LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:soft:lloyds_cyber_exclusions

Lloyd's requirements on State-backed cyber-attack exclusions (2022)

As of 1 October 2026. Information only, not legal advice – see the disclaimer.

Full title Lloyd's Market Bulletin Y5381 “State backed cyber-attack exclusions”, 17 August 2022, with the model clauses LMA5564–LMA5567 of the Lloyd's Market Association (November 2021)
Type Market requirement of an insurance market; model contract clauses
Adopted by Lloyd's (Corporation of Lloyd's); Lloyd's Market Association
Adopted 17 August 2022
Legal status Not law. Binding on managing agents at Lloyd's under Lloyd's market supervision; applies to standalone cyber-attack policies incepting or renewing from 31 March 2023. The clauses bind policyholders only as terms of their contracts
Official text Lloyd's (Market Bulletin Y5381)
Subject area Private actors, liability and insurance; Use of force, intervention and cyber operations

Note: This entry describes the market requirements and model clauses as published. Clauses and market practice change; the wording of individual policies varies. The entry does not describe any particular policy and is not insurance advice.

Overview

After disputes about the application of traditional war exclusions to cyber-attacks, Lloyd's required all standalone cyber-attack policies written in its market to contain a suitable clause excluding liability for losses arising from State-backed cyber-attacks. The bulletin sets minimum requirements for such clauses. It is referred to in discussions on how private markets deal with cyber operations attributed to States and on the insurability of cyber war.

Provisions relevant to the cyber and information sphere

The bulletin requires that the exclusion, at a minimum:

  • excludes losses arising from war (whether declared or not), where the policy does not have a separate war exclusion;
  • excludes losses arising from State-backed cyber-attacks that significantly impair the ability of a State to function or that significantly impair the security capabilities of a State;
  • is clear as to whether cover excludes computer systems located outside any State affected in this way;
  • sets out a robust basis on which the parties agree how any State-backed cyber-attack will be attributed to one or more States.

The model clauses LMA5564–LMA5567 differ in the scope of cover they retain; their attribution provisions refer primarily to attribution by the government of the State in which the affected computer system is located.

Application to cyber and information operations

The requirements transfer concepts from the law of State responsibility and armed conflict – war, attribution to a State, impairment of essential State functions – into private contracts. Whether a loss is covered can thus depend on public attribution by governments. For the prior case law see Merck v. Ace American (2023).

Recent developments

  • 2021-11: Lloyd's Market Association publishes model clauses LMA5564–LMA5567.
  • 2022-08-17: Market Bulletin Y5381.
  • 2023-03-31: Requirements apply to policies incepting or renewing from this date.

Sources

Change log

  • 2026-10-01: Entry created; note on the scope of the entry added.
law/soft/lloyds_cyber_exclusions.txt · Last modified: by lfpo