with exceptions for businesses that are collateral damage rather than the target. Wording varies widely between insurers.

Does cyber insurance cover employee theft?

Generally no. Theft of money or property by employees is covered by a crime policy, under employee dishonesty coverage. Cyber policies focus on outside attacks, breaches, and privacy claims.

What happens if I said I had multifactor authentication and I did not?

The insurer may deny the claim or seek to rescind the policy, because the application is part of the contract. Some policies also contain an exclusion for failing to maintain the security controls described in the application.

Does cyber insurance cover upgrading my systems after an attack?

Usually not. Data restoration coverage pays to restore what you had. Improvements beyond that are excluded as betterment, although a few policies offer limited betterment coverage.

Sources

This page describes exclusions and conditions commonly found in cyber policies. Policies differ widely; what yours excludes depends on its actual wording. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.