Cyber Insurance Coverage Disputes: Where Claims Actually Get Denied
By the Legal Cyber Academy editorial team ·
Where cyber insurance claims actually get denied
Cyber insurance coverage disputes rarely turn on whether an attack happened. They turn on a short list of recurring grounds: war and hostile-act exclusions, notice measured from what a senior officer knew, misrepresentation in the application, failure to maintain the security controls the applicant described, sublimits that route social-engineering losses into a smaller bucket, and prior-consent conditions governing ransom payments, vendors, defense counsel and settlement. Most of them are decided on paper written before the incident.
Start with the declarations page, not the exclusions
The denial letter will cite an exclusion. The number that decides the case is often on the declarations. The Travelers CyberRisk Tech policy filed as Exhibit 3 in the International Control Services rescission action shows the shape: a $1,000,000 CyberRisk aggregate limit, with Privacy and Security at $1,000,000 over a $50,000 retention — but Computer Fraud, Funds Transfer Fraud, Social Engineering Fraud and Telecom Fraud each capped at $100,000 with a $25,000 retention. Cyber Extortion, Data Restoration and Business Interruption sat at $500,000, with a 12-hour wait period and a "Defense Within Limits" legend: the limit available to pay settlements or judgments "will be reduced, and may be completely exhausted, by Defense Costs."
Two dates on that same declarations page do as much work as any exclusion. The Retro Date (April 4, 2014) feeds a Prior Acts exclusion barring loss arising out of a wrongful act occurring before it. The Knowledge Date (April 4, 2022, equal to inception) feeds a Prior Matters exclusion barring loss arising out of any fact or wrongful act that "is, or reasonably would be regarded as, the basis for a Claim under the Liability Insuring Agreements about which any Executive Officer had knowledge" before that date. For the pre-purchase version of this analysis, see what attorneys should advise clients about cyber coverage.
War exclusions: what NotPetya settled, and what it did not
In Merck & Co. v. ACE American Insurance Co., Nos. A-1879-21, A-1882-21, the New Jersey Appellate Division — an intermediate appellate court applying New Jersey law — affirmed on May 1, 2023 (approved for publication) that a "hostile or warlike action" exclusion did not bar Merck's NotPetya losses under twenty-six "all risk" property policies. The insurers argued "hostile" should be read in its broadest sense, as "showing ill will or a desire to harm" by a government or sovereign power. The court rejected that reading: the exclusion "requires the involvement of military action," and the NotPetya attack "is not sufficiently linked to a military action or objective as it was a non-military cyberattack against an accounting software provider."
That holding construes a legacy property wording. It says little about a standalone cyber policy written after March 2023. Lloyd's Market Bulletin Y5381 (16 August 2022) requires managing agents at Lloyd's to include, in all standalone cyber-attack policies falling within risk codes CY and CZ, "unless agreed by Lloyd's," a clause excluding liability for losses arising from state backed cyber-attacks — effective from 31 March 2023 at the inception or on renewal of each policy, with no requirement to endorse in-force policies unless they expire more than 12 months after that date. At a minimum, the clause must exclude losses from state backed cyber-attacks that "significantly impair the ability of a state to function" or "significantly impair the security capabilities of a state," and must "set out a robust basis by which the parties agree on how any state backed cyber-attack will be attributed to one or more states."
So the modern fight is attribution, not semantics. LMA5567A (War and Cyber Operation Exclusion No. 4, 18 January 2023) provides that, "[n]otwithstanding the insurer's burden of proof, which shall remain unchanged by this clause," in determining attribution of a cyber operation to a state "the insured and insurer will consider such objectively reasonable evidence that is available to them," which "may include formal or official attribution by the government of the state in which the computer system affected by the cyber operation is physically located to another state or those acting at its direction or under its control." Its "impacted state" definition reaches any state where a cyber operation has had a major detrimental impact on the functioning of that state through disruption to an essential service, or on the security or defence of that state. The LMA's own compliance table records that the "B" versions of these clauses lack the attribution paragraph, so managing agents using them "will need to articulate to Lloyd's how they expect attribution to be addressed."
