Lloyd's of London Cyber Insurance Requirements and Underwriting Standards
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Affirmative Coverage + LMA Model Clauses + March 2023
Lloyds of London Cyber Insurance Requirements - Affirmative Cyber Coverage Mandate. Following Lloyds Market Bulletin Y5258 (issued 16 August 2022) all Property Policies underwritten by Lloyds market participants must clearly state from 31 March 2023 onwards whether cyber-related losses are covered + excluded + with no implicit ambiguity (silent cyber elimination). Lloyds Market Association (LMA) issued LMA Model Clauses set including: LMA5400 Cyber War and Cyber Operation Exclusion + LMA5401 Cyber War and Cyber Operation Exclusion (No Attribution Required) + LMA5402 Cyber War and Cyber Operation Exclusion with Carve-Backs + LMA5403 Cyber War and Cyber Operation Exclusion with Attribution Bureau + LMA5404 + LMA5405 various carve-backs and definitions. Coverholder + delegated authority business must use compliant LMA model clauses or equivalent + filed with Lloyds Coverholder Services. All
- Property policy wordings post-March 2023
- LMA5400-5405 model clause incorporation
- Coverholder binder LMA compliance evidence
- Lloyds Risk Code CY separation
- Class of Business Review compliance
- Property policies still silent
- Pre-2023 clauses used
- Coverholder non-compliant
- Silent cyber unmonitored
Claims + Sanctions + Ransomware Payment + OFAC
Lloyds Cyber Insurance Requirements - Claims Handling Standards for Cyber Events and Sanctions/Ransomware Compliance. Claims Handling Standards for Cyber Events: (a) Specialised cyber claims handling capability + Lloyds claims handler training in cyber-specific issues + Computer Forensics + Digital Forensics and Incident Response (DFIR) integration + Coalition + Crawford + Sedgwick cyber claims specialists; (b) 24/7 cyber incident response hotline + breach coach lawyer + IR firm appointment (Mandiant + CrowdStrike + Coalition Incident Response + Kroll + Aon Crisis Management + Marsh Cyber); (c) Lloyds Claims Standards alignment + LMG ECF (Electronic Claims File) + IUA (International Underwriting Association) cyber claims handling; (d) Pre-approved vendor panels for forensics + legal + crisis communications + ransomware negotiation + cryptocurrency tracing; (e) Cyber claim severity assess
- Cyber-specialised claims handler evidence
- 24/7 incident response hotline
- Pre-approved vendor panels
- OFAC SDN screening procedure
- HMT OFSI compliance evidence
- Ransomware payment decision protocols
- Cryptocurrency tracing evidence (Chainalysis/Elliptic)
- Mandatory ransomware reporting compliance
- No specialised cyber claims
- No OFAC screening
- No vendor panels
- No cryptocurrency tracing
- No ransomware payment protocol
Conduct + TCF + Silent Cyber + Regulatory
Lloyds Cyber Insurance Requirements - Conduct Risk, Cross-Class Reviews and Regulatory Notifications. Conduct Risk and Treating Customers Fairly (TCF): (a) FCA Principles for Businesses Principle 6 (TCF) + Principle 7 (Communications) + Principle 8 (Conflicts of Interest) + Principle 9 (Vulnerable Customers); (b) Insurance Conduct of Business Sourcebook (ICOBS) + Insurance Distribution Directive (IDD) + UK Senior Managers and Certification Regime (SM&CR) + Consumer Duty (effective 31 July 2023); (c) Plain English policy wording + cyber-specific terminology glossary + clear communication of exclusions including war + state-backed + retroactive date + sub-limits + sublimits per occurrence + aggregate; (d) Treating Cyber claimants fairly + responsive claims handling + access to specialist resources; (e) Vulnerable customer considerations including SME with limited cyber expertise + protecte
- FCA Principles 6/7/8/9 compliance evidence
- Consumer Duty 2023 evidence
- Plain English policy wordings
- Annual cross-class silent cyber review
- PRA SS5/14 + SS3/15 notifications
- FCA Principle 11 evidence
- SFCR cyber disclosure
- Bank of England Stress Test cyber participation
- No Consumer Duty alignment
- No cross-class review
- No PRA notifications
- Silent cyber unresolved
- No Stress Test participation
Pricing + Rate + Authority + Bordereaux
Lloyds Cyber Insurance Requirements - Pricing, Rate Adequacy and Underwriter Authority. Pricing and Rate Adequacy Monitoring: (a) Risk-based pricing methodology + actuarial loss models + frequency-severity modeling + cyber-specific loss development triangles (long-tail vs short-tail nature of cyber loss) + IBNR reserving + industry-wide cyber loss ratios; (b) Lloyds Pricing Standards aligned with Solvency II + Internal Model + Standard Formula technical provisions + best estimate + risk margin; (c) Cycle Management monitoring (cyber market hard 2020-2022 + softening 2023-2024); (d) Rate Adequacy Monitoring per Lloyds Class of Business Review + benchmarking against industry standards; (e) Reinsurance pricing alignment + retrocession; (f) Capital adequacy linked to cyber portfolio aggregate risk. Underwriter Authority: (a) Tiered underwriting authority limits by referral threshold + Lloyds
- Actuarial loss models
- Rate Adequacy Monitoring evidence
- Underwriter authority matrix + referral limits
- SM&CR SIMF allocation
- LM TOM Phase 2 Bordereaux Format v3
