This is an old revision of the document!
Table of Contents
Private actors, liability and insurance
As of 1 October 2026.
Overview
Much of the infrastructure through which cyber and information operations are conducted – networks, cloud services, platforms, software and connected products – is privately owned and operated. This subject area collects private-law and market instruments that bear on such operations: rules on liability for insecure products, security obligations of manufacturers, the treatment of war and State-backed cyber-attacks in insurance contracts, expectations of responsible business conduct in conflict-affected contexts, and private procedures for resolving disputes. These instruments do not govern relations between States and do not attribute conduct to States under international law. They determine how losses are allocated among private parties, which security obligations attach to products and services, and how businesses are expected to act where conflict and human rights are concerned.
Main points of debate
- War and attribution in private contracts. Courts and insurers have had to decide whether traditional war exclusions apply to cyber-attacks attributed to States. The insurance market has since introduced specific exclusions for State-backed cyber-attacks, which require the parties to agree how attribution is to be established; commentators discuss whether private contracts should depend on public attribution by governments.
- Liability and security. The EU has extended product liability to software and linked it to cybersecurity requirements. Supporters expect stronger incentives for secure products; industry associations and some commentators have raised concerns about the burden on manufacturers and on open-source development.
- Technology companies in armed conflict. Providers of connectivity, cloud and software services play a role in armed conflicts. The UN Guiding Principles call for heightened due diligence in conflict-affected areas; how this applies to digital services is discussed by the UN Working Group on business and human rights, civil society organisations and companies.
- Remedies. Whether disputes about business conduct in conflict-affected contexts are best resolved by courts, by arbitration or by mediation is discussed.
Entries
- EU Product Liability Directive (2024) – software as a product; cybersecurity and updates in the assessment of defects.
- EU Cyber Resilience Act (2024) – security requirements and vulnerability reporting for products with digital elements.
- Merck v. Ace American, NotPetya and the war exclusion (2023) – a court decision on a war exclusion after a State-attributed cyber-attack.
- Lloyd's requirements on State-backed cyber-attack exclusions (2022) – market standard for cyber insurance.
- UN Guiding Principles on Business and Human Rights (2011) – corporate responsibility, including in conflict-affected areas.
- Hague Rules on Business and Human Rights Arbitration (2019) – arbitration rules for business and human rights disputes.