A third pattern persists in the US retail market. The Travelers form filed in the ICS litigation pairs an ordinary war exclusion — war, warlike action by a government, military force or sovereign, insurrection and usurped power — with a write-back: the exclusion "does not apply to an actual or threatened attack against a Computer System with intent to cause harm, or further social, ideological, religious, political, or similar objectives, except when in support of" those war and insurrection prongs. The final clause matters as much as the write-back. Identify which family of wording the policy uses before reading Merck onto it.
The application, and the rescission remedy
Travelers sued to rescind a $1,000,000 CyberRisk Tech policy issued to International Control Services, alleging the insured had answered "Yes" to whether it required multi-factor authentication for "[a]dministrative or privileged access," and "Yes" to every affirmation on a signed MFA Attestation covering email access, all remote access, and internal and remote admin access to directory services, backup environments, network infrastructure and endpoints/servers. The attestation stated that these "are the minimum controls that must be in place in order to be eligible for a Cyber policy." After a ransomware attack beginning on or about May 25, 2022, Travelers alleged it learned that MFA was not protecting the compromised server and that ICS used MFA only to protect its firewall.
The case ended by agreement, not adjudication. On August 30, 2022, on an agreed motion, the court entered an order rescinding the policy and declaring it "null and void from its inception," and dismissed the matter with prejudice. The order records that "Travelers asserts in this action that in applying for the Policy, ICS made incorrect statements"; the court made no finding that the statements were false or material. So the case shows what an insurer will plead and what an insured may concede — not a judicial holding that application answers operate as warranties.
Note the gap between two instruments. The same form's Representations condition is comparatively narrow: coverage is lost only where a representation was untrue, was material to the acceptance of the risk and is material to a covered loss, and then only as to an insured person who knew — or an insured entity whose executive officer knew — that the representation was untrue at inception. Rescission under state insurance law runs on different terms and unwinds the policy entirely. Standards vary by jurisdiction; in New York, Insurance Law § 3105(b)(1) provides that "[n]o misrepresentation shall be deemed material unless knowledge by the insurer of the facts misrepresented would have led to a refusal by the insurer to make such contract." The documents that decide such a dispute are the attestation, the questionnaire as submitted, the signer's identity, and what IT told that signer. On the exposure of executives who sign such attestations, see CISO personal liability after United States v. Sullivan.
"Continuously implement": the controls exclusion
Columbia Casualty's 2015 declaratory-judgment complaint against Cottage Health System quoted an exclusion titled "Failure to Follow Minimum Required Practices," barring loss "based upon, directly or indirectly arising out of, or in any way involving... [a]ny failure of an Insured to continuously implement the procedures and risk controls identified in the Insured's application for this Insurance and all related information submitted to the Insurer in conjunction with such application whether orally or in writing." A separate "Minimum Required Practices" condition had the insured warrant, "as a condition precedent to coverage," that it would follow the listed minimum required practices and maintain all risk controls identified in its application. The insurer alleged, on information and belief, that the breach arose from FTP settings on internet servers that permitted anonymous user access and from a failure to replace factory default settings. Those allegations were never tested: the action was dismissed on the ADR ground discussed below, so no court ruled on the exclusion.
The operative word is "continuously." Wording of that kind converts a point-in-time questionnaire into a running obligation, which can make the forensic root-cause conclusion the coverage conclusion. Where an incident report names an unpatched edge device or a service account without MFA as the intrusion path, and the application described otherwise, the same paragraph supports both the exclusion and a rescission theory — which is a reason to read such a report closely (how to read a forensic report).
Notice runs from what an officer knew, not from when counsel got involved
In the Travelers form, "Discovery" occurs "when an Executive Officer first becomes aware of facts that would cause a reasonable person to assume that a First Party Loss has been or will be incurred" — Executive Officer being defined as the chief executive officer, chief financial officer, chief information security officer, risk manager, in-house general counsel, or the functional equivalent of those. Notice of the particulars of the event is due "as soon as practicable" from that point. Where the first party event causes loss under the Cyber Crime or Business Loss insuring agreements in an amount more than 25% of the applicable retention, the insured must give a detailed, sworn proof of loss within 120 days, submit to an examination under oath and give a signed statement of its answers, and notify law enforcement if the event violates law. Legal action on the cyber crime coverages may not be brought until 60 days after the proof of loss is filed, and must be commenced within two years from the date the insured entity discovers the first party event. (Notice of a Claim runs on a separate track: it is due as soon as practicable once an executive officer becomes aware that a claim has been made.)
