Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesTreasury has asked whether the federal terrorism-insurance program should do more for cyber losses tied to qualifying terrorist acts. Its March 25, 2026 request for comments did not expand coverage or change existing policies. It opened a policy review as the program approaches its scheduled December 31, 2027 expiration.
What Treasury asked—and what it did not decide
In a March 25, 2026 notice, the U.S. Treasury Department sought comments and data for its review of the Terrorism Risk Insurance Program (TRIP). It asked stakeholders to address cyber-related losses that may fall within the program, losses that may remain outside it, and whether changes could encourage insurance coverage for cyber losses arising from qualifying terrorist acts. Read the Federal Register notice.
Treasury asked questions; it did not endorse a particular design. The reported public-comment deadline was May 8, 2026. The notice itself did not create coverage, override exclusions, or change a policyholder’s contract.
Treasury’s official TRIP reports and resources page lists a June 2026 report on the program’s effectiveness. That report is part of the policy record, not a law change. The consequential decisions about the program’s future remain with Congress and the administration of the existing statute.
Recommended Free Tools
What TRIA and TRIP do
The Terrorism Risk Insurance Act of 2002 (TRIA) established a federal backstop for certain insured losses from a certified act of terrorism. The Terrorism Risk Insurance Program (TRIP) is the Treasury-administered program under that law. It is a public-private risk-sharing arrangement, not a general federal cyber-insurance policy: participating insurers must meet statutory requirements, and an event must qualify before the federal share can apply. Treasury provides background on TRIA and the terrorism insurance program.
TRIA requires insurers to make terrorism coverage available in specified commercial property-and-casualty lines. Cyber coverage written within an eligible line may potentially fall within TRIP, but that possibility does not make every cyber policy or cyber loss eligible. Treasury codified its position on qualifying cyber coverage in eligible lines in 2021; its 2025 small-insurer study reiterates that the statutory conditions still apply.
When a cyber loss might qualify
There are three distinct questions. A policyholder, broker or insurer needs to consider all three; a “yes” to one does not settle the others.
- Is the cyber coverage written in a TRIP-eligible insurance line? Eligibility depends on the type and structure of the insurance, not simply on the fact that a policy is called cyber insurance.
- Does the event meet TRIA’s definition of an act of terrorism? A severe attack, a large loss or a suspected government connection does not by itself satisfy the statutory standard.
- Has the Treasury secretary certified the event? Certification is a formal determination, not something established just because a government, media outlet or insurer describes an incident as state-sponsored or terrorism.
Treasury says the secretary may not certify an act of terrorism unless aggregate commercial property-and-casualty insurance losses exceed $5 million. That is an event-level threshold for certification, not a promise of payment to any individual insured. See Treasury’s federal-share claim process.
Even if the event and insurance line meet program requirements, the policy must cover the specific loss. Policy wording, limits, deductibles and exclusions remain important. A federal backstop does not automatically erase cyberwar, infrastructure-outage, sanctions or other exclusions.
Why catastrophic cyber risk does not fit neatly
The central gap is between a catastrophic cyber event and a certifiable act of terrorism. A cyberattack can disrupt many businesses, cause substantial economic damage or affect critical infrastructure without meeting TRIA’s certification standard. The Government Accountability Office (GAO) warned that even catastrophic cyberattacks may fall outside TRIP if they cannot be certified under those standards. Its report also found limits in both private cyber insurance and TRIP for potentially systemic attacks. Read GAO’s cyber-insurance report.
- Attribution may be uncertain. Public attribution to a nation-state is not the same as Treasury certification under TRIA.
- Systemic losses can accumulate across policyholders. One campaign or outage may affect many firms, sectors, insurers and jurisdictions at once, making aggregate exposure difficult to model and allocate.
- Policy exclusions can leave gaps. Insurers have limited exposure to catastrophic scenarios through exclusions and other restrictions. Treasury’s 2024 effectiveness report described cyber-market responses to ransomware losses, including higher pricing, stronger underwriting and more restrictive coverage for catastrophic events. See Treasury’s 2024 report.
- Cyber incidents do not all have the same purpose. Ransomware, espionage, ordinary cybercrime, cyberwar and terrorism are not interchangeable categories under the law or under an insurance contract.
Labels alone do not trigger TRIP. A ransomware campaign affecting many companies, a major infrastructure outage, a multibillion-dollar cyber loss, or an attack described as state-linked is not automatically a certified act of terrorism. Cyber-physical damage may affect the analysis, but physical consequences alone do not guarantee certification.
