Stress tests reveal gaps in US cyber terrorism insurance

New analysis suggests the US federal insurance backstop may face structural challenges if a major cyber attack occurs, as existing frameworks were not designed for digital threats.
The Terrorism Risk Insurance Act has maintained a record of zero paid claims since its inception in 2002. This statistic is often cited as evidence of the program's stability, yet recent analysis suggests it may mask significant structural vulnerabilities. A program that has never been tested under actual catastrophic conditions is not equivalent to one that has been verified through stress testing. As the threat landscape shifts toward digital infrastructure, the absence of historical claims data leaves key questions about capacity and coverage unresolved.
According to a 25th-anniversary report by Morningstar DBRS, the analytical focus has shifted from the program’s historical performance to its potential response to a catastrophic cyber event. The report highlights a hypothetical scenario modeled by the US Treasury, which examines the financial impact of a hybrid attack targeting data centers in Virginia. This scenario, included in the Treasury’s own statutory review, serves as a stress test for the federal backstop, revealing how the system might function under extreme digital strain.
Federal exposure in hybrid scenarios
The Treasury’s 2026 effectiveness report modeled a hybrid attack combining kinetic and cyber elements. The scenario estimated total insured losses at approximately $14.6 billion, with 88% of that amount attributable to cyber-related damages. Under the Terrorism Risk Insurance Program, the modeled federal payment would be roughly $4.85 billion. The remaining balance, approximately $9.75 billion, would be absorbed by insurers and reinsurers within their deductible and copayment layers. This allocation highlights that while the federal government plays a role, the private sector would bear a substantial portion of the financial burden.
Uncertainties in attribution and coverage
The report identifies three compounding sources of uncertainty that distinguish cyber terrorism from conventional acts of violence. The primary challenge is attribution. Physical attacks typically have clear perpetrators, whereas sophisticated cyber operations may use intermediate infrastructure to obscure their origin. The certification process required by the Act, which relies on the Treasury Secretary confirming an act of terrorism, was designed for events where attribution is clear within days. In the case of state-linked cyber operations, this determination could take months or years, creating a lag in claims processing.
Additionally, the distinction between cybercrime, cyber terrorism, and state-sponsored operations remains blurred in insurance terms. A ransomware attack on critical infrastructure, if sponsored by a hostile state, raises complex questions about whether the loss falls under cyber coverage, terrorism coverage, or acts of war exclusions. These classifications carry different implications for primary and reinsurance contracts. Furthermore, the risk of accumulation across independently priced policies presents a challenge. Unlike geographic diversification used in property insurance, shared dependency on cloud infrastructure creates correlated risks that standard tools may not effectively mitigate.
International frameworks offer context
A comparative view of international markets reveals a different timeline for addressing terrorism risk. According to the GN geopolitics/terror (en-US) analysis, institutions such as the UK’s Pool Re and Spain’s Consorcio de Compensación de Seguros were established before the September 11 attacks. These were not ad hoc crisis responses but standing infrastructure built because terrorism was already recognized as a systemic risk. In contrast, the US framework has evolved as a reactive mechanism, reauthorized multiple times since 2002 without the benefit of having been tested by a major claim. This difference in timing and foundational design may influence how the US system adapts to emerging digital threats.






