Summary

  • Cyber insurance can respond to some losses caused by a route hijack, especially forensic expense, extra cost and business interruption, but only if the event fits the policy's definitions of computer system, security failure, interruption and covered loss. The word “cyber” on the schedule does not insure every failure involving the Internet.
  • A routing event, a registry error and a dispute over number-resource rights are distinct perils. The first changes propagated reachability; the second changes or disables authoritative registration and related services; the third contests entitlement between parties. They require BGP evidence, registry evidence and transactional or legal evidence respectively.
  • Standard specimen wordings expose a coverage gap. Business-interruption clauses often require unavailability of an insured or covered computer system caused directly by listed events and lasting beyond a waiting period. A global routing system or RIR service may not fit neatly within a policyholder's own system or a named supplier definition.
  • Restoring the market value of an IPv4 block is not the same as restoring data. Some specimen policies expressly exclude the economic or market value of data from recovery costs. A clean route and corrected registry record can restore operations while leaving a permanent value discount, legal bill or lost sale outside ordinary cyber cover.
  • Number-resource insurance should therefore be modular: a routing-interruption endorsement, a registry-integrity or dependent-service endorsement, and, if the market wants it, separately underwritten rights-defence or agreed-value cover. Combining them under one vague “IP hijack” phrase invites disputes about cause and remedy.
  • Claims must preserve synchronized evidence before the network converges: route-collector observations, ROA state, router and upstream logs, registry tickets, authenticated account history, RDAP changes, contracts, corporate succession, cash-flow records and a counterfactual loss calculation. No single screenshot proves both hijack and ownership.
  • The Number Resource Society approach can make the risk insurable by giving it a defined inventory, control standard and evidence protocol. It cannot guarantee coverage, create title or supply a global loss frequency. Better governance reduces uncertainty; the actual policy wording, schedule, endorsements and governing law decide the claim.

The question is not whether the addresses were stolen

The language of theft is irresistible. Traffic intended for an address block appears to move towards an unauthorized network. Customers cannot reach the legitimate service. Monitoring calls the event a hijack. Executives ask whether a capital asset has been stolen and whether the cyber insurer will pay.

The first answer is that the event may be severe without being a transfer of the underlying registration position. BGP distributes claims about how to reach prefixes. A false or mistaken origin can attract some routes while the RIR record remains unchanged and the legitimate holder retains account control. When the false announcement is withdrawn and filters converge, traffic can return without a registry transfer.

The second answer is that a registry compromise can be serious without looking like a classic route hijack. An attacker may alter contacts, obtain account access, change a Route Origin Authorization or initiate an unauthorized transfer process. The holder's routers may continue to announce normally for a time. The decisive event occurs in the authority and service layer rather than in the first observed path.

The third answer is that a rights dispute may involve no computer intrusion. A seller and buyer may disagree about closing; affiliates may contest which company controls a legacy block; a creditor may assert a security interest; a registry may place a request on hold because status is disputed. The network can remain reachable while the economic asset becomes illiquid.

Insurance responds to defined causes and defined loss, not to the emotional force of “stolen”. A policy may cover income lost when a covered system is unavailable after a security failure. It may cover incident-response expenses. It may exclude contractual liability, intellectual-property disputes, property damage or the market value of data. It may require a named dependent provider. It may apply a waiting period longer than the most visible phase of a routing event.

The productive question is therefore: which control surface failed, what event caused the failure, which insured interest was damaged, what measurable loss followed, and which insuring clause and exclusion govern it? Unless the policy is written around those questions, the holder discovers its real coverage only during a contested claim.

Three perils sit behind one alarming headline

An insurer should begin by splitting the scenario into three peril classes.

Routing integrity risk is the risk that unauthorized, accidental or policy-violating route information changes how other networks reach the insured prefix. The mechanism can be a false origin, a more-specific announcement, a route leak or another manipulation. The immediate harm is traffic diversion, denial, interception risk, latency, instability or degradation. Evidence sits in BGP updates, route collectors, routers, upstream records and routing-security state.

Registry integrity risk is the risk that the authoritative administrative position or services associated with a number resource are changed, disabled or made inaccessible without proper authority, or changed incorrectly by an authorized institution. The mechanism can be account compromise, fraudulent documentation, human error, a failed authentication process, a mistaken transfer, a wrong organisation association, or disruption of RPKI and reverse-DNS administration. Evidence sits in authenticated account logs, tickets, signed documents, registry records, service timestamps and credential history.

