Article
Cyber Risks: The Limits of Liability in Modern Marine Insurance
Financial University under the Government of the Russian Federation
1. Introduction
The advance of new technologies not only raises productivity and lowers costs; it also heightens the risks attendant on their use. According to the Microsoft Digital Defence Report 2024, users faced 600 million cyberattacks a day between July 2023 and July 2024.1CYTUR Inc. 2recorded 828 maritime cyberattacks in 2025, an increase of 103 per cent on the previous year. 3 In its 2025 report, Microsoft observes that transport is among the principal targets of cyberattack, with consequences at once digital and physical. 4 The fact that conduct in the digital field can cause physical damage changes the traditional concept of marine risk and requires us to reconsider the scope of marine insurance coverage.
2. The Concept and Characteristics of Cyber Risk
No settled definition of cyber risk, or of a cyber incident, has yet emerged. Participants in the insurance market characterise cyber risks as “any risks arising from the use of information and communication technologies that jeopardise the confidentiality, availability, and integrity of data and of the services relating to such data.”5 To grasp what makes these risks distinctive, it helps to consider the classification of the interests that may be insured against them. According to a study by the Organisation for Economic Co-operation and Development (OECD), the subject matter of cyber insurance may include business interruption; fines and penalties; physical damage to the property targeted by the attack, which is not always directly connected with navigation; bodily injury and death; and directors’ and officers’ liability. 6 For a legal definition of cyber risk it is worth returning to the definition of the traditional insured risk, which may be formulated as “the possible infliction of harm through the operation of a particular peril, account being taken of the probabilistic characteristics of the infliction of that harm by that peril.”7 On this definition, an insured risk exhibits the properties of a peril; of the harm that the peril may inflict; of a causal link between peril and harm; and of the probabilistic character of that harm. 8
In the English doctrine of marine insurance, the insured risk is an event contemplated by the contract whose harmful operation may result in the loss of, or a diminution in, the property interests of the assured or of the beneficiary. The insured risk may also be characterised through its specific features. The risk must be fortuitous –that is, it must not be the ordinary action of marine natural forces upon the subject matter insured;9 it must constitute a peril consequent on, or incidental to, navigation, bearing the requisite connection with the sea and with the character of the marine adventure;10 and it must, moreover, proceed from “external” fortuitous circumstances, which distinguishes it from the qualities inherent in the ship or cargo by virtue of their nature as things–from ordinary wear and tear or inherent vice. 11Like any insured risk, a marine risk must possess the property of probability, ascertained from statistical data on the occurrence of comparable events. 12 And that probability must remain a mere possibility: the loss must not be inevitable. 13
Cyber risk resembles the traditional insured risk. It is marked by uncertainty, given the wide range of external acts capable of triggering an insured event–unintentional occurrences such as system failures, for instance, or malicious attacks by persons unconnected with the assured. 14 Like any insured risk, cyber risk imports the prospect of adverse consequences for the insured interest. 15
And, as with recovery in respect of any risk, a causal link must be established between the peril and the harm. Given the growing automation of shipping, however, damage to digital systems may entail not only the malfunction of a particular vessel’s automated systems but also damage to property. In such cases insurers will confront the question whether proximate causation links, say, a cyberattack with a fire it has indirectly provoked. 16 Since the wording of fire and explosion policies does not confine to any closed list the causes capable of producing an insured event, it may be supposed that fires and explosions resulting from a cyberattack will fall within standard cover. 17Yet the question arises not only where property damage has an indirect cause but also where digital systems are brought to a halt, impeding the operation of a ship or a port without any physical damage to property at all. 18
It should be observed that cyber risk may manifest itself both in deliberate acts aimed at causing harm and in unintended, accidental events. The diversity of cyber threats is borne out by open databases: the most common are DDoS attacks, ransomware and malware, GPS jamming and the spoofing of data in navigation systems (ECDIS, AIS), and the theft of informa tion. 19Either way, the harm done by deliberate acts (cyber acts) and accidental operational errors (cyber incidents) alike, in all its variety and unpredictability, poses a problem for insurers, because the probability of an insured event turns on how cyber risks are managed aboard the particular vessel. 20
3. The Relationship between Cyber Risk and Cyber Incident
As cyber risk is probabilistic and subject to underwriting assessment, it encompasses a wide variety of deliberate and negligent actions that are conducive to harm. An incident, by contrast, denotes a “casualty,” an “event,” or an “occurrence” – that is, the cause of a specific happening, arising at a particular place, at a particular time, and in a particular manner. 21 For instance, it may involve the loss, unauthorised destruction, alteration or disclosure of, or unauthorised access to, a digital system. 22
What ties risk and incidents together is the fact that they both have an underlying proximate cause. 23
The development of English case law has isolated two factors bearing on the “proximity” of a cause: first, proximity in time; second, “efficiency,” the part a factor plays in producing the immediate result. 24 The efficiency of a cause identifies the factor that brought the harm about notwithstanding the operation of maritime perils. In Leyland Shipping, for example, the proximate cause of the loss was held to be the torpedoing of the vessel, even though the ship, after being struck, had reached harbour, where water entered through the breach. 25
Although the ingress of water stood closer in time to the loss, it was the torpedo that had opened the breach in the first place. The same case yielded the dictum that “[c] ausation is not a chain, but a net,” so that a single factor may draw a whole “net” of circumstances in its train. The approach was developed in Allianz Insurance (2023),26 in which the court weighed the competition between two “proximate” causes: acts of war in 1942 and the controlled detonation of a bomb in 2021. Neither factor was the sole cause, and each depended directly on the other, whatever the interval of time between them. As applied to cyber risks, this approach suits cases in which a cyber incident has become the knot in such a “net” of factors that made the harm inevitable. 27
It follows logically that other established principles may also be applied to cyber incidents. Wayne Tank, for example, established the rule that where a loss is produced by two equally efficient causes, one insured and the other excluded from the policy, the exclusion prevails and relieves the insurer of liability. 28 Where, by contrast, one cause is insured and the other merely uninsured rather than excluded, the insurer remains liable. 29 As clauses excluding cyber risks spread, the likelihood that insurers will escape liability for cyber incidents rises accordingly.
