An act of war clause is an insurance provision that can deny coverage when damage is attributed to war or war-like activity. In cyber contexts, the clause can become contentious when state-linked malware or cross-border attacks are involved. Its exact wording can decide whether a claim is paid or rejected.
How an Act of War Clause Works
An act of war clause is not a general exclusion for every hostile event. It is a narrow policy term that tries to separate ordinary cyber loss from damage the insurer believes is tied to war, armed conflict, or war-like activity, which makes the wording itself central to coverage disputes.
In cyber insurance, that distinction matters because the same malware event can be framed as routine criminal activity, espionage, or state-enabled hostile action. The closer the facts appear to government direction, military purpose, or conflict-linked targeting, the more pressure the clause creates on interpretation.
These clauses often become contentious because cyber operations do not map neatly to classic kinetic-war concepts. Attribution is uncertain, intent is disputed, and insurers may rely on the clause to argue that a systemic event falls outside the risk they agreed to cover.
Why the Clause Becomes Disputed in Cyber Claims
The dispute usually starts with attribution. If a loss is linked to a campaign that looks state-sponsored, the insurer may argue the event is war-like; the policyholder may argue it was criminal, opportunistic, or too attenuated from armed conflict to qualify.
Cyber incidents are also unusually cross-border and multi-actor, which makes legal characterisation harder than in physical conflict. A single intrusion may involve proxies, contractors, criminal affiliates, or infrastructure in several jurisdictions, complicating any attempt to label it an act of war.
That ambiguity is why the clause can decide whether a large claim is paid or rejected. The wording may turn on whether the policy requires formal war, hostile acts, government action, or some broader concept of belligerence.
What the Clause Means for Coverage and Policy Wording
For buyers, the practical issue is not just whether the clause exists, but how precisely it is written. Small differences in definitions, attribution standards, and exclusions can materially change which cyber losses remain insured.
For insurers, the clause is a boundary-setting tool that preserves the distinction between insurable cyber events and losses they believe belong in the war-risk category. For insureds, it is a source of coverage uncertainty unless the policy language is tested against realistic cyber scenarios.
Because the term is often litigated or negotiated, the key question is whether the policy uses a narrow military concept or a broader state-linked activity test. That drafting choice determines how much room exists for disagreement when a major incident is blamed on a hostile state actor.
How to Read the Clause in a Cybersecurity Context
In a cyber policy, the clause should be read alongside the rest of the coverage grant, attribution language, and any separate exclusion for hostile acts or infrastructure attacks. The real meaning comes from the interaction of those terms, not from the phrase alone.
When reviewing it, practitioners should focus on whether the policy requires formal war, military operations, government sponsorship, or merely a war-like effect. Those thresholds are not interchangeable, and they strongly affect how a cyber event is classified after the fact.
It also helps to distinguish the technical event from the legal narrative. A malware outbreak, destructive payload, or supply-chain compromise may be technically similar across incidents, while the insurance outcome differs sharply based on how the event is characterised.
Risk and Threat Considerations
Act of war wording creates coverage uncertainty when major cyber incidents are blamed on state-linked activity, because the same facts can support either an insured cyber loss or an excluded war-risk loss. That uncertainty matters most when the event is large, cross-border, and difficult to attribute with confidence.
Failure mechanism: The clause becomes a denial lever when attribution, intent, or state linkage is framed broadly enough to move the incident outside ordinary cyber coverage, even if the policyholder sees the event as criminal or ambiguous hostile activity.
Impact: A disputed interpretation can delay recovery, deny payment for a major loss, and leave the insured exposed at the exact moment when business interruption, restoration, and incident response costs are highest.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Act of war clauses create cyber insurance risk decisions that belong in enterprise risk strategy. |
| GV.RM-03 — Legal and Regulatory Requirements | Coverage disputes depend on legal interpretation of war-like activity and insurance terms. | |
| RC.RP-01 — Recovery Plan Execution | Coverage denial can affect how recovery is funded and executed after a major cyber event. | |
| Recommendation — Review policy exclusions against the organisation's risk appetite and incident recovery assumptions. Map policy wording to legal and contractual obligations before relying on cyber coverage. Align recovery assumptions with the possibility that insurance may not pay for a disputed event. | ||
| ISO/IEC 27001:2022 | A.5.31 — Legal, statutory, regulatory and contractual requirements | Insurance clauses are contractual terms that affect security and recovery planning. |
| Recommendation — Track war-exclusion wording as a contractual requirement affecting incident response and resilience. | ||
Practitioner Guidance
What to watch for: The most important drafting issue is how the policy defines war-like activity and whether it ties exclusion to formal conflict, state direction, or broader hostile conduct. Those details should be tested against plausible cyber events, not just physical-war scenarios.
Governance implication: Risk teams should treat this as a policy interpretation issue, not only a legal one. The clause should be reviewed against the organisation's threat profile, incident history, and dependence on cyber insurance for recovery planning.
Practitioner takeaway: If the wording is vague, the organisation may believe it has coverage that disappears when the claim becomes most expensive.
Related resources from NHI Mgmt Group
- How should security teams prove DORA compliance for AI agents that act autonomously?
- How should organisations prove EU AI Act compliance across the AI lifecycle?
- How should security teams govern AI assistants that can act inside IAM systems?
- How should security teams govern MCP-enabled AI assistants that can act on tools and data?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org