Rights and transaction risk is the risk that parties dispute who may use, control, pledge or transfer the recognised position. The mechanism can be defective acquisition documents, corporate succession, breach of contract, insolvency, competing security interests, sanctions or unresolved legacy history. Evidence sits in contracts, invoices, board authority, corporate filings, court orders, registry agreements and the transfer process. A network log can show use but cannot settle all legal entitlement.

The three can interact. An attacker may compromise a registry account, create or delete routing authorization and then announce the prefix. A seller may continue routing after a disputed sale. A holder may call an accidental upstream leak a hijack while an insurer investigates whether any insured system suffered a security failure. Interaction does not erase distinction.

It is useful to add a fourth category: reputation and dependency risk. A hijack can cause spam, fraud or abusive traffic to be attributed to the addresses. Even after routing is corrected, blocklists, fraud systems, geolocation and customer allowlists may remain wrong. The holder retains the block but loses part of its productive acceptance. This is often the long tail of the event, and it may not fit a policy's period of restoration.

Each peril has a different remedy. Routing incidents need withdrawal, filtering, correct authorization and propagation. Registry incidents need account containment, authenticated correction and service restoration. Rights disputes need agreement, adjudication or a recognized transfer. Reputation damage needs third-party remediation. Paying for one remedy cannot be presumed to cure the others.

A route hijack is an availability event with security consequences

NIST Special Publication 1800-14 defines a route prefix hijack as an autonomous system accidentally or maliciously originating a BGP update for a prefix it is not authorized to originate. NIST identifies consequences including denial of service, unwanted traffic detours, misdelivery and serious performance degradation. That is a strong starting point for insurance because it describes an event and harm without claiming that registry title changed.

BGP is distributed. The holder does not own or operate every router that receives an announcement. Each network applies its own path selection and policy. A more-specific unauthorized route may attract traffic from many places; an equal-length false origin may affect a different set. Filtering and Route Origin Validation are not uniform. The event can therefore be partial and geographically uneven.

Partiality complicates business interruption. A website may remain available to the policyholder's monitoring location while customers behind affected networks fail. An API may accept some calls and time out others. A payment service may continue at reduced capacity. A policy requiring “total” unavailability could produce a different argument from one covering partial interruption, slowdown or degradation.

Duration is also slippery. The hostile route may be visible for twenty minutes, while caches, sessions, DNS, fraud controls and customer confidence take longer to normalize. A waiting period can eliminate the short route event even though response costs and downstream losses continue. Conversely, a policy that begins the indemnity period at discovery may need a clear method for losses that started before the holder saw the anomaly.

Security causation is not automatic. An unauthorized origin can result from malicious action, accidental misconfiguration, stale customer authorization or a disputed commercial relationship. A policy limited to malicious acts may treat them differently. A broader system-failure or human-error extension may help, but only if the relevant system and actor fit its definition.

RPKI improves the evidence and defence but does not make the route self-enforcing. A ROA expresses which origin AS is authorized for covered prefixes under RFC 9582. Networks using Route Origin Validation can classify conflicting announcements, but local routing policy determines the effect. A valid ROA is evidence of origin authorization; it is not proof of business interruption, attacker identity, market-value loss or legal ownership.

For insurance, a route hijack should be drafted as a measurable integrity and availability peril. Treating it as theft of the number itself creates a proof burden the routing evidence cannot satisfy.

The ordinary cyber policy starts with the insured system

Public specimen policies do not tell us what every buyer has purchased. They do show the drafting problem.

Allianz UK's current Cyber Select wording provides business-interruption cover for loss directly resulting from total or partial unavailability of the company's computer system, caused by a defined event and exceeding a waiting period. Its basic business-interruption event is a cyber attack in systems under the insured's direct operational control; extensions address human error and technical failure in those systems.

Chubb Australia's Cyber Enterprise Risk Management Version 2.2 specimen defines a business-interruption incident through inability to access, disruption or disturbance to a covered or shared computer system caused directly by listed events, including malicious acts, unauthorized use, human error, network-security failure and programming error. Its covered-system definition includes systems owned, leased or operated by the insured and systems operated solely for its benefit by a contracted provider.

RSA's Cyber Protection wording likewise ties cyber business interruption to unavailability of the insured's computer system and offers contingent interruption for named or unnamed suppliers when purchased. It calculates loss through gross profit or gross revenue and increased cost, subject to waiting period and schedule.