What policy changes Treasury put on the table
The March notice asked for views on existing cyber-related terrorism losses, losses outside TRIP, eligible insurance lines, insurer deductibles, the federal share of losses, reinsurance and capital-markets capacity, and whether changes should be made as part of TRIA reauthorization. Those are questions for analysis, not decisions already made.
Clarify how existing TRIP rules apply
Treasury or Congress could clarify when cyber policies written in eligible lines may qualify, how policy exclusions interact with the program, or what information is relevant to certification. This would preserve the existing framework, but would not reach incidents that fail the terrorism test.
Expand eligible insurance lines
Congress could modify the lines covered by TRIP so the program better fits cyber coverage purchased through other commercial insurance structures. That could make the backstop relevant to more policies, while increasing potential federal exposure and administrative complexity.
Change insurer deductibles or the federal share
Treasury specifically asked about the insurer deductible and the federal percentage of losses. A more generous federal share could make insurers more willing to offer capacity or higher limits, but it could also move more risk to taxpayers and weaken incentives to price and manage exposure. Neither change guarantees lower premiums.
Create a separate catastrophic-cyber backstop
A new program could address defined catastrophic cyber incidents even when they are not acts of terrorism. It would need a clear event definition, rules for uncertain attribution and a way to finance losses. It would also have to specify how it interacts with private policies and exclusions.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Condition federal assistance on cybersecurity controls
One option identified in GAO’s analysis of TRIA reauthorization is to link federal assistance for cyber-related losses to cybersecurity requirements. Such conditions could encourage baseline security, but might burden smaller organizations, become outdated or prompt disputes over compliance.
Use reinsurance or capital markets
Reinsurers and investors could share risk beyond primary insurers and the federal government. Treasury asked about the availability of those sources of capacity. Their participation would not, by itself, resolve questions about which events count, how losses are aggregated or how uncertain attribution is handled.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Who could bear the costs and benefit?
Changes to TRIP would affect more than cyber insurers. Commercial property insurers, reinsurers, brokers, businesses, critical-infrastructure operators, public entities and taxpayers could all have a stake. The details determine whether a change mainly increases available capacity, transfers more loss to the government, or changes the security and pricing incentives facing policyholders.
- Businesses and other policyholders could gain access to broader coverage or higher limits, but a federal backstop would not necessarily lower premiums. Availability and affordability are separate outcomes.
- Insurers could have more protection against qualifying losses, potentially supporting their willingness to offer coverage. The effect would depend on the event definition, insurer retention and federal share.
- Reinsurers and capital-market investors could provide additional capacity, though correlated losses and uncertain event attribution may make the risk difficult to price.
- The federal government and taxpayers could assume more exposure if the program’s coverage or share expands. Congress would have to weigh that public risk against the value of keeping commercial coverage available.
Key design questions include who determines attribution and when, whether claims can be paid before attribution is conclusive, how simultaneous losses are aggregated, whether assistance is limited to U.S. losses, how existing exclusions interact with a backstop, and whether small businesses can meet any required security standards. The treatment of a U.S. company’s losses abroad, for example, cannot be assumed without the eventual program rules and policy wording.
Best Value
What businesses should check now
The Treasury proceeding does not change current insurance contracts. Organizations assessing a cyber policy should review the actual wording with their broker, insurer or legal adviser rather than assume TRIP will respond to a severe event.
- Identify which policy and insurance line would cover the loss.
- Check cyberwar, terrorism, infrastructure-outage, sanctions and contingent-business-interruption provisions, including how the clauses interact.
- Confirm limits, retentions, aggregation terms and whether the policy addresses widespread events affecting multiple insureds.
- Ask how the policy treats losses when attribution is unresolved or an event is not certified under TRIA.
- For critical operations, consider how an outage or supplier incident could affect coverage even if the organization itself was not directly attacked.
Why December 31, 2027 matters
TRIA is currently scheduled to expire on December 31, 2027, unless Congress reauthorizes it. Treasury’s 2026 notice invited comments on reauthorization and possible program changes, making the review part of a legislative window—not evidence that a cyber expansion will occur.
Congress could reauthorize TRIA without changing cyber treatment, clarify eligibility, modify loss-sharing, create a separate catastrophic-cyber mechanism, attach cybersecurity conditions, or leave the issue to private insurance and other federal programs. A broad new federal cyber backstop would generally require congressional action; Treasury’s comment process alone cannot create one.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




