Author: Damion Walker
As organizations become increasingly reliant on connected technologies, cyber incidents are no longer limited to data breaches and privacy concerns. A cyber event can disrupt operations, damage equipment, impact critical infrastructure or contribute to bodily injury. At the same time, insurance carriers continue to refine where cyber-related losses belong within an insurance program.
This has created an important consideration for technology companies and other organizations that rely on connected systems: the potential gap between general liability and cyber insurance coverage. Understanding how these policies work together can help organizations better assess their exposure and avoid unexpected coverage concerns when a loss occurs.
Why insurers are separating cyber risk
As cyber incidents have become more frequent and complex, insurers have increasingly sought to define which policies are intended to respond to specific types of losses. Stand-alone cyber insurance has evolved to address exposures such as data breaches, ransomware attacks, privacy liability, network security failures and other technology-related risks. Meanwhile, traditional liability policies weren't designed to provide dedicated cyber coverage.
For many organizations, this distinction makes sense. Cyber insurance provides specialized coverage and response resources tailored to today's threat landscape. However, as coverage responsibilities are divided among different policies, it becomes increasingly important to understand where one policy ends and another begins.
How cyber exclusions are changing general liability coverage
Many general liability insurers now attach cyber incident exclusion endorsements that remove coverage for losses arising from cyber-related events. Depending on the endorsement's wording, exclusions may apply to claims involving:
- Data breaches
- Privacy violations
- Loss, corruption or unauthorized access to electronic data
- Network security failures
- Related liabilities and defense costs
These endorsements are becoming increasingly common across the insurance marketplace and may significantly narrow how a general liability policy responds to cyber-related incidents. Certain endorsements can also contain broad causation language that may affect coverage even when a cyber event is only one contributing factor to a loss.
While policy wording varies, organizations should review any cyber exclusion endorsements carefully and understand their potential impact on overall coverage.
The other side of the equation: Cyber insurance
Most stand-alone cyber and technology Errors & Omissions (E&O) policies are designed to address financial losses associated with data, networks, privacy obligations and business interruption. As a result, they commonly exclude bodily injury, death and physical damage to tangible property.
The reasoning is straightforward: Physical injuries and property damage have traditionally been handled by other insurance lines that are specifically underwritten and priced for those exposures.
However, some cyber insurers offer limited carve-backs or endorsements that may help address certain situations, including:
- Emotional distress arising from a data breach
- Damage to owned hardware resulting from a cyber event
- Specialized cyber-physical coverage enhancements
Because these provisions vary by carrier and policy form, organizations should review available options carefully.
Where coverage questions can arise
The greatest area of concern is often cyber-physical risk, where a cyber incident produces a real-world consequence in the form of bodily injury and/or property damage.
Examples can include:
- Ransomware disrupting a manufacturing operation
- A compromised building management system affecting facility functions
- Connected medical devices impacted by unauthorized access
- Industrial control systems operating outside intended parameters
- Technology failures that contribute to equipment damage or operational disruption
As technology becomes more deeply embedded within physical operations, products and infrastructure, these scenarios are becoming increasingly relevant for many organizations.
When a general liability policy excludes cyber-related incidents and a cyber policy excludes bodily injury or property damage, organizations may face uncertainty regarding how, or even whether, coverage would respond to a particular claim. While every situation depends on the specific facts and policy language involved, this overlap is an area that deserves careful attention.