These examples contain useful cover. They also show why an IPv4 holder should not rely on implication. Is an unauthorized announcement by a foreign autonomous system an event “in” the insured's computer system? Is the global inter-domain routing system a shared computer system? Does an RIR operate a system solely for the holder's benefit, or for a regional community? Is an upstream a named supplier? Is degradation enough, or must the insured system be unavailable?

The answers depend on the wording and facts. A holder's own edge routers may remain healthy while incoming traffic is diverted elsewhere. The insured application may be ready but unreachable from affected networks. If the trigger focuses on compromise of owned hardware, the physical location of the cause becomes contentious. If it focuses on loss of reachability to scheduled prefixes caused by unauthorized route propagation, the policy can address the actual peril.

An endorsement should close that semantic distance before inception, not ask a claims adjuster to reinterpret “computer system” after an outage.

Registry services do not fit neatly into supplier boxes

An RIR provides registry and related services within a policy and contractual framework. It is not simply a cloud vendor hired to operate one customer's application.

ARIN's Registration Services Agreement describes services that include registry entries, reverse name service, RPKI, maintenance of records and administration of address space. Its relationship with the holder is directly relevant to control of those services. APNIC's transfer policy makes current registered-holder status and the absence of a resource-status dispute conditions of transfer. These primary documents illustrate institutional authority; they do not make the registries guarantors of every routing or commercial result.

For cyber insurance, the classification question is difficult. A contingent business-interruption clause may cover a named supplier's computer-system outage. A registry mistake might not involve outage of the registry's system at all. The system can function exactly as designed while a record is changed on fraudulent evidence or assigned to the wrong account. The harmful output is incorrect authority, not server unavailability.

Account compromise presents another boundary. If the policyholder's credentials are phished and used in an RIR portal, the security failure may begin on an insured email system or identity account. If an attacker compromises the registry directly, the event occurs at the provider. If a staff member processes an authentic but mistaken instruction, the event may be human error without unauthorized access. The same visible record can result from different insured causes.

The effect also differs from ordinary supplier downtime. A two-hour portal outage may cause no loss if no change is needed. A two-minute unauthorized transfer can create months of remediation. Measuring only service availability misses integrity.

A registry endorsement should therefore define a “registry integrity event” in functional terms: unauthorized or erroneous creation, deletion, alteration, transfer, suspension or denial of access affecting a scheduled number-resource record or related authorization, by or through a scheduled RIR, NIR or approved registry service. It should specify whether malicious acts, insured error, provider error and fraudulent documents are covered.

The endorsement must preserve institutional limits. Insurance cannot order an RIR to recognise a claimant, bypass policy or issue a ROA. It can pay covered response cost, business interruption and perhaps agreed remediation expense while the proper process runs. The registry remains the evidence source and decision-maker within its remit; the insurer remains the payer only within its contract.

A rights dispute is closer to title risk than network security

Suppose a company buys a /16, pays the seller and announces it successfully. Later, a former affiliate alleges the seller lacked authority. The registry freezes a transfer request. No credential was stolen, no system failed and no route was unauthorized under the operating arrangement. Yet the buyer cannot sell or finance the block as expected.

That is not the same peril as a hijack. The loss may arise from warranties, corporate authority, contract breach, creditor priority or a court decision. Cyber forensics may contribute little. The decisive evidence is transactional.

Ordinary cyber wording can exclude or limit precisely these disputes. The Allianz specimen contains a contractual-liability exclusion subject to stated exceptions and an exclusion concerning intellectual-property and licence disputes, while its business-interruption definition excludes some losses from suspension or cancellation of contracts and licences. The Chubb specimen excludes certain intellectual-property disputes and says data-recovery costs do not include the economic or market value of data. These clauses do not decide any hypothetical IPv4 claim; they demonstrate why “intangible asset” is not automatically “covered cyber property”.

Number resources also resist familiar title-insurance assumptions. RIR agreements and regional policies define registration and service rights in different language. ARIN's current agreement identifies a bundle of specified rights within its database and under policy. APNIC says the source no longer has rights to transferred resources after completion and the recipient becomes registered. A court or contract can address interests outside the registry relationship, but the insurer must know what interest it is scheduling.

