Lockton Re Warns Inconsistent Critical Infrastructure Clauses Create Hidden Cyber Insurance Risks

Administrator

Administrator
Staff member
Apr 20, 2025
3,754
686
113

Lockton Re Warns Inconsistent Critical Infrastructure Clauses Create Hidden Cyber Insurance Risks

6a9ec71517786.jpg


How Outdated Cyber Insurance Rules are Creating Hidden Risks for the Industry

The cyber insurance market is facing a quiet but serious challenge. Many insurance policies contain confusing and outdated rules about critical infrastructure, such as power grids, phone networks, and financial systems. Because these rules are inconsistent, insurance companies might be taking on much more financial risk than they realize.

For the past few years, the industry has spent a lot of time debating cyber war policies. While war is a major concern, some experts believe this focus has distracted companies from a more immediate problem: how policies handle failures in basic public services. Infrastructure failures are highly likely to happen, and the industry needs to be prepared for the fallout.

Why Old Policy Rules are Failing Modern Technology

Technology changes rapidly, but the language used in insurance contracts often lags behind. In fact, some insurance providers are still using rules that have not been updated or revised in ten years. This delay creates major gray areas, especially when it comes to modern communication systems.

For example, consider how phone services work today:

  • Many insurance policies do not cover failures in traditional phone networks.
  • However, these same policies often do cover outages in cloud computing services.
  • Today, most phone networks actually run on cloud services, making it very hard to decide if a modern phone outage should be covered or not.

Additionally, governments around the world are starting to classify data centers as critical infrastructure. This shift means insurance companies must be much clearer about what hardware they will and will not cover as the official definition of infrastructure grows wider.

The Real Cost of Unclear Contracts

Unclear rules do not just cause confusion; they also cost money. Computer modeling shows that cleaning up the language in these contracts could make a massive difference. For instance, during a major 1-in-50-year cyber event, having clear and well-drafted rules could reduce the industry's loss ratio by 15 percentage points, which is a relative decrease of 20%.

This difference shows how much the outcome of a claim depends on the exact wording of a contract. Disputes over infrastructure failures are actually much more likely to happen than disputes over cyber war. This is because the trigger point for a power outage or network failure is much lower than the trigger point for a full-scale war. While war might threaten a company's survival, these infrastructure failures are more likely to hurt regular yearly earnings.

How the Industry Can Fix the Problem

To address this issue, industry groups are working independently to create new, standardized templates for these contracts. The goal is not to force every company to use the exact same rules, but rather to make sure everyone understands what is covered. Just as the insurance industry previously created clear standards for asbestos and diseases, it now needs to do the same for cyber infrastructure.

Currently, larger companies that insure the insurance providers—known as reinsurers—have often given their clients a pass. They have trusted that the primary insurance companies were writing sensible rules. However, many of these larger companies are now pushing for a clearer agreement on what actually counts as critical infrastructure.

Finding Better Ways to Share the Burden

If insurance companies can better define what a major cyber event looks like for them, they can share their risks more effectively. Currently, most cyber insurance risk is shared using simple, one-size-fits-all agreements. These agreements do not distinguish well between regular losses that hurt earnings and massive disasters that threaten a company's survival.

By defining these risks more clearly, insurance companies can match different types of cyber threats with the right financial backers. This approach will help make the entire cyber insurance market safer and more stable for the future.