up:: For Business Leaders MOC

Does our cyber insurance cover this?

Nobody can tell you from outside your policy, and any advisor who answers confidently in either direction is guessing.

Cyber policies are built around an event that happens inside a policy period and gets discovered inside a policy period. The scenario here has a copying date and a reading date that could be a decade apart, with no detection at either end. Nearly every structural feature of a standard policy assumes those 2 dates are close together.

As of this writing, no published standard market clause or major carrier wording names cryptographic obsolescence or quantum decryption as either a covered or an excluded peril. It sits in the space where a loss is neither clearly covered nor clearly excluded, which historically ends in litigation the first time it matters.

Not legal advice

This is general education about how cyber policies are structured. Coverage under your specific policy is a determination for your broker and coverage counsel.

The short version:

  • Nothing in the standard market names this yet, so it’s neither clearly covered nor clearly excluded.
  • The retroactive date is the sharpest problem. Policies cover breaches first occurring after a stated date, and a copying event years back sits behind it.
  • Your application answers are binding. A carrier has already voided a policy over a security attestation the insured couldn’t substantiate.
  • The encryption question on the form is currently yes or no. It doesn’t ask which algorithms, and a more detailed version would need an inventory to answer honestly.
  • State-backed exclusions add a second problem, because a practical decryption capability is most plausibly a government one.
  • The market moves fast. U.S. cyber premium grew roughly 73% in 2021, and the market contracted about 7% in 2024, so terms can shift inside 1 renewal cycle.

What does a cyber policy actually cover?

A standalone cyber policy is assembled from coverage grants, which are the losses it insures, and structural levers, which decide how much it pays and under what conditions.

The grants split into your own losses and your liability to others. Your own losses include incident response and forensics, notification and credit monitoring, business interruption, ransom payments, and the cost of restoring data. Liability to others includes defense and damages when somebody else’s data is exposed, plus regulatory defense and, where the law permits insuring them, penalties.

Cyber insurance is voluntary in the U.S. rather than statutory. It becomes effectively binding 3 ways: a customer, lender, or partner demands a stated limit; a sector expects it; or a board asks for it, which usually happens right after an incident.

Source: NAIC, “Report on the Cybersecurity Insurance Market” (2025 report, 2024 data), NAIC 2025 cyber report.

Why does a delayed harm sit badly against a policy?

Because 5 of the 6 dials that decide what a carrier pays assume a loss with a knowable date.

The dialWhat it doesWhy a delayed harm strains it
Retroactive dateBreaches must have first occurred after this date to be coveredThe copying may predate it by years, while the harm surfaces long after
Policy periodThe window in which the covered event has to fallWhich year does the loss belong to, the copying or the reading?
Discovery triggerCoverage attaches when the insured learns of the eventCopying encrypted traffic leaves no trace, so there’s nothing to discover
Waiting periodHours of outage before business-interruption coverage startsThere’s no outage at all
Limits and sub-limitsCaps on total and per-grant payoutsA decade of accumulated records exceeds a limit sized for 1 incident
RetentionYour first-dollar exposure per claimApplies normally, and it’s the only one that behaves as designed

The first row is the one to raise with a broker. A policy whose retroactive date sits a few years back, held alongside records that have to stay confidential for decades, has a structural gap that predates any argument about quantum computers.

What can void a policy we already hold?

Two mechanisms, and the first one is entirely within your control.

Your own application answers. The proposal form has become a security audit. Since the market hardened in 2021 and 2022, carriers ask detailed control questions, and every written answer is a representation the carrier relied on to price and bind the risk. If a representation was materially inaccurate at binding, the carrier can rescind the policy, unwinding it as though it never existed.

That has already happened. In Travelers Property Casualty Co. of America v. International Control Services, a carrier moved to rescind after the insured attested to using multi-factor authentication that turned out to exist in only 1 location. The policy was rescinded by stipulated judgment in August 2022.

Source: Travelers Property Casualty Co. of America v. International Control Services, Inc. (C.D. Ill., filed July 2022; rescinded by stipulated judgment August 26, 2022), Insurance Journal report.

The relevant line on your own form is the encryption question, which currently asks whether sensitive data is encrypted at rest and in transit. It’s a yes-or-no field. It doesn’t ask which algorithms, which key sizes, or whether you could change algorithms without rebuilding. A truthful answer to a more detailed version of that question requires an inventory you may not have.