If the market wants rights cover, it should be separately underwritten. The proposal might cover defence costs for an unknown third-party challenge, loss caused by a final adverse determination, or failure of specified transfer representations. It would need a schedule of exact prefixes, chain-of-control diligence, named agreements, known-dispute exclusion, valuation basis, choice of law, cooperation duties and subrogation rights against sellers or advisers.

That product would resemble specialty title, representations-and-warranties or transactional-risk insurance more than ordinary network business interruption. It could be valuable. Calling it cyber cover without separate terms would obscure both underwriting and policyholder expectations.

Rights risk also has a moral-hazard problem. Insurance should not reward a buyer for ignoring an obvious chain defect or a seller for transferring while a known claimant entities. Detailed diligence is not bureaucracy added by insurers; it is the evidence that makes an uncertain intangible interest insurable.

Business interruption protects cash flow, not the abstract asset

The strongest ordinary coverage case after a route hijack is often not for the market value of the block. It is for income lost and extra expense incurred while the business cannot use it.

Specimen policies typically define the financial measure. Chubb's Australian wording calculates business-interruption loss by comparing expected and actual pre-tax net profit, subject to waiting period and adjustment provisions. RSA's wording uses gross profit or gross revenue and reasonable increased cost of working. Allianz uses projected and actual net operating profit with relevant trends and business developments. The schedule, retention, sublimit and indemnity period remain decisive.

An IPv4 claim needs a counterfactual tied to affected services. The policyholder should identify which customers, regions, applications or transactions were unreachable; when the effect began; when it ended; what revenue would probably have occurred; what costs were saved; and what extra expenditure reduced the loss. A fall in all company revenue during the incident window is not automatically attributable to the route.

Routing data and finance data operate on different clocks. BGP collectors can show when selected observers received an unauthorized announcement. Application logs can show request failure. Customer-support records can show affected users. Billing and transaction data can show economic impact. The claim should align them rather than selecting the longest interval from each.

Partial interruption requires a defensible denominator. If 30 of 200 monitoring locations failed, that does not prove that 15 per cent of revenue was lost. The locations may not represent customer traffic. If one payment region failed, the revenue effect depends on actual demand. No global conversion rate can be supported by the available public evidence.

Extra expense may be more provable: emergency transit, DDoS or routing support, incident response, temporary infrastructure, customer communication, forensic accounting, overtime where covered, and expedited remediation. Prior consent and approved providers may be required. The holder should know those conditions before authorizing a costly response.

The period of restoration also needs an IPv4 definition. Is restoration achieved when the false route disappears, when intended reachability returns, when RPKI state is correct, when the registry record is restored, or when dependent reputation systems normalize? A policy can choose. Silence produces an argument.

Business interruption is therefore a cash-flow bridge across a covered event. It is not a valuation policy for the permanent capital asset.

Data restoration is not number-resource restoration

Cyber policies commonly pay to recover or reconstruct data and restore systems. An IPv4 holder may reasonably think correction of an RIR record or routing entity is data restoration. The analogy has limits.

A registry record is electronic information, but its authority derives from the institution maintaining it. The policyholder cannot restore a local backup and thereby reverse an official transfer. A ROA is a signed entity within a certification hierarchy; copying yesterday's file does not recreate current authority. BGP reachability emerges from other networks' acceptance. These are governed states, not merely lost files.

The Chubb specimen is particularly instructive. It covers reasonable costs to recover or reconstruct damaged, compromised or lost data and to repair or restore software, subject to definitions and limits. It also states that data and system recovery costs do not include the economic or market value of data. Even if a number-resource record were treated as data for one clause, that would not necessarily make the block's market value a restoration cost.

Restoration should be separated into four tasks. Technical restoration returns intended routing and service. Authority restoration returns authenticated registry and RPKI control. Information restoration corrects records, configurations and documentation. Economic restoration addresses lost cash flow, sale value, financing value or reputation. A policy may cover one, several or none.

Betterment creates another boundary. After a hijack, the holder may want new RPKI automation, diverse transit, monitoring and account controls. Some wordings cover narrowly defined betterment where consented or cheaper than like-for-like restoration; others return only to the prior condition. The cost of reaching a security standard the holder should already have met may be excluded or limited.

The practical solution is a number-resource restoration-cost definition. It can include reasonable costs to authenticate and correct scheduled registry records, recreate valid ROAs and routing entities, coordinate withdrawal and filtering, restore reverse DNS, and remediate address reputation, subject to consent and sublimits. It should state whether registry fees, legal petitions and specialist broker costs are included.

