Bricking in cyber insurance refers to a device being rendered permanently useless by a cyberattack or a software failure, even though its physical components are undamaged. The name comes from the result: the device becomes as useful as a brick. Whether your policy pays to replace bricked equipment is not automatic. Standard cyber policies often leave bricking in a gray area, and recovery usually depends on specific policy wording, a bricking endorsement, and how the insurer and the courts read the word “damage.”
What a Bricked Device Actually Is
A device is bricked when malware, a flawed update, or a deliberate attack corrupts its firmware or boot software so thoroughly that no troubleshooting can bring it back. The hardware inside still works. The device won’t turn on, won’t boot past an error screen, or sits in an unrecoverable loop. Servers, laptops, point-of-sale terminals, medical equipment, and industrial control systems are all vulnerable.
Two incidents define the category. The 2017 NotPetya attack, disguised as ransomware, actually destroyed data and rendered machines permanently inoperable. Merck reported roughly $1.4 billion in losses. Mondelez International saw 1,700 servers and 24,000 laptops damaged and filed more than $100 million in claims. In July 2024, a faulty sensor configuration update for CrowdStrike’s Falcon security software triggered a logic error that crashed Windows systems worldwide. That one wasn’t malicious, and the distinction matters: most cyber policies treat malicious events differently from accidental system failures. Some carriers offer “system failure” coverage that would respond to a CrowdStrike-type event, but many standard policies do not include it without an endorsement.
Why Standard Cyber Policies Often Don’t Pay
The central fight in most bricking disputes is whether a device that works physically but can’t function due to corrupted software has suffered “direct physical loss or damage.” That phrase appears in most property and many cyber insurance policies.
Insurers generally argue the phrase requires tangible, physical harm: a fried circuit board, a cracked screen, a power surge that melts components. Under that reading, a server with corrupted firmware hasn’t suffered physical loss because, in theory, new firmware could be installed. Policyholders argue the opposite: a device that cannot perform its intended function has suffered a real, measurable loss regardless of what happened to its circuits.
Courts have split. The Ohio Supreme Court held in EMOI Services v. Owners Insurance Company that a ransomware attack on a medical billing company did not constitute direct physical loss because the computer equipment itself was unharmed and software lacks “material existence.” Other courts have found that total loss of functionality can satisfy the physical loss requirement when the device is permanently inoperable. Which state’s law applies to your policy can decide the claim.
Policy language carries just as much weight as case law. Policies that define damage to include “electronic impairment” or “system corruption” offer the broadest path to bricking coverage. Policies that require “physical loss or damage” without further clarification give insurers room to argue intact hardware hasn’t been damaged. Policies that explicitly require “physical alteration” of components are the hardest to recover under for any software-related bricking event.
War and Nation-State Exclusions
Attribution can kill a bricking claim even when the policy language otherwise fits. NotPetya was attributed to Sandworm, a unit of Russia’s military intelligence agency. Insurers covering Merck and Mondelez invoked traditional war exclusions, which bar losses from “hostile or warlike action” by a government or military force.
The argument failed in Merck’s case. A New Jersey appellate court ruled the war exclusion didn’t apply because the attack didn’t involve military action in any traditional sense, and stretching “hostile” to cover a cyberattack on a pharmaceutical company would conflict with the principle that insurance exclusions are construed narrowly. Mondelez settled with Zurich American on confidential terms.
The industry rewrote the clauses. Starting March 31, 2023, Lloyd’s of London required all its insurer groups to include exclusions specifically addressing state-backed cyberattacks. These go beyond traditional war clauses and must, at minimum, exclude losses from state-backed attacks that significantly impair a nation’s ability to function or its security capabilities. The exclusion must also set out how a cyberattack will be attributed to a state, a determination that is often contested. If your business suffers a bricking event later traced to a nation-state actor, this exclusion can eliminate coverage entirely regardless of how the policy defines damage.
What a Bricking Endorsement Adds
Because standard cyber policies leave bricking in a gray area, many insurers now sell a bricking endorsement, sometimes called “computer replacement coverage,” as an add-on. It exists specifically to fill the gap left by ambiguous physical-loss language.
A typical endorsement covers hardware replacement (the cost of buying new servers, laptops, point-of-sale systems, and other devices confirmed to be permanently inoperable), setup and labor (installation of replacement devices, system reconfiguration, and disposal of the bricked equipment), and forensic assessment (the cost of a technical evaluation confirming the device is truly bricked and cannot be restored).