- Lloyds Risk Code CY documentation
- No actuarial methodology
- No rate monitoring
- No authority matrix
- No bordereaux compliance
Reinsurance + Capital + Solvency II + Coverholder
Lloyds Cyber Insurance Requirements - Reinsurance, Capital Protection and Solvency II Alignment. Reinsurance and Capital Protection for Cyber: (a) Cyber-specific retrocession programmes + per-event + aggregate excess of loss + quota share + facultative; (b) Lloyds Reinsurance Programme participation + ABI Cyber Reinsurance Pool consideration + Lloyds-recognised reinsurers (Munich Re + Swiss Re + Hannover Re + Lloyds Reinsurance Syndicates); (c) Industry Loss Warranties (ILW) cyber + parametric cyber covers; (d) Cyber Catastrophe Bond consideration (cyber CAT bond market $1B+ outstanding) + Insurance Linked Securities (ILS) + alternative capital sources; (e) Cyber Retro pricing + capacity constraints; (f) Stop-loss reinsurance with cyber-specific triggers (named cyber event + cyber catastrophe + government attribution). Solvency II and ORSA Alignment for Cyber: (a) Own Risk and Solvency A
- Cyber-specific reinsurance programme
- ILS/CAT bond evidence
- ORSA cyber risk section
- SFCR cyber disclosure
- Coverholder Cyber Risk Assessment
- Binder cyber-specific provisions
- Lloyds Capital Sub-Group cyber assessment
- No cyber reinsurance
- No ORSA cyber
- No coverholder assessment
- No SFCR cyber
Risk Selection + Cyber Hygiene + Pre-Bind
Lloyds Cyber Insurance Requirements - Risk Selection and Cyber Hygiene Underwriting Criteria. Underwriters must conduct rigorous risk selection + due diligence assessing insured-cyber hygiene including: (a) Mandatory cyber hygiene requirements (insurance-grade baseline expectation): Multi-Factor Authentication (MFA) on all privileged accounts + all remote access + email + cloud admin consoles + Endpoint Detection and Response (EDR) on all endpoints + immutable + air-gapped + tested backups + Email Security Gateway + DMARC + SPF + DKIM + Patch SLA Critical 7 days + High 30 days + Vulnerability Disclosure programme + Security Operations Centre (SOC) capability + Incident Response Plan + tabletop exercises + Privileged Access Management (PAM); (b) Additional underwriting criteria for higher coverage: NIST Cybersecurity Framework alignment + ISO 27001 certification + SOC 2 Type II + Penetrat
- Mandatory hygiene requirements documented (MFA + EDR + backups)
- External attack surface scan reports (Bitsight/SecurityScorecard)
- Dark web monitoring
- Industry-specific underwriting criteria
- SME tiered hygiene
- Cyber hygiene declarations + warranties
- No mandatory hygiene
- No external scan
- No dark web monitoring
- No SME tier
Systemic Aggregation + Catastrophe Modelling
Lloyds Cyber Insurance Requirements - Systemic Cyber Risk Aggregation + Catastrophe Modelling. Lloyds Catastrophe Modelling Standards require all managing agents to: (a) Model Cyber Realistic Disaster Scenarios (Cyber RDS) developed by Lloyds + Cambridge Centre for Risk Studies + Aon + Marsh + Munich Re including: Cyber Cloud Outage (USD 53B industry loss scenario) + Cyber Ransomware Pandemic (USD 193B) + Cyber Data Exfiltration (USD 17B) + Cyber DDoS Wave + Cyber Power Grid Attack + Cyber Industrial Control System; (b) Use Lloyds-approved Catastrophe Models: Verisk Cyber Catastrophe Model + AIR Cyber + RMS Cyber Solutions + CyberCube Industry Exposure Databases + Moodys ESG + Guy Carpenter + (c) Maintain industry-wide concentration risk analysis: cloud provider concentration (AWS + Azure + GCP outage exposure) + software supply chain concentration (Microsoft + Oracle + SAP) + ransomware
- Lloyds Cyber RDS modelling outputs
- Verisk/AIR/RMS/CyberCube vendor model use
- PML 1-in-100/200/250/500 analysis
- Cloud concentration risk analysis
- Supply chain compromise scenarios
- Independent PMD validation
- No Cyber RDS
- No vendor catastrophe model
- No PML analysis
- No concentration analysis
War + State-Backed Exclusions + Attribution
Lloyds Cyber Insurance Requirements - War, Cyber Operation, and State-Backed Exclusions. Following NotPetya 2017 + WannaCry 2017 + SolarWinds 2020 + Colonial Pipeline 2021 industry-wide reassessment of war + state-backed cyber exclusion language driven by Lloyds Market Bulletin Y5258. LMA5400-LMA5403 model exclusions for war + cyber operation provide tiered language: (a) LMA5400 broadest exclusion requires no attribution + state-backed cyber excluded; (b) LMA5401 limited carve-back for bystander attacks where target not government/military; (c) LMA5402 narrower exclusion with explicit carve-backs for ransomware + denial of service even if state-backed; (d) LMA5403 attribution bureau mechanism requires government attribution or independent cyber attribution service. Attribution Mechanisms: (a) Government Attribution - sovereign attribution by impacted government (US + UK + EU + Five Eyes
- LMA5400/5401/5402/5403 selection rationale
- Attribution mechanism documentation
- Government attribution monitoring
- Independent attribution service contracts
- War-cyber claims handling procedure
- No attribution mechanism
- Outdated war exclusion
- No state-backed analysis
- No carve-back consideration
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.