Cyber insurance exclusions: what your policy won't cover

The forensic report arrives three weeks after your systems went down, and it confirms what the IT consultant suspected on day one: an employee opened a phishing email on a company laptop, and the ransomware spread from there within forty minutes. Your cyber insurance policy is active. You've paid the premiums. Then the insurer's response references your failure to enforce multi-factor authentication as a condition precedent, a requirement buried in the policy schedule that, if not met, removes the insurer's obligation to pay. The cover was real. The claim is not.
What are cyber insurance exclusions?
Cyber insurance exclusions are the conditions, events, and categories of loss your policy explicitly removes from cover. Most cyber policies are written broadly at the front and narrowed significantly through exclusion clauses later in the wording. Understanding these exclusions isn't a legal exercise, it's the difference between a policy responding when you need it and one that doesn't.
Key Takeaways
- Most cyber policies exclude losses flowing from a failure to meet stated minimum security controls, such as multi-factor authentication or patched software.
- War and state-sponsored cyberattacks are excluded under standard wordings, and the line between criminal and state-sponsored activity is rarely obvious at claim time.
- Losses caused by employees acting dishonestly or fraudulently typically fall outside cyber cover and require a separate crime or fidelity policy.
- Pre-existing vulnerabilities and systems known to be unpatched at inception are commonly excluded from day one.
- Infrastructure your business owns but doesn't list on the schedule, legacy servers, decommissioned hardware, shadow IT, may sit outside cover entirely.
- Knowing your exclusions before an incident is the only time you can act on them.
How security control failures void your claim

The most common reason a cyber claim is partially or wholly rejected isn't that the peril was outside the policy, it's that the insured failed to maintain the security controls listed as conditions of cover. Conditions precedent are requirements that must be met for the policy to respond at all; if one is breached, the insurer's obligation falls away regardless of the loss.
A manufacturing business in Ekurhuleni buys a cyber policy in March. The questionnaire at inception asked whether multi-factor authentication (MFA), the practice of requiring a second verification step, such as a code sent to a mobile phone, before granting system access, was in place across all remote access points. The operations manager ticked "yes" because MFA was deployed on the main ERP system. Six months later, a legacy remote desktop protocol (RDP) port, an older remote-access tool, is exploited by an attacker. MFA was never applied to that port. The insurer declines the claim on the basis that the answer on the questionnaire was inaccurate and the condition was not met.
The lesson isn't that insurers are looking for reasons to decline. The lesson is that the cyber insurance questionnaire is a factual declaration, and the policy is priced and written on the accuracy of that declaration. Security controls aren't window dressing at inception and irrelevant thereafter; they're the ongoing terms of the arrangement.
The war exclusion and the problem of attribution
Cyber policies universally exclude losses caused by war, and most now extend that exclusion explicitly to cyberattacks attributable to nation-states or state-sponsored actors. The difficulty is that attribution, determining who actually conducted the attack, is one of the hardest problems in cybersecurity, and it's rarely resolved before the claim needs to be lodged.
The question of what counts as a "state-sponsored" attack became a live commercial dispute after the NotPetya incident in 2017, when a destructive piece of malware initially disguised as ransomware caused billions of dollars in damage globally. Several major insurers argued the attack was an act of war by the Russian state, which would trigger the war exclusion. Courts in multiple jurisdictions have since weighed in, with outcomes varying by policy wording. South African insureds shouldn't assume that the resolution in a foreign court settles the question under their own policy.
Under standard wordings, the risk to a South African business is real. If your network is damaged in what is later attributed to a state-sponsored attack, and attribution sometimes takes months, your insurer may decline on war exclusion grounds. The SAIA guidance on cybersecurity threats notes the financial services sector remains a primary target for sophisticated actors whose origins aren't always immediately clear. The practical advice is to confirm with your broker whether your policy contains an "acts of war" carve-back for commercially motivated attacks, and what the attribution standard in your wording is.
Fraudulent or dishonest acts by employees
A cyber policy covers digital incidents originating outside your organisation, and sometimes from careless insiders. It doesn't, in most standard wordings, cover deliberate fraud or dishonest acts by employees, people who intentionally exfiltrate data, redirect payments, or sabotage systems for personal gain.
Suppose a finance clerk at a logistics business in Cape Town spends three months diverting supplier payments to a personal account through a manipulated EFT system. When the fraud is discovered, the business looks to its cyber policy. The insurer declines: the loss arose from an intentional act by an employee, which is a category most cyber wordings exclude explicitly. As one industry analysis of common exclusions on cyber liability policies notes, employee dishonesty, fraud, and illegal acts are among the most consistently excluded categories in the market.
The cover for this exposure sits under a crime or fidelity policy, a separate product covering financial loss from employee dishonesty. The gap between a cyber policy and a crime policy isn't academic. Businesses assuming their cyber cover responds to all digital-origin losses, including internal fraud conducted through digital systems, often discover the distinction under the worst possible circumstances.
Pre-existing vulnerabilities and prior incidents
Cyber insurance isn't retrospective. A policy written today doesn't cover an incident beginning before inception, and "began" in a cyber context is more complex than it sounds. Many breaches involve attackers who have been inside a network for weeks or months before anyone detects them. If the initial intrusion predates the policy's start date, the insurer may treat the entire incident as pre-existing.
Beyond timing, policies commonly exclude vulnerabilities the insured knew about at inception. If your IT team identified an unpatched critical vulnerability in your firewall software two months before the policy started and the patch was never applied, and that vulnerability is later exploited, a decline on prior-knowledge grounds is a foreseeable outcome.
Illustrative example: known-vulnerability scenarios at policy inception
| Scenario | Vulnerability known at inception? | Patch applied before inception? | Likely exclusion? |
|---|---|---|---|
| Firewall software — critical patch available | Yes | No | Yes |
| Firewall software — critical patch available | Yes | Yes | No |
| Zero-day exploit — publicly unknown | No | Not applicable | No |
| Legacy server — out-of-support OS | Yes | Not applicable (no patch exists) | Likely — discuss with broker |
This table illustrates how known-vulnerability scenarios interact with typical exclusion clauses. Outcomes depend on the specific policy wording and the facts of each case.
The practical implication is that cyber cover should be placed alongside a genuine review of the IT environment. A vulnerability scan conducted before inception, with identified items remediated or disclosed to the insurer, is a cleaner basis for a policy than a declaration made without looking.
Infrastructure outside the schedule: shadow IT and legacy systems

