PONOPT FIELD NOTES · Страхование и риск

Where Cyber Insurance Ends and Physical Site Risk Begins

Traditional cyber insurance excludes physical property damage, while property and liability policies increasingly exclude cyber-caused loss. Here's where the gap sits.

Standalone cyber insurance indemnifies data breaches, ransomware and IT interruption but almost always excludes physical damage to property and bodily injury. Property and general-liability policies, in turn, increasingly exclude cyber-caused loss through clauses such as LMA 5400/5401 and ISO CG 40 35. The seam where both stop is the moment a cyber event damages a physical asset: equipment, buildings or control systems. Closing it requires affirmative cyber-property cover plus site-level controls that underwriters now price.

Key takeaways

  • Cyber policies typically cover digital losses but exclude physical property damage and bodily injury; property policies exclude cyber perils — a documented, structural gap.
  • "Silent cyber" is closing: LMA 5400/5401 and ISO CG 40 35 exclude cyber-caused physical losses, so assuming a GL or property policy will respond is no longer safe.
  • The network-to-site bridge runs through OT, ICS/SCADA, building-management and power/cooling systems, where digital manipulation becomes overheating, fire, explosion or flooding.
  • Underwriters now underwrite operational resilience, not just IT security: full asset visibility, network segmentation, secure third-party remote access and verified recovery.
  • Options to close the gap include affirmative property-damage extensions on a cyber policy, dedicated cyber "gap" policies that un-exclude LMA clauses, and single-insurer cyber-property endorsements.
  • Coverage wording and jurisdiction determine outcomes; confirm exact scenarios with a broker before relying on any policy.
  • Site-level controls (perimeter, access, monitoring of control systems) cut both the likelihood of loss and the cost of insurability.

A cyber policy stops at the digital boundary

Standalone cyber insurance was built to pay for a narrow class of harm: forensic investigation, breach notification and credit monitoring, ransom negotiation, network restoration and the business interruption that flows directly from a systems outage. Damage to physical things was never part of the design. In a typical wording, the same incident that corrupts a server may be covered while the fire or the burst pipe that follows is not, because bodily injury and property damage sit outside the cyber insuring agreement.

This boundary is explicit, not accidental. Specialist insurer Beazley captures the common trap: an organisation often assumes "either their property insurance or cyber policy will respond," yet property policies may not respond or may heavily sublimit cover when damage is caused by a malicious cyberattack, while cyber policies "may not clearly respond when the loss is physical rather than digital." The result is a high-severity exposure that sits between two products designed for different worlds.

  • Typically covered: data breaches, ransomware, privacy defence costs, incident response, IT-driven business interruption.
  • Typically excluded: damage to buildings, equipment and inventory, plus bodily injury arising from a cyber event.

Property and liability lines are shutting the "silent cyber" door

For years, physical consequences of a cyberattack could be "silently" picked up by property and liability policies that simply never mentioned cyber. Regulators and the market have ended that. As reinsurer Munich Re explains, exclusion clauses such as LMA 5400 and LMA 5401 were introduced into property insurance to explicitly exclude cyber risks and control silent-cyber exposure. With those clauses in place, physical damage directly or indirectly caused by a cyberattack is not covered by the property policy.

A parallel shift hit liability lines. According to Insurance Journal, since 2023 most carriers have adopted the Insurance Services Office (ISO) "Cyber Incident" exclusion wording (CG 40 35 12 23), which removes from general-liability policies all resulting bodily injury, property damage, and personal and advertising injury tied to a broad definition of a cyber incident. Approaches vary: some insurers apply absolute exclusions with no exceptions, while others keep narrow carve-backs for named perils such as fire or explosion that are directly triggered by a cyber event, often conditioned on demonstrated cybersecurity measures.

  • LMA 5400/5401 pull cyber-caused loss out of property policies.
  • ISO CG 40 35 12 23 excludes BI and property damage from GL policies.
  • Net effect: a visible uninsured zone between property and cyber cover.

How a digital event becomes a site event

The transition from network to physical world happens wherever a digital system controls a real process. Munich Re lists the scenarios: tampering with the control systems of an industrial plant to manipulate temperature sensors or release valves can cause overheating, rising pressure and explosions; attacking a building's heating, water pumps or ventilation can freeze and burst pipes in winter; manipulating sprinklers and smoke detectors is dangerous in a fire. A documented example is the 2022 attack on an Iranian steel mill, where attackers moved through a third-party software back door to disable a gas-venting step, causing molten steel to overflow and ignite.

