Skip to content

At The Identity Organisation, we're here to help!

    Your privacy is important to us, and we want to communicate with you in a way which has your consent and which is in line with UK Law on data protection. As a result of a change in UK law on 25th May 2018, by providing us with your personal details you consent to us processing your data in line with current GDPR requirements.

    Here is where you can review our Privacy & GDPR Statement

    To remove consent at any time, please e-mail info@tidorg.com with the word "unsubscribe" as the subject.

    +44 (0) 1628 308038 info@tidorg.com

    State-Based Cyberattacks to be Excluded from Lloyd’s of London Cyber Insurance Policies

    As cyber insurers evolve their understanding of the cyber attack landscape, who’s responsible, and what’s at stake, a logical next step is taken by Lloyd’s to better isolate what is covered and what isn’t.

    It’s inevitable; cyberinsurers can’t blindly just cover every kind of cyberattack and pay out every time one happens – there are too many to count, and often times it’s the insured’s own employees that enabled an attack potentially covered by a cyber insurance policy.

    A new market bulletin put out by Lloyd’s of London makes it clear that very specific types of attacks – those that are essentially akin to cyber warfare – are not going to be covered.

    “We are therefore requiring that all standalone cyber-attack policies…must include, unless agreed by Lloyd’s, a suitable clause excluding liability for losses arising from any state backed cyber-attack.”

    Some of the requirements around this exclusion includes:

    • Losses arising from a war
    • Losses arising from state backed cyber-attacks the “that (a) significantly impair the ability of a state to function or (b) that significantly impair the security capabilities of a state.”

    It also mentions that coverage with such an exclusion must also:

    • Specify whether computer systems outside an affected state (presumably within the context of the requirements above) are excluded or not
    • Provide an agreement between Lloyd’s and the insured as to “how any state backed cyber attack will be attributed to one or more states”

    This puts more of the burden of having a strong protective cyberstance all the more important – one that includes Security Awareness Training as part of a layered defense to prevent cyber attacks from ever gaining entrance to a victim network and wreaking havoc – state actor or not.


    Request A Demo: Security Awareness Training

    New-school Security Awareness Training is critical to enabling you and your IT staff to connect with users and help them make the right security decisions all of the time. This isn’t a one and done deal, continuous training and simulated phishing are both needed to mobilize users as your last line of defense. Request your one-on-one demo of KnowBe4’s security awareness training and simulated phishing platform and see how easy it can be!

    PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/one-on-one-demo-partners?partnerid=001a000001lWEoJAAW

    Sign Up to the TIO Intel Alerts!

    Back To Top