Clause

Cyber War Exclusion (LMA5567)

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

LMA5567 excludes losses in cyber policies caused by a cyber attack carried out in the course of war or attributable to a state as a hostile act, but requires a demonstrable attribution process before it applies.

Clause type
Exclusion
Origin/Market
London Market (LMA/NMA/Lloyd’s)
Favours
Insurer
Negotiability
Market standard

Standard wordings

  • LMA5567

Purpose

Following several large, state-attributed cyber attacks (such as NotPetya), the Lloyd’s market called for clearer contractual rules on when war-like cyber incidents are excluded from cover. LMA5567 excludes losses arising from a cyber attack carried out in the course of a declared or undeclared war, or attributable to a state as a hostile act, but requires robust attribution by the government of the affected state or recognised forensic or intelligence sources before the exclusion bites.

Effect and limits

The clause contains a carve-back in favour of so-called “bystander cyber attacks” — collateral damage suffered by insureds not specifically targeted — as well as its own mechanism for allocating the burden of proof on the attribution question. Because robust state attribution is often only available after a considerable delay, resolving whether the exclusion applies can significantly delay the conclusion of claims handling.

Negotiation and practice

Cyber policyholders should check which specific version of the exclusion (LMA5567 or one of its successor versions) is used in the contract, as attribution thresholds and carve-backs can differ between versions, and how the exclusion interacts with a separate sanctions clause.