The definition should not silently promise to buy a replacement block. Replacement value is a different exposure requiring an agreed valuation and a trigger that establishes permanent loss of the scheduled interest.

Evidence determines which policy responds

An insurer investigating a number-resource event should be able to construct a time-aligned evidence matrix.

For routing integrity, preserve the exact prefix, authorized origin, observed unauthorized origin, announcement lengths, AS paths, collectors and vantage points, first and last observations, upstream sessions, filter changes and ROA validation state. Router logs, looking-glass outputs and route-collector data should be time-stamped in UTC. A public route collector is independent evidence of observation at its peers, not a complete map of every network.

For registry integrity, preserve the organization and resource identifiers, authenticated user list, multifactor events, portal audit history, tickets, call records, submitted documents, RDAP or directory snapshots, RPKI changes, reverse-DNS changes and transfer status. If the registry provides a formal incident or correction record, retain it. Public records may show the result but not who authenticated the request.

For rights, preserve acquisition agreements, schedules of exact CIDRs, invoices and payment, board approvals, seller representations, corporate succession, merger documents, registry agreements, prior transfers, liens, correspondence with claimants and court orders. A letter of authorization may support routing but may not establish transferable registration rights.

For business interruption, preserve application availability, customer tickets, transaction attempts, cancellations, service credits, saved expenses, mitigation spending and historical comparators. The calculation should state the unaffected baseline and trends. It should distinguish interruption during the waiting period from loss after it.

For reputation, preserve blocklist entries, delisting requests, fraud-score changes, rejected mail or API traffic, customer notices and remediation timelines. Avoid attributing every post-event customer loss to the hijack without a causal link.

The insured should notify the carrier promptly and obtain consent where required, while preserving the ability to act urgently to protect service. The policy can pre-authorize a panel of routing, RIR, legal and forensic specialists. A ransomware response panel that lacks inter-domain routing expertise may waste the first hours asking whether a router was encrypted.

Evidence also protects the policyholder from category error. If route data shows no unauthorized origin but registry history shows a deleted ROA, the claim is not a classic hijack. If both are unchanged and a seller's affiliate sends a demand letter, the case belongs in the rights module. Correct classification accelerates both remedy and coverage analysis.

The endorsement should schedule the control surface

A useful policy does not need to insure the entire Internet. It needs to schedule the policyholder's dependency precisely.

The declarations can list covered prefixes or an objectively maintained inventory, covered origin ASes, relevant RIR or NIR accounts, authorized upstreams, material services and named dependent providers. Changes during the period can be reported through a controlled process. Very large portfolios may use categories with audit rights rather than printing millions of addresses, but the insured quantity must remain reproducible.

A routing integrity event can be defined as an unauthorized BGP origination, unauthorized more-specific announcement, covered route leak or malicious path manipulation affecting a scheduled prefix and causing measurable interruption or degradation. The definition should address accidental events, malicious events and commercial disputes separately. It should not label every reachability failure a hijack.

A registry integrity event can cover unauthorized or erroneous change, deletion, transfer, suspension or denial of access affecting scheduled registry or RPKI services. The policy should identify whether provider error and insured human error are covered, and whether the RIR must be named as a dependent service. Integrity loss should not require the provider's entire system to be offline.

A number-resource restoration expense clause can pay for specialized investigation, route coordination, registry correction, RPKI remediation, reverse-DNS restoration, reputation work and necessary temporary capacity. The schedule can apply sublimits and approved vendors.

A network interruption loss clause can cover partial or total loss of reachability, defined degradation and resulting income loss after a waiting period suited to routing events. A shorter time deductible or monetary retention may be more appropriate than a long waiting period if incidents are sharp and expensive.

A separate rights defence or agreed-value module can address unknown adverse claims under strict diligence. It should not be smuggled into data-restoration wording. Known disputes, intentional unauthorized transfers, sanctions and uninsurable remedies require explicit treatment.

The policy must coordinate the modules. If account compromise causes a bad ROA and then a false route, one event should not attract duplicated limits or retentions unless intended. At the same time, an exclusion in the rights module should not erase otherwise covered interruption merely because parties later dispute ownership. Anti-concurrent-causation language, related-event provisions and priority of coverage need deliberate drafting.

Precision is not anti-policyholder. It lets the insurer price the exposure and lets the holder know what recovery to expect.

