On Aug. 16, 2022, Lloyd’s of London issued Market Bulletin Y5381, requiring that from March 31, 2023, every standalone cyber policy written in the market exclude losses arising from state-backed cyberattacks, unless Lloyd’s agreed otherwise. The bulletin, from underwriting director Tony Chaudhry, applied at inception or renewal to policies in risk codes CY and CZ, and required the exclusion in addition to any war exclusion already present.
The clause had to meet five minimum requirements. It had to exclude war losses where no separate war exclusion existed. It had to exclude losses from state-backed attacks that significantly impaired a state’s ability to function or its security capabilities. It had to say whether systems outside an affected state were covered. It had to set out a robust basis for attributing an attack to a state. And it had to define its key terms. Managing agents had to show the wording had been legally reviewed with underwriters’ interests in mind.
Why The Clause Exists
The bulletin followed the Merck ruling filed at 22-0121, in which a court held that a war exclusion written for armies did not reach NotPetya, and the Mondelez case filed at 22-1031, which was heading to trial on the same question. Insurers had discovered that their largest catastrophe exclusion did not work for the catastrophe they were most worried about. Y5381 was the market’s answer: write a clause that names the risk directly, and write the attribution mechanism into it so that no court has to decide what warlike means.
The Attribution Problem, Contractualised
Requirement four is the hard one. Attribution of a cyberattack to a state is a judgment made by governments, slowly, on classified evidence, and frequently never made at all. A policy that excludes state-backed attacks needs a way to decide, at claims time, whether this was one. The model clauses point to government attribution by the affected state, with fallbacks to what the insurer can reasonably infer. The corpus records elsewhere how rarely attribution reaches high confidence, and every policy written under Y5381 now depends on it.
Priced, Not Abandoned
Buyers read the bulletin as Lloyd’s exiting the risk. Lloyd’s said the opposite: the requirement was meant to have state-backed risk priced and written separately rather than absorbed silently into standard cover. A later bulletin, Y5433, revised the approach after market feedback. Whether the exclusion has ever been invoked against a claim was not established in the material reviewed, and the test will be the next NotPetya.
Compiled from the bulletin itself and its successor, Y5433, and from trade and legal commentary, listed below. The five requirements are the bulletin’s; the four model clauses are the Lloyd’s Market Association’s. No claim under the exclusion was found. Graded high. Corrections: corrections@forensicpost.com.