It is also worth noting that the general rule that human intervention does not ordinarily break the chain of causation extends to cyber incidents. 30
In JB Cocoa Sdn Bhd the court considered the bearing of the NotPetya cyberattack on a delay in the release of cargo. 31The attack was held to be a concurrent cause, the original cause being the carrier”s failure to care for the cargo, a duty that comprised, alongside the classical obligation of proper stowage, the taking of reasonable measures of cybersecurity. The court found that the cyberattack was no more “efficient” than the carrier’s breach of its duty to keep the cargo safe.
The parties are free to redraw the limits of their obligations and may vary the test of causation applicable to a particular policy. Clause CL 380, for instance, uses the formula “directly or indirectly caused by,” which widens the “net” of connected factors. Section 55 (2) of the Marine Insurance Act 1906 uses “attributable to,” likewise broader than the classical “proximately caused.” Charterparties, for their part, employ “consequent on” or “arising from,” which presupposes an intermediate event between the loss, meaning the loss of freight and the proximate cause, that is, the insured peril. 32
4. The Accumulation of Cyber Risks
Insurance doctrine has developed the concept of the accumulation of risks: the spatiotemporal accumulation of insured objects or property interests in a single location, rendering them simultaneously vulnerable to same insured event.33 Such a situation may defeat the principle of equivalence on which insurers found their business, maintained as it is through the diversification of the risks they underwrite. 34 Where cyber risks are concerned, accumulation assumes a systemic character and a transnational scale. 35Its principal causes are three: (1) the use of identical software or cloud services (VSAT satellite-communication technology, for example, or the ECDIS navigation system); 36 (2) the interconnection on board, including on board autonomous vessels, between the information technologies that handle digital data and the operational technologies that control physical equipment, which is what gives digital incidents their physical consequences;37 and (3) the concentration of cargoes in logistics hubs under automated management, which generates both “mobile” and “stationary” accumulation. 38The chief danger of accumulation is the failure of traditional actuarial models: built on the independence of events, they simply leave out of account the situation in which many insurers are struck at once. 39 It is difficult to conceive of a cyber incident on a scale that would produce insured events of every description among unconnected assureds in such volume that insurers could not meet all the resulting claims; yet, at the present pace of technological development, such a situation could arise at least locally. 40
5. Watford Community Housing Trust v Arthur J Gallagher Insurance Brokers Ltd
Where a single incident affects a group of persons who all assert claims against one and the same insurer, English legal doctrine deploys the mechanism of aggregation of losses, whereby several claims are consolidated into one for the purpose of observing the limits of cover, provided that all of them arise from a single source or original cause. 41
Against this background the English case of Watford Community Housing Trust v Arthur J Gallagher Insurance Brokers Ltd 42 deserves attention. On 23 March 2020 an employee of the assured (Watford Community Housing Trust) mistakenly sent an email to 3,167 recipients, leaking the personal data of 3,544 individuals. The incident prompted 1,136 complaints, of which some 1,050 were accepted as well-founded claims. The assured sued its broker (Arthur J Gallagher Insurance Brokers Ltd) for professional negligence consisting in the failure to give timely notice to one of the three insurers potentially answerable under a professional indemnity policy. The broker admitted the negligence but raised a “no loss” defence, contending that even upon proper notification the “double insurance” provisions in all the policies would have capped the aggregate indemnity at GBP 5 million, a sum the assured had already recovered from the other insurers.
The case repays study for its application of the contractual machinery of aggregation, by which a multitude of individual claims may be characterised as a single insured event for the purposes of fixing the limits of liability and applying the deductible.
First, the court analysed the operation of the aggregation clauses contained both in the cyber policies and in the professional indemnity policies. Under the relevant terms, multiple claims arising out of the same act, error, or omission, or out of a series of related acts, errors, or omissions, fell to be treated as a single claim. The unifying factor was held to be the single mistaken dispatch of the email, which had given rise to thousands of potential claims.
