TRIA has never paid a claim. A cyber terrorism scenario shows what happens when it does | Insurance Business
TRIA has never paid a claim. A cyber terrorism scenario shows what happens when it does
The US Treasury has modelled a hybrid cyber attack on Virginia data centres generating $14.6 billion in insured losses – and 88% of it sits in a coverage category TRIA was not designed to handle
Cyber
The Terrorism Risk Insurance Act has been reauthorized five times since Congress created it in November 2002. It has never paid a claim. That zero-claim record is the program’s most quoted statistic and, in the current threat environment, its most misleading one. A program that has never been stress-tested is not the same as a program that has been tested and held.
Morningstar DBRS’s 25th-anniversary report on terrorism insurance, published September 9, makes the point precisely. The report’s analytical interest is not in what TRIA has done – that ground is well covered – but in what a catastrophic cyber terrorism event would reveal about it.
The scenario the Treasury has already modeled
The US Treasury’s 2026 Report on the Effectiveness of the Terrorism Risk Insurance Program examined a hypothetical hybrid attack: kinetic and cyber, targeting data centers in Virginia, with the cyber effects cascading into cloud operations supported by those centers. The scenario is not speculative threat-modeling from a think tank. It is the Treasury’s own stress test of its own program, published in its own statutory review.
The modeled total insured losses: approximately $14.6 billion. Of that, 88% was cyber-related. The modeled federal payment under TRIP: approximately $4.85 billion. The remainder – roughly $9.75 billion – absorbed by insurers and reinsurers within their deductible and copay layers.
That allocation is the practical problem the report surfaces. TRIA can respond to qualifying cyber terrorism under eligible policies, subject to certification and statutory requirements. But it was not built as a comprehensive catastrophic cyber backstop. The 88% cyber component of the scenario sits in a coverage category that did not exist when Congress wrote the original act, and for which the certification, attribution and policy wording questions remain unresolved.
Three wording problems that do not exist for conventional terrorism
Morningstar DBRS identifies three distinct sources of coverage uncertainty that compound each other in a cyber terrorism scenario and do not apply to a conventional bombing or mass casualty event.
The first is attribution. A physical attack has a perpetrator. Attribution of a cyber attack, particularly one deliberately designed to obscure its origin through intermediate infrastructure, can take months or years. TRIA requires the Treasury Secretary to certify an act of terrorism. That certification process was designed for events where attribution is clear within days. For a sophisticated state-linked cyber operation, it may not be.
The second is the overlap between cybercrime, cyber terrorism and state-sponsored operations. The three are not interchangeable insurance categories. A ransomware attack on hospital systems that disrupts care, causes deaths, and was sponsored by a hostile state intelligence service raises questions about whether the loss falls under cyber coverage, terrorism coverage, acts of war exclusions, or some combination of all three. Those questions have different answers under different policy forms, and different answers again under primary versus reinsurance contracts.
The third is accumulation across policies that were priced independently. The September 11 attacks activated property, aviation, life, workers’ compensation and liability portfolios simultaneously. A destructive attack on shared cloud infrastructure activates cyber, property and contingent business interruption coverages across geographically dispersed policyholders who share a technology dependency but not a location. Geographic diversification, which is the standard tool for managing property catastrophe accumulation, does not address that risk.
How other countries have handled the same problem
What is notable about the international comparison in the Morningstar DBRS report is the timing. The UK’s Pool Re and Spain’s Consorcio de Compensación de Seguros both existed before September 11. They were not crisis responses – they were standing infrastructure built because terrorism was already a recognized systemic risk in those markets.
France created GAREAT and Germany created Extremus in 2002, immediately after the attacks. Australia established its pool in 2003. Each structure combines insurer participation, reinsurance and government support in different proportions, but the common thread is that each was built when the relevant threat was conventional: bombs, mass casualty events, physical infrastructure attacks.
None of those schemes were designed around the specific characteristics of a large-scale cyber terrorism event either. But Pool Re in the UK has explicitly extended its coverage to include cyber terrorism losses where a physical damage trigger is met, giving it at least a working framework for the overlap problem. The US equivalent is a certification process that has never been exercised and a statutory framework that the Treasury’s own modeling shows would leave roughly $9.75 billion of a major cyber terrorism event’s losses sitting outside federal reimbursement.
What the reauthorization debate should actually resolve
The House bill passed in June 2026 extends TRIA to 2034 and raises the certification threshold to $10 million from 2029. The Senate companion bill extends the program seven years without other changes. Neither addresses the cyber terrorism gap directly.
Morningstar DBRS’s view on what a cyber backstop should require is specific: clearly defined covered events and attribution procedures, retained meaningful private risk rather than wholesale government assumption, and a requirement that policyholders maintain adequate cybersecurity standards as a condition of coverage. That third condition is the most practically significant – it creates an underwriting-style requirement at the policy level that gives the program a loss-prevention mechanism conventional terrorism coverage has never needed.
The reauthorization debate is unlikely to resolve any of this before the current program expires in December 2027. But the Treasury’s own scenario modeling has now established that the question is not theoretical. A hybrid attack generating $14.6 billion in insured losses with 88% of it in cyber is a plausible enough scenario that the federal government has already done the arithmetic. The result is a program that works for the risk it was designed for, and has an unresolved gap for the risk that has since emerged around it.
