Exclusions in cyber policies.

1. Introduction

A cyber insurance policy protects an insured against specified losses arising from cyber incidents such as:

  • hacking;
  • ransomware;
  • malware;
  • data breaches;
  • phishing;
  • business email compromise;
  • cyber extortion;
  • data restoration costs;
  • business interruption;
  • privacy liability;
  • regulatory investigations, where covered;
  • third-party claims.

However, cyber insurance is not an unlimited guarantee against every loss involving computers or the internet.

The insurer's liability is determined by the precise terms of the policy, including its exclusions, conditions, definitions, limits and endorsements.

An exclusion clause identifies circumstances in which the insurer will not be liable even though the event might otherwise fall within the general subject matter of the policy.

2. Why Cyber Policies Contain Exclusions

Cyber risks are unusually broad and difficult to quantify.

A single incident may involve:

  • criminal activity;
  • employee misconduct;
  • technology failure;
  • infrastructure failure;
  • contractual disputes;
  • privacy violations;
  • physical damage;
  • war;
  • regulatory action.

Insurers therefore use exclusions to define the boundaries of the risk they have agreed to assume.

For example, a policy may cover:

"loss resulting from a data breach"

but exclude:

"loss arising from bodily injury or property damage."

Thus, the fact that a loss arose from a cyberattack does not automatically make every consequence insured.

3. Basic Rule: Policy Wording Controls

The starting principle in insurance law is:

An insurance contract must ordinarily be interpreted according to its terms.

The insured cannot claim a risk merely because it appears commercially desirable that the policy should cover it.

At the same time, an insurer cannot enlarge an exclusion beyond the wording actually agreed.

This creates two competing principles:

Insurer: "The policy excludes this loss."

Insured: "The exclusion does not apply to these facts."

The dispute therefore often turns on the construction and application of the exclusion clause.

4. Common Exclusions in Cyber Insurance Policies

The precise exclusions vary between policies, but commonly encountered categories include:

  1. war and terrorism;
  2. infrastructure/system failure;
  3. bodily injury and property damage;
  4. contractual liability;
  5. prior known circumstances;
  6. dishonest or fraudulent acts;
  7. intentional acts;
  8. unencrypted data or inadequate security;
  9. regulatory fines and penalties;
  10. intellectual-property disputes;
  11. patent/trademark/copyright claims;
  12. failure to maintain security standards;
  13. professional services;
  14. cryptocurrency/digital assets;
  15. territorial or jurisdictional exclusions;
  16. communicable-disease-related cyber exclusions;
  17. physical damage caused by cyber events;
  18. losses suffered by related entities;
  19. failure of third-party service providers where not covered;
  20. business interruption outside the defined insured period.

5. War and Cyber-War Exclusion

One of the most controversial exclusions is the war exclusion.

Traditional insurance policies often exclude losses caused by:

  • war;
  • invasion;
  • hostilities;
  • military action;
  • civil war;
  • terrorism.

The problem becomes difficult when a cyberattack is allegedly conducted by:

  • a foreign government;
  • a military organisation;
  • a state-sponsored group; or
  • an independent criminal group.

Example

A ransomware attack is attributed to a hacking group allegedly sponsored by a foreign government.

The insurer argues:

"This is a hostile state-sponsored cyber operation and falls within the war exclusion."

The insured argues:

"This was simply a criminal ransomware attack."

The result depends heavily on:

  • the exact exclusion wording;
  • attribution evidence;
  • the nature of the attack;
  • whether "cyber operation" is specifically defined;
  • applicable governing law.

6. Terrorism Exclusion

Some policies exclude losses arising from:

  • terrorism;
  • politically motivated attacks;
  • organised violence;
  • terrorism-related cyber operations.

Again, attribution is crucial.

A politically motivated hacking incident may create difficult questions concerning whether the attack actually satisfies the policy's definition of terrorism.

7. Infrastructure Failure Exclusion

A cyber policy may exclude losses caused by failure of:

  • telecommunications networks;
  • internet service providers;
  • electricity suppliers;
  • cloud providers;
  • public infrastructure.

This is important because the insured may experience a computer outage without suffering a conventional cyberattack.

Example

A company loses access to its servers because its electricity provider suffers a major grid failure.

If the cyber policy requires a defined "cyber event", the loss may fall outside coverage.

8. Bodily Injury and Property Damage Exclusion

Many cyber policies focus on digital and financial losses rather than traditional physical losses.

