Cryptojacking sounds like the kind of attack that should obviously fall under cyber insurance. Someone gets into your system and secretly uses your computers to mine cryptocurrency. Simple enough. But insurance policies rarely work on the word “obvious.”

The Loss Has to Fit the Policy

This is where things get less straightforward. A policy might cover the cost of investigating an incident while treating lost computing resources differently. Another policy could include business interruption protection, but only when a covered event causes the interruption.

When an Exclusion Can Get in the Way

Some policies contain exclusions that can affect a cryptojacking claim. The wording might relate to poor security practices, known vulnerabilities, system failure, or another condition tied to the incident. A separate exclusion can also apply if the claimed loss doesn’t meet the policy’s definition of a covered cyber event.

• An old unpatched system could complicate a claim, particularly if the policy required reasonable security controls.

• Business interruption coverage sounds useful, but the loss still needs to come from a covered event under the wording.

• If your main complaint is a higher electricity bill, coverage isn’t guaranteed. That type of expense needs to fit the policy’s definition of loss.

What Should You Look For?

The trick is to check the actual wording before an incident happens. Look for how the policy defines a cyber event, malware, system damage, business interruption, and covered loss. Then read the exclusions beside those sections.

Honestly, broad coverage language is less reassuring than clear wording. I’d rather have a policy that plainly explains how it treats malware-driven incidents than one filled with impressive-sounding promises.

Cryptojacking itself isn’t necessarily the problem. The real question is what happened, what financial loss followed, and whether the policy connects those losses to a covered event.