16.3 Cyber, Aviation, and Other Specialty Lines

Key Takeaways

  • Cyber policies split into first-party coverage (breach response, business interruption, ransomware, data restoration) and third-party liability (privacy, regulatory, network security); they are almost always claims-made with sublimits
  • Aviation insurance separates agreed-value hull coverage from aircraft liability, the latter often written on a split limit with a per-passenger cap
  • When limits conflict, always apply the most specific (smallest applicable) sublimit first - a per-passenger or per-peril sublimit overrides the broader occurrence or aggregate limit
  • Specialty lines include E&O, D&O (Side A/B/C), EPLI, kidnap & ransom, Difference in Conditions, and builders risk, each with a distinct coverage trigger
  • Claims-made forms (cyber, E&O, D&O, EPLI) respond to claims first made during the period subject to a retroactive date and may offer an Extended Reporting Period tail; occurrence forms respond to when injury or damage happened
Last updated: June 2026

Cyber Liability Insurance

General liability and commercial property forms were never designed for data breaches, ransomware, or network interruption. The ISO Commercial General Liability form's electronic data exclusion and the Coverage B definition of personal/advertising injury leave large data-breach gaps, so cyber became a standalone line. Cyber policies split into two halves:

  • First-party coverage - the insured's own losses: breach-response/forensics costs, notification expenses, credit monitoring, business interruption from a network outage, cyber-extortion (ransomware) payments, and data restoration.
  • Third-party (liability) coverage - claims by others: privacy liability, regulatory defense and fines where insurable, and media/network-security liability.

Cyber forms are almost universally claims-made, often with a retroactive date that excludes prior breaches, and use a per-claim and aggregate limit structure with sublimits (e.g., a $1,000,000 policy with a $250,000 ransomware sublimit). Watch for the failure-to-maintain-security-standards condition and social-engineering/funds-transfer sublimits, which are frequent exam and real-world dispute points.

Aviation Insurance

Aviation is its own specialty market because the aircraft hull values, catastrophic liability exposure, and federal regulation fall outside standard auto/property forms. Two core components:

  • Hull coverage - physical damage to the aircraft, written on an agreed value basis. Sub-forms include in-motion, not-in-motion, and in-flight hull coverage, each with different rates because most losses happen in flight.
  • Aircraft liability - bodily injury and property damage to others, often split into passenger liability and public (non-passenger) liability.

Liability limits are frequently quoted as a split limit with a per-passenger cap.

Worked example - split limit with per-passenger cap. A policy reads $1,000,000 each occurrence, $100,000 per passenger, carrying four passengers. A crash injures all four with proven damages of $150,000 each ($600,000 total).

  1. Each passenger's recovery is capped at the $100,000 per-passenger sublimit.
  2. Four passengers x $100,000 = $400,000.
  3. That $400,000 is within the $1,000,000 each-occurrence limit, so the occurrence limit is not the binding constraint.
  4. Insurer pays $400,000; each passenger's uninsured balance is $50,000.

The trap: students apply the $1,000,000 occurrence limit and ignore the more restrictive per-passenger cap. Always apply the most specific (smallest applicable) limit first.

Other Specialty Lines and Their Triggers

The national exam expects recognition of several niche lines and what each one is designed to cover:

LineDesigned to coverKey feature
Professional liability (E&O)Financial loss from negligent professional servicesClaims-made; pure economic loss, no bodily injury needed
D&O liabilityWrongful acts of directors/officersSide A/B/C structure; entity vs. individual coverage
EPLIWrongful termination, discrimination, harassmentOften a CGL/cyber companion form
Employment / kidnap & ransomExtortion, ransom, crisis responseConfidentiality condition voids if disclosed
Difference in Conditions (DIC)Fills gaps - flood/quake on a named-peril property programWraps around primary property
Builders riskProperty under constructionISO inland-marine; covers materials at site/in transit

Occurrence vs. claims-made recap (critical across specialty lines). An occurrence form covers injury/damage that happens during the policy period regardless of when the claim is filed. A claims-made form covers claims first made during the policy period (subject to the retroactive date). Cyber, E&O, D&O, and EPLI are almost always claims-made and may offer an Extended Reporting Period (ERP / tail) to cover late claims after cancellation. Aviation hull is property-based; aviation liability is typically occurrence.

Routing Specialty Exposures to the Right Policy

Specialty lines fill gaps that standard property/casualty forms exclude. Cyber liability covers first-party costs (breach response, notification, data restoration, business interruption from a cyber event) and third-party liability for failing to protect data — exposures the CGL's "tangible property" definition and data exclusions leave uncovered. Aviation insures aircraft hull and liability, which the auto and CGL forms exclude. Other specialty markets address weather, event cancellation, kidnap and ransom, and political risk.

ExposureSpecialty Policy
Data breach, ransomware, network failureCyber liability
Aircraft physical damage and liabilityAviation (hull and liability)
Outdoor event rained outEvent cancellation / weather
Executive abduction abroadKidnap and ransom
Pollution cleanup and third-party harmEnvironmental / pollution liability

The recurring exam point is that the CGL excludes auto, aircraft, watercraft, pollution, professional services, and (largely) data, so each of those exposures must be insured under its own specialty form. Cyber is the modern growth line precisely because intangible data losses fall outside traditional property-damage definitions.

First-Party vs. Third-Party Cyber and the Silent-Cyber Problem

Cyber policies split into first-party coverages (the insured's own breach-response costs: forensics, customer notification, credit monitoring, data restoration, cyber extortion/ransomware payments, and business interruption from a network outage) and third-party liability (claims by customers or regulators for failing to protect data, plus regulatory fines where insurable).

Standard property and CGL forms increasingly add cyber exclusions to eliminate so-called "silent cyber" — unintended coverage for cyber events under policies never priced for them — which pushes the exposure onto dedicated cyber forms. A worked routing: ransomware locks a retailer's systems for a week, triggering extortion costs, data-restoration costs, and lost income, then customers sue over exposed card data. The first-party cyber coverages pay the response and business-interruption costs; the third-party cyber liability defends and indemnifies the customer suits.

The CGL would deny because data is not "tangible property" and a cyber exclusion applies. The exam rewards routing intangible-data losses to cyber rather than property or general liability.

Test Your Knowledge

A cyber policy carries a $1,000,000 aggregate limit with a $250,000 ransomware sublimit. A ransomware event causes a $400,000 extortion payment plus $300,000 in business-interruption loss (no separate BI sublimit). How much does the policy pay before the deductible?

A
B
C
D
Test Your Knowledge

An aircraft liability policy reads '$1,000,000 each occurrence, $100,000 per passenger.' Four passengers each prove $150,000 in damages. What does the insurer pay?

A
B
C
D
Test Your Knowledge

Which statement best distinguishes claims-made from occurrence coverage on specialty lines like E&O and D&O?

A
B
C
D