Therefore, policies may exclude:

  • bodily injury;
  • death;
  • physical property damage.

Example

A hacker attacks the software controlling industrial machinery, causing the machinery to physically explode.

Two separate questions arise:

  1. Is the cyber incident covered?
  2. Is the resulting physical damage covered?

A cyber policy may cover certain cyber-response costs while excluding the physical damage itself.

9. Contractual Liability Exclusion

A cyber policy may exclude liability that exists solely because the insured assumed it under a contract.

For example:

Company A contracts with Company B and promises to pay ₹10 crore for any data-security failure.

If Company B brings a claim based solely upon the contractual promise, the insurer may rely on a contractual-liability exclusion.

However, policies sometimes provide exceptions for liabilities that would have existed even without the contract.

The exact wording is therefore critical.

10. Prior Knowledge / Prior Acts Exclusion

Insurance generally operates against fortuitous risks, rather than losses that the insured already knew about when purchasing the policy.

A policy may therefore exclude circumstances:

  • known before inception;
  • previously notified;
  • already reasonably anticipated;
  • already the subject of a claim.

Example

A company discovers in January that hackers have stolen customer data.

It purchases cyber insurance in February.

It then reports the January breach as a new insured event.

The insurer may invoke a prior-known-circumstance exclusion.

11. Fraudulent or Dishonest Acts

Cyber policies may contain exclusions concerning:

  • fraud;
  • dishonesty;
  • deliberate criminal conduct;
  • intentional wrongdoing.

The purpose is to prevent an insured from obtaining insurance protection for losses deliberately caused by itself.

Important distinction

There may be a difference between:

employee misconduct

and

misconduct by the insured organisation itself.

Some policies contain a final adjudication requirement, meaning the exclusion applies only after fraud/dishonesty has been established through an appropriate final determination.

12. Intentional Acts Exclusion

Insurance generally does not provide a licence for deliberate self-created loss.

For example:

A company deliberately transfers ₹5 crore to a fake account and later describes it as a cyber loss.

The insurer may argue that the loss was intentionally caused or falls within a fraud exclusion.

But an employee's intentional act may raise a different question where:

  • the employee acted without the employer's knowledge;
  • the employee intended to benefit themselves;
  • the employer was an innocent victim.

The policy wording becomes decisive.

13. Failure to Maintain Cybersecurity

Some policies impose minimum-security conditions.

These may require the insured to maintain:

  • multi-factor authentication;
  • antivirus/endpoint protection;
  • backups;
  • encryption;
  • access controls;
  • patch management;
  • privileged-access controls.

The insurer may attempt to deny a claim where the insured materially failed to maintain required security measures.

However, the insurer must still establish that the particular policy condition/exclusion applies to the facts.

An insurer should not be able to convert every cybersecurity weakness into an automatic exclusion unless the policy supports that result.

14. Regulatory Fines and Penalties

Cyber incidents can result in:

  • regulatory penalties;
  • statutory fines;
  • enforcement actions.

Whether these are insurable depends upon:

  • applicable law;
  • policy wording;
  • nature of the fine;
  • jurisdiction;
  • public-policy considerations.

A policy may expressly exclude:

"fines, penalties and punitive damages."

Some policies may provide limited coverage for certain regulatory defence costs while excluding the actual penalty.

15. Intellectual Property Exclusion

Cyber incidents can generate claims involving:

  • copyright;
  • trademarks;
  • patents;
  • trade secrets;
  • confidential information.

A cyber policy may contain an intellectual-property exclusion or may cover only specified forms of IP liability.

Example

A company is sued after a hacker steals and publishes copyrighted software.

The insured cannot assume that every resulting IP claim is automatically covered under the cyber policy.

16. Professional Services Exclusion

Cyber insurance may exclude losses arising from professional services.

For example:

  • legal advice;
  • financial advice;
  • medical advice;
  • engineering advice;
  • software consulting.

A technology company may therefore need to distinguish:

cyber liability

from

professional indemnity/errors-and-omissions liability.

17. Cryptocurrency and Digital Assets

Some policies specifically exclude or limit losses involving:

  • cryptocurrency;
  • crypto wallets;
  • digital tokens;
  • blockchain assets.

This is important because the value of stolen digital assets can be extremely volatile.

The policy may distinguish between:

  • theft of cryptocurrency;
  • theft of fiat currency through a cyberattack;
  • costs of restoring systems;
  • ransomware payments.

