16.3 Cyber, Aviation, and Other Specialty Lines
Key Takeaways
- Cyber policies split into first-party coverage (the insured's own breach-response, business-interruption, and cyber-extortion costs) and third-party liability (claims by others for a data breach or network injury), and almost always carry a separate retention and sublimits.
- Standard CGL and property forms largely exclude cyber and electronic-data losses (ISO endorsements such as CG 21 06 / CG 21 07), which is why a standalone cyber policy is needed.
- Aviation insurance is written on manuscript forms outside ISO, splitting hull coverage (the aircraft itself, often on an agreed-value basis) from liability, with passenger liability frequently shown as a combined single limit or a per-passenger sublimit.
- Aircraft liability is commonly written with split limits such as $1,000,000 per passenger / $5,000,000 per occurrence, or as a single combined limit.
- Other specialty lines include directors and officers (D&O), employment practices liability (EPLI), and cyber-extortion/ransomware coverage, each filling gaps the standard market excludes.
Why Specialty Lines Exist
The standard market - Commercial General Liability (CGL), Commercial Property, and Commercial Auto - deliberately excludes several modern, volatile, or technical exposures. Specialty lines are nonstandard products built to cover what those forms leave out: cyber risk, aircraft, professional and management liability, and similar niche perils. Many are written on manuscript forms (custom, non-ISO wording) and frequently placed through surplus lines when the admitted market will not write them.
Quick Answer: Specialty lines cover risks the standard CGL/property/auto forms exclude, such as cyber breaches, aircraft, and management liability.
Cyber Insurance - First Party Versus Third Party
A cyber liability policy is the prime example. Standard forms exclude it: the ISO CGL excludes most electronic-data and breach losses, reinforced by endorsements such as CG 21 06 (Exclusion - Access or Disclosure of Confidential Information and Data-Related Liability) and CG 21 07. Because of these exclusions, the insured needs a standalone cyber policy, which divides into two halves:
| Side | What It Pays | Examples |
|---|---|---|
| First-party | The insured's own breach costs | Forensics, notification, credit monitoring, cyber business interruption, cyber extortion / ransomware payments |
| Third-party (liability) | Claims by others against the insured | Customer lawsuits over a breach, regulatory fines and defense, media/content injury |
Cyber policies almost always apply a separate retention (a deductible the insured absorbs before coverage responds) and sublimits that cap specific coverages such as extortion below the overall aggregate.
Worked Example - Cyber Retention and Sublimit
A retailer carries a cyber policy with a $5,000,000 aggregate limit, a $50,000 retention, and a $250,000 cyber-extortion sublimit. A ransomware attack triggers a $200,000 ransom payment plus $600,000 in forensics and notification costs. The extortion payment is capped by its $250,000 sublimit, so the full $200,000 is available there. The retailer first absorbs the $50,000 retention, then the insurer pays $200,000 - $50,000 = $150,000 toward the ransom plus the $600,000 in response costs, for $750,000 total - well under the $5,000,000 aggregate.
Aviation Insurance
Aviation insurance is a technical, manuscript market written largely outside ISO. It separates two exposures:
| Coverage | What It Insures | Common Basis |
|---|---|---|
| Hull | The aircraft itself (physical damage) | Often agreed value - a stated amount paid for a total loss, avoiding depreciation disputes |
| Liability | Bodily injury and property damage to others, including passengers | Split limits or a combined single limit |
Agreed value matters because aircraft values are volatile; the insurer and owner fix the hull value at inception. Aviation liability is frequently written with split limits - for example $1,000,000 per passenger / $5,000,000 per occurrence - or as a combined single limit that applies one pooled amount to all bodily injury and property damage in an occurrence.
Worked Example - Split-Limit Aviation Liability
A charter aircraft carries liability limits of $1,000,000 per passenger / $5,000,000 per occurrence. A crash injures four passengers with damages of $1,200,000 each. The per-passenger cap pays $1,000,000 to each (the $200,000 excess per passenger is uninsured), totaling $4,000,000 - within the $5,000,000 per-occurrence ceiling, so the full $4,000,000 is payable.