Statutory relief is narrower than practitioners sometimes assume, and is easy to invoke in the wrong lane. New York Insurance Law § 3420 governs policies "insuring against liability for injury to person... or against liability for injury to, or destruction of, property" that are "issued or delivered in this state." It is a liability-insurance statute: it does not reach first-party coverages such as business interruption, extortion or data restoration, and its application to a cyber policy responding to purely economic privacy losses cannot be assumed. Where it does apply, subsection (a)(5) provides that late notice "shall not invalidate any claim made by the insured, injured person or any other claimant, unless the failure to provide timely notice has prejudiced the insurer." Subsection (c)(2)(A) puts the burden on the insurer to prove prejudice if notice came within two years of the time required under the policy, and on the insured, injured person or other claimant to disprove prejudice if it came later. Subsection (c)(2)(C) adds that the insurer's rights "shall not be deemed prejudiced unless the failure to timely provide notice materially impairs the ability of the insurer to investigate or defend the claim." But subsection (c)(2)(B) imposes an irrebuttable presumption of prejudice where, before notice, the insured's liability was determined by a court or binding arbitration, or the insured "resolved the claim or suit by settlement or other compromise." Settling first and noticing later forfeits the argument entirely.
Social engineering sits in the small bucket by design
Mississippi Silicon Holdings, L.L.C. v. Axis Insurance Co., No. 20-60215 (5th Cir. Feb. 4, 2021), is unpublished and, by its own terms, not precedent except under Fifth Circuit Rule 47.5.4 — and it construes a commercial crime policy under Mississippi law, not a cyber policy. A vendor-impersonation scheme produced roughly $1.025 million in wire transfers. Axis paid the $100,000 Social Engineering Fraud limit and denied the $1,000,000 Computer Transfer Fraud coverage. The Fifth Circuit affirmed summary judgment for the insurer. The fraudsters had gained access to the company's email system, but "did not manipulate those systems through the introduction of data or programs that could independently instruct the Computer System." Independently, the provision reached only transfers made "without the Insured Entity's knowledge or consent," and three employees had affirmatively authorized the transfer.
Some cyber forms remove the argument at the definitional stage. In the Travelers wording, "Computer Fraud" and "Funds Transfer Fraud" each state that they do "not include Social Engineering Fraud" — the higher limit is unreachable by definition rather than by construction. Check the definitions before pleading the theory that lost in Mississippi Silicon.
Ransomware raises the mirror-image question. In G&G Oil Co. of Indiana, Inc. v. Continental Western Insurance Co., No. 20S-PL-617 (Ind. Mar. 18, 2021), the Indiana Supreme Court construed the phrase "fraudulently cause a transfer" in the Computer Fraud provision of a commercial crime coverage part as reasonably understood "simply 'to obtain by trick.'" It held that G&G Oil's losses did result directly from the use of a computer, but that neither side was entitled to summary judgment: it reversed the grant of summary judgment for the insurer, affirmed the denial of the insured's motion, and remanded. On the insured's motion the court wrote: "We do not think every ransomware attack is necessarily fraudulent. For example, if no safeguards were put in place, it is possible a hacker could enter a company's servers unhindered and hold them hostage. There would be no trick there." Coverage turned on evidence about the hack's initiating event that neither side had developed.
Consent: ransom, vendors, counsel, settlement
Consent conditions bind from the first hours of an incident, often before coverage counsel is retained. In the Travelers form, Cyber Extortion Costs mean, "with the Insurer's prior written consent," the ransom paid in direct response to an extortion threat and reasonable amounts incurred in the process of paying it; Restoration Costs and Extra Expense likewise require the insurer's written consent. Computer and Legal Expert Costs and Public Relations Costs are covered only where the services are "recommended and provided by an Approved Provider" — a service provider approved by the insurer in writing to the insured — and Privacy Breach Notification Costs are covered where recommended and provided by an approved provider. Defense Costs are reasonable fees and costs incurred by the insurer, or by the insured with the insurer's prior written consent.