Coverage typically triggers only when devices are confirmed permanently inoperable due to malicious activity. That confirmation usually requires a forensic report documenting the firmware corruption and explaining why restoration isn’t possible. Carriers won’t pay based on an IT team’s say-so.
Read the exclusions as carefully as the grant of coverage. Devices that fail due to normal wear, manufacturing defects, or unpatched known vulnerabilities are generally excluded. If a company knew about a critical security flaw and didn’t apply available patches before the attack, the insurer has grounds to deny the claim. Design defect exclusions can be invoked when bricking results from a vulnerability in the device’s original software architecture rather than from malicious code. Some insurers also classify firmware corruption as a maintenance failure rather than an insurable loss, arguing the company should have kept systems updated.
Sublimits matter too. Endorsements commonly cap the total payout for a single bricking event or limit reimbursement by device type, so a company with thousands of bricked machines may find coverage falls well short of actual replacement costs.
How Your Payout Gets Calculated
Even an approved claim can disappoint. Two valuation methods dominate cyber policies, and the gap between them is wide for older equipment.
Replacement cost coverage pays what it costs to buy equivalent new equipment. If bricked servers would cost $50,000 to replace with comparable current models, that’s what the policy pays, minus the deductible. Actual cash value coverage factors in depreciation. A three-year-old server that originally cost $15,000 might have an actual cash value of $5,000 after age and wear, even though replacing it with a current equivalent costs $15,000 or more.
This hits businesses running older infrastructure hardest, which is exactly the equipment most vulnerable to bricking attacks. Outdated systems with unpatched firmware are prime targets, and actual cash value coverage on heavily depreciated hardware may cover only a fraction of what the business needs to get back online.
Watch the sublimit schedule, not just the headline coverage amount. Some policies impose lower sublimits for data restoration and software recovery than for hardware replacement. A policy might cover $5 million in hardware replacement but only $500,000 in data restoration, which forces the policyholder to absorb a disproportionate share of a combined loss.
What To Check in Your Policy Before a Loss
A few questions, asked before anything goes wrong, decide whether a bricking claim gets paid in full, partially, or not at all:
- How does the policy define “damage”? Look for “electronic impairment” or “system corruption” language. Policies that require “physical alteration” are the weakest for bricking.
- Is there a bricking or computer replacement endorsement, and what does it exclude?
- Does the policy use replacement cost or actual cash value for destroyed hardware?
- What are the sublimits for hardware replacement, data restoration, and forensic costs, and do they match the scale of your deployment?
- Is there a system failure endorsement that would respond to a non-malicious event like a faulty vendor update?
- How does the nation-state or war exclusion read, and what attribution standard does it use?
- Does the policy exclude losses tied to unpatched known vulnerabilities, and what is your patching discipline?
Disclosure Obligations for Public Companies
If the policyholder is a public company, the insurance claim is only one piece of the response. Under rules the SEC adopted in July 2023, public companies must disclose material cybersecurity incidents under Item 1.05 of Form 8-K within four business days of determining the incident is material. The materiality assessment is not limited to financial impact. Companies must also consider harm to reputation, customer and vendor relationships, competitiveness, and the possibility of litigation or regulatory investigations. The SEC has said companies should consider “qualitative factors alongside quantitative factors.” A large-scale bricking event that takes down critical infrastructure or triggers significant replacement costs can easily clear that threshold.
Tax Treatment of the Payout
Insurance proceeds for bricked business equipment can produce a taxable gain if the payout exceeds the equipment’s adjusted tax basis, meaning the original cost minus accumulated depreciation. A fully depreciated server with a $0 basis that generates a $10,000 insurance payout creates $10,000 in recognized gain.
Section 1033 of the Internal Revenue Code allows that gain to be deferred. If the proceeds are reinvested in similar replacement property within two years after the close of the tax year in which the gain is first realized, the gain is not recognized to the extent the replacement cost equals or exceeds the payout. The replacement property must be “similar or related in service or use” to the destroyed equipment. Replacing bricked servers with comparable servers qualifies; using the proceeds to shift to an entirely different technology platform can jeopardize the deferral. Involuntary conversions of business assets are reported on IRS Form 4797.