Specialist underwriter Tokio Marine Kiln (TMK) frames the systemic dimension: Asia-Pacific accounted for around a third of global cyber incidents in 2024 and was the most-targeted region, up 13% year on year, with manufacturing the most attacked industry and system-intrusion breaches rising from 38% to roughly 80% of regional incidents. Attacks are increasingly aimed not at corporate IT but at the operational technology steering physical processes. Manufacturing, logistics, healthcare, utilities and power generation carry the highest exposure because their interconnected, automated systems can turn a single-site disruption into a regional supply-chain event.

  • Industrial controllers: overheating, pressure, explosion, fire.
  • Building-management systems: heating, ventilation, sprinklers, flooding.
  • Data-center power and cooling: hardware loss, outages and SLA breaches.
  • Sensor and valve manipulation with safety overrides disabled — a real metallurgy attack vector.

Underwriters now look inside the physical perimeter

Writing cyber-physical cover forced a new style of underwriting. As security vendor Claroty reports, operational resilience is the guiding principle behind the questionnaires used to judge insurability: operators must show they can withstand not just IT ransomware but attacks against building-management systems, power and cooling, and physical access controls. Questionnaires increasingly require asset visibility well beyond servers and endpoints — programmable logic controllers, BMS assets, UPS controllers, intelligent PDUs, HVAC systems, sensors and remote-management interfaces.

The expectations concentrate on physical and virtual network segmentation to contain an attack's blast radius, tightly governed remote access for third-party contractors and integrators (MFA, just-in-time privileges, session recording and audit), and recovery that is verified by testing rather than asserted. Backup generators, redundant power, spare hardware and failover capability affect insurability because they set the downtime exposure. For end-of-life assets that cannot be patched, underwriters expect compensating controls such as isolation by segment. In short, insurance readiness now depends on how the site actually behaves under stress, not only on security policies.

  • A complete inventory of CPS and OT assets, not just servers and endpoints.
  • Segmentation that limits lateral movement between operational zones.
  • Secure vendor remote access: MFA, just-in-time access, session recording.
  • Verified backups and continuity plans resilient against attacks on the backup systems themselves.

Affirmative covers and what to verify before binding

Munich Re describes two market mechanisms for closing the gap. The first is an affirmative property-damage extension, added to an existing cyber policy or bought separately, that explicitly covers physical property damage and resulting financial loss from targeted hacker attacks or technical failure of computer systems. The second is a dedicated cyber "gap" policy that "un-excludes" the risks pulled out by the LMA clauses and responds on the conditions of the underlying property policy. Insurers such as Beazley also offer a cyber-property-damage endorsement designed to close the same hole and route the claim through a single insurer and claims team, avoiding disputes between separate property and cyber carriers.

The limitations matter. These products are aimed mainly at large corporates and OT-dependent sectors, market capacity is still limited, and terms vary by jurisdiction and insurer. Insurance also covers only residual risk: Munich Re advises companies to close the "back doors" that let an attacker cause physical damage, because reducing both probability and severity is what makes coverage financially attractive. A sound purchase decision therefore combines affirmative cover with genuine site-level control and a written confirmation of exactly which scenarios are covered, which are excluded and where a potential uninsured loss remains.

  • Affirmative property-damage extension on the cyber policy.
  • Standalone cyber "gap" policy that lifts LMA 540X exclusions.
  • Cyber-property endorsement with single-insurer claims handling.
  • Site controls as both an insurability requirement and a real mitigation.

Site-to-policy gap audit: finding where your cover ends

This five-step audit surfaces the scenarios in which neither your cyber policy nor your property and liability policies respond, then turns each into an action. Run it with your broker and a site engineer; the output is a mapped uninsured-loss register and a remediation plan.