18. Third-Party Service Provider Exclusion

Modern companies frequently depend upon:

  • cloud providers;
  • payment processors;
  • SaaS providers;
  • data centres;
  • managed-service providers.

A cyber incident at a third-party provider can therefore interrupt the insured's business.

Some policies cover such incidents; others may restrict them through exclusions or narrow definitions of dependent business interruption.

19. Exclusion Must Be Read in the Context of the Whole Policy

An exclusion cannot ordinarily be interpreted in isolation.

The policy must be examined as a whole, including:

  • insuring clause;
  • definitions;
  • exclusions;
  • conditions;
  • endorsements;
  • schedules;
  • deductibles;
  • sub-limits.

For example, the policy may initially appear to cover:

"all cyber incidents"

but a definition may narrow "cyber incident" substantially.

20. Important Indian Case Law

There is relatively limited Indian reported case law dealing specifically with modern cyber-insurance exclusions such as ransomware or cyber-war clauses.

Therefore, the principles are largely derived from Indian Supreme Court decisions concerning insurance-contract interpretation and exclusion clauses generally. These principles are directly useful when analysing cyber policies.

Case 1 — General Assurance Society Ltd. v. Chandmull Jain

AIR 1966 SC 1644

This is a foundational Supreme Court decision concerning insurance contracts.

The Court emphasised that insurance contracts must be interpreted according to the terms agreed between the parties.

Relevance to cyber insurance

A cyber policy must therefore be examined through:

  • the coverage clause;
  • definitions;
  • exclusions;
  • conditions;
  • endorsements.

The court cannot rewrite the policy merely because a different allocation of risk might appear commercially preferable.

Principle

Insurance liability arises from the contract actually entered into by the parties.

21. Case 2 — United India Insurance Co. Ltd. v. Harchand Rai Chandan Lal

(2004) 8 SCC 644

This is one of the leading Supreme Court authorities on insurance exclusion clauses.

The Court stressed that where the policy contains an exclusion, the parties are bound by the contractual terms.

The Court also emphasised that courts should not extend the scope of coverage beyond what the policy provides.

Relevance

This is highly relevant to cyber policies.

If a cyber policy expressly excludes:

"loss arising from war"

the court must examine the actual meaning of that exclusion rather than assuming that every cyberattack is covered.

Principle

The insurer's liability is controlled by the agreed policy terms.

22. Case 3 — Oriental Insurance Co. Ltd. v. Sony Cheriyan

(1999) 6 SCC 451

The Supreme Court held that an insurance policy is a contract and the parties are governed by its terms.

The Court stated, in substance, that the insurer cannot be made liable for risks that were not covered by the policy.

Relevance to cyber insurance

A business cannot claim:

"We purchased cyber insurance, therefore all cyber-related losses must be covered."

Instead, the precise scope of the policy must be established.

Principle

Insurance coverage cannot be expanded beyond the contractual undertaking.

23. Case 4 — Vikram Greentech India Ltd. v. New India Assurance Co. Ltd.

(2009) 5 SCC 599

The Supreme Court considered interpretation of insurance-policy terms and emphasised the importance of reading the policy as a whole.

The Court recognised that insurance contracts contain carefully defined allocations of risk.

Relevance

For cyber policies, definitions and exclusions must be read together.

For example:

"Cyber event"

must be considered together with:

"excluded cyber event."

Principle

Policy interpretation requires consideration of the contract as a whole.

24. Case 5 — Canara Bank v. United India Insurance Co. Ltd.

(2020) 3 SCC 455

The Supreme Court considered an insurance dispute involving the interpretation of policy conditions and the insured's obligations.

The judgment illustrates the importance of compliance with contractual requirements imposed by an insurance policy.

Relevance to cyber policies

Cyber policies frequently contain conditions concerning:

  • security controls;
  • notification;
  • incident reporting;
  • cooperation;
  • preservation of evidence.

Failure to comply may become a major issue in a cyber claim.

Principle

The insured must comply with material policy requirements.

25. Case 6 — New India Assurance Co. Ltd. v. Zuari Industries Ltd.

(2009) 9 SCC 70

The Supreme Court dealt with interpretation of insurance policy terms and the scope of contractual coverage.

The judgment reinforces the principle that courts should examine the actual contractual allocation of risk.

Relevance

In cyber insurance, the distinction between:

  • covered loss;
  • excluded loss;
  • partially covered loss; and
  • loss subject to a sub-limit

can be decisive.

