A Kremlin-linked adviser's warning that British factories supplying drones and missile parts to Ukraine could face "semi-military" action has landed just as insurers were already grappling with a fresh wave of state-linked attacks on UK infrastructure. For manufacturers tied to the war effort, and the brokers who cover them, it's a useful prompt to check exactly where existing policies start and stop.
Andrei Fedorov, a former Russian deputy foreign minister who now advises the Kremlin, told the BBC's Newsnight programme this week that Moscow would not "100% exclude" some form of "semi-military" response against British manufacturers involved in producing components for Ukraine's war effort. Pressed on what that might look like, he said such firms "could be attacked, not by Russia, but by... from unknown sources" - language widely read as pointing towards deniable sabotage or cyber intrusion rather than a direct military strike.
The comments followed the UK's decision to declassify blueprints for British-made components used in Storm Shadow/SCALP cruise missiles, clearing the way for Ukraine to manufacture the parts domestically. Prime Minister Andy Burnham, on his first overseas trip since taking office in July, confirmed the move during a visit to Kyiv, where Ukrainian officials in turn handed UK security services what has been described as a substantial cache of intelligence on Russian sabotage networks operating in Britain.
The Kremlin's response was blunt. Spokesman Dmitry Peskov accused London of adding "fuel to the fire" of the war. Burnham's retort - "who started the fire? That's the question, isn't it?" - has since become one of the more widely quoted lines of his young premiership.
The threat lands only days after it emerged that hackers linked to Iran's regime managed to knock a UK power generation facility offline for four days last month - reportedly the first time a state-linked cyber intrusion has succeeded in forcing a British electricity-generating site to shut down. Officials have stressed the plant was small and posed no risk to the wider grid, but security specialists have flagged the episode as evidence that critical infrastructure operators, including smaller and mid-tier sites, remain exposed to sophisticated state actors.
Government cyber agencies had already been sounding the alarm before that attack. GCHQ's National Cyber Security Centre has previously said it handled more than 200 attacks on critical national infrastructure in a single year, while trade body the Association of British Insurers has backed the government's Cyber Security and Resilience Bill, noting insurers paid out close to £200 million in UK cyber claims last year alone.
For brokers advising defence-adjacent manufacturers, Fedorov's remarks crystallise a coverage problem that has been building for some time: sabotage attributed to a hostile state, but carried out by unnamed proxies or cyber intrusion rather than uniformed forces, sits awkwardly across standard property, business interruption, terrorism and war-risk wordings.
The UK's government-backed terrorism reinsurer, Pool Re, was created in 1993 on the premise that the private market alone cannot absorb losses from politically motivated attacks. It has since expanded its scope to include certain cyber-triggered events, but its cover typically applies to certified acts of terrorism rather than the broader, greyer category of state-linked sabotage or acts of war - a distinction that matters enormously when a claim is being assessed.
The Lloyd's Market Association's Political Violence and Terrorism Claims Group has been tracking the Russia-Ukraine conflict closely and has produced updated sabotage and terrorism wordings reflecting how far the market has had to move to keep pace with this kind of ambiguity, according to earlier Insurance Business reporting on Russian insurers pricing drone-war risk. Separately, MI5 has reported a rise in state threat investigations, with Russia specifically flagged for its use of proxies and criminal groups to destabilise the UK, precisely the kind of "unknown sources" framing Fedorov used this week.
Tony Gallagher, CEO Asia-Pacific for reinsurance broker Guy Carpenter, made a similar point earlier this year when discussing how the terrorism market is adapting to threats that no longer resemble conventional attacks. He argued that today's threat landscape now spans everything from state-sponsored sabotage and lone-actor violence to cyberattacks and even the threat of biological or chemical incidents, and that insurers can no longer treat terrorism as a narrow peril defined only by large-scale property damage. It's a description that reads uncannily like the scenario Fedorov sketched out this week, as covered in Insurance Business's earlier report on the blurring of terrorism cover.
To see why the distinction matters in practice, take a hypothetical: a mid-sized components manufacturer supplying parts for Storm Shadow production loses four days of output to a cyber intrusion that investigators later attribute, with low confidence, to a proxy group acting on Russia's behalf. Under a standard all-risk property policy with a conventional terrorism exclusion, that loss could fall into a genuine grey area - not clearly "terrorism" as legally defined, not clearly a certified act of war, and potentially outside what a standalone cyber policy's war exclusion was drafted to capture either. Getting an answer to that question before an incident happens, rather than during a claim, is precisely the gap brokers are being encouraged to close.
None of this means UK factories are about to come under direct attack - Fedorov himself stopped well short of that, and the government has shown no sign of changing its approach as a result. What it does mean, for firms in the defence supply chain, is that a threat which sounded speculative before this week's Storm Shadow decision now sits closer to a live underwriting question. Specialist markets have already built products for exactly this kind of risk: the AEGIS London Political Violence Consortium, for instance, writes standalone cover spanning sabotage, civil commotion, insurrection and war for industrial and logistics clients whose all-risk property policies exclude those perils outright.
Manufacturers producing components destined for Ukraine, or otherwise publicly associated with the war effort, would be well placed to go back to their broker this week. Would business interruption cover respond if a cyberattack, rather than a bomb, took a production line offline? Would a war or terrorism exclusion bite if the attack were later attributed, even loosely, to a hostile state rather than a criminal gang? And is a standalone political violence or cyber-war endorsement worth the premium, given how the threat has been framed in public by a Kremlin-linked adviser this week? Those are the sort of questions better asked now than after the event.