  1. Inventory every asset steered by OT, ICS/SCADA, building-management, power, cooling and access-control systems — beyond pure IT.
  2. For each asset, write the physical scenario: overheating, fire, explosion, flooding, line stoppage, spoiled goods or raw materials.
  3. Read the cyber policy wording and note its property-damage and bodily-injury exclusions, plus which systems and sums fall inside the definition of covered assets.
  4. Check the property policy for LMA 5400/5401 or equivalent clauses and any fire-or-explosion carve-backs and their conditions.
  5. Check the liability policy for an ISO CG 40 35 (or local equivalent) cyber-incident exclusion and what it removes.
  6. Identify the "silent zone": scenarios where no policy responds, and estimate the maximum probable loss for each.
  7. Score existing site controls — segmentation, vendor remote-access governance, MFA, redundancy, verified recovery — as compensating measures.
  8. Ask the broker for written options: affirmative extension, gap policy or endorsement, with exact wording before you bind.
  9. Summarise findings for management: covered scenarios, excluded scenarios, and the security gaps that deserve investment first.

Questions people ask

Does cyber insurance cover physical damage to equipment or buildings?

Generally no. A standard cyber policy pays for digital losses — data breaches, ransomware, network restoration and IT-driven business interruption — but excludes property damage and bodily injury. If an attack causes a fire, overheating or flooding, that loss normally sits outside the insuring agreement. Coverage appears only through a specialised affirmative property-damage extension, a dedicated cyber "gap" policy that lifts LMA exclusions, or a cyber-property endorsement from a specialist carrier. Always verify the exact wording, which varies by insurer and jurisdiction.

What is "silent cyber" and why is it disappearing?

"Silent" (or non-affirmative) cyber risk is when a property or liability policy unintentionally covers a cyber loss simply because it never mentions cyber. Regulators and the market demanded certainty, so most carriers now insert explicit exclusions: LMA 5400/5401 in property insurance and ISO CG 40 35 12 23 in general liability. The effect is that physical consequences of a cyberattack are no longer silently covered, making the gap between cyber and property policies visible and leaving businesses to manage it deliberately.

Should my property policy respond to a fire caused by a cyberattack?

It depends on the wording. Many property policies now carry cyber exclusions, often modelled on LMA 5400/5401, after which a fire or explosion caused by a cyberattack is not covered. Some carriers retain a narrow carve-back for ensuing fire or explosion, frequently conditioned on demonstrable cybersecurity measures. You must read the exact policy text and confirm with your broker how the contract defines a "cyber event" and which ensuing perils it excludes.

What site controls do underwriters expect before writing cyber-physical cover?

Modern underwriting centres on operational resilience. Expect to demonstrate a complete inventory of OT and CPS assets (PLCs, building-management systems, UPS controllers, HVAC, sensors), network segmentation that limits an attacker's lateral movement, secure third-party remote access with MFA and session recording, and recovery verified by testing. For end-of-life assets that cannot be patched, compensating controls such as segment isolation are expected. Redundant power, spare hardware and continuity planning directly affect insurability because they set the downtime exposure.

Where does an uninsured cyber-physical loss most often arise?

Most often in operational technology and building-management systems. An attack on industrial controllers can cause overheating and explosions; manipulation of heating or sprinklers can flood a building; an attack on a data center's power or cooling can halt equipment and breach service-level agreements. A cyber policy will not pay for such harm as "physical," while a property policy excludes it as a "cyber event." The uninsured zone sits precisely between these two products.

Can I close the gap just by raising my cyber limit?

No. Raising a limit does nothing if the policy itself excludes physical damage, because the limit applies only to what is already covered. Close the gap structurally: add an affirmative property-damage extension, buy a dedicated cyber "gap" policy that un-excludes LMA clauses, or add a single-insurer cyber-property endorsement. Pair that with genuine site-level controls, since insurance prices residual risk only after you have reduced both the probability and the severity of a physical loss.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. Physical damage from cyberattacks: an underestimated risk in the age of automation and digitalisation | Munich ReMunich Re
  2. Cyber-Physical Risks: Addressing Coverage Gaps in Traditional Insurance | Gallagher SpecialtyArthur J. Gallagher (AJG)
  3. Viewpoint: Is Your GL Policy Leaving You Exposed as Digital Risk Shifts? | Insurance JournalInsurance Journal
  4. Achieving Cyber-Insurance Readiness for Data Centers | ClarotyClaroty
  5. Asia's manufacturers face uninsured cyber physical damage risk as insurance lags exposure | Tokio Marine KilnTokio Marine Kiln
  6. When cyber incidents cause physical damage | BeazleyBeazley
  7. Бизнес в АТР сталкивается с дефицитом страховой защиты от физического ущерба при кибератаках | Страхование сегодня (Allinsurance.kz)Страхование сегодня / Allinsurance.kz