Editor’s Note: As data breach incidents and related cyber risks continue to increase and gain publicity—and government agencies become more actively involved in policing the corporate response—many organizations are taking a close look at the protections that cyber insurance policies provide. Manatt’s insurance coverage leaders have joined with our integrated team of privacy, data protection, information security and governance professionals to deliver guidance on maximizing premium dollars when purchasing cyber policies and effectively dealing with claims that may arise under these policies. The article below captures key definitions, tips and recommendations to help you understand your options—and make the optimal decisions—when choosing cyber coverage.
Although cyber coverage is a relatively new product in the insurance marketplace, there are now roughly 50 insurance carriers that offer it (although the amounts of coverage available often are limited). These policies are sold under a number of different names, including “cyber risk,” “information security,” “privacy” and “media liability” coverage. Unlike other types of insurance, there is no standard form on which the insurance industry as a whole underwrites cyber coverage. While this presents some challenges to purchasing coverage, especially for the uninitiated, it often provides more room for negotiating the terms of cyber policies than many other types of coverage.
Most cyber policies currently in the marketplace offer some combination of traditional liability coverage protecting against claims by third parties and first-party coverage protecting against losses suffered by the insured. There also are important terms and conditions of cyber policies that can have a significant impact on available coverage. While no organization can reasonably expect to secure every available component of coverage, awareness of differences among the policies being offered is critical to optimizing premium dollars spent.
While not exhaustive, following are some of the important features to be mindful of when shopping for cyber coverage.
Third-Party (Liability) Coverages: Types, Tips and Considerations
- Privacy liability coverage. This type of coverage includes liability to the insured’s customers/clients and employees for breach of private information. Seek trigger language that focuses on the insured’s failure to protect confidential information, regardless of the cause (e.g., “any failure to protect”), rather than language requiring an intentional breach. Some, but not all, cyber policies also provide coverage for the insured’s failure to disclose a breach in accordance with privacy laws. Because this can be a major component of liability in the case of a data breach, it is important to obtain this coverage.
- Regulatory actions. There is substantial variance among cyber policies regarding whether and to what extent they provide coverage for regulatory and other governmental actions. Even when they do provide regulatory coverage, some policies require that the action be initiated by a formal “suit” to trigger the defense obligation. This limitation typically would preclude defense of the investigative stage of government actions—often the most expensive stage for the entities being investigated. Look for policies that cover defense from the earliest stages of an investigation, typically including a civil investigative demand or similar request for information. In addition, be aware that civil fines and penalties are covered under many cyber policies. Be careful that an insurer does not seek to exclude such coverage.
- Notification costs. This coverage includes the costs of notifying third parties potentially affected by a data breach. There are an ever-increasing and constantly evolving landscape of breach notification laws on a state-by-state basis. Notification cost coverage is included in most cyber policies. However, many policies, often by endorsement, limit the number of individuals that must be notified and the method(s) of notification. Some policies also may vest some control over the notification process (which is often sensitive to the insured) with the insurer. These limitations could leave an organization absorbing at least some of the notification costs if a breach occurs, and may require it to relinquish some control over the notification process.
- Crisis management. Crisis management coverage includes the costs of managing the public relations outfall from most data breach scenarios. Most, but not all, cyber policies contain some form of crisis management coverage. The insured sometimes is required to choose from a predetermined list of vendors. In most cases, if the insured chooses another vendor, the insurer is not required to pay for the services. However, this restriction may be negotiable.
- Call centers. This coverage may be included within the notification and crisis management coverages, may be a stand-alone coverage, or may not be provided at all. Because call centers tend to be one of the higher costs associated with data breaches, it is important to identify whether this coverage is expressly provided and any applicable limitations (including the number of affected persons who are eligible to receive call center services, the hours and locations of the call center, and the specific services the call center staff will provide).
- Credit/identity monitoring. Although this coverage is included in most cyber policies, like call center coverage, it may limit the number of affected individuals who can receive the services and the prescribed vendors that are available.
- Transmission of viruses/malicious code. As its name suggests, this coverage protects against liability claims alleging damages from the transmission of viruses and other malicious code or data. Not all cyber policies have this coverage. Before making it a priority, organizations should consider the extent to which their operating systems realistically have the potential to be a source of this type of liability.
First-Party Coverages: Defining Key Terms
- Theft and fraud covers certain costs related to the theft or destruction of the insured’s data, as well as theft of the insured’s funds.
- Forensic investigation covers the costs of determining the cause of a loss of data.
- Network/business interruption covers the costs of business lost, as well as additional expenses resulting from an interruption in the insured’s computer systems. Some cyber policies require that the interruption be caused by an intentional cyber attack, and some do not. There typically are limitations to this coverage, including a requirement that the interruption last a minimal length of time before coverage begins and a limit on the total length of an interruption that will be covered. This coverage may also include contingent business expenses.
- Extortion covers the costs of “ransom” if a third party demands payment to refrain from publicly disclosing or causing damage to the insured’s confidential electronic data.
