Category Archives: Denial-of-service

Please join me for: Data Breaches and Advanced Persistent Threats: Planning for Them, Getting Them Resolved, and Getting Insurance to Cover Them

Cybersecurity_email_banner

Hosted by

DS+Logo+Green+2_67+inch+72dpGeneral_Dynamics

Data Breaches and Advanced Persistent Threats:
Planning for Them, Getting Them Resolved, and Getting Insurance to Cover Them

Dickstein Shapiro LLP and General Dynamics Fidelis Cybersecurity Solutions invite you to participate in a webcast, “Data Breaches and Advanced Persistent Threats: Planning for Them, Getting Them Resolved, and Getting Insurance to Cover Them” on Friday, June 21, 2013. This interactive program, of particular interest to chief privacy officers, risk managers, those in government affairs, and privacy counsel, will discuss how enterprises can deal with a risk that has been in the news on a daily basis: data breaches and advanced persistent threats. With these risks quickly becoming board-level concerns, enterprises should have a plan in advance of a data breach and know what happens after a data breach. The discussion will include:

  • Internal and forensics investigations;
  • Inquiries from governmental entities, including State Attorneys General and the Federal Trade Commission; and
  • Insurance coverage that could apply to help defray the costs related to getting the breach or threat resolved.

This webcast will be interactive with an opportunity for Q&A with our speakers.

DATE
Friday, June 21, 2013
2:00 PM – 3:00 PM ET

SPEAKERS
Scott Godes, co-chair of the American Bar Association’s Computer Technology Subcommittee of the Insurance Coverage Litigation Committee
Brian Finch, Global Security Practice Leader, Dickstein Shapiro LLP
Divonne Smoyer, Partner, State Attorneys General Practice, Dickstein Shapiro LLP; IAPP Certified Information Privacy Professional
Jim Jaeger, Vice President, Cybersecurity Services, General Dynamics Fidelis Cybersecurity Solutions

REGISTER
Please click here to register for this complimentary program.

Disclaimer:

This blog is for informational purposes only. This may be considered attorney advertising in some states. The opinions on this blog do not necessarily reflect those of the author’s law firm and/or the author’s past and/or present clients. By reading it, no attorney-client relationship is formed. If you want legal advice, please retain an attorney licensed in your jurisdiction. The opinions expressed here belong only the individual contributor(s). © All rights reserved. 2013.

The materials in this message are provided for informational purposes only and do not constitute legal advice. In some states, this email message may be considered advertising. Please see Dickstein Shapiro’s full disclaimer.

Copyright Dickstein Shapiro LLP 2013. All Rights Reserved.  Reposted with permission.

Advertisements

Join me for the ABA Insurance Coverage Litigation Committee’s 2013 Annual CLE Seminar in Tucson, Arizona!

Tucson skyline and Catalina Mountains at duskWinter got you down?  Want to get away to someplace warm and dry?  Do you want to learn about insurance coverage, mingle with insurance coverage practitioners, and get continuing legal education (CLE) credits while you are enjoying the weather?  Of course you do.  Insurance coverage is crucial at any time, and you know that insurance coverage during the economic downturn is essential.  And if you are an attorney licensed in a jurisdiction that requires CLE credits, aren’t you always on the lookout for high quality legal education seminars that will help you meet your CLE annual requirements?

If you said yes to any of those questions, then you’ll want to join me in Tucson, Arizona at the Loews Ventana Canyon Resort for the ABA’s 2013 Insurance Coverage Litigation Committee (ICLC) CLE seminar, from February 28 through March 2, 2013 in Tucson, Arizona.

Here’s what the ABA ICLC says about the seminar:

Please join the nation’s top insurance and policyholders’ counsel and other industry leaders at the Insurance Coverage Litigation Committee’s 25th Anniversary CLE Seminar at the Loews Ventana Canyon Resort in Tucson, Arizona starting on February 28 through March 2, 2013. This year’s program will feature high-quality presentations and valuable networking opportunities as prior ICLC programs. Our program chairs Suzan Charlton and Rahul Karnani and vice chairs, Anna Torres and Jim Cooper have put together a great program touching on multiple hot topics that are sure to touch upon your practice, and cutting edge trial techniques. Please look for the brochure shortly and be sure to reserve you room quickly.  If you missed last year’s meeting, you will certainly enjoy the amenities at the Loews including its hiking trails, pool side bar and restaurant, spa and golf course.  We look forward to seeing you in Tucson.

You ABA Section of Litigation Insurance Coverage Litigation Co-Chairs,

Ronald L. Kammer and Sherilyn Pastor

I will be speaking at a roundtable discussion about cyber legislation and regulation, and insurance coverage for those issues.  Will we discuss issues such as the Securities and Exchange Commission’s (SEC) Corporation Finance’s Disclosure Guidance Topic No. 2, Cybersecurity and insurance coverage in light of that guidance?  Come to the session and find out!:

Friday, March 1, 2013
12:35 pm – 2:00 pm

Cyber Legislation and Regulation: The Full Employment for Lawyers Acts.

Speakers:

Scott N. Godes

Rick Bortnick

Elissa Doroff

Interested in attending?  Then head on over to the ABA’s website to register.  If you’re looking for the reservations page for the event on the Loews Ventana Canyon hotel website, you can find it by clicking here.

Disclaimer:

This blog is for informational purposes only. This may be considered attorney advertising in some states. The opinions on this blog do not necessarily reflect those of the author’s law firm and/or the author’s past and/or present clients. By reading it, no attorney-client relationship is formed. If you want legal advice, please retain an attorney licensed in your jurisdiction. The opinions expressed here belong only the individual contributor(s). © All rights reserved. 2013.

myspace profile views counter

“Cybersecurity: Does Your Company Have Insurance For Claims Arising Out Of An Alleged Data Breach?”

