The short version
- Standard exclusions remove incidents that began before the policy, physical injury and damage, outages of the power grid or internet backbone, war, and system upgrades.
- The exclusions that vary most between insurers are the ones to compare: wrongful collection of data, unencrypted devices, failure to maintain security, and state-sponsored attacks.
- Conditions deny claims too. Inaccurate application answers, late notice to the insurer, and spending money without consent are common problems.
- Some losses fall between policies. Stolen funds, employee theft, and physical damage may belong to a crime or property policy, not cyber.
- Coverage you did not buy is not "excluded," but it is still missing. Dependent business interruption, system failure, and social engineering are often optional.
Exclusions found in almost every cyber policy
| Exclusion | What it removes | Why it exists |
|---|---|---|
| Prior knowledge and prior acts | Incidents you knew about, or that began before the retroactive date | Insurance covers unknown future events, not existing problems |
| Bodily injury and property damage | Physical injuries and damage to tangible property | These belong to general liability and property policies |
| Infrastructure failure | Outages of power, internet, telecommunications, or other utilities not under your control | Losses across whole regions could not be priced |
| War and hostile acts | Losses from war, and in many forms, cyberattacks attributed to a nation state | Catastrophic and correlated across policyholders |
| Betterment | Upgrading systems beyond what you had before the incident | Coverage restores you; it does not improve you |
| Contractual liability | Penalties or obligations you agreed to in a contract, beyond what the law would impose anyway | You cannot transfer a promise you made to the insurer without its agreement |
| Intentional acts | Dishonest or criminal acts by the business's owners or executives | You cannot insure your own wrongdoing; innocent insureds are often protected |
| Fines uninsurable by law | Penalties a state does not allow to be insured | Public policy; insurability of fines varies by state |
| Intellectual property | Patent infringement and theft of trade secrets | Usually a separate specialty risk |
| Government seizure | Systems seized or shut down by government order | Not a fortuitous loss |
Exclusions that vary from insurer to insurer
These are where two policies with the same limit can perform very differently.
Wrongful collection and tracking technology
Many privacy claims do not involve a hacker at all. They allege that a business collected or shared data without proper consent, through website tracking pixels, session replay tools, or biometric data. Some cyber policies exclude these "wrongful collection" claims or limit them to a small sublimit. For Washington businesses that collect health-related data, this matters under the My Health My Data Act.
Failure to maintain security
Some policies exclude or reduce coverage if the business failed to maintain security measures it described on the application, such as multifactor authentication or patching. Others address the same issue through the application itself. Either way, the controls you claim must actually be in place.
Unencrypted devices
A few policies exclude or limit breaches involving unencrypted laptops or portable media. Encryption also matters legally: under Washington's breach law, properly encrypted data generally does not trigger notice at all unless the key is also taken.
Unsupported software
Some insurers exclude or reduce coverage for incidents that exploit software the vendor no longer supports with security updates, or apply a coinsurance penalty.
Widespread events and state-sponsored attacks
War exclusions have been rewritten across the market in recent years, and many now address cyberattacks attributed to a nation state, sometimes with exceptions for a business that is collateral damage. Some insurers also limit coverage for "widespread events" that hit many policyholders at once. The wording here differs a great deal; read it rather than assuming.
Prior incidents and retroactive dates
When you switch cyber insurers, the new policy may set a retroactive date of its start, excluding incidents that began earlier but are discovered later. Attackers often sit inside a network for weeks before they are found, so matching your prior retroactive date, when possible, is worth asking for.
Conditions that deny claims
An exclusion removes a type of loss. A condition is something you must do. Breaking a condition can cost you coverage for a loss the policy would otherwise pay.
| Condition | What goes wrong | How to avoid it |
|---|---|---|
| Accurate application | The application said multifactor authentication was in place for email and remote access; it was not | Answer from fact, and fix gaps before applying |
| Prompt notice | The business waited weeks to tell the insurer while its IT provider tried to fix things | Call the breach hotline as soon as you suspect an incident |
| Consent for costs | The business hired its own forensic firm and lawyer without approval | Use the insurer's panel or get written consent first |
| Cooperation | Logs were deleted or systems wiped before forensics | Preserve evidence until the investigators say otherwise |
| Ransom approval | The business paid the attacker directly | Never pay or negotiate without the insurer |
| Verification procedures | A payment change was not confirmed by phone, as the social engineering coverage required | Build call-back verification into your payment process |
Losses that fall between policies
| Loss | Usually belongs to | Notes |
|---|---|---|
| Money stolen by an employee | Crime (employee dishonesty) | Cyber policies generally do not cover employee theft |
| Wire sent because of a fake invoice | Cyber (social engineering) or crime | Coordinate the two so the loss is not caught between them, and check both sublimits |
| Server destroyed in an office fire | Property | Cyber covers data, not physical damage |
| Laptop stolen from a car | Property or inland marine for the device; cyber for any breach it causes | Two claims, two policies |
| Customer injured by a hacked connected device | General liability, possibly with gaps | Bodily injury is excluded from most cyber policies |
| Mistakes in software you sell or IT services you provide | Technology errors and omissions | Often combined with cyber on one form for tech businesses |
Common gaps that are not exclusions
Some of the most painful surprises are coverages that were never purchased:
- Dependent business interruption: lost income when a vendor's systems go down
- System failure: outages from accidental errors or bad updates, with no attacker
- Social engineering: employees tricked into sending money
- Invoice manipulation: customers paying fake invoices sent from your hacked email
- Reputational harm: income lost to customers who leave after a breach
See what cyber insurance covers for how each one works.