The two-tower problem: where affirmative cyber stops and the fire wording is supposed to begin
Most Indian commercial buyers now run two separate insurance towers for cyber risk without ever describing them that way. The first is the affirmative tower: a standalone cyber policy that names data breach, network interruption, cyber extortion and system damage as insured events and prices them explicitly. The second is the property tower: the Standard Fire and Special Perils cover, the Industrial All Risks (IAR) policy, and the engineering lines (Machinery Breakdown, Erection All Risks, Contractors All Risks) that were written long before anyone underwrote a cyber peril at all.
The gap between them is what the market calls silent cyber or non-affirmative cyber. It describes the situation where a cyber event triggers a loss that the property wording neither clearly grants nor clearly excludes. A ransomware strain corrupts a plant's control logic, a boiler over-pressurises, and the resulting explosion damages the turbine hall. The physical damage is a classic fire-policy event. The cause is a cyber act. Which tower pays, and for how much, depends entirely on the exclusion language, not on the buyer's intent when they placed the cover.
For years Indian insurers carried this exposure without pricing it, because the underlying wordings inherited from the tariff era simply did not contemplate a computer-driven cause of physical loss. That silence was tolerable while reinsurance treaties were also silent. It stopped being tolerable once the treaty layer, led by the London market, decided that silence was an uncosted liability it would no longer accept. The result is a coordinated tightening of exclusion language that is working its way from the reinsurance contract down into the direct policy that an Indian broker places on a factory. Understanding that transmission path is now part of reading a property renewal properly, not a specialist cyber conversation.
How LMA5410 rewrote the treaty, and why the direct wording had to follow
The pivot point is LMA5410, the Cyber Loss Limited Exclusion Clause (Property Treaty Reinsurance) No.1, published by the Lloyd's Market Association on 6 March 2020. It is a reinsurance clause, not a policyholder clause, and that distinction is exactly why Indian buyers rarely hear its name even though it is reshaping their cover.
LMA5410 excludes from the property treaty any loss connected to damage to a computer system or to data. Two features make it aggressive. The data exclusion is absolute, with no write-back at all, so any element of a loss that represents the value, restoration or reproduction of data falls outside the treaty. The clause also does not distinguish between malicious and non-malicious cyber events, unlike the direct-side clauses that came before it. What it does grant back is narrow and specific: physical damage to property insured under the original policies, and any time-element loss directly resulting, where that physical damage is directly occasioned by a named peril. The named perils are the familiar property set: fire, lightning, explosion, aircraft or vehicle impact, falling objects, windstorm, hail, earthquake, flood and a handful of others.
The transmission into Indian direct wordings runs through the treaty renewals. GIC Re and the domestic market cede a large share of fire and engineering risk into obligatory and surplus treaties, and into excess-of-loss protections placed with international reinsurers. When those reinsurers adopt LMA5410 at the 1 April and 1 January renewals across 2024 and 2025, the ceding insurer faces a choice. It can carry the cyber exposure net, unreinsured, or it can push a matching exclusion down onto the direct policy so its inward cover and its outward protection line up. Almost every insurer chooses the second path, because carrying an uncosted, unmodelled cyber accumulation net of reinsurance is not a decision an Indian underwriter can defend to their board or to IRDAI.
Reading the LMA5400 fire and explosion carve-out line by line
On the direct side, the clause an Indian broker will actually see endorsed onto a fire or IAR policy is usually a version of LMA5400 or a locally drafted equivalent that follows its architecture. LMA5400 excludes loss arising from a cyber act or a cyber incident, then writes a specific carve-out back in. The carve-out is where the money sits, and it is narrower than most buyers assume.
LMA5400 responds to fire or explosion that results from a cyber incident, which the clause treats as an accidental or non-malicious event, such as a software fault or an operator error in a control system. It does not respond to fire or explosion that results from a cyber act, meaning a malicious or deliberate use of a computer system, including a hostile attack. So the carve-back is switched off precisely in the scenario buyers worry about most: a targeted ransomware or wiper attack that pushes an industrial process into a physical failure.
That asymmetry between the treaty and the direct clause matters. Read them together:
- LMA5410 (treaty) grants back physical damage from named perils including fire and explosion, and does not care whether the cyber trigger was malicious.
- LMA5400 (direct) grants back fire and explosion only where the cyber trigger was non-malicious.
Brokers should read the exact definitions of cyber act, cyber incident and computer system in the endorsement rather than trusting the label. A one-word difference in whether malice is required decides whether a plant fire caused by a compromised programmable logic controller is a paid claim or a declined one.
Where Indian fire and engineering policies now sit under the new endorsements
The Indian property market reached this point from a different starting line than London. Fire pricing was fully de-tariffed in 2007, but the wordings stayed heavily standardised, and the Insurance Information Bureau (IIB) burning-cost rates still anchor how the market prices the Standard Fire and Special Perils cover and its successors. The current retail-to-SME structure runs through Bharat Sookshma Udyam Suraksha for risks up to five crore rupees and Bharat Laghu Udyam Suraksha for risks between five and fifty crore, with larger and complex risks on Standard Fire and Special Perils or bespoke IAR wordings.
