Critical infrastructure clauses in cyber insurance are inconsistent across the market, creating uncertainty for insurers, reinsurers, brokers and policyholders, according to a report by Lockton Re, the reinsurance business of Lockton.
Critical infrastructure presents systemic exposures for the cyber market. Those exposures span utilities, telecommunications and financial infrastructure, and sit beyond the scope of the current market.
The report, When the Lights Go Out: Cyber’s Infrastructure Blind Spot, identified significant inconsistencies and shortcomings in current wordings for critical infrastructure clauses.
Lockton Re modelled a range of scenarios to illustrate the potential impact of critical infrastructure clauses in cyber insurance. The modelling demonstrated a potential 20% relative decrease in industry loss ratios at the 1-in-50 (1:50) return period. This illustrates the range of outcomes that clause wording can produce; it is not a forecast of any single event.
Lockton Re noted that the clauses have been neglected in the wake of the industry discussion of cyber war clauses.
Governments are increasingly treating data centres as critical infrastructure. That presents a new challenge for insurance products, which must be clear about the coverage they maintain as the definition widens.
Oliver Brew, Head of Cyber Centre of Excellence at Lockton Re and co-author of the report, said, “The clauses have been neglected in the wake of the industry discussion of cyber war clauses. Clarity of intent for critical infrastructure is key to understanding where the boundary lies of what is insurable. Our review of current critical infrastructure clauses identified significant inconsistencies and shortcomings across the market. The result is uncertainty for insurers, reinsurers, brokers and policyholders alike.”
Laura Betts, Cyber Account Executive at Lockton International and co-author of the report, commented, “We engaged with participants across the market including insurers, reinsurers, brokers, and industry associations to provide insights. With the rapid advancement of new technology, insurance policy language has failed to keep up with the changes in the ways technology is used.”
Lockton Re stressed that critical infrastructure clauses in cyber insurance should be consistent across the market and clearly reflect what they are intended to say.
The report set out a four-point call to action, which included evaluating what constitutes critical infrastructure across key areas; considering whether other categories of critical infrastructure should be addressed; reviewing current critical infrastructure clauses to ensure that language is consistent and matches the intent behind them; and assessing the language framework through the lens of rapidly changing technology to ensure it remains fit for purpose.
Brew added, “There is an urgency to ensure that the intent of these clauses is aligned with the reality of how they can be interpreted. It is incumbent on the whole industry to improve the clarity of what is intended in order to enhance the industry’s reputation.”
Ed Le Flufy, Global Head of Cyber at Lockton Re, concluded, “As new technologies proliferate and aggregation potential grows, the definition of what constitutes critical infrastructure and clarifying the coverage afforded by the market is essential to sustainable growth.”





