Insurers treat risk assessment and mitigation as a precondition of cover and ask ever more about cyber programmes; economic loss and data rebuilding are generally uninsured, though stand-alone ransomware products exist. Companies should be able to show reasonable care in managing cyber risk. Property cover varies: exclusions such as CL380 or the American Institute cyber exclusion clause, silent cover under scrutiny, or buy-back for extra premium, so check policies in advance and expect insurer questions. Consult the P&I Club on liability: a cyber-caused malfunction does not in itself exclude normal P&I cover, but many cyber losses are not third-party liabilities, and war and terror exclusions may catch state-linked attacks. Standard cyber security clauses for charter parties are available and emphasise sharing incident information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.