Skip to main content
znobia

Cyber + Crime crossover

Cyber towers built to dovetail with Crime and Specie cover at the digital-asset boundary — where the binder that responds depends on the path the loss took.

Cyber and Crime cover frequently overlap at the digital-asset boundary, and frequently leave gaps. A theft that begins with a phishing email and ends with a hot-wallet drain may sit on the Crime binder, the cyber binder, neither, or both — depending on the wording. Placing a cyber tower for a digital-asset operator requires placing it against the Crime / Specie / Custody binders that already cover that operator’s other perils.

Perils

How cover responds — peril by peril.

01

First-party cyber loss

Insuring clause ·Cover responds to business-interruption loss, data-restoration costs, ransomware payments (where insurable by jurisdiction), and forensic-investigation costs.

Exclusions ·Wordings vary on whether digital-asset assets are treated as “money” for first-party theft purposes — a material question that turns on the specific wording.

02

Third-party cyber liability

Insuring clause ·Cover responds to liability arising from network-security failures affecting third parties (clients, counterparties), including regulatory investigations under data-protection regimes.

Exclusions ·Excludes liability arising from contractual obligations the insured would not have at law, and bodily-injury / property-damage outside any cyber endorsement extension.

03

Social engineering / fraudulent instruction

Insuring clause ·Cover responds (subject to sub-limits and consent-verification language) to loss arising from deceptive instructions to authorised personnel.

Exclusions ·Often sub-limited materially below the policy limit; verification protocols and call-back evidence requirements affect coverage and are read carefully at placement.

04

Crime / cyber boundary — direct theft of digital assets

Insuring clause ·Where the loss is direct theft of digital assets from a Listed Wallet, the Crime / Specie binder is the primary response; cyber may sit excess or in DIC. Where the loss is denial-of-service, data exfiltration, or non-monetary cyber events, cyber is primary.

Exclusions ·Cross-class exclusions — “loss insured under Crime / Specie” language — sit in many cyber wordings and create the gap that DIC layers are designed to close.

05

Smart-contract / oracle / bridge exploits

Insuring clause ·Where the loss is contract-logic failure (including oracle compromise and bridge exploit), cover sits, where placed, on a specific Listed Contract Schedule under either a cyber binder or a discrete smart-contract binder.

Exclusions ·Hot-wallet wording does not respond to this peril. Economic-attack vectors and oracle-manipulation losses may be expressly excluded depending on the carrier’s appetite.

Underwriting

What an underwriter will ask.

  1. 01

    Network architecture and segmentation. Production / dev / corporate segmentation. Network monitoring stack.

  2. 02

    Identity and access management. Privileged-access workflow, MFA enforcement, hardware-key adoption, joiner-mover-leaver cadence.

  3. 03

    Incident-response readiness. Named IR retainer. Last tabletop exercise. Mean-time-to-detect / contain over the past 12 months.

  4. 04

    Data protection posture. Encryption at rest and in transit. Key-management system. Backup posture and immutability.

  5. 05

    Vendor and supply-chain. Critical third parties, software bill of materials, last vendor-risk assessment.

  6. 06

    Existing programmes. Current cyber incumbent, retention, sub-limits, claims experience.

Use the RFI form to indicate your operating posture — same business day response from a named broker.

Carrier panel

Carrier panel — published on authorisation.

Panel slot 01

Published on authorisation.

Panel slot 02

Published on authorisation.

Panel slot 03

Published on authorisation.

Panel slot 04

Published on authorisation.

Panel slot 05

Published on authorisation.

Panel slot 06

Published on authorisation.

Editorial reference · public-press third-party reporting

Public reporting indicates that the Lloyd’s market continues to write cyber and Crime / Specie capacity for digital-asset operators, including via consortium structures — for example, Beazley’s combined cyber + FI consortium has been described in public press as one such structure. This is third-party editorial reference based on public reporting, not a representation of an existing binder relationship.

Process

From enquiry to instruction-to-bind.

  1. 01

    Enquiry

    RFI form or direct email to a named broker. Same-business-day acknowledgement; named broker assigned within one business day.

  2. 02

    Pre-qualification

    Six-question Q-pack run jointly. Initial appetite read from the cyber market. Typically 5-10 business days.

  3. 03

    Submission

    Underwriting submission drafted by znobia; reviewed with the client; sent to the target market. Typically 5-15 business days.

  4. 04

    Quote

    Markets respond with indicative terms. We summarise quotes against the original risk and the buyer’s stated priorities — limit, retention, sub-limits, exclusions.

  5. 05

    Bind

    Client issues an instruction-to-bind. Binder issued by the carrier. Typically a further 5-10 business days post-quote.

  6. 06

    Servicing

    Endorsements, mid-term changes, claims notifications, renewal. Each handled by the same named broker as on placement.

Typical timeline: 4-10 weeks for new cyber towers; 4-6 weeks for renewals. Expedited paths available for renewal.

Related primers

Recent intelligence on this class.

znobia acts as an insurance intermediary. We do not underwrite risk. Cover, where available, is placed with authorised carriers and is subject to underwriter approval, policy terms, exclusions and conditions. Nothing on this site is investment, tax, legal or financial advice. Cover described on this page is illustrative. Availability, terms, limits, retentions, sub-limits, and pricing are determined by the underwriter and are subject to underwriter approval, policy terms, exclusions, and conditions. Digital assets are volatile and may be subject to total loss. Insurance, where placed, is limited to specified perils and does not protect against market-value fluctuation.