A new report from Morningstar DBRS which marks 25 years since the September 11 attacks found that the federal terrorism backstop built in their aftermath has proven durable for conventional terrorism risk but faces a genuinely unresolved question when it comes to cyber terrorism.
According to the report, credible government backstops support insurer credit strength, but that their value depends on coverage scope, retained exposures and timeliness of claim payments, conditions increasingly tested by interconnected digital infrastructure that can transmit losses across borders.
The attacks killed nearly 3,000 people and caused roughly $60 billion in insured losses in today's dollars, the second-largest US insured loss event after Hurricane Katrina.
Reinsurers absorbed roughly two-thirds of that total, distributing the shock internationally, but the report identifies the core structural problem as something less obvious than the raw dollar figure: the synchronized nature of the attacks activated multiple insurance portfolios, property, liability, workers' compensation, aviation, business interruption and life, that insurers had previously priced and reserved for separately.
That correlation across lines, rather than the size of any single line's loss, is what generated the sharpest earnings and capital pressure industry-wide.
Swiss Re's own 2001 results illustrate that pressure directly, with the reinsurer reporting CHF2.95 billion in September 11 claims against a CHF165 million group net loss for the year. Litigation compounded the uncertainty further: a dispute over whether the World Trade Center's collapse constituted one occurrence or two, driven by inconsistent policy wording and incomplete documentation, wasn't resolved until a $2 billion settlement in 2007, nearly six years after the attacks.
Before 9/11, US commercial policies typically included terrorism coverage at no additional cost. Within weeks of the attacks, reinsurers withdrew capacity and primary insurers introduced exclusions or sharp price increases, a coverage collapse serious enough to threaten lending freezes and construction stoppages across real estate and infrastructure projects.
Congress responded by passing the Terrorism Risk Insurance Act (TRIA) in November 2002, establishing a federal program under which the Treasury shares large terrorism losses with insurers once a certified event exceeds statutory thresholds.
Under the current framework, in effect until December 31, 2027, a single event must be certified by the Treasury Secretary and cause more than $5 million in losses, with aggregate annual industry losses needing to exceed $200 million before the program activates; insurers then retain a deductible equal to 20% of their prior-year eligible earned premium, with Treasury reimbursing 80% of losses above that threshold.
Congress has reauthorized TRIA four times since its creation, in 2005, 2007, 2015 and 2019, and reauthorization is active again now: the House Financial Services Committee reported a bill in March 2026 that would extend the program to 2034 while raising the certification threshold to $10 million starting in 2029, while a separate Senate bill introduced in April would extend the program seven years without other changes.
That legislative activity gives this 25th-anniversary report a genuinely live policy backdrop rather than a purely retrospective one.
The report's central forward-looking concern is that a destructive attack on shared cloud services, payment infrastructure or electricity networks could generate correlated losses among geographically dispersed policyholders, meaning geographic diversification alone may no longer be a sufficient risk management tool for insurers.
Cybercrime, cyber terrorism and state-sponsored operations can overlap in practice while remaining distinct insurance categories, and the report warns that attribution disputes and gaps between primary and reinsurance contract wording could leave insurers holding more risk than they expected.
The US Treasury's own 2026 Report on the Effectiveness of the Terrorism Risk Insurance Program modeled a hypothetical hybrid kinetic-and-cyber attack on data centers in Virginia, with cyber effects cascading into cloud operations those centers support.
The scenario generated approximately $14.6 billion in modeled total insured losses, 88% of which were cyber-related, with roughly $4.85 billion of that total falling to federal TRIP payments and the remainder absorbed by insurers and reinsurers within their deductible and copay layers.
While TRIA can respond to qualifying cyber terrorism under eligible policies subject to certification, the report is explicit that it was never designed as a comprehensive catastrophic cyber backstop.
Terrorism risk pooling predates 9/11 in some markets. The UK's Pool Re and Spain's Consorcio de Compensación de Seguros both existed before the attacks, with Pool Re reinsuring member insurers under an unlimited Treasury guarantee and Spain's scheme compensating eligible losses through compulsory surcharges.
France created GAREAT and Germany established Extremus after 9/11, in 2002, and Australia formed its own terrorism pool in 2003, each combining insurer participation, reinsurance and government support in different proportions.
For insurers, the report's practical recommendation is that underwriting assessments account for simultaneous property, casualty and business interruption claims stemming from a single event, along with reinsurance counterparty quality and liquidity while recoveries remain outstanding, exactly the correlated-exposure problem that caught the industry off guard in 2001.
For risk managers and cyber underwriters specifically, the report argues that any future cyber terrorism backstop should prioritize clearly defining covered events and attribution procedures, retaining meaningful private risk rather than shifting it entirely to government, and requiring policyholders to maintain adequate cybersecurity standards as a condition of coverage, a framework Congress will need to weigh directly as it works through TRIA's current reauthorization debate.