Scenario modelling in When the Lights Go Out: Cyber’s Infrastructure Blind Spot shows a potential 20% relative decrease in industry loss ratios at the 1-in-50 return period, depending on how the clauses are drafted and interpreted.
MONTE CARLO, 7th September, 2026 — Lockton Re, the reinsurance business of Lockton, the world’s largest privately held independent insurance broker, has published a report finding that critical infrastructure clauses in cyber insurance are inconsistent across the market. The report, When the Lights Go Out: Cyber’s Infrastructure Blind Spot, examines how those clauses have evolved, how they are applied, and how they are interpreted across the cyber insurance and reinsurance market.
Critical infrastructure presents systemic exposures for the cyber market. Those exposures — spanning utilities, telecommunications and financial infrastructure — sit beyond the scope of the current market.
Lockton Re modelled a range of scenarios to illustrate the potential impact of critical infrastructure clauses in cyber insurance. The modelling demonstrates a potential 20% relative decrease in industry loss ratios at the 1-in-50 (1:50) return period. The figure illustrates the range of outcomes that clause wording can produce; it is not a forecast of any single event.
Oliver Brew, Head of Cyber Centre of Excellence at Lockton Re and co-author of the report, said: “The clauses have been neglected in the wake of the industry discussion of cyber war clauses. Clarity of intent for critical infrastructure is key to understanding where the boundary lies of what is insurable. Our review of current critical infrastructure clauses identified significant inconsistencies and shortcomings across the market. The result is uncertainty for insurers, reinsurers, brokers and policyholders alike."
What a critical infrastructure clause is
A critical infrastructure clause defines which infrastructure sectors — such as utilities, telecommunications and financial infrastructure — fall outside, or are limited within, the scope of a cyber insurance or reinsurance policy. It is the wording that sets the boundary between the cyber risk the market is prepared to carry and the systemic exposure it is not. Definitions of critical infrastructure have been updated over time, often in response to specific cyber-attacks, but the language inevitably falls behind the technology it describes.
What the report found
Critical infrastructure clauses in cyber insurance are inconsistent across the market. Lockton Re’s review of current wordings identified significant inconsistencies and shortcomings.
The ambiguity creates uncertainty for insurers, reinsurers, brokers and policyholders alike.
Scenario modelling demonstrates a potential 20% relative decrease, or 15-point loss ratio reduction in industry loss ratios at the 1:50 return period.
The clauses have been neglected in the wake of the industry discussion of cyber war clauses.
Governments are increasingly treating data centres as critical infrastructure. That presents a new challenge for insurance products, which must be clear about the coverage they maintain as the definition widens.
How the report was researched
Lockton Re engaged with participants across the market, including insurers, reinsurers, brokers and industry associations.
Laura Betts, Cyber Account Executive at Lockton International and co-author of the report, said: “We engaged with participants across the market including insurers, reinsurers, brokers, and industry associations to provide insights. With the rapid advancement of new technology, insurance policy language has failed to keep up with the changes in the ways technology is used.”
Oliver Brew added: “There is an urgency to ensure that the intent of these clauses is aligned with the reality of how they can be interpreted. It is incumbent on the whole industry to improve the clarity of what is intended in order to enhance the industry’s reputation.”
What Lockton Re is asking the market to do
The report sets out a four-point call to action:
Evaluate what constitutes critical infrastructure across key areas.
Consider whether other categories of critical infrastructure should be addressed.
Review current critical infrastructure clauses to ensure that language is consistent and matches the intent behind it.
Assess the language framework through the lens of rapidly changing technology, to ensure it remains fit for purpose.
Ed Le Flufy, Global Head of Cyber at Lockton Re, concluded: “As new technologies proliferate and aggregation potential grows, the definition of what constitutes critical infrastructure and clarifying the coverage afforded by the market is essential to sustainable growth.”
Lockton Re’s position is that critical infrastructure clauses in cyber insurance should say the same thing across the market and should say what they are intended to say.