HospitalityLawyer e-magazine recently published an article that my former colleague, Ken Trotter, and I wrote regarding insurance coverage for data breaches and cybersecurity risks.  It’s in the November 2012 edition of the magazine.  We discuss risks relating to data breaches, cybersecurity, and privacy, as well as what insurance might apply to provide coverage for those risks.  The article is focused on cyberrisks and insurance coverage for the hospitality industry.

The article’s lede is:

Cybersecurity risks, including data breaches, are among the most significant risks facing any company in the hospitality industry that receives what may be characterized as personally identifiable information, including credit card information.  When hackers, rogue current or former employees, or others steal or otherwise gain access to such personally identifiable information, the data breach may expose the company to liabilities under statutory and regulatory schemes and to third parties, resulting in significant costs to mitigate, remediate, and comply with the obligations arising out of the liabilities.

We then discuss insurance coverage for data breaches, cybersecurity risks, and other privacy-based risks.  We analyze coverage under commercial general liability (CGL) insurance policies and crime insurance policies, and provide comments and pointers regarding the scope of coverage under cyberinsurance policies.

If you are interested in reading the entire article, please click here and check out the article starting on page 8.

An archived version of the article, via the Internet Wayback machine, may be found here.

Disclaimer:

This blog is for informational purposes only. This may be considered attorney advertising in some states. The opinions on this blog do not necessarily reflect those of the author’s law firm and/or the author’s past and/or present clients. By reading it, no attorney-client relationship is formed. If you want legal advice, please retain an attorney licensed in your jurisdiction. The opinions expressed here belong only the individual contributor(s). © All rights reserved. 2014.

myspace profile views counter

My Co-Authored Chapter, “Helping Clients Evaluate Their Cyber Risks” Just Published In “Understanding Developments in Cyberspace Law, 2012 ed.”!

I’m happy to announce that the chapter that I co-authored with Mike Tomasulo, who practices intellectual property law in our firm‘s Los Angeles office, was published in “Understanding Developments in Cyberspace Law, 2012 ed.: Leading Lawyers on Analyzing Recent Trends, Case Laws, and Legal Strategies Affecting the Internet Landscape (Inside the Minds) New Edition.”

Here is a brief overview of what’s in the book, Understanding Developments in Cyberspace Law, 2012 ed.: Leading Lawyers on Analyzing Recent Trends, Case Laws, and Legal Strategies Affecting the Internet Landscape (Inside the Minds) New Edition:
This Aspatore legal title provides an authoritative, insider’s perspective on recent cases and legislation that are influencing the Internet. Written by partners from some of the nation’s leading law firms, this book examines current issues such as privacy, intellectual property, and data security. From mobile commerce to social media, these experts analyze the ways in which cyberspace demands new legal perspectives. In addition, these top lawyers discuss e-discovery issues and the best methods for helping clients protect themselves in a rapidly growing electronic environment.
For more information on the entire book, please check out the Summary of Contents.
Here is an excerpt from the introduction to our chapter:

Due to the increasing implementation of connected computer systems, courts and legislators around the world are creating Internet law, also known as cyber law, on a daily basis. . . .  Among many issues in cyber law, property rights are one of the most conceptually challenging issues that attorneys must assist their clients with. . . .

The chapter  discusses multiple cyber-related topics, including:

I.  Trends in Cyberspace Law

II.  Legislation and Rulings Impacting Cyber Law Issues

III.  The Intersection of Insurance and Cyber Risks

IV.  Patent Issues and Litigation in Cyberspace 

V.  Contracting in Cyberspace Media 

VI.  Understanding Cyber Law in Other Jurisdictions 

We conclude the chapter with some key takeaways for companies facing these risks.
Here are more details about the book, click here.  Ordering information is below:
ISBN-13: 9780314285249
Last Updated: 6/29/2012
Availability: In Stock
List Price:
$90.00

Disclaimer:

This blog is for informational purposes only. This may be considered attorney advertising in some states. The opinions on this blog do not necessarily reflect those of the author’s law firm and/or the author’s past and/or present clients. By reading it, no attorney-client relationship is formed. If you want legal advice, please retain an attorney licensed in your jurisdiction. The opinions expressed here belong only the individual contributor(s). © All rights reserved. 2012.

myspace profile views counter

Insurance for Cyber Risks: Coverage Under CGL and “Cyber” Policies

Recently, I gave a presentation, along with Rick BortnickJennifer SmithWilliam T. Um, and Hon. Carl West (Ret.), about cyber risks, privacy class action claims, and insurance coverage for cybersecurity claims, cyber risks, privacy claims and privacy class actions, and other emerging risks.  We discussed these claims and we gave our thoughts about insurance coverage for cyber risks under cyberinsurance policies, as well as under Commercial General Liability policies (CGL), commercial crime policies, first party property and all risks policies, directors and officers policies (D&O), errors and omissions policies (E&O), and more.

As part of the presentation, Jennifer and I submitted a paper, Insurance for Cyber Risks:  Coverage Under CGL and “Cyber” Policies.  A nicely formatted version may be found here, hosted by Lockton.

ABA Section of Litigation 2012 Insurance Coverage Litigation Committee CLE Seminar,

March 1-3, 2012:
Insurance coverage for data breaches, denial of service attacks, and cybersecurity events

Insurance for Cyber Risks:
Coverage Under CGL and “Cyