A policy clause that lets an insurer deny coverage for losses tied to warfare or hostile state action. In cyber insurance, the phrase can be hard to apply because attacks may spread beyond their intended target and cause damage without resembling traditional kinetic conflict.
What the Act Of War Exclusion Means in Cyber Insurance
An act of war exclusion is a policy carve-out that can let an insurer deny coverage for losses tied to warfare or hostile state action. In cyber, the hard part is deciding when a digital event is really war-like conduct versus ordinary criminal or disruptive activity.
Why the Clause Is Hard to Apply in Cyber Losses
Traditional war exclusions were built around kinetic conflict, declared hostilities, and clear state actors. Cyber events often cross borders, use proxies, hide attribution, and create broad collateral damage, which makes the line between war, espionage, sabotage, and criminal intrusion much less stable.
That ambiguity matters because the same malware campaign may look like a routine criminal operation in one fact pattern and a state-directed operation in another. Coverage disputes usually turn on attribution, intent, target selection, scale, and whether the loss arose from a hostile act that can fairly be treated as warfare.
How Insurers and Policyholders Interpret It
In practice, the clause is not just a legal phrase, it is a risk-allocation device. Insurers use it to limit exposure to catastrophic, correlated losses, while policyholders want enough certainty that a disruptive cyber incident will still be covered even if the attacker is advanced or politically motivated.
The interpretation problem is compounded when an incident spreads beyond the intended victim. A worm, destructive payload, or supply-chain compromise may create widespread damage without looking like a conventional battle, which is why courts and claims teams often focus on the specific policy wording and the available evidence of state involvement.
What Makes the Exclusion So Contested
The clause is contested because cyber operations rarely announce themselves as war. Attribution can be uncertain, state sponsorship may be indirect, and damage can be accidental, opportunistic, or intentionally indiscriminate, all of which complicate whether the exclusion should apply.
For that reason, many disputes center on whether the loss was caused by hostile state action, merely facilitated by infrastructure in another country, or carried out by non-state actors who happened to benefit from geopolitical conflict. The legal answer often depends on whether the policy language requires a war nexus, a hostile state nexus, or something broader.
Risk and Threat Considerations
Cyber war exclusions create a real coverage gap when an incident is large, fast-moving, and difficult to attribute. That gap can leave organisations exposed precisely when they face the most severe disruption, especially if a policy uses broad hostile-action wording without clear attribution standards.
Failure mechanism: Ambiguous wording, uncertain attribution, and correlated damage can allow an insurer to argue that the loss falls outside cover even when the event began as a conventional cyber intrusion.
Impact: A claims denial can shift major response, recovery, business interruption, and third-party liability costs back to the insured, increasing financial shock after a systemic incident.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Cyber war exclusions affect enterprise cyber risk transfer decisions. |
| GV.SC-01 — Supply Chain Risk Management Strategy | State-backed or propagated cyber events often travel through third-party dependencies. | |
| RC.RP-01 — Recovery Plan Execution | Coverage denial changes how recovery funding and continuity planning must work after a major cyber event. | |
| Recommendation — Assess cyber insurance exclusions as part of your risk transfer strategy. Map third-party dependencies that could trigger or amplify excluded cyber losses. Align recovery funding assumptions with possible exclusion-driven claim denial. | ||
| ISO/IEC 27001:2022 | A.5.23 — Information security for use of cloud services | Cyber insurance coverage disputes often hinge on cloud-delivered attack paths and dependent services. |
| Recommendation — Review cloud and third-party dependencies when assessing insurer exclusion exposure. | ||
| NIST SP 800-53 Rev 5 | RA-3 — Risk Assessment | The clause requires structured assessment of hostile-state, attribution, and loss scenarios. |
| Recommendation — Evaluate hostile-state cyber loss scenarios in the enterprise risk assessment. | ||
Practitioner Guidance
Why practitioners should care: This clause is one of the most consequential coverage disputes in cyber insurance because it determines whether a severe incident is treated as an insurable cyber loss or an excluded act tied to war. Policy language should be read for how it handles attribution, hostile state action, and silent or indirect sponsorship.
Common misunderstanding: Many buyers assume an exclusion only applies to declared war or obvious military conflict. In cyber, the clause may turn on broader concepts such as state direction, hostility, or coordinated destructive activity, so the wording deserves close review before a loss occurs.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org