THREAT BRIEFING · 13.07.2026 DEENFRES

Strategy & Governance

Why Your Cyber Insurance May Not Pay Out in a Crisis – The Industry’s Toxic Exclusion Clauses

By Tobias Massow · May 15, 2025 · 6 min read

Cyber insurance is booming – the market grows by 25 percent annually. But the disillusionment comes when a claim is made: More and more companies are experiencing that their policy does not pay out. War exclusions, compliance requirements, and retroactive clauses make many policies worthless in an emergency. What companies need to know before signing up.

TL;DR

The Fear-Based Business Model

Cyber insurance sells security. What it actually delivers is a contract full of conditions that systematically work against the insured in the event of a claim. This is not fraud – it is a business model based on asymmetric information.

A medium-sized manufacturing company pays 40,000 Euros annually for a cyber policy with a 5 million Euro coverage limit. Sounds solid. Then comes the ransomware attack. The insurance company reviews the case – and finds: Three out of 200 servers were still running Windows Server 2012 without Extended Security Updates. Clause 4.7: “Coverage is void if known security vulnerabilities are not patched within 30 days.” No payment.

The Three Most Dangerous Clauses

1. War Exclusion: After the NotPetya attack in 2017, insurers refused to pay Mondelez 100 million dollars – reason given: The attack was an act of Russian warfare. Lloyd’s of London expanded the war exclusions in 2023: All “state-sponsored” attacks can be excluded. The problem: Over 60 percent of all APT attacks are attributed to state-affiliated actors.

2. Compliance Requirements: Modern policies list technical minimum requirements: MFA on all remote accesses, EDR on all endpoints, regular vulnerability scans, tested offline backups. If one element is missing, insurers argue “breach of duty.” The burden of proof lies with the insured.

3. Sublimits and Waiting Periods: A 5 million Euro coverage limit sounds reassuring – until you read the sublimits. Business interruption: maximum 500,000 Euros. Ransom payment: excluded. Forensics: capped at 100,000 Euros. Waiting period before business interruption coverage begins: 12 hours. In a ransomware attack that shuts down production for a week, the actual coverage rarely matches the real damage.

Why Insurers Are Tightening Conditions

The insurance industry has its reasons: The combined ratio – the ratio of losses to premiums – for cyber policies has been over 100 percent for years. The business was running at a loss. The tightening of clauses is the response. Whether it is fair is another question.

Insurers argue that strict prerequisites force insured parties to improve their security. This is partly true – companies with cyber policies have demonstrably better baseline security. But the discrepancy between marketing promises and contractual reality remains problematic.

What Companies Should Do

Before Signing Up: Have the policy reviewed by an independent broker AND a specialized lawyer. Pay special attention to war exclusions, technical prerequisites, and sublimits. Ask explicitly: “Under what circumstances will you NOT pay?”

During the Policy Period: Document your security measures comprehensively. Every patch, every scan, every awareness training. In the event of a claim, the burden of proof is on you. Treat your security documentation like a tax return – it must withstand scrutiny.

Alternative Strategy: Consider whether the 40,000 Euros annual premium might be better invested in an incident response retainer, better backups, and a crisis team. For many medium-sized companies, self-insurance with targeted prevention is more economically sensible than a policy full of exclusions.

Conclusion: Insurance Is No Replacement for Security

Cyber insurance has its place – as a last line of defense, not the first. Those who buy a policy to replace security will be doubly punished in an emergency: by the damage and by the rejection. The industry must become more transparent. And companies must stop treating insurance premiums as a security budget.

Key Facts

Rejection Rate: Over 30 percent of cyber claims are fully or partially rejected by insurers (Marsh, 2024).

NotPetya Lawsuit: Merck won a 1.4 billion dollar lawsuit against Ace American Insurance in 2023 – an exceptional case that shook the industry.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Is cyber insurance still worth it?

For large companies with dedicated security teams and clean documentation: Yes, as risk transfer for catastrophic damages. For SMEs with patchy security: The premium is often better invested in direct protective measures.

How do I spot problematic clauses?

Three red flags: First, if “state-sponsored attacks” are fully excluded. Second, if technical prerequisites are formulated without tolerance rules. Third, if sublimits effectively reduce the total coverage to a fraction.

Will regulation improve the situation?

The EU is working on standards for cyber insurance contracts. Until these take effect, the responsibility lies with the insured: thoroughly check policies, meet prerequisites and document them, seek legal advice if in doubt.

Related Articles

More from the MBF Media Network

MyBusinessFutureRisk management for decision-makers on mybusinessfuture.comDigital ChiefsStrategic IT decisions on digital-chiefs.de

Further reading

News · July 2, 2026

When Attackers Are Faster Than the Patch

Between disclosure and exploitation of a vulnerability, only days often pass today. The State of Vulnerabilities Report 2026 reveals what matters now.

A magazine by Evernine Media GmbH