This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…
Auto insurers have no problem covering claims ranging from a chip in a windshield to eight car pileups with multiple fatal and life-altering injuries. The range of possible losses doesn't really make it harder for insurers. The fuzzy definition of an act of cyber war is what makes it hard for policyholders though.
But it _is_ hard on insurerers to do under-writing on cyber attacks -- UNRELATED to the "war" exemption, even non-war attacks. Because it's _new_, so they don't have all the historical data and methods for estimating risk. As others are saying, this is the business insurance companies are in, estimating statistical risk and figuring out the right premiums to charge to cover it. But the cyber stuff is new, which _does_ make it hard.
As original article says:
> Cyberattacks have created a unique challenge for insurers. Traditional practices, like not covering multiple buildings in the same neighborhood to avoid the risk of, say, a big fire don’t apply. Malware moves fast and unpredictably, leaving an expensive trail of collateral damage.
But nobody said they had to cover cyber stuff. They can put stuff in their policies saying they don't cover it at all, if they don't know how to underwrite it. What they can't do is put stuff in their policies saying they cover it, take your premiums on that basis, but then try to weasel out of it.