Underwriting should reward control rather than size alone

Counting addresses is a weak proxy for loss. A /16 supporting one resilient service may present less interruption risk than a /22 embedded in a critical payment identity with one upstream and no ROA.

Underwriting should begin with inventory quality. Can the applicant produce exact prefixes, registered entities, origin ASes, services, contracts and carrying values? Are leased and owned positions separated? Are disputed or legacy resources identified? Unknown inventory is not diversification; it is unmeasured exposure.

Routing controls matter. The underwriter can ask about ROA coverage and maximum-length discipline, upstream prefix filtering, route monitoring, diverse transit, emergency contacts, change approval and tested withdrawal procedures. RPKI is valuable but should not be treated as a binary warranty of safety. NIST notes that route-origin validation mitigates a class of hijacks; it does not eliminate every path manipulation or operational error.

Registry controls matter separately. The underwriter can assess multifactor authentication, role accounts, backup authorized contacts, corporate-record reconciliation, transfer approval, account recovery, legal-entity changes and periodic verification. The policyholder should be able to show who can create a ROA or request a transfer and how destructive action is reviewed.

Rights controls include acquisition diligence, exact CIDR schedules, seller authority, warranties, registry completion, lien searches where relevant, corporate succession and treatment of legacy space. A clean BGP history does not compensate for a broken acquisition chain.

Business continuity should test address dependence. Can the service use alternate prefixes? How long would customer allowlists take to change? Is temporary capacity available? Does the company have pre-agreed help from upstreams? A replacement block may be technically easy to announce and commercially impossible to substitute because customers trust the old addresses.

The underwriter should also identify concentration. Many insureds can depend on the same RIR, transit provider, cloud platform, RPKI repository or widely used route-validation software. A single event can produce correlated claims. The GAO's 2022 report on catastrophic cyber risk notes that private insurers have limited exposure to systemic cyber events through exclusions and other measures. Internet routing is inherently systemic, so aggregation cannot be ignored.

None of these controls supplies a global probability of loss. Public BGP incidents, fraud reports and transfer logs have different denominators and reporting bias. Underwriting should price uncertainty honestly rather than invent a frequency from visible events alone.

Claims need a cause tree, not a blame contest

During an incident, operators need to restore service before lawyers finish naming the peril. The policy should support that priority while preserving evidence.

The first claim meeting can use a cause tree. Did an unauthorized route appear? Did a scheduled registry or RPKI state change? Did an insured or provider system suffer unauthorized access, human error or technical failure? Did a third party assert rights? Which event came first? Which losses continued after each state was corrected?

This sequence prevents simplistic causation. Suppose compromised RIR credentials allow deletion of a ROA. An unrelated upstream then rejects the legitimate route as invalid, causing interruption. The immediate route is originated by the insured; there is no false origin. The cause may be a registry-security event leading to routing-policy rejection. A policy that covers only “hijack” could miss it.

Suppose an upstream accidentally leaks the holder's routes, creating congestion but no unauthorized origin. NIST and operational practice distinguish route leaks from origin hijacks even though both disrupt service. The endorsement should say whether leaks are covered.

Suppose a seller revokes routing authorization during a payment dispute. Technically the route may become invalid. Commercially the act may arise from contract enforcement rather than malicious intrusion. The business-interruption module and contractual exclusion may conflict unless the policy states how disputed authorization is treated.

The adjuster should measure loss by phase: detection, active route or registry event, technical restoration, dependent-service normalization and long-tail remediation. Coverage can differ by phase. Forensic and response costs may attach immediately; business interruption may start after a waiting period; reputation expense may have a sublimit; rights litigation may sit elsewhere.

Subrogation also depends on category. Recovery from a malicious actor is usually unrealistic. Recovery from a negligent service provider may be limited by contract. Recovery against a seller, broker or adviser may be material in a defective transfer. The policyholder must preserve those rights and avoid admissions that prejudice the insurer, subject to the actual policy.

A cause tree does not guarantee payment. It makes disagreement legible. The insurer can point to the trigger, exclusion or quantum issue; the policyholder can answer with evidence. That is preferable to debating whether an address is “really property” while customers remain offline.

RIRs are evidence institutions, not insurers of last resort

Regional Internet Registries occupy a difficult position in these claims. Their records and audit trails may be decisive, yet they are not parties to the cyber policy and do not control every route.