Across the 2024 and 2025 treaty renewals, insurers began endorsing cyber exclusions onto these wordings to mirror their inward treaty terms. In practice a broker now sees three patterns on a fire or engineering schedule. The first is a full cyber exclusion with no carve-back, most common on smaller package business where the insurer does not want to underwrite the cause at all. The second is an LMA5400-style exclusion with the non-malicious fire and explosion write-back, typical on mid-market IAR. The third, still rare, is a negotiated write-back that restores malicious-attack fire and explosion for a named premium, available mainly to large risks with strong operational-technology controls.
Engineering lines are exposed in a distinct way. Machinery Breakdown and Boiler and Pressure Plant policies insure sudden and accidental internal damage, exactly the failure mode a manipulated control system can induce. A cyber exclusion on an MB policy can strip out the very scenario where operational-technology risk and physical breakdown converge. The Boilers Act, 2025 framework tightens inspection duties on pressure plant, but statutory compliance does not restore contractual cover once an exclusion is endorsed. Brokers placing engineering programmes should treat the cyber endorsement as a coverage-defining term, not boilerplate.
Reconciling the two towers at renewal, clause by clause
The practical task for a broker is to line up the affirmative cyber policy and the property policy so that a cyber-triggered physical loss lands cleanly in one tower rather than falling between both. That reconciliation is a wording exercise, and it turns on four checks.
-
Match the trigger definitions. Confirm whether the property endorsement excludes on a cyber act, a cyber incident, or both, and whether it requires malice. Then read the affirmative cyber policy's property-damage and business-interruption sections to see whether they grant what the property tower now excludes. A standalone cyber policy that only covers data and network interruption, with a property-damage exclusion of its own, leaves a genuine orphan.
-
Trace the physical-damage grant. Standalone cyber policies in India historically excluded physical property damage and bodily injury. If the fire policy has now excluded malicious cyber fire, and the cyber policy also excludes physical damage, neither tower pays for a ransomware-induced plant fire. This is the single most common gap on 2026 renewals.
-
Align the business-interruption periods and bases. A cyber-triggered fire can produce both a data-restoration loss (cyber tower) and a gross-profit loss from physical damage (property tower). Confirm the indemnity periods, the material-damage proviso and the waiting periods do not conflict or double-count.
-
Check the reinsurance-driven sublimits. Where an insurer grants back malicious cyber fire, it often does so with an event sublimit and an annual aggregate that reflect what its treaty allows. Document these, because they cap the recovery regardless of the sum insured on the fire schedule.
What the carve-back is doing to fire and machinery-breakdown premiums
The repricing effect is real but uneven, and it is easy to misread as a general hardening. On the base fire and IAR rate, adding a full cyber exclusion with no carve-back is, in isolation, a coverage reduction, and a well-advised buyer should resist paying more for less. Where the number moves is in the carve-back. Restoring malicious-attack fire and explosion, or restoring cyber-triggered Machinery Breakdown, is additional cover that the insurer must reinsure separately or retain net, and it is priced accordingly.
Three forces are pushing the affirmative cyber-into-property premium up. First, the treaty terms themselves: reinsurers granting back malicious cyber physical damage do so at a load, and that load flows to the ceding insurer and then to the buyer. Second, accumulation. A single ransomware strain can hit many insured plants at once, so the physical-damage carve-back behaves like a catastrophe exposure rather than an independent risk, and it is loaded for correlation. Third, the quality of operational-technology controls. Insurers offering the widest carve-backs increasingly require evidence of network segmentation between IT and OT, tested backups, and control-system access governance before they will quote the malicious-attack write-back at all.
For a broker, the negotiating room sits in that third factor. A risk that can document strong OT segregation and incident-response readiness can often secure a meaningful carve-back at a defensible rate, while a risk that cannot will be pushed toward the full exclusion. The premium conversation, in other words, is really a controls conversation. CFOs asking why their fire renewal now carries a separate cyber-fire sublimit and load should be shown the treaty logic behind it: the insurer is not inventing a charge, it is passing through the cost of the reinsurance that lets it grant the cover back at all.
Turning wording intelligence into a renewal advantage
The silent-cyber repricing is fundamentally a wordings problem before it is a pricing one. The exposure a client carries is decided by whether their fire endorsement excludes on a cyber act or a cyber incident, whether malice is required, how the carve-back sublimit is set, and whether the affirmative cyber policy grants what the property policy now takes away. Those answers are buried in clause language that varies from insurer to insurer and from renewal to renewal, and they change quietly as treaty terms update.
This is where searchable policy-wordings intelligence earns its place on a broker's desk. Two insurers can write what looks like the same fire cover yet diverge on the one word that decides a claim: whether the carve-back requires the cyber trigger to be non-malicious, and whether the data element is excluded absolutely. Those differences do not show up in a rate sheet.
Sarvada indexes insurer fire, IAR and engineering wordings and their cyber endorsements so a broker can compare, side by side, how each carrier drafts the cyber exclusion and its fire and explosion carve-out, and can spot the day an insurer switches from a non-malicious to a full exclusion. Instead of re-reading a fifty-page schedule under renewal pressure, the broker queries the exact clause, checks it against the client's affirmative cyber tower, and evidences the gap in writing. If you advise Indian commercial clients on fire or engineering programmes and want to reconcile the two towers clause by clause this renewal season, request access to Sarvada.