Cyber policies cover the systems described in the schedule. They don't automatically extend to every server, application, or network segment your business operates, particularly those not disclosed at inception because they were considered decommissioned, low-risk, or simply forgotten.
Shadow IT, technology deployed by individual departments without formal IT oversight, a spreadsheet-based system running on a personal laptop, a cloud storage account set up by a marketing team, a printer connected to the network without a password, represents a category of exposure sitting outside most cyber schedules. The statistics on cyber insurance coverage gaps suggest roughly 27% of data breach claims result in exclusion or only partial payment, a figure reflecting how frequently the actual incident falls outside what was declared and scheduled.
Legacy systems deserve particular attention. A server running an operating system no longer supported by its manufacturer, Windows Server 2008 is the textbook example, can't receive security patches because none are released. Most cyber wordings treat systems running unsupported software as uninsurable by definition, or as a condition precedent breach if you confirmed at inception that all systems were maintained on supported software. Auditing your IT estate before placing or renewing a cyber policy isn't a technicality; it is the mechanism by which you establish whether the cover you're buying actually extends to the infrastructure you're running.
System outages caused by third parties and cloud providers
Your business may store data, run applications, or process transactions through third-party platforms, a cloud accounting system, a payments gateway, a hosted CRM. When a third party experiences an outage or a breach, the disruption lands on your business, but the incident didn't originate in your systems.
Standard cyber policies often distinguish between "system failure" events on infrastructure you operate and those on infrastructure operated by a vendor. A business interruption extension under a cyber policy, the component covering lost revenue while systems are down, may not respond to an outage at a cloud provider unless the policy wording specifically includes "dependent systems" or "contingent business interruption" for third-party failures.
This is a practical concern because the direction of travel in South African business is toward hosted and cloud-based systems. As the cyber insurance statistics for 2026 indicate, adoption of cloud infrastructure is accelerating across SMEs, which means third-party system dependency is rising. A cyber policy responding only when the incident originates on your own infrastructure covers a shrinking proportion of the actual risk for many businesses. Checking whether your policy includes contingent business interruption for named or unnamed cloud providers is a question worth putting to your broker before renewal, not after a provider outage has already cost you a week of revenue.
When the fine print changes what "cyber cover" means
Cyber insurance isn't one product. It is a class of products, and the wording differences between policies in the market are significant. Two businesses paying similar premiums for what both call "comprehensive cyber cover" may hold policies with materially different exclusions for war, employee fraud, cloud dependency, and security control failures.
Described plainly: a policy is only as useful as what it actually covers, and the declaration on the front page, "Cyber Liability and Business Interruption Insurance", tells you almost nothing about the exclusions on pages twelve to nineteen. As one analysis of hidden coverage gaps in cyber insurance notes, a significant proportion of senior financial decision-makers at large organisations believe their cyber policy would cover most or all losses from a cyberattack, when the actual policy wording frequently excludes the most common attack vectors or applies conditions making cover contingent on security standards many organisations aren't meeting.
The answer isn't to distrust the product. The answer is to read the wording, or have someone read it for you who can translate the exclusions into operational terms: what this policy won't cover if the incident looks like this.
When the gap between assumption and cover is most expensive

The cyber exclusions with the greatest consequence aren't the ones in the abstract. They're the ones your specific business is most likely to trigger, given your systems, your team, your security posture, and your vendors. A logistics business with legacy warehouse management software faces a different exclusion risk profile than a law firm running modern cloud-based case management.
The distance between what you believe your policy covers and what it actually covers is rarely discovered in a comfortable setting. It surfaces in the weeks after an incident, when the forensic firm is already billing, the IT team is working weekends, and the insurer is reviewing the claim file. Finding at that point that MFA was a condition of cover and was never applied to the breached system is an expensive education.
You shouldn't have to find out at claim time what your cyber policy excludes. With Mont Blanc Financial Services you won't.
Contact Mont Blanc Financial Services to have your current cyber wording reviewed against your actual IT environment, so the gaps are found before an incident finds them for you.
South African businesses regularly ask whether their specific security setup qualifies for cover, and what the most commonly triggered exclusions look like in practice. The questions below address the ones that come up most often.
Frequently Asked Questions
What are common exclusions on a cyber liability policy?
The most consistently excluded categories across standard cyber liability wordings are: failure to meet stated security controls (particularly multi-factor authentication and current software patching); war and state-sponsored attacks; deliberate or fraudulent acts by employees; losses originating before the policy's inception date or from vulnerabilities known at inception; and infrastructure not listed on the schedule, including legacy and shadow IT systems. Some policies also exclude reputational damage as a standalone loss, regulatory fines in certain jurisdictions, and losses from social engineering fraud unless a specific endorsement, an additional clause extending the cover, is added to the policy. The exact exclusions in your policy depend entirely on the wording of that policy, not on the class of insurance in general. Reading the exclusion section before a claim is the only time it's useful. The cyber insurance exclusions causing the most disputes at claim time are those tied to security controls and employee conduct, because both depend on facts established only after the incident.
What are the minimum security controls required to qualify for cyber insurance?
The controls required vary by insurer and by the size and complexity of your business, but the baseline demanded across most South African and international cyber markets in recent years includes multi-factor authentication on all remote access and email systems, current patching on operating systems and key applications, endpoint detection and response (EDR) software, a system monitoring devices for unusual activity and responding automatically, regular offline backups, and a documented incident response plan. Larger businesses or those in higher-risk sectors (financial services, healthcare, logistics) typically face additional requirements around network segmentation, privileged access management, and employee security training. The cyber insurance questionnaire you complete at inception is where these requirements are set out; the answers you provide become the factual basis for the policy. If your security environment changes materially after inception, you decommission a tool, a third party takes over a system, a key control is dropped, disclose that change to your insurer. The controls aren't a compliance exercise; they're the agreed basis on which the insurer accepted the risk.
What does cyber insurance actually cover if so much is excluded?
Despite the exclusions above, a well-structured cyber policy responds to a wide range of incidents when the security controls are in place and the policy wording matches your risk profile. Cover typically includes: forensic investigation costs to identify the source and scope of a breach; legal costs associated with notifying affected parties and responding to regulatory enquiries; ransom payments and negotiation costs in a ransomware event, subject to wording; business interruption losses while systems are restored; and third-party liability for data subjects whose personal information was compromised. The key phrase is "well-structured", a cyber policy placed without a proper review of your IT environment, your vendor dependencies, and your security posture is likely to carry exclusions matching your most probable incident types. The cyber insurance cost article explains how security controls affect both what you pay and what you're covered for, and reviewing it alongside your current policy wording gives you a clearer picture of where your cover sits.

Nicola Iozzo
Founder & CEO, Mont Blanc Financial Services
Nicola has spent his career reading the policy wording most people skip, and writes here so you don't discover at claim stage what page 14 meant.
Everything on this blog is written to inform and educate. It is for information only. Nothing here is professional legal, financial, or technical advice. If you are making a significant business decision, speak to a qualified professional first. Mont Blanc Financial Services works hard to keep this content accurate and current, but is not liable for decisions made based on what you read here.
Mont Blanc Financial Services (PTY) Ltd. is an authorised financial services provider. FSP 8271