On counsel: the declarations state whether the insurer has the duty to defend. Where it does — as in the ICS policy — the insurer "has the right to select defense counsel." Where it does not, the insured has the duty to defend, and the insurer has the right to participate in the selection of defense counsel and in the investigation, defense and settlement of claims. In either case the insured must not, without the insurer's prior written consent, make an offer to settle or settle a claim, admit liability, or — except at the insured's own cost — make a voluntary payment or incur defense costs or other expense. The hammer clause operates as co-insurance: where the insurer and claimant agree to settle but the insured withholds consent, the insured is responsible for 20% of defense costs incurred after the date consent was withheld and 20% of loss, other than defense costs, in excess of the settlement offer. One general condition cuts the other way and is worth quoting back to an adjuster: "Where the Insurer's consent is required, such consent will not be unreasonably withheld." For the operational sequence around extortion payments, see ransomware response and legal obligations.
The ADR clause can decide when suit is possible at all
Some cyber policies make mediation a condition precedent to suit, and the condition runs against insurers too. The Cottage Health policy provided that all disputes and differences between the insured and the insurer arising under or in connection with the policy "shall be submitted to the alternative dispute resolution ('ADR') process," and that where mediation is the chosen method "no... judicial proceeding shall be commenced until the mediation shall have been terminated and at least 60 days shall have elapsed from the date of the termination." On July 17, 2015, the court held that this language "controls the timing of suits arising out of the policy and requires that the ADR process take place before a lawsuit is initiated," and dismissed the insurer's own declaratory-judgment complaint without prejudice, treating the failure to exhaust as clear from the face of the complaint.
The court also noted, in a footnote, that the plaintiff had identified no prejudice from dismissal rather than a stay, "such as the running of a statute of limitations." A contractual suit limitation — for example, the two-year cyber-crime provision in the Travelers form — is exactly the kind of clock that would raise that question, which is a reason to calendar the ADR sequence against any such limitation.
Learn more
Legal Cyber Academy faculty whose work touches this area include Tamara Snowdon, Head of Cyber Risk Wordings at Beazley; Aaron Tantleff, Partner at Foley & Lardner LLP; and Roland Cloutier, former Global Chief Security Officer of TikTok. Because these policies can route disputes into mediation first, the neutrals matter too: Gregory M. Sleet and James Orenstein serve as JAMS neutrals.
This is general information, not legal advice; policy language and governing law vary, and any coverage question should be evaluated against the specific policy and jurisdiction at issue.
Go deeper — courses on this
Digital ForensicsFrom Feed to Evidence: A Lawyer's Guide to Authenticating Social Media Posts
This course covers how social media data functions as litigation evidence, including how to access…
Daniel B. Garrie · 1h 1m
RansomwareDecrypting the Threat: How to Protect Your Organization from Ransomware Risk
Technical and legal experts explain how ransomware works and what today's threat environment looks like…
Daniel B. Garrie · 1h 3m
FreeRansomwareBest Practices to Limit an Organization's Ransomware Risk from a Legal Perspective
This seminar covers the ransomware threat landscape alongside both technical and legal risk-management…
Daniel B. Garrie
Keep reading
- Smart Contract Disputes: Where Code Meets Contract LawSmart contract disputes turn on off-chain facts: which terms attached, who held the admin keys, whether an oracle was manipulated, what a ju…
- Cyber Insurance: What Attorneys Should Advise Their ClientsCyber insurance is now a frontline risk-management tool. Learn what practicing attorneys need to know to guide clients toward the right cove…
- Legal Hold: What Triggers the Duty to Preserve, and What Actually Satisfies ItWhen the duty to preserve attaches, how far a legal hold must reach, and what FRCP 37(e) requires before a court can sanction a party for lo…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.