Other Specialty Lines
- Directors and Officers (D&O) - protects company executives from claims arising out of their management decisions; Side A protects individuals when the company cannot indemnify.
- Employment Practices Liability Insurance (EPLI) - covers claims of wrongful termination, discrimination, and harassment, which the CGL excludes.
- Cyber extortion / ransomware - a first-party cyber coverage, usually sublimited, paying ransom demands and the cost of negotiation.
- Kidnap and ransom (K&R) and media liability - further niche manuscript covers.
Claims-Made Triggers in Specialty Liability
Most specialty management-liability forms - D&O, EPLI, and many cyber policies - are written on a claims-made basis rather than occurrence. A claims-made policy responds to claims first made during the policy period (and reported per the policy terms), regardless of when the wrongful act happened, provided it occurred after the retroactive date. When the insured switches carriers or closes, an Extended Reporting Period (ERP), or tail, can be purchased to report later claims arising from earlier acts. Confusing claims-made with occurrence triggers is a frequent exam error in this segment.
Surplus Lines Placement
Because many of these exposures are too volatile or unusual for admitted insurers, they are often placed through the surplus lines (non-admitted) market. A surplus lines policy is not protected by the state guaranty fund, and the producer must hold a surplus lines license and confirm the risk was rejected by admitted carriers first. Buyers trade that guaranty-fund safety net for access to coverage the standard market declines to write, a tradeoff the exam expects you to recognize.
Common Exam Traps
- First-party versus third-party cyber - first party = the insured's own costs; third party = claims by others.
- Cyber is not covered by the CGL - the ISO CGL excludes data breaches (CG 21 06 / CG 21 07).
- Hull versus liability - hull is the aircraft's physical damage (agreed value); liability covers injury to others.
- Split limits cap each passenger separately - the per-passenger limit can leave large injuries partly uninsured even when the per-occurrence limit is not exhausted.
An insured's cyber policy pays for its own forensic investigation, customer-notification expenses, and a ransomware payment. These costs fall under which part of a cyber policy?
An aircraft liability policy is written with split limits of $1,000,000 per passenger / $5,000,000 per occurrence. Four passengers each suffer $1,200,000 in damages. What is the insurer's total payout?
Cyber Coverage: First-Party vs. Third-Party
Standard CGL and property forms largely exclude cyber and electronic-data losses (ISO endorsements such as CG 21 06 / CG 21 07 strip out access-or-disclosure and electronic-data liability), which is why a standalone cyber policy is needed. Cyber coverage splits into two halves:
| Side | What It Pays |
|---|---|
| First-party | The insured's own costs: breach response, notification, forensics, business interruption, cyber-extortion/ransomware |
| Third-party | Claims by others for a data breach or network injury (liability, regulatory defense) |
Cyber policies almost always carry a separate retention and sublimits for categories like ransomware payments and regulatory fines. A breach that shuts a retailer's systems triggers first-party business interruption; a class action by affected customers triggers third-party liability.
Aviation and Other Specialty Lines
Aviation insurance is written on manuscript forms outside ISO and splits hull coverage (the aircraft itself, often on an agreed-value basis) from liability. Passenger liability is frequently shown as a combined single limit or a per-passenger sublimit - a common notation is $1,000,000 per passenger / $5,000,000 per occurrence, or a single combined limit. Hull coverage may be written for ground-and-flight, ground-only (not in motion), or not-in-motion exposures.
Other specialty lines fill gaps the standard market excludes: Directors & Officers (D&O) for management wrongful acts, Employment Practices Liability (EPLI) for discrimination and harassment, cyber-extortion/ransomware coverage, and environmental/pollution policies. The unifying exam theme is that each specialty line exists because a standard form excludes the exposure - cyber because of the data exclusions, aviation because of the aircraft exclusion in the CGL/auto forms, and D&O/EPLI because the CGL covers only bodily injury and property damage.
A retailer suffers a ransomware attack that halts operations and incurs forensic and notification costs to the business itself. Which part of a cyber policy responds to the retailer's OWN costs?