The cyber reinsurance market has no consistent standard for how critical infrastructure exclusion clauses are written, interpreted, or applied. A Lockton Re report published at the Monte Carlo Reinsurance Rendez-Vous puts a number on the problem. Its modelling shows a 15-percentage-point swing in industry loss ratios at the 1-in-50 return period, based on how those clauses are drafted.
The report, When the Lights Go Out: Cyber's Infrastructure Blind Spot, was built on input from insurers, reinsurers, brokers, legal specialists, and cyber modellers. Clause inconsistency, it concludes, is not a drafting technicality. It is a quantified accumulation risk inside cyber reinsurance treaties.
Lockton Re modelled five exclusion groups against a control benchmark. Groups ran from traditional utility-only exclusions to broad interpretations covering utilities, telecommunications, and financial market infrastructure. The benchmark produced a 76% industry loss ratio at the 1:50 return period.
Broad infrastructure exclusions reduced that to 61%. Under the broadest exclusion group, the modelling found 27% fewer loss events compared with the benchmark. The variance matters because systemic cyber events do not respect portfolio boundaries. A failure in one widely used technology can generate correlated losses across industries and geographies that look diversified under conventional underwriting measures.
Critical infrastructure exclusions exist to manage that tail risk. Their effectiveness depends on the clarity of language in the underlying primary policies.
"The clauses have been neglected in the wake of the industry discussion of cyber war clauses," said Oliver Brew, head of Cyber Centre of Excellence at Lockton Re. "Clarity of intent for critical infrastructure is key to understanding where the boundary of what is insurable lies."
Reinsurance treaties often include fall-back language stipulating that an infrastructure exclusion applies only in the absence of an underlying exclusion. Where primary wordings vary considerably, a reinsurer may follow the fortunes of a cedant without visibility into what is excluded at the original policy level. Definitional fragmentation compounds the difficulty.
The UK's National Protective Security Authority defines Critical National Infrastructure (CNI) across 13 sectors. The US Cybersecurity and Infrastructure Security Agency (CISA) identifies 16. Neither framework maps cleanly onto a cyber market where policy language standardisation remains incomplete.
"With the rapid advancement of new technology, insurance policy language has failed to keep up with the changes in the ways technology is used," said Laura Betts, cyber account executive at Lockton International and co-author of the report.
The definitional boundary is already moving. In September 2024, the UK government designated data centres as critical national infrastructure. The Cyber Security and Resilience Bill proposes classifying them as essential services. HM Treasury has separately designated several cloud service providers as critical third parties in financial services.
AWS, Microsoft Azure, and Google Cloud account for approximately 58% of global hyperscale data centre capacity, according to Synergy Research Group. That concentration creates potential aggregation nodes.
Cloud computing is not currently classified as critical infrastructure, yet it relies on the same physical and network resources as infrastructure the market already excludes. The question of how reinsurers price and manage data centre accumulation sits directly alongside the infrastructure clause debate.
"Incidents affecting infrastructure are more likely to occur than war events so they are potentially even more impactful given the crucial role of infrastructure in modern economies," said Jason Glasgow, senior vice president and cyber lead at Allied World. "Policy language must be clear on what is and is not covered."
The UK National Cyber Security Centre (NCSC) recorded over 200 attacks against CNI in 2025, up from 89 in 2024, according to a report from The Guardian. That trajectory makes the absence of consistent clause language a live underwriting exposure, rather than a future-proofing exercise.
The International Underwriting Association (IUA) and the Lloyd's Market Association (LMA) are both reviewing critical infrastructure clause language.
"It is essential that critical infrastructure clauses are drafted with clarity," said Joe Shaw, director of claims at the IUA. "The IUA has been exploring the issue through its cyber reinsurance committee and has recognised a need for consistent definitions."
The LMA is also working on a model infrastructure failure exclusion through its cyber business panel. Chris Mather, senior executive, technical underwriting at the LMA, said its members recognise the systemic accumulation risk. A single large-scale infrastructure failure could generate claims from thousands of insureds simultaneously.
Lockton Re has called on the market to evaluate what constitutes critical infrastructure, review whether clause language matches intent, and develop technology-agnostic wordings. If adopted, the LMA's model clause would be the market's first standardised infrastructure failure exclusion for cyber insurance policies.