Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Act Of War Exclusion
Governance, Ownership & Risk

Act Of War Exclusion

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Governance, Ownership & Risk

A policy clause that lets an insurer deny coverage for losses tied to warfare or hostile state action. In cyber insurance, the phrase can be hard to apply because attacks may spread beyond their intended target and cause damage without resembling traditional kinetic conflict.

What the Act Of War Exclusion Means in Cyber Insurance

An act of war exclusion is a policy carve-out that can let an insurer deny coverage for losses tied to warfare or hostile state action. In cyber, the hard part is deciding when a digital event is really war-like conduct versus ordinary criminal or disruptive activity.

Why the Clause Is Hard to Apply in Cyber Losses

Traditional war exclusions were built around kinetic conflict, declared hostilities, and clear state actors. Cyber events often cross borders, use proxies, hide attribution, and create broad collateral damage, which makes the line between war, espionage, sabotage, and criminal intrusion much less stable.

That ambiguity matters because the same malware campaign may look like a routine criminal operation in one fact pattern and a state-directed operation in another. Coverage disputes usually turn on attribution, intent, target selection, scale, and whether the loss arose from a hostile act that can fairly be treated as warfare.

How Insurers and Policyholders Interpret It

In practice, the clause is not just a legal phrase, it is a risk-allocation device. Insurers use it to limit exposure to catastrophic, correlated losses, while policyholders want enough certainty that a disruptive cyber incident will still be covered even if the attacker is advanced or politically motivated.

The interpretation problem is compounded when an incident spreads beyond the intended victim. A worm, destructive payload, or supply-chain compromise may create widespread damage without looking like a conventional battle, which is why courts and claims teams often focus on the specific policy wording and the available evidence of state involvement.

What Makes the Exclusion So Contested

The clause is contested because cyber operations rarely announce themselves as war. Attribution can be uncertain, state sponsorship may be indirect, and damage can be accidental, opportunistic, or intentionally indiscriminate, all of which complicate whether the exclusion should apply.

For that reason, many disputes center on whether the loss was caused by hostile state action, merely facilitated by infrastructure in another country, or carried out by non-state actors who happened to benefit from geopolitical conflict. The legal answer often depends on whether the policy language requires a war nexus, a hostile state nexus, or something broader.

Risk and Threat Considerations

Cyber war exclusions create a real coverage gap when an incident is large, fast-moving, and difficult to attribute. That gap can leave organisations exposed precisely when they face the most severe disruption, especially if a policy uses broad hostile-action wording without clear attribution standards.

Failure mechanism: Ambiguous wording, uncertain attribution, and correlated damage can allow an insurer to argue that the loss falls outside cover even when the event began as a conventional cyber intrusion.

Impact: A claims denial can shift major response, recovery, business interruption, and third-party liability costs back to the insured, increasing financial shock after a systemic incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyCyber war exclusions affect enterprise cyber risk transfer decisions.
GV.SC-01 — Supply Chain Risk Management StrategyState-backed or propagated cyber events often travel through third-party dependencies.
RC.RP-01 — Recovery Plan ExecutionCoverage denial changes how recovery funding and continuity planning must work after a major cyber event.
Recommendation — Assess cyber insurance exclusions as part of your risk transfer strategy. Map third-party dependencies that could trigger or amplify excluded cyber losses. Align recovery funding assumptions with possible exclusion-driven claim denial.
ISO/IEC 27001:2022A.5.23 — Information security for use of cloud servicesCyber insurance coverage disputes often hinge on cloud-delivered attack paths and dependent services.
Recommendation — Review cloud and third-party dependencies when assessing insurer exclusion exposure.
NIST SP 800-53 Rev 5RA-3 — Risk AssessmentThe clause requires structured assessment of hostile-state, attribution, and loss scenarios.
Recommendation — Evaluate hostile-state cyber loss scenarios in the enterprise risk assessment.

Practitioner Guidance

Why practitioners should care: This clause is one of the most consequential coverage disputes in cyber insurance because it determines whether a severe incident is treated as an insurable cyber loss or an excluded act tied to war. Policy language should be read for how it handles attribution, hostile state action, and silent or indirect sponsorship.

Common misunderstanding: Many buyers assume an exclusion only applies to declared war or obvious military conflict. In cyber, the clause may turn on broader concepts such as state direction, hostility, or coordinated destructive activity, so the wording deserves close review before a loss occurs.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org