Container port operations at DP World Australia
Media & Insights
Infrastructure

The Most Expensive Days of a Cyber Outage May Come After Restart

Customer credits, tariff waivers and delayed demand can prolong the loss long after systems are technically restored.

Anthony Anakwue
Anthony Anakwue
Chief Executive Officer
Published 24 September 2026

Infrastructure sponsors often treat cyber as an operating risk managed through security controls, insurance and force majeure. The evidence from ports, pipelines, telecommunications and industrial companies shows a different problem: an asset can be excused from performing, or prudently shut down, while revenue falls and debt obligations continue. The central task is to test every plausible incident against contractual payments, insurance wording, reserve capacity and lender remedies.

Key takeaways
  • ·Force majeure may provide time or relief from liability without replacing lost revenue, stopping availability deductions or paying debt service.
  • ·A precautionary shutdown can create a major interruption loss even where the physical asset remains intact.
  • ·Insurance can work, as Norsk Hydro showed, but waiting periods, exclusions and claims timing still matter to projects with fixed payment dates.
  • ·Customer credits, tariff waivers and delayed demand can extend the economic impact well beyond technical restoration.
  • ·Sponsors should price cyber protections into bids, tariffs and financing costs rather than treating them as a post-signing insurance question.

On 10 November 2023, DP World Australia detected unauthorised access to its network.

The company, which operates container terminals in Australia as part of the Dubai-based global port group, disconnected its corporate network from the internet. Landside port operations stopped until 13 November. By 20 November, DP World Australia had cleared a backlog of 30,137 containers.

The company’s public update establishes the shutdown and the backlog. It does not need a more dramatic detail to make the point.

The interruption was a containment decision. It may have limited the compromise. Yet it also stopped the flow of containers, trucks and revenue. While the operator does the sensible thing, who pays for the days in which the asset cannot earn?

That question is more useful than asking whether the operator had a cyber policy.

Imagine you own a road, port, power asset or telecoms network financed with borrowed money. An incident-response adviser tells you to isolate the network. Your concession may excuse your failure to perform. Your insurer may need time to assess the claim. Your lenders still have a payment date circled in red.

Cyber risk, in other words, is not just an IT problem. It is a timing problem.

The comforting story is incomplete

Most project documents begin with a reassuring chain of assumptions. The operator meets security standards. It buys cyber insurance. If something extraordinary occurs, force majeure, the contract mechanism that can excuse a party from performing after an event outside its control, will provide relief.

Each part can be sensible. Together, they can still leave a hole.

The UK’s PF2 standard terms preserve availability and performance deductions during force majeure and pay only for services actually delivered. The UK Government’s standardisation guidance makes the position unusually plain: being excused from performing does not necessarily mean being paid as if performance continued.

India’s Ministry of Road Transport and Highways model concession agreement, published in 2026, reaches a similarly awkward result for toll roads. It can grant an extension after force majeure, but excludes lost fee revenue and debt-repayment obligations from compensable costs. For a non-political event, each party bears its own costs.

Time, not cash.

The World Bank’s PPP guidance asks procurers to confront the issue directly: should payments continue during an event in order to prevent financing default? That is not a theoretical drafting point. It is an allocation decision that can be priced before bids are submitted.

A sponsor seeking payment continuity can calculate the expected cost of that protection, then build it into the bid price, proposed tariff or financing model. A public authority can decide whether the higher upfront price is worth avoiding the possibility that an otherwise viable asset fails during an outage. The brief does not identify a named project that successfully negotiated cyber-specific payment continuity, so it would be irresponsible to manufacture one. What it does show is the exact contractual choice that procurers are being asked to make.

Four clocks start when the network goes dark

The relevant question is not simply, “How long will restoration take?”

There are four clocks.

First, the concession clock: how long the project is relieved of contractual duties. Second, the insurance clock: when cover starts, what loss qualifies and when proceeds arrive. Third, the reserve clock: how long the cash set aside for debt service lasts. Fourth, the recovery clock: when customers, volumes and normal revenue return.

A project is safe only if those clocks overlap in the right direction.

Rio Grande LNG, a disclosed $10.3 billion liquefied natural gas facility in the United States, funded a debt-service reserve of up to six months. That sounds robust until you ask what it is being measured against. Not the day technicians restore a system. The day the project’s cash buffer is exhausted.

The US TIFIA template for federal transport lending treats failure to replenish required reserves as an event of default and applies coverage tests to projected cash flow. UK PFI distress guidance makes the same basic point from another direction: loan defaults are designed to arise before termination of the project agreement.

A project can therefore be physically intact, contractually alive and operationally recovering while its financing is already in distress.

Put the UK, Indian and US approaches side by side and a pattern appears that none of the documents says outright. Infrastructure contracts decide who is excused. Insurance policies define what loss is covered. Debt documents identify cash weakness early. None automatically bridges the gap between those three jobs.

That gap is the cyber loss sponsors should model.

A pipeline made the same mistake visible

Two years before the DP World Australia interruption, Colonial Pipeline disconnected systems supporting its 5,500-mile US fuel pipeline after ransomware entered its business network.

The shutdown lasted several days. Colonial paid a $4.4 million ransom. Joseph Blount, Colonial’s chief executive, told Congress that insurance was expected to cover the ransom. The US Government Accountability Office’s account of the event records those core facts.

What surprised us was how often this episode is reduced to the ransom.

The more revealing fact is that public evidence did not establish equivalent recovery for all interruption losses. The pipeline did not need to be physically damaged. Uncertainty around billing and safety was enough to stop throughput.

Colonial’s shutdown showed that a business-network compromise can halt physical infrastructure without physical damage.

Colonial’s shutdown showed that a business-network compromise can halt physical infrastructure without physical damage. Photo: National Transportation Safety Board / Wikimedia Commons, Public domain.

The usual assumption is that separating operational technology from corporate IT protects the physical asset. Colonial showed why that is too neat. A business-network compromise can still make it unsafe or impossible to run the physical system.

For sponsors, the practical lesson is narrow but important: test insurance and concession language against a voluntary or precautionary shutdown. Do not test only the more dramatic scenario of destroyed equipment or encrypted industrial controls.

Beazley, the specialist insurer, publishes cyber wording that applies waiting periods and limits dependent-business cover to qualifying contracted providers. That is not a criticism of insurance. It is a warning against treating the existence of a policy as proof that cash will arrive when it is needed.

The port where every crane was fine

At the Port of Nagoya in Japan, ransomware disabled the unified terminal system serving all container terminals on 4 July 2023. Container entry and exit stopped for approximately three days.

The cranes were still there. The berths were still there. The physical port had not vanished.

Its common digital system had become the bottleneck.

Japan’s transport ministry later created a committee to develop security requirements for core port systems. The lesson is bigger than Nagoya. Redundant machinery is not the same as operational resilience when booking, billing, gate access or terminal movements run through one shared platform.

Nagoya’s unified terminal system turned a digital failure into a port-wide interruption.

Nagoya’s unified terminal system turned a digital failure into a port-wide interruption. Photo: ccfarmer / Wikimedia Commons, CC BY 3.0.

This is where most people stop looking. They count backup generators, duplicate pumps and spare parts, then overlook the single system through which every physical asset receives permission to move.

The same distinction appeared in South Africa. Transnet, the state-owned company that runs freight rail, ports and pipelines, was hit by ransomware in July 2021. Its systems went completely offline. Container terminals shifted to manual processing and Transnet declared force majeure, according to the company’s financial statements.

That declaration could reduce some customer claims. It did not reimburse Transnet. It did not reimburse exporters affected by the disruption. South Africa’s Auditor-General later identified weaknesses in Transnet’s business continuity, disaster recovery and third-party outsourcing.

Transnet’s force-majeure declaration could reduce liability without creating restoration or debt-service cash.

Transnet’s force-majeure declaration could reduce liability without creating restoration or debt-service cash. Photo: BonganiDude / Wikimedia Commons, CC BY-SA 4.0.

Relief from liability and cash for restoration are separate assets. A force-majeure notice may protect an operator’s legal position. It does not fill the bank account.

The loss can continue after service returns

Kyivstar, the Ukrainian telecommunications operator owned by VEON, was attacked on 12 December 2023. Mobile, fixed-line, roaming and SMS services were disrupted.

The systems coming back did not end the economic damage. VEON’s FY2024 filing reported $23 million of lost 2023 revenue, a $24 million EBITDA impact and a further $46 million revenue effect in 2024 after Kyivstar gave customers a free billing cycle. EBITDA means earnings before interest, tax, depreciation and amortisation, a common measure of operating profit before financing and accounting charges.

Here is the twist. Customer compensation can be commercially wise and still lengthen the financial loss.

A free billing cycle, tariff waiver or delayed return of demand may fall after the technical restoration date. That is why an insurance review needs to ask whether the indemnity period, the period over which a policy measures loss, includes customer credits and delayed demand recovery.

The wider insurance market has become clearer about other boundaries. Lloyd’s required standalone cyber policies from 31 March 2023 to exclude war and certain state-backed attacks that significantly impair a state’s functioning or security. The US Government Accountability Office has separately concluded that private insurance and the US terrorism insurance backstop remain limited for catastrophic systemic cyber events, including cyberwar and infrastructure outages.

No standard contract can be assumed to carry this loss. Some may allocate part of it. Some may provide time. Some insurance programmes may pay substantially. But the evidence does not support assuming that ordinary force-majeure wording, a generic cyber policy and a debt reserve will collectively cover every interruption.

The counterexample is not comforting either

Norsk Hydro, the Norwegian aluminium and renewable-energy company, shows that insurance can work.

Its March 2019 ransomware attack caused an estimated NOK650 million to NOK750 million loss in 2019. Hydro kept plants operating manually and had a specifically negotiated cyber programme. Its 2019 annual report recognised NOK216 million of insurance compensation in that year.

That is a meaningful recovery, not a token payment.

The lesson is not that insurance fails. It is that insurance is one layer of resilience. Hydro also had manual operating capability. For a tightly financed project, the question remains whether the project can survive until any insured recovery is received.

GI Network’s view: A cyber policy is not a debt-service plan. Treat it as one input into a cashflow waterfall, then identify the month in which the project runs out of money if the insurer pays late or declines part of the claim.

What sponsors should change before signing

Start with credible event paths: ransomware, unauthorised access requiring isolation, failure at a dependent technology provider and loss of a shared platform.

Then trace each path through the documents. What operations stop? What payments disappear or deductions begin? Does the concession provide time, money, both or neither? What does insurance cover after waiting periods, limits and exclusions? How many debt-service months remain?

If payment continuity, additional reserves, manual fallback capability or wider insurance cover improves the answer, price it. Include it in the bid. Reflect it in proposed tariffs where the model permits. Or accept a higher financing cost if lenders require more liquidity. The protection is not free, but neither is pretending the residual loss does not exist.

This is the same discipline behind asking whether a nominal protection actually protects revenue, as GI Network examined in who pays when the grid rejects renewable power.

For technology businesses, the investable explanation is similarly practical. Do not simply say that you have a certification. Show the dependent systems, manual fallback, shutdown authority, contractual commitments and cash consequence if the service goes dark. It is the difference between reported ARR and bankable ARR.

What experienced investors ask

First-time investors ask whether there is cyber insurance. Experienced investors ask for the wording.

They examine waiting periods, dependent-system limits, exclusions for systemic or state-backed events, treatment of precautionary shutdowns, customer credits and the destination of insurance proceeds. They compare those answers with debt reserves and lender cure rights, the ability of lenders to step in and remedy a default before harsher enforcement.

The psychology is straightforward. Investors are checking whether every party has quietly assumed somebody else will write the cheque. That is the same hard question behind the term sheet that was not cash.

GI Network would build an event-by-event allocation matrix before investor outreach or financial close. We would test projected cash flow against reserve exhaustion, compare concession relief with insurance wording, identify gaps around shutdown authority and proceeds, and prepare the evidence a lender’s credit committee will require.

Use the Four-Clock Test

The practical tool is the Four-Clock Test.

  1. 1.Relief: When does the concession excuse performance, and does it preserve payment?
  2. 2.Insurance: When does cover begin, what is excluded, and when can proceeds realistically arrive?
  3. 3.Reserve: On what date does debt-service cash run out?
  4. 4.Recovery: When do operations, customers and revenue genuinely return?

Here is a worked allocation-matrix example. It is illustrative, but it forces the questions that contracts often leave in separate folders.

| Incident path | Concession outcome | Insurance question | Cash question | Required decision |

|---|---|---|---|---|

| Operator isolates a port network after unauthorised access | Is the operator excused, and do availability deductions continue? | Does the policy respond to a precautionary shutdown after its waiting period? | Does the reserve last until traffic and billing resume? | Seek payment continuity, additional reserves or both. |

| Shared terminal platform fails | Are lost movements treated as excused non-performance or as unpaid service? | Is the platform a qualifying dependent provider under the policy? | Can debt service be paid while the system and backlog are restored? | Add shared-platform treatment and manual fallback plans. |

| Service returns but customers receive credits | Does the contract recognise the revenue aftershock? | Does the indemnity period include customer credits and delayed demand? | Does the reserve cover the period after technical restoration? | Model recovery through normal revenue, not merely system restart. |

If the recovery clock ends after the reserve clock, the project has a liquidity problem. If the insurance clock ends after the reserve clock, it has a financing problem. If relief supplies time but not cash, it has both.

That is the question every cyber clause should answer before the network goes dark.

ShareWhatsAppLinkedInX
Questions people ask

What happens if you get breached?

A cyber breach can become a cash-flow and debt-service problem even when physical assets are undamaged. An operator may shut systems down as a precaution, lose revenue, face service deductions and continue owing scheduled debt payments. Force majeure may excuse performance without providing payment, while insurance proceeds can be subject to waiting periods, coverage limits and claims assessment.

Sources
  • Media statement: update on cybersecurity incident · DP World · 2023
  • GAO-21-105263 · US Government Accountability Office · 2021
  • Government Accountability Office analysis of catastrophic systemic cyber insurance risk · US Government Accountability Office · Not stated in research brief
  • Infrastructure Standardisation of Contracts · UK Government · 2012
  • PFI Distress Guidance · UK Government · Not stated in research brief
  • Model Concession Agreement · India Ministry of Road Transport and Highways · 2026
  • PPP Guidance · World Bank · Not stated in research brief
  • Current Report on Form 8-K · US Securities and Exchange Commission · 2023
  • TIFIA Loan Agreement Template · US Department of Transportation · Not stated in research brief
  • Cybersecurity measures for port facilities · Japan Ministry of Land, Infrastructure, Transport and Tourism · 2023
  • Annual Financial Statements · Transnet · 2021
  • Audit findings on Transnet · Auditor-General of South Africa · Not stated in research brief
  • FY2024 20-F with Exhibits · VEON · 2024
  • First Party Cyber Insurance Wording · Beazley · 2021
  • Annual Report 2019 · Norsk Hydro · 2019
  • Cyber War and Cyber Operation Exclusions · Lloyd’s · 2023
  • Critical Infrastructure Protection: TSA Is Taking Steps to Address Some Pipeline Security Program Weaknesses | U.S. GAO
  • Annual financial statements
  • Media Statement: Update on Cybersecurity Incident
  • Form 20-F_FY2024
  • 港湾:コンテナターミナルにおける情報セキュリティ対策等検討委員会について - 国土交通省
  • Hydro  Annual Report 2019  Consolidated financial statements  141
  • next20230712_8k.htm
  • Coverages Error! Bookmark not defined. Exclusion
Reviewed by the GI Advisory Team
GI Network

Raising capital? Open a capital file and let the advisory team assess your position.

Apply for Capital

Seeking capital?

Your application is the first step into the GI Network capital process.

Apply for Capital