26. Case 7 — National Insurance Co. Ltd. v. Ishar Dass Madan Lal

(2007) 4 SCC 105

The Supreme Court considered the interpretation of insurance-policy terms and exclusions.

The decision reinforces the principle that courts cannot disregard clear contractual conditions simply because the insured considers the result inconvenient.

Relevance

Cyber-insurance exclusions such as:

  • prior knowledge;
  • security-condition breaches;
  • excluded liabilities;

must be analysed against the actual contractual language.

27. Case 8 — Export Credit Guarantee Corporation of India Ltd. v. Garg Sons International

(2014) 1 SCC 686

The Supreme Court dealt with the interpretation of insurance-policy exclusions and conditions.

The Court emphasised that contractual terms governing the insurer's liability must be given effect.

Relevance

This principle is particularly important for cyber policies because they frequently contain technically detailed exclusions and conditions.

Principle

Clear contractual limitations on insurance coverage must generally be respected.

28. Case-Law Summary

CaseCitationPrinciple relevant to cyber exclusions
General Assurance Society v. Chandmull JainAIR 1966 SC 1644Insurance liability depends on contractual terms
United India Insurance v. Harchand Rai Chandan Lal(2004) 8 SCC 644Exclusion clauses must be given contractual effect
Oriental Insurance v. Sony Cheriyan(1999) 6 SCC 451Coverage cannot exceed policy undertaking
Vikram Greentech v. New India Assurance(2009) 5 SCC 599Policy must be read as a whole
Canara Bank v. United India Insurance(2020) 3 SCC 455Compliance with policy requirements matters
New India Assurance v. Zuari Industries(2009) 9 SCC 70Contractual allocation of insurance risk is important
National Insurance v. Ishar Dass Madan Lal(2007) 4 SCC 105Policy conditions/exclusions cannot simply be ignored
ECGC v. Garg Sons International(2014) 1 SCC 686Clear contractual limitations generally receive effect

29. Rule of Strict Construction of Exclusions

Indian insurance jurisprudence has repeatedly recognised that exclusion clauses require careful construction.

This does not necessarily mean that every exclusion is interpreted automatically against the insurer.

The proper approach is:

  1. determine the basic coverage;
  2. identify the exclusion;
  3. determine whether the exclusion's wording applies;
  4. consider the policy as a whole;
  5. avoid rewriting the contract;
  6. resolve genuine ambiguity according to applicable principles of insurance-contract interpretation.

The insurer cannot simply point to a vaguely related exclusion and assume that the claim disappears.

30. Burden of Proof

In a cyber-insurance dispute, the insured generally has to establish that the loss falls within the basic coverage.

Once the insurer relies upon a specific exclusion, the exclusion becomes an important issue requiring proper interpretation and factual application.

For example:

Insured establishes:

  • ransomware occurred;
  • systems were encrypted;
  • covered business interruption resulted.

Insurer asserts:

"The attack was a war-related cyber operation."

The insurer would need to establish the factual and contractual basis for applying that exclusion.

The dispute may therefore become heavily evidence-driven.

31. Evidence in Cyber-Insurance Disputes

Evidence may include:

  • forensic reports;
  • SIEM logs;
  • firewall records;
  • endpoint logs;
  • threat-intelligence reports;
  • incident-response reports;
  • ransom communications;
  • email headers;
  • authentication records;
  • cloud logs;
  • employee statements;
  • insurer notification records.

For cyber-war exclusions, attribution evidence can become particularly important.

32. Exclusion vs Condition

These concepts should not be confused.

Exclusion

Defines a risk the insurer does not cover.

Example:

Loss caused by war is excluded.

Condition

Imposes an obligation upon the insured.

Example:

The insured must notify the insurer within a specified period.

A breach of a condition may have consequences specified by the policy and applicable insurance law.

33. Exclusion vs Deductible

These are also different.

Exclusion

No coverage for the excluded risk.

Deductible

Coverage exists, but the insured bears the first specified portion of the loss.

Example:

Cyber loss = ₹50 lakh

Deductible = ₹5 lakh

Potential insurer liability = ₹45 lakh, subject to all other terms.

An excluded loss, by contrast, may result in:

Insurer liability = ₹0

34. Exclusion vs Policy Limit

A policy may cover a cyber event but impose a limit.

Example:

  • Total cyber policy limit: ₹10 crore
  • Regulatory defence sub-limit: ₹50 lakh

A regulatory claim is therefore not necessarily excluded; it may simply be subject to a sub-limit.