Second, the judgment reflects the settled English position that aggregation is a distinct contractual mechanism, resting on a specially constructed causal link and designed above all to define (and most often to restrict) the scope of cover. 43 Having confirmed the presence of a single unifying factor, the court held that a mass leak of personal data flowing from one erroneous act must be treated as a single event when the limits of liability are applied.
6. The Limitation of Insurers” Liability
The unsettled state of cyber insurance has confronted the market with numerous economic challenges. Insurers have responded by writing into standard Hull & Machinery (H&M) policies clauses excluding liability to indemnify damage caused by cyberattack. Clause CL 380, drafted in 2003, excludes any loss, damage, or liability directly or indirectly caused by the use of a computer, software, or virus “as a means for inflicting harm.”44 The doctrine emphasises, however, that a “means for inflicting harm” presupposes malicious intent: the clause captures the use of a cyber risk specifically for attack, and a technical failure of a system ought therefore to fall outside the exclusion.45
Clause LMA 5402 (Marine Cyber Exclusion), for its part, excludes cyber incidents of every kind, system failures and errors included; clause LMA 5403 (Marine Cyber Endorsement) covers only unintentional cyber risks and excludes deliberate cyberattacks. 46
With cyber incidents excluded from cover, insurers frequently attempt to classify cyberattacks as “hostile or warlike action” or “acts of terrorism,” perils traditionally excluded from standard H&M policies. 47
7. Merck & Co Inc v ACE American Insurance Co
Merck & Co Inc v ACE American Insurance Co,48 widely known as the NotPetya case after the cyberattack of 2017, shaped the interpretation of war exclusions in relation to state-sponsored cyberattacks. At the heart of the dispute was the question of whether a standard clause excluding losses caused by “hostile or warlike action” could extend to a cyberattack mounted by a state actor but directed against civilian commercial infrastructure.
The attack was aimed initially at Ukrainian public bodies and commercial organisations through the compromise of the M. E. Doc accounting software, but it subsequently spread to the information systems of organisations across the world. The infection of more than 40,000 computers in its global corporate network left Merck & Co with losses estimated at approximately US 1.4 billion.
The insurers, who had written the cover under all risks property policies, refused to indemnify, invoking the exclusion of losses caused by hostile or warlike action on the part of a government or other sovereign power. The court reasoned as follows. First, it held that the assured had every right to expect the exclusion to apply solely to “traditional forms of warfare” involving physical force. As the judgment observes, “[a] lthough cyberattacks have become commonplace, the insurers made no attempt to change the language of the exclusions so as to put the assured on notice of an intention to exclude cyber incidents.”49
Second, drawing on international law, the court found that the terms war and hostilities have historically been understood as the use of armed force between contending states. It accordingly agreed that stretching those concepts to embrace a digital attack on a commercial company (a noncombatant in international law) would offend the principle that exclusions are construed narrowly.50
It is worth noting that English law takes a similar approach: provisions extending cover are construed broadly, while provisions restricting it (that is, exclusions) are construed narrowly. 51 The court reached its conclusion in order to protect the reasonable expectations of the assured, who was entitled to assume that the exclusion reached only “traditional forms of warfare.” 52
Ambiguity in the interpretation of the policy has resulted in cyber risks being treated as covered because they are not expressly excluded.53 In response, on 16 August 2022 Lloyd’s issued a market bulletin requiring participants, from 31 March 2023, either to exclude expressly, or to affirm expressly, cover for damage from state-backed attacks. 54
The doctrine also examines other clauses through which, in theory, attacks might be characterised as other perils. Capture and seizure clauses, for example, require physical possession or the presence of physical force, which rules out their application to intangible cyberattacks. 55 It appears more reasonable to classify a cyberattack that does not amount to an act of war as an act of terrorism or as an action carried out by politically motivated individuals.56That, in turn, requires proof of an intention to harm the assured or the public at large (malicious intent). 57
As the result, the numerous exclusions and the legal uncertainty surrounding cyber risks and cyber incidents often leave the assured unable to determine in advance the extent of its cover. The same incident may involve several factors at once: some excluded, some covered by the policy, and some simply uninsured. How the incident is legally classified has a direct impact on the insured’s ability to obtain insurance coverage. Further difficulties arise from the overlap of several exclusions, wording variations in the clauses, and the lack of consistent criteria to distinguish between deliberate cyberattacks and unintentional cyber incidents. The dispute between the parties accordingly shifts from the question whether damage has occurred to the questions of its legal characterisation and of the identification of its proximate cause. Such uncertainty inflates the costs of litigation, reduces the predictability of the allocation of risk between assured and insurer, and impedes the sound development of the marine insurance market as shipping is digitalised.
8. Conclusion
The digitalisation of maritime transport thus means that cyber incidents have ceased to be a purely technical problem and now bear directly on the operation of the traditional institutions of marine insurance law. The main legal issue lies not merely in whether there was a cyberattack or technical failure, but in how the proximate cause of the loss is characterised and how the limits of the cover are determined. Many exclusions, together with inconsistent distinctions between cyberattacks and cyber incidents, make insurance coverage uncertain and increase disputes between insureds and insurers. Rather than abandoning traditional legal principles, these factors require adapting them to the digital environment while preserving the balance of interests the parties involved in insurance.

