This is an old revision of the document!
Table of Contents
Lloyd's requirements on State-backed cyber-attack exclusions (2022)
As of 1 October 2026.
| Full title | Lloyd's Market Bulletin Y5381 “State backed cyber-attack exclusions”, 17 August 2022, with the model clauses LMA5564–LMA5567 of the Lloyd's Market Association (November 2021) |
|---|---|
| Type | Market requirement of an insurance market; model contract clauses |
| Adopted by | Lloyd's (Corporation of Lloyd's); Lloyd's Market Association |
| Adopted | 17 August 2022 |
| Legal status | Not law. Binding on managing agents at Lloyd's under Lloyd's market supervision; applies to standalone cyber-attack policies incepting or renewing from 31 March 2023. The clauses bind policyholders only as terms of their contracts |
| Official text | Lloyd's (Market Bulletin Y5381) |
| Subject area | Private actors, liability and insurance; Use of force, intervention and cyber operations |
Overview
After disputes about the application of traditional war exclusions to cyber-attacks, Lloyd's required all standalone cyber-attack policies written in its market to contain a suitable clause excluding liability for losses arising from State-backed cyber-attacks. The bulletin sets minimum requirements for such clauses. It is referred to in discussions on how private markets deal with cyber operations attributed to States and on the insurability of cyber war.
Provisions relevant to the cyber and information sphere
The bulletin requires that the exclusion, at a minimum:
- excludes losses arising from war (whether declared or not), where the policy does not have a separate war exclusion;
- excludes losses arising from State-backed cyber-attacks that significantly impair the ability of a State to function or that significantly impair the security capabilities of a State;
- is clear as to whether cover excludes computer systems located outside any State affected in this way;
- sets out a robust basis on which the parties agree how any State-backed cyber-attack will be attributed to one or more States.
The model clauses LMA5564–LMA5567 differ in the scope of cover they retain; their attribution provisions refer primarily to attribution by the government of the State in which the affected computer system is located.
Application to cyber and information operations
The requirements transfer concepts from the law of State responsibility and armed conflict – war, attribution to a State, impairment of essential State functions – into private contracts. Whether a loss is covered can thus depend on public attribution by governments. For the prior case law see Merck v. Ace American (2023).
Recent developments
- 2021-11: Lloyd's Market Association publishes model clauses LMA5564–LMA5567.
- 2022-08-17: Market Bulletin Y5381.
- 2023-03-31: Requirements apply to policies incepting or renewing from this date.
Related entries
Sources
- Lloyd's Market Bulletin Y5381, accessed 2026-10-01
- Kennedys: New Lloyd's Market Bulletin addresses state backed cyber attacks, accessed 2026-10-01
Change log
- 2026-10-01: Entry created.