35. Importance of Drafting Cyber Exclusions

Cyber exclusions should ideally be:

  • specific;
  • technically clear;
  • internally consistent;
  • appropriately defined;
  • connected to identifiable risks.

Ambiguous language can create litigation.

For example:

"All losses caused directly or indirectly by cyber terrorism."

Questions immediately arise:

  • What constitutes cyber terrorism?
  • Is political motivation required?
  • Who determines attribution?
  • Does state sponsorship matter?
  • What if attribution is uncertain?
  • Does the exclusion apply to indirect consequential losses?

A well-drafted policy should address such questions.

36. Practical Example — Ransomware

Assume:

A company suffers a ransomware attack.

Losses:

  • ₹30 lakh system restoration;
  • ₹20 lakh business interruption;
  • ₹10 lakh forensic costs;
  • ₹5 lakh ransom;
  • ₹2 crore regulatory penalty.

The policy may treat each component differently:

LossPossible treatment
System restorationPotentially covered
Business interruptionPotentially covered
Forensic costsPotentially covered
Ransom paymentDepends on policy and law
Regulatory penaltyMay be excluded
Reputational lossOften excluded or difficult to quantify

Thus:

One cyberattack does not necessarily produce one uniform insurance result.

37. Practical Example — Employee Fraud

Suppose an employee steals ₹1 crore by manipulating an electronic payment system.

Potentially relevant policies could include:

  • cyber insurance;
  • crime/fidelity insurance;
  • bankers' blanket bond;
  • professional indemnity.

The insurer may argue that the loss falls within an employee-fraud exclusion in the cyber policy.

The insured may argue that the incident constitutes a covered cybercrime.

The correct answer depends upon the policy wording and factual mechanism of the theft.

38. Practical Example — Cloud Outage

A company's cloud provider experiences a major outage.

The company loses ₹2 crore in revenue.

If the policy covers dependent business interruption, the loss may potentially be covered.

If the policy excludes ordinary infrastructure/provider failure, coverage may be denied.

Therefore, the insured must examine whether the policy expressly covers third-party technology dependencies.

39. Practical Checklist for Businesses

Before purchasing cyber insurance, companies should examine:

1. War exclusion

Does it specifically cover or exclude cyber warfare?

2. Ransomware

Are ransomware response costs and payments covered?

3. Business interruption

Does it cover dependent business interruption?

4. Cloud failure

Are third-party technology providers covered?

5. Regulatory costs

Are investigation and defence costs covered?

6. Fines and penalties

What is excluded?

7. Employee fraud

Is employee-caused cybercrime covered?

8. Prior acts

What constitutes a prior known circumstance?

9. Security warranties

What cybersecurity controls must be maintained?

10. Territorial scope

Does the policy cover international operations?

11. Digital assets

Are cryptocurrency losses covered?

12. Physical damage

Does cyber-triggered physical damage fall within the policy?

40. Key Principles

The law relating to exclusions in cyber insurance can be summarised as follows:

  1. The insurance policy is the starting point.
  2. Coverage cannot normally be expanded beyond the agreed risk.
  3. Exclusion clauses must be examined carefully.
  4. An exclusion should not be applied beyond its contractual scope.
  5. The policy must be read as a whole.
  6. Definitions can be as important as exclusions.
  7. The insured must establish the basic covered loss.
  8. The insurer relying upon an exclusion must establish its applicability.
  9. Policy conditions concerning cybersecurity and notification can materially affect claims.
  10. Cyber-war attribution can be particularly difficult.
  11. Regulatory fines, ransom payments and physical damage may require separate analysis.
  12. A cyber policy does not automatically cover every loss that has a digital or technological connection.

Conclusion

Exclusions are a fundamental part of cyber-insurance coverage. They determine the boundary between the risks an insurer has agreed to assume and those retained by the insured.

Indian Supreme Court decisions such as General Assurance Society v. Chandmull Jain, Oriental Insurance v. Sony Cheriyan, United India Insurance v. Harchand Rai, Vikram Greentech, Canara Bank and ECGC v. Garg Sons International establish the broader insurance-law principles that are applicable when interpreting cyber-policy exclusions.

The central formula is:

Covered cyber event + covered loss + compliance with policy conditions − applicable exclusion = potential insurance recovery.

The most important practical point is that the occurrence of a cyberattack alone does not establish coverage. The insured must examine the policy's definitions, exclusions, conditions, limits, deductibles and endorsements to determine whether each individual component of the resulting loss is insured.

LEAVE A COMMENT