16.3 Cyber, Aviation, and Specialty Lines
Key Takeaways
- Cyber liability splits into first-party breach-response costs (forensics, notification, extortion, downtime) and third-party liability (lawsuits, regulatory fines) that neither CGL nor commercial property is designed to cover
- Cyber underwriting emphasizes security controls — MFA, encryption, backup isolation, patch management, and incident response plans — because a single control gap can drive catastrophic loss frequency
- Aviation hull coverage ranges from broad all-risk to cheaper not-in-motion forms; aviation liability, passenger liability, and non-owned aircraft liability parallel auto liability concepts but with aviation-specific vocabulary
- War risk is a standard aviation exclusion requiring a separate buy-back endorsement; named-pilot and territory/use warranties can void an aviation claim even for an otherwise covered loss
- CGL and business auto forms specifically exclude aircraft; data breach and network exposures route to cyber liability, not crime or property coverage
Every commercial lines producer eventually meets an exposure that doesn't fit neatly into CGL, property, auto, or workers compensation. Data breaches, aircraft ownership, kidnap-and-ransom demands, and warranty obligations all require specialty lines built around a single, narrowly defined exposure. Nevada's national Casualty blueprint expects producers to recognize when a risk needs to be routed to cyber or aviation coverage rather than forced into a package policy that was never designed for it.
Cyber Liability: First-Party and Third-Party Halves
Cyber liability policies (also sold as "cyber risk" or "network security and privacy liability") split into two functional halves, and exam stems usually ask which half applies to a given cost:
| Half | Covers | Example Costs |
|---|---|---|
| First-party (breach response) | The insured's own costs to respond to and recover from an incident | Forensic investigation, breach notification to affected individuals, credit monitoring, crisis PR, data restoration, cyber extortion/ransomware payments, business interruption from network downtime |
| Third-party (liability) | Claims and legal costs from others harmed by the insured's failure to protect data or systems | Lawsuits from customers whose data was breached, regulatory investigations and fines, payment card industry (PCI) assessments, media/content liability |
Worked scenario — ransomware. A Reno logistics company's servers are encrypted by ransomware, halting shipping operations for eight days. First-party cyber coverage responds to the ransom payment (if the insurer approves it), forensic and recovery costs, and business interruption from the downtime. If customer shipment data was also exposed and customers sue, third-party cyber liability responds to that litigation and any required breach notifications — potentially triggered under Nevada's own data breach notification statute (NRS 603A), which requires notifying affected Nevada residents of a breach of personal information within a defined timeframe.
Why CGL and Property Don't Fill the Gap
Standard ISO CGL forms contain electronic-data exclusions and generally do not treat loss of electronic data as "property damage." Commercial property forms typically define covered property as tangible property, excluding data and software except in narrow endorsed circumstances. Neither line was built to fund breach notification costs, regulatory defense, or the reputational and PR spending a real breach requires — which is exactly why cyber liability exists as its own specialty line rather than an endorsement.
Cyber Underwriting Basics
Cyber underwriters focus heavily on security controls rather than traditional loss history alone, because a single control gap (no multifactor authentication, unpatched systems, no offline backups) can drive catastrophic loss frequency across an entire book. Common underwriting questions cover:
- Multifactor authentication (MFA) on remote access and privileged accounts
- Encryption of data at rest and in transit
- Frequency and isolation of backups (ability to restore without paying ransom)
- Patch management and endpoint detection
- Written incident response plan and employee phishing training
- Social engineering / funds-transfer fraud controls (many cyber policies also cover fraudulent wire transfers induced by deception)
Aviation Insurance: Hull and Liability
Aviation risks split similarly into physical damage (hull) and liability, echoing the auto physical damage/liability split but with aviation-specific vocabulary and exposures:
| Coverage | Protects Against | Notes |
|---|---|---|
| Hull — "all risk" | Physical damage to the aircraft whether in flight, taxiing, or parked | Broadest, most expensive hull option |
| Hull — "not in motion" | Physical damage only while the aircraft is parked/stored, not taxiing or flying | Cheaper; excludes damage during any movement under its own power |
| Aircraft liability | Bodily injury and property damage to third parties on the ground or in other aircraft | Parallels CGL/auto liability |
| Passenger liability | Bodily injury to passengers aboard the insured aircraft | Often written with per-passenger sublimits distinct from the liability limit |
| Medical payments | Medical expenses for passengers regardless of fault | Similar function to auto MedPay |
Non-owned aircraft liability protects a business or individual who does not own an aircraft but occasionally rents or borrows one — analogous to non-owned auto liability, and a coverage gap producers must flag for executives who charter or borrow planes.