An RIR can authenticate its account events, explain transfer status, correct errors under its process, manage hosted RPKI service and maintain public registration. It can say whether a source is the current registered holder under policy or whether a dispute prevents a transfer. Those facts can establish the registry layer.

It normally cannot prove the policyholder's lost profit, decide how every network routed, value the block, or determine insurance coverage. Nor should an insurer demand that the RIR label an event “theft” before paying interruption caused by a covered integrity event. The registry's vocabulary follows its institutional remit.

ARIN's fraud-reporting form accepts reports of suspected fraudulently obtained resources or unauthorized changes to records. That is a useful incident path. It does not publish a global fraud denominator or promise a particular remedy. APNIC's policy condition excluding disputed sources from transfer is a control. It does not adjudicate every private claim.

The best insurance design creates a liaison protocol. The insured authorizes designated specialists to communicate with the registry, preserves ticket identifiers, supplies authenticated corporate documents and records decision timestamps. The insurer funds covered specialist cost without attempting to direct the registry outside policy.

Registries can also improve insurability through exportable account history, strong authentication, multiple role holders, delayed destructive changes where safe, clear incident escalation and machine-readable transfer status. These improvements reduce evidence uncertainty for everyone, not just insurers.

There is a boundary to transparency. Publicly exposing account-security details, claimants or restricted documents could create new risk. Insurers can receive evidence under consent and confidentiality. Public transfer and routing data remain useful but incomplete.

An insurance market that respects these limits will use RIR evidence correctly: strong evidence of registration and service state, not a universal certificate of ownership, routing or economic loss.

Systemic routing risk needs explicit capacity decisions

Cyber insurance works best when losses are sufficiently independent to pool. Internet routing is built on common dependencies.

A widely propagated bad route can affect thousands of policyholders and their suppliers at once. A fault in a major platform can interrupt many networks. A RPKI repository or validation problem can create correlated routing responses. A state-linked campaign can create attribution and war-exclusion questions. These are not reasons to leave every holder uninsured; they are reasons to define aggregation.

The GAO's 2021 cyber-insurance report found an evolving market in which clients can struggle to determine coverage because key terms lack standard definitions and insurers face limited historical data. The 2022 GAO report describes the limited ability of private insurance to absorb catastrophic attacks and notes steps insurers take to limit systemic exposure. The NAIC's cybersecurity overview likewise characterises cyber policies as highly customized.

For number-resource cover, the insurer should state whether a widespread routing event, Internet infrastructure outage, provider failure, war-linked event or government action is excluded, sublimited or covered. The holder should not infer catastrophe cover from a clause designed for a single compromised network.

Aggregation modelling needs identifiers: RIR, RPKI trust anchor and repository, validation software, transit providers, cloud platforms, DNS dependencies and geographic concentration. Exact data may be incomplete. The insurer can use scenarios rather than false precision: simultaneous invalidation, major route leak, provider account compromise, or region-wide registry-service interruption.

Capacity can be layered. Ordinary short routing events may sit in the primary cyber policy. Widespread-event cover may have a separate sublimit and retention. Rights cover can remain transaction-specific. Parametric cover based on observed reachability could pay rapidly, but only if the index correlates with actual loss and resists manipulation.

The policyholder should understand silent cyber in traditional property and business-interruption policies. Conventional business interruption often depends on physical damage, while stand-alone cyber wording addresses network events. Overlap and gaps need coordination. A tower containing property, cyber, technology errors and omissions, crime and transactional cover should identify which layer leads for each number-resource peril.

The most dangerous systemic assumption is that another policy will respond. Explicit capacity is cheaper than litigating silence.

A Number Resource Society can create an insurable discipline

The Number Resource Society proposition is useful here because insurance needs the same thing good stewardship needs: a defined exposure with controlled change and recoverable evidence.

First, NRS treats number resources as managed dependencies rather than forgotten configuration. That encourages exact inventories, named custodians, registry reconciliation, routing-security controls and continuity plans. An insurer can underwrite those facts.

Second, it treats operational control and economic interest as related but separate. The network team can prove origin and route history. The registry team can prove account state. Legal and finance can prove acquisition and cash flow. Claims become less vulnerable to the belief that one database answers every question.

Third, it values continuity. An address can become embedded in customer allowlists, partner access, compliance rules and service identity. A short routing event can therefore cause business loss out of proportion to the number of affected addresses. Underwriting address count alone misses that dependency; NRS-style mapping makes it visible.

Fourth, it supports prevention. Accurate ROAs, provider filters, authenticated registry access, tested contacts and planned substitution reduce loss. Insurance should reward these controls without promising that they eliminate risk. NIST describes route-origin validation as mitigation, not total security.

The evidence boundary remains firm. NRS does not create title, compel an RIR decision, prove a loss rate, or override exclusions. It should not market a “fully insured address” when the actual policy covers only response expense. Positive institutional language must be matched by the schedule.

The best outcome is a feedback loop. Better holders produce better evidence. Better evidence permits narrower definitions and fairer pricing. Clearer cover funds faster expert response. Claims data, suitably protected, reveal which controls work. Registries and operators can improve procedures without becoming insurers.

This is how a society around number resources becomes economically serious: not by declaring every prefix priceless, but by making control, continuity and risk measurable enough to govern.

The policy should answer twelve questions before inception

A holder and broker can test a proposed policy with twelve questions.

  1. Are the exact prefixes or a reproducible portfolio definition scheduled?
  2. Does covered computer system include the holder's routing infrastructure and relevant externally operated systems?
  3. Is unauthorized route propagation itself a trigger, or must the insured's own system be compromised?
  4. Are route leaks, accidental origins, malicious hijacks and disputed authorization treated differently?
  5. Does interruption include partial reachability loss and measurable degradation?
  6. What waiting period, retention and indemnity period apply to a short routing event with a long tail?
  7. Are the RIR, NIR, RPKI and upstream services named or functionally included as dependencies?
  8. Does registry integrity cover erroneous change as well as hostile compromise?
  9. Which specialist response, registry correction, temporary capacity and reputation costs are covered, and whose prior consent is required?
  10. Is the market value or agreed value of the number-resource position covered anywhere, or only cash-flow loss and restoration expense?
  11. How are contractual, title, intellectual-property, infrastructure, war and known-event exclusions applied?
  12. What evidence, notice, cooperation, valuation and subrogation duties must the insured satisfy?

If the answers are not in the wording, endorsements and schedule, a sales presentation cannot supply them. Product summaries routinely say “business interruption” without defining the system, trigger or loss. The contract does.

The holder should then run three tabletop claims. In the first, a false origin diverts half of observed traffic for forty minutes and customer failures continue for six hours. In the second, an authenticated but fraudulent registry change disables ROA control for two days. In the third, a pre-acquisition affiliate asserts rights and freezes a planned sale without disrupting routes. The broker and underwriter should identify the clause, retention, evidence and likely uncovered loss for each.

Any answer that treats all three as the same claim is a warning. Any answer that guarantees payment without reviewing definitions is worse.

The purpose is not to eliminate every ambiguity. Insurance always applies words to unexpected facts. The purpose is to place the foreseeable boundaries where both parties can see them.

Insure the loss that can actually occur

The IPv4 block does not vanish when a bad BGP announcement appears. What can vanish is reachability, trustworthy control, saleability, revenue or confidence. Each can be insured only if it is named and measured.

Routing events belong primarily in a network-interruption and response module. The trigger should reflect unauthorized reachability, not physical possession of the address. Registry errors belong in an integrity and dependent-service module that covers wrong authoritative state as well as system outage. Ownership disputes belong, if covered at all, in a separately diligenced rights or transactional module. Reputation and long-tail remediation need their own limits and period.

This separation is good for insurers. It prevents an ordinary business-interruption premium from silently carrying disputed asset value. It makes aggregation visible. It directs adjusters to the right evidence.

It is equally good for holders. They can see that an insurer may pay forensic cost and lost profit without buying a replacement block. They can align registry, routing, legal and finance controls. They can choose whether rights cover is worth its diligence and price.

No public source supplies a global percentage of IPv4 hijacks that produce insured loss, registry errors that become permanent, or ownership disputes that defeat holders. Visible incidents lack a common denominator, and private claims are not comprehensively published. An honest policy should not depend on invented certainty.

The final answer to whether cyber insurance covers a number-resource asset is conditional but useful. It can cover important consequences. It should not be assumed to cover the asset's legal or market value. The gap can be narrowed through precise endorsements, scheduled dependencies, suitable waiting periods and a claim evidence protocol.

A hijacked capital asset needs more than a cyber label. It needs a policy that knows the difference between the route, the registry and the right.

Sources