Exclusions. Three carry weight here:

  1. War and hostile action. The traditional clause, written for kinetic conflict, produced the biggest coverage fight of the decade in the Merck NotPetya litigation, where a New Jersey appellate court held in May 2023 that it didn’t reach a cyberattack on a non-military company.
  2. State-backed cyber attack. In response to exactly that ambiguity, Lloyd’s required all standalone cyber-attack policies in its market to carry a state-backed exclusion from March 31, 2023. Attribution under these clauses leans primarily on the government of the state where the affected system sits.
  3. Failure to maintain minimum security standards. A warranty-style exclusion tying coverage to the controls you attested to, and the mechanism that connects your application to your claim.

Source: Merck & Co., Inc. v. ACE American Insurance Co. (N.J. Super. Ct. App. Div., approved for publication May 1, 2023), opinion; Lloyd’s of London, Market Bulletin Y5381, “Cyber-attack exclusions,” August 16, 2022, Y5381.

The state-backed exclusion creates a specific problem for this scenario. Building a machine capable of breaking today’s public-key encryption is most plausibly a government or government-adjacent undertaking, which means a future decryption loss could be argued into that exclusion, layering a coverage fight on top of the breach itself.

Is any carrier underwriting for this yet?

Generally no, and the direction of travel is analyzable. Keeping those 2 statements apart is what makes this useful rather than alarming.

What’s true today: applications ask whether data is encrypted, they don’t ask which algorithms, and no published standard clause names cryptographic obsolescence. A carrier’s external scanning can see your attack surface and can’t see your internal cryptography.

What the market’s own history suggests: multi-factor authentication went from unasked, to an application question, to a bind-or-decline control, to a rate factor, in roughly 2 renewal cycles during the hardening. Cryptographic inventory is a candidate to follow the same path once a catalyzing loss or a regulatory deadline makes carriers treat quantum-vulnerable estates as a correlated risk across their whole book.

There’s also a precedent for how this kind of exposure gets resolved. Before the Lloyd’s mandate, carriers carried unintended cyber exposure inside non-cyber policies until they were forced to either affirm or exclude it. The likely path here mirrors that one: a model exclusion or a control warranty appears, and then propagates.

The practical read is that the first sign of quantum reaching underwriting will be a new control question on the application rather than a headline. An organization holding its own cryptographic inventory answers that question from a position of strength at renewal.

What should we do before the next renewal?

Four things, and none of them require a decision about quantum computers.

  1. Confirm you can substantiate every security answer on your last application. Particularly the encryption line. An attestation with no inventory behind it is an uncosted risk you’re already carrying, independent of anything in this Guide.
  2. Read your retroactive date against your longest-lived data. Ask your broker directly what happens to a loss whose cause predates that date and whose harm surfaces after the policy ends.
  3. Ask your broker and coverage counsel how the state-backed exclusion in your specific wording would treat an attributed decryption event. The clause language varies, and the answer is knowable now and unknowable during a claim.
  4. Ask about your critical vendors. Contingent business-interruption coverage inherits the cryptographic posture of the suppliers you depend on. See What can I not fix myself.

Placing coverage, interpreting policy language, and recommending limits belong to a licensed broker and coverage counsel. The cryptographic facts underneath the decision are knowable now, and knowing them early is what keeps a future underwriting question from becoming a renewal problem.

Questions people ask

So is it covered? No one can say from outside your policy. Coverage turns on your specific wording, your retroactive date, and the exclusions your carrier uses, which makes it a question for your broker with your actual document in hand.

Will this raise our premium? Not today, because carriers generally aren’t asking about it. The forward view is that cryptographic inventory could become a rate factor once a catalyzing event makes it an aggregation concern.

Should we buy more limit to cover it? Limit doesn’t help with a coverage question. If the loss falls outside the grant or inside an exclusion, a higher limit pays the same amount, which is nothing.

Does saying yes to the encryption question protect us? It’s a representation you may have to substantiate years later, so it protects you exactly as far as your evidence does. That’s the Travelers pattern.

Can we get a carrier to affirm coverage in writing? You can ask, and specialty markets do write manuscript wording. Whether any carrier will affirm this particular exposure is a market question your broker can test.

Is our directors and officers policy relevant here? Potentially, on a different theory: oversight of a known, dated, material risk. That’s a separate conversation with separate counsel.

Why does the market keep changing? Cyber premium grew roughly 73% in 2021, more than 50% in 2022, then U.S. direct written premium contracted about 7% in 2024 to roughly $9.14 billion. A transfer strategy calibrated to last year’s terms can go stale inside a single cycle.

Where to go next

Go deeper into the technical detail

The technical treatment, with every grant, lever, and clause cited, is Cyber Insurance.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.