Aviation-Specific Concepts
Several aviation concepts have no clean auto or CGL parallel:
- War risk exclusion. Standard aviation hull and liability policies exclude losses from war, hijacking, and similar perils; a separate war risk endorsement or standalone policy buys back this coverage, common for aircraft flying into higher-risk regions.
- Admitted liability / voluntary settlement coverage. Some aviation liability policies allow limited payments to injured passengers without a formal finding of legal liability, smoothing goodwill claims after an accident.
- Territory and use restrictions. Aviation policies commonly restrict coverage to a described territory and a stated use (personal, business, or commercial/for-hire); flying outside the described territory or using the aircraft for a prohibited commercial purpose (such as charter flights on a policy written for personal use only) can void coverage for that flight.
- Named-pilot / open-pilot warranties. Coverage may be restricted to specifically named, qualified pilots; an unlisted or under-qualified pilot at the controls during a loss can breach the warranty and defeat the claim.
Worked scenario: A Las Vegas business owner's aviation policy is written for personal, non-commercial use with a named-pilot warranty listing only the owner. The owner lets an employee — not a named pilot — fly clients to a conference for a fee. A hard landing damages the aircraft. Because the flight was both an unauthorized commercial use and flown by an unlisted pilot, the insurer may properly deny the hull claim.
Rounding Out the Specialty Shelf
Cyber and aviation dominate this section of the blueprint, but a handful of other narrowly defined specialty lines appear in national P&C content and deserve quick recognition:
| Line | Core Exposure |
|---|---|
| Kidnap and ransom (K&R) | Ransom payments, negotiator fees, and related costs after an executive or employee is kidnapped or extorted |
| Event cancellation | Lost revenue and costs when a scheduled event is canceled, postponed, or relocated for a covered reason |
| Product warranty / extended service contracts | Contractual obligation to repair or replace a product after the manufacturer's warranty expires — regulated differently from insurance in many states |
| Media/multimedia liability | Defamation, copyright, and IP claims arising from published or broadcast content, often bundled into cyber forms today |
Routing Rule for the Exam
When a fact pattern describes data, networks, or electronic information being compromised, stolen, or held hostage, the answer routes to cyber liability — not CGL, not property, not crime coverage (crime covers employee or third-party theft of money and tangible property, not data breach response). When a fact pattern describes an aircraft — whether hull damage, a passenger injury, or a non-owned plane a business executive borrowed — the answer routes to aviation, never business auto (aircraft are specifically excluded from auto liability and physical damage forms) and never CGL (aircraft liability is a standard CGL exclusion, requiring the dedicated aviation line).
Memory anchors: cyber = first-party breach response + third-party liability, data ≠ CGL property · aviation = hull (all-risk vs. not-in-motion) + liability + passenger/medical, war risk excluded absent buy-back · named-pilot and territory/use warranties can void aviation claims · K&R, event cancellation, and warranty coverage round out the specialty shelf.
A company pays forensic investigators and notifies affected customers after a data breach, then is later sued by those customers. Which coverage specifically handles the resulting lawsuit?
An aviation policy names only the owner as an authorized pilot. An unlisted employee flies the aircraft and it is damaged in a hard landing. What is the most likely outcome?
A hacker steals customer payment card data from a retailer's network. Which policy is designed to respond to notification costs and the resulting third-party lawsuits?