← Back to Blog
Coverage GuideCyberCover Team8 min read14 August 2026

Cyber Insurance Exclusions: What Your Policy Won't Pay For

Why Exclusions Deserve More Attention Than the Cover Summary

Most businesses buying cyber insurance for the first time read the schedule of covered events, check the limit, compare the premium against a couple of alternatives, and sign. The exclusions section — usually several pages of dense wording near the back of the policy — gets skipped. That is understandable, because exclusions are tedious to read and written for lawyers rather than business owners. It is also the single most common reason a claim ends in disappointment.

An exclusion is not a trap. It is the insurer defining the boundary of the risk they have priced. Cyber policies are broad by insurance standards, and the exclusions exist to keep the product commercially viable — no insurer can cover every possible loss connected to a computer and still charge a premium a small business would pay. The problem arises when a business assumes something is covered, does not check, and discovers the gap only when they are trying to recover from an incident. Reading the exclusions before you buy turns those surprises into decisions.

Losses From Systems You Failed to Maintain

Almost every cyber policy contains wording that limits or removes cover where a loss resulted from a failure to apply known security patches, from continued use of software the vendor no longer supports, or from a failure to maintain the security controls you told the insurer you had in place at the time of application. The specific wording varies significantly between insurers. Some policies exclude losses arising from unsupported software outright. Others apply the exclusion only where the unpatched vulnerability was the direct cause of the incident, and some are silent on the point altogether.

This matters more than most businesses realise, because running end-of-life systems is extremely common. An accounting package on an old server, a point-of-sale terminal running an operating system that stopped receiving updates three years ago, or a line-of-business application that nobody has updated because the upgrade path is expensive — any of these can sit at the centre of a claim. If your business relies on legacy systems and you cannot replace them quickly, the right move is to disclose them at application stage and ask the broker to confirm in writing how the policy responds. Insurers will often cover known legacy risk if it has been disclosed and priced. What they will not do is cover it retrospectively when it was never mentioned.

Anything You Knew About Before the Policy Started

Prior known circumstances exclusions remove cover for incidents, breaches, or circumstances that a director or senior manager was aware of before the policy incepted. Cyber attacks frequently have long dwell times — an attacker may be inside a network for weeks or months before the ransomware is deployed or the data is exfiltrated. If the intrusion began before your policy started, or if someone in the business noticed unusual activity and did nothing about it, the insurer may decline on the basis that the circumstance predated the cover.

The practical implication is that switching insurers is a moment of genuine risk. Moving to a new policy without a retroactive date that matches or predates your original cover can leave a gap for anything already in motion. When changing insurers, ask specifically about the retroactive date and whether continuity of cover is preserved. A broker arranging the replacement should raise this without being asked, but it is worth confirming.

Where Social Engineering Cover Stops

Social engineering and funds transfer fraud are among the most frequently claimed cyber losses, and they are also among the most heavily conditioned. Many policies cover fraudulent payment instructions only where the business followed a documented verification process — typically a call-back to a previously known phone number before changing any supplier bank account details. If the payment was made without that verification, the insurer may reduce or decline the claim even though the fraud itself is clearly covered in principle.

Sub-limits are the second issue. A policy with a $1 million aggregate limit may carry a social engineering sub-limit of $50,000 or $100,000. For a business that pays large supplier invoices, that sub-limit can be far below a realistic worst case. It is worth calculating your largest single outgoing payment and comparing it against the sub-limit rather than the headline limit — that comparison usually prompts a more useful conversation with your broker than any other question you can ask.

Property Damage, Bodily Injury and the Physical World

Cyber policies are financial loss products. When a cyber incident causes physical consequences — machinery damaged because control systems were manipulated, product spoiled because refrigeration failed, or injury arising from a compromised safety system — the standard cyber policy will generally exclude those losses and point you toward your material damage or liability cover. The difficulty is that traditional property and liability policies increasingly carry their own cyber exclusions, written to prevent the insurer picking up cyber losses they never priced for.

The result is a potential gap between the two policies. For manufacturers, food processors, logistics operators and anyone running industrial control systems or connected operational technology, this is a genuine exposure that deserves a specific conversation. Some insurers offer cyber-triggered property extensions, and some property policies can be written back to cover cyber-caused damage. Neither happens automatically.

War, State Actors and Infrastructure Failure

War and hostile act exclusions have become the most contested area of cyber insurance globally, following major disputes over attacks attributed to state actors that spread far beyond their intended targets. Most insurers now use wording that carves out cover for attacks attributed to a state or state-sponsored actor, with varying tests for how attribution is established. Given that a significant share of serious ransomware and espionage activity is linked to groups operating with state tolerance or sponsorship, the breadth of this wording is worth understanding.

Separately, most policies exclude losses caused by failure of infrastructure outside your control — power outages, telecommunications failures, or internet backbone disruption — unless the failure was itself the result of a cyber attack on a provider you directly contract with. If you depend heavily on a single cloud provider, ask how the policy responds to an outage at that provider as distinct from a breach of your own systems.

Fines, Betterment and the Cost of Doing It Properly

Two further limitations catch businesses out regularly. Regulatory fines and penalties are only covered where they are insurable at law, and the position varies by jurisdiction and by the nature of the penalty. Policies will typically fund the legal cost of responding to a Privacy Commissioner investigation, but the penalty itself may not be recoverable.

Betterment is the other. Insurance restores you to the position you were in before the loss — it does not fund an upgrade. If your systems are rebuilt after ransomware with better security than they had before, the incremental cost of that improvement usually sits with you. Businesses recovering from a serious incident almost always want to rebuild more securely, and it is sensible to budget for the difference rather than assume the policy will absorb it.

Questions Worth Asking Before You Sign

You do not need to read every clause to buy well. Five questions will surface most of the material gaps: what is the social engineering sub-limit and what verification process must we follow; what is the retroactive date and does it preserve cover from our previous policy; how does the policy respond if the cause was an unpatched or unsupported system; what is the waiting period before business interruption cover begins, and how is the loss calculated; and how is the war and state-actor exclusion worded. Ask these, get the answers in writing, and you will understand your policy better than most buyers.

An adviser who arranges cyber cover regularly will have these answers to hand and will be able to tell you how the wordings differ across the main insurers in the market. If you would like a policy comparison that sets out the exclusions alongside the cover, complete the enquiry form and one of our referred advisers will be in touch. Financial advice is provided by Cover4You, Registered Financial Service Providers.

About the Author

CyberCover Team is part of the CyberCover team — dedicated to making cyber insurance transparent and accessible for NZ businesses of all sizes.

Ready to Get Protected?

Get tailored cyber insurance quotes from licensed NZ brokers. Free advice, no obligation.

Get Your Free Cyber Insurance Quote

Free advice. No obligation. Licensed NZ brokers respond within 1 business day.