The NotPetya Wake-Up Call for Insurers

June 2017’s NotPetya malware attack began in Ukraine and swept across corporate networks worldwide, ultimately causing more than $10 billion in damage. Shipping giant Maersk lost up to $300 million, while pharmaceutical firm Merck suffered an estimated $870 million hit. Yet when Merck sought compensation, most of its 30 insurers and reinsurers denied coverage, citing an “act of war” exclusion in its property policies—even though the policies provided $1.75 billion of protection for destruction of computer data and software.

The denial stunned the industry. Suddenly, a malware attack attributed to Russia by the UK government had starkly illustrated the gap between the cyber risks companies face and the coverage they assume they have. The event ignited a debate about “silent cyber”—cyber exposures implicitly covered or excluded within traditional property and liability policies—and whether those half‑baked protections were fit for purpose.

Three years later, the NotPetya aftershocks are reshaping the cyber insurance market. Experts say the industry is moving decisively toward standalone cyber policies that define coverage explicitly, including for cyber terrorism and systemic events, rather than relying on ambiguous grants inside other policies. The change is still underway, but the direction is clear: clarity over convenience.

Why Silent Cyber Coverage Is Fading and What Replaces It

The War Exclusion That Stunned Merck

Merck’s property policies specifically excluded losses caused by hostile or warlike acts. When the British government publicly attributed NotPetya to Russia, insurers invoked that clause. Conan Ward, president of MGA/MGU Operations at QOMPLX, says the case exposed a fundamental tension: “Everyone fundamentally understands why you would exclude war in a property policy—it’s a systemic risk that no company could hope to cover.” Yet the event showed how a state-linked cyber operation, even without a declaration of war, could immediately render tens of millions in coverage void. The lesson for the insurance market was that blending cyber risks into property contracts, with decades‑old definitions of war, creates legal and financial uncertainty for both sides.

Silent Cyber: The Half‑Baked Grant

Before NotPetya, many insureds relied on “silent cyber” – cyber-related coverage embedded in non‑cyber policies without explicit inclusion or exclusion. Ward calls this “playing with fire.” The attack revealed that such grants rarely cover the full range of recovery costs a severe malware event demands, from forensic investigations to business interruption and reputational harm. “A cyber grant inside of a property policy doesn’t do the kinds of things you need it to do,” he notes. The result is a dual failure: insurers miscalculate their aggregate exposure, and buyers believe they are protected when they are not.

Standalone Cyber Gains Traction

The market’s response has been a shift toward dedicated cyber policies. Caroline Thompson, head of underwriting at Cowbell Cyber, points out that only standalone insurance can provide “a detailed and precise definition of what the policy intends to cover,” leading to higher policyholder satisfaction and smoother claims processes. Such policies now routinely address cyber terrorism and can tailor coverage limits to sophisticated attacks. Oliver Brew of CyberCube adds that NotPetya also accelerated efforts to close the definitional gap around “systemic risk”—the possibility that a single event triggers losses across multiple insureds—pushing insurers to build more realistic disaster scenario frameworks.

New Threats, New Tools

Even as the industry refines policy language, the threat environment has not stood still. Scott Fouts of Hub International notes that the remote‑work surge during the COVID‑19 crisis has dramatically expanded corporate attack surfaces, warning that “the likelihood of having a cyber attack right now is pretty high.” At the same time, “artisan‑level malware is now in the hands of a ton of attackers,” says Ward, raising the odds of another systemic event. To meet this challenge, Thompson advocates for cyber underwriting built on data, artificial intelligence and continuous monitoring that can respond in near real-time to evolving threats.

What the Shift Means for Insurers, Brokers and Policyholders

  • For insurers: Phase out silent cyber grants embedded in property and liability policies. Instead, build standalone cyber products that clearly define coverage—including war, terrorism, and systemic event clauses—so that exposure is modelled and priced accurately.
  • For brokers: Proactively audit client policies for silent cyber exposure. Use the Merck denial as a case study to educate corporate buyers on the chasm between perceived and actual coverage, and recommend dedicated cyber limits informed by a realistic assessment of potential losses (Merck’s hit reached $870 million).
  • For policyholders: Review all property and casualty policies for cyber‑related wording. Assumptions that a property policy will cover malware destruction are dangerous; a standalone cyber policy with explicit triggers and limits, particularly for business interruption and data restoration, should be central to risk transfer strategy.
  • Leverage technology: Insurers and risk managers should invest in data‑driven underwriting tools and continuous monitoring platforms that ingest real‑time threat intelligence—especially critical as the remote‑work expansion reshapes exposure patterns.

Risk & Opportunity Assessment

Commercial RiskMediumInsurers carrying large portfolios of property policies with silent cyber exposure face potential claim aggregations and unexpected payouts if systemic malware events recur, mirroring NotPetya.
Competitive RiskMediumCarriers that fail to roll out clear standalone cyber products risk losing market share to newer entrants like Cowbell Cyber, which explicitly design policies around cyber threats and data‑driven underwriting.
Regulatory RiskLowWhile NotPetya did not trigger regulatory intervention, continued ambiguity in war exclusions and silent cyber could attract scrutiny from insurance regulators seeking policyholder protection, especially after high‑profile claim denials.
Reputation RiskMediumThe Merck denial, widely reported, damaged trust in the industry’s ability to handle cyber claims. Further headline‑making denials under opaque war clauses could deepen reputational harm and invite litigation.
Technology DisruptionTransformationalThe shift to standalone cyber demands the adoption of AI‑based continuous underwriting and real‑time data feeds to model fast‑changing attack methods; legacy, static risk assessment tools will become obsolete.
Commercial OpportunityHighThe flight from silent cyber opens a substantial market for dedicated cyber insurance, especially as remote work enlarges the attack surface. Carriers that build precise, data‑rich standalone products can capture growing corporate demand.