- Data loss and restoration covers the costs of restoring data if it is lost, and in some cases, diagnosing and repairing the cause of the loss. It is included in some but not all cyber policies. Data loss and restoration coverage typically is subject to a substantial retention, and may be limited in terms of the cause of the data loss at issue.
Other Key Provisions
- Trigger—loss or claim. Cyber policies typically are triggered either by an event that results in the loss of data, or a “claim” arising from the event that is made against the insured (or made against the insured and reported to the insurer) during the policy period. The claims-made type policies usually are more restrictive in terms of the events that can trigger coverage. In addition, the timing of resulting claims in relation to the loss may limit or preclude available coverage. For these reasons, the loss type policy is the preferred option, even though it may be more expensive.
- Trigger—defense. In some cyber policies, the defense obligation is triggered by a “Suit,” which requires a lawsuit or written demand against the insured. This definition may preclude defense of a claim that has yet to ripen into a lawsuit or a written demand (where much of the defense costs on a particular matter may be spent). If available, seek less restrictive defense language. In some cyber policies, the “Suit” limitation does not apply to governmental actions (such as investigations), which would make this language somewhat more palatable.
- Defense—choice of counsel. In some cyber policies, defense costs are covered only to the extent that the insured chooses from the insurer’s (sometimes short) list of “panel” law firms. If the insured chooses a different firm, its defense costs probably will not be covered. Given the substantial costs likely to be associated with a significant data breach (which could exceed the limits of the policy), the insured should have more substantive input into the choice of counsel. Accordingly, it’s preferable to seek a more balanced choice of counsel language (e.g., the insured and the insurer shall mutually agree on defense counsel; and if they cannot agree, the insured shall choose counsel for which the insurer shall pay up to a set hourly rate).
- Retroactive coverage. Cyber policies often contain a “retroactive date.” Losses arising from events prior to the retroactive date will not be covered. Insurers often fix the retroactive date at the initial date of coverage by the insurer, although the insured may be able to negotiate a retroactive date further back in time.
- Acts and omissions of third parties. Acts or omissions of third parties often may not be covered expressly, or even may be excluded, under cyber policies. For example, if a company uses the services of a third-party vendor to maintain its confidential employee or subscriber information in the “cloud” and the vendor experiences a data breach, the company could be sued by its subscribers or employees and may not have any coverage. We are aware of cyber policies providing coverage for breaches of data maintained by third parties as long as there is a written agreement between the insured and the vendor to provide such services. If an organization relies on any third parties to maintain any of its confidential subscriber or employee information, it should seek to have coverage for breaches of data maintained by third parties expressly covered. Moreover, any self-insured retention language applicable to this coverage should be clear that any payments made by the third party indemnifying the company for loss sustained by the breach count toward satisfaction of the retention.
- Coverage for unencrypted devices. Many cyber policies exclude coverage for data lost from unencrypted devices. If possible, seek cyber coverage without this limitation.
- Coverage for corporations and other entities. Cyber policies often define covered persons, for liability purposes, to include only natural persons—real human beings as opposed to “legal persons” which may be public or private organizations or entities. However, entities affected by data breaches may include corporations and other business entities. Companies should seek coverage that appropriately defines the scope of entities potentially affected by a data breach.
- Policy territory—occurrences outside the United States. Even if a company does not operate outside the Uniteds States, its employees may lose their laptops, PDAs and other electronic devices containing confidential information (or have them stolen) while traveling abroad. Many cyber policies restrict the applicable coverage territory to the United States and its territories. Organizations should ensure that their cyber policies provide coverage even if the loss or theft of confidential information at issue occurs outside the United States.
- Breaches not related to electronic records. Some cyber liability policies restrict coverage to loss or theft of electronic data. However, many breaches occur as a result of loss or theft of paper (or other nonelectronic) records. The best course of action is to choose a policy that covers both electronic and nonelectronic data.
- Location of security failure. Coverage under some cyber policies is limited to physical theft of data on the organization’s premises. This could be problematic in a number of situations, including theft of a laptop, PDA or external drive from an airport or an employee’s home. Other policies limit coverage for data breaches resulting from password theft to situations where the theft occurs by nonelectronic means. Be wary of these types of limitations, which may not seem particularly pernicious on initial review but could be extremely costly.
- Exclusion for generalized acts or omissions. Some cyber policies exclude coverage for losses arising from (i) shortcomings in security of which the insured was aware prior to the inception of coverage; (ii) the insured’s failure to take reasonable steps to design, maintain and upgrade its security; and (iii) certain failures of security software. Avoid these types of exclusions, if possible. They can be problematic, because they use broad language, lack adequate definition and may be applied subjectively.
- Exclusion for acts of terrorism or war. It is unclear to what extent insurers will rely on this common type of exclusion when a data breach results from an organized attack by a foreign nation or hostile organization. To the extent possible, it’s preferable to avoid these types of exclusions.
Cyber insurance is a new but quickly expanding area, as more and more data breach incidents hit the headlines. When choosing a policy, it’s critical to understand the differences among options—and be aware of limitations and exclusions—to make the optimal decision.