Critical infrastructure exclusions on cyber insurance could produce materially different loss outcomes depending on how they are drafted and interpreted, with Lockton Re modelling a 20% relative reduction in industry loss ratios at the 1-in-50 return period
Lockton Re has warned that inconsistent critical infrastructure exclusions are creating uncertainty over the boundary between insurable cyber risk and systemic exposures the private market is unwilling to carry.

In its report, timed for RVS 2026 and titled “When the Lights Go Out: Cyber’s Infrastructure Blind Spot”, the reinsurance broker found significant variations in policy language covering utilities, telecoms and financial infrastructure, at a time when technology is increasingly blurring distinctions between traditional infrastructure and digital services.
The broker’s in-house modelling found a 15 percentage point difference at the 1-in-50 return period between a scenario with no relevant infrastructure exclusions and the broadest interpretation of those clauses.
Oliver Brew, head of Cyber Centre of Excellence at Lockton Re and co-author of the report, said: “The clauses have been neglected in the wake of the industry discussion of cyber war clauses.
“Clarity of intent for critical infrastructure is key to understanding where the boundary lies, of what is insurable. Our review of current critical infrastructure clauses identified significant inconsistencies and shortcomings across the market.
“The result is uncertainty for insurers, reinsurers, brokers and policyholders alike.”
Loss ratio impact
Lockton Re reported it tested five groups of exclusions against a control scenario, ranging from traditional utilities alone to a broad interpretation encompassing utilities, telecommunications and financial infrastructure.
At the 1-in-50 return period, the benchmark generated a 76% industry loss ratio, compared with 61% under the broadest exclusion. The modelling also produced 27% fewer loss-generating events when the widest interpretation was applied. Lockton Re stressed that the results are directional and will vary by portfolio.
Laura Betts, cyber account executive at Lockton International and co-author, said: “We engaged with participants across the market including insurers, reinsurers, brokers, and industry associations to provide insights. With the rapid advancement of new technology, insurance policy language has failed to keep up with the changes in the ways technology is used.”
The report highlights telecoms as a particular grey area.
Cyber policies typically intend to cover outages involving cloud providers, but infrastructure exclusions do not always clearly distinguish cloud services from traditional telecoms networks, the broker warned.
Financial infrastructure definitions can similarly range from core clearing systems to payment processing platforms, Lockton Re highlighted.
Data centre dilemma
Uncertainty is becoming more significant as governments expand their definitions of critical infrastructure.
The UK, for instance, has designated data centres as critical national infrastructure since 2024.
Lockton Re noted that AWS, Microsoft Azure and Google account for approximately 58% of global hyperscale data centre capacity.
Brew added: “There is an urgency to ensure that the intent of these clauses is aligned with the reality of how they can be interpreted. It is incumbent on the whole industry to improve the clarity of what is intended in order to enhance the industry’s reputation.”
Lockton Re called on the cyber re/insurance market to reassess what constitutes critical infrastructure, consider whether additional categories should be included and make wording more consistent and technology-agnostic.
Ed Le Flufy, global head of cyber at Lockton Re, added: “As new technologies proliferate and aggregation potential grows, the definition of what constitutes critical infrastructure and clarifying the coverage afforded by the market is essential to sustainable growth.”
Lockton Re’s cyber report is available here.



No comments yet