By Archie Whitehead, Tech, Media & Cyber Senior Broker at New Dawn Risk.
A ransomware attack that encrypts data is, by now, a familiar threat. One that overrides the safety controls on a petrochemical plant’s cooling system and triggers an explosion is a different proposition entirely. So is a hacker disabling a hospital’s refrigeration units and rendering millions of dollars of pharmaceutical stock worthless overnight, or a safety-system intrusion that brings an entire manufacturing line to a halt for months. These are not theoretical scenarios, but rather the foreseeable consequences of a world in which operational technology (OT) is increasingly networked and increasingly exposed. The insurance industry, largely, has not caught up with that reality.
Standard property policies frequently exclude losses “caused by” cyber acts. Cyber policies offer only sublimited, contingent cover for physical damage, which is useful as a backstop but not designed to absorb a full-scale physical loss. The result is a coverage fault line that sits silently in most risk programmes, invisible until the aftermath of a major incident, when property and cyber carriers point at each other’s exclusions and the insured is left without a clear recovery path. This is not a niche problem. For any business operating networked industrial infrastructure, it is the default position.
Dedicated cyber property damage (Cyber PD) coverage closes this gap by affirmatively covering physical loss or damage (and resulting business interruption) where the proximate cause is a cyber event. The London Market has been engineering solutions at this intersection for over a decade. It remains, by some distance, the most credible place to place this risk.
The Coverage Gap in Practice
The problem is structural. Property underwriters have long relied on cyber exclusions, most notably variants of the Lloyd’s Market Association’s LMA5400 series, to ringfence their exposure. Cyber underwriters, meanwhile, have built their products primarily around data restoration and liability, with physical damage treated as an afterthought. A manufacturing company with £50 million of property cover and a £10 million cyber policy may believe it is comprehensively insured. In practice, it could face a cyber-induced fire and find that neither policy responds adequately. That £60 million of combined limit offers less protection than it appears, and the gap only becomes visible when a claim is already underway.
Why the London Market Leads Where Others Can’t Follow
London’s manuscript policy drafting tradition means coverage intent is clear from inception, leaving no ambiguity to litigate at the point of loss. Lloyd’s 300-year history of absorbing catastrophic and novel perils, combined with its capital structures and market collaboration culture, means it can provide the high limits and capacity that Cyber PD tail risks require. Other markets can offer cyber cover, but few can credibly back it with the financial strength and wording sophistication that large physical losses demand. London Market underwriters have also accumulated over a decade of claims experience in this specific product class, marking considerable institutional knowledge that cannot be replicated quickly.
The Stakes Are Higher Than Most Programmes Acknowledge
For industries reliant on OT, such as utilities, energy, manufacturing, mining, construction, and life sciences, the physical consequences of a cyber intrusion can be enormous and swift. Specialist industrial equipment can cost tens of millions to replace, with lead times stretching to months or years. Regulatory pressure is adding further urgency, with many contracts and lenders now requiring cyber coverage that explicitly extends to physical damage. The US, bodies such as NERC and FERC impose fines following cyber-triggered physical incidents that, without the right wording, would simply fall between the towers.
What Best-in-Class Cover Actually Looks Like
London wordings can go further than the core physical damage grant. Regulatory fines and penalties can be incorporated affirmatively, covering sanctions and enforced shutdown costs that admitted markets cannot or will not touch. Failure to supply coverage steps in when a cyber event disrupts the delivery of essential services, protecting utilities and energy companies from the contractual and commercial fallout that often exceeds the physical damage itself. Spoilage coverage responds to cyber-induced refrigeration failures or production shutdowns, critical for pharma, food producers, and any business where perishable inventory can be rendered worthless within hours.
The Renewal Conversation Most Brokers Are Missing, and the London Market’s Answer
The cyber market has been soft for some time, and meaningful coverage differentiation is proving hard to find. Cyber PD is one of the few areas where a broker can still bring a genuinely different proposition to the table that delivers meaningful limits and requires expertise and market access that not every intermediary can offer. That opportunity carries a corresponding obligation. Brokers placing cyber policies without reviewing whether their clients’ property tower contains cyber exclusions are leaving a significant exposure unaddressed. For businesses in utilities, energy, manufacturing, and life sciences, that gap almost certainly already exists.
The London Market’s ability to offer Cyber Property Damage at high limits, with bespoke wordings and Lloyd’s financial backing, is an enduring differentiator. For brokers and insureds who understand the true scope of their exposure, Cyber PD should be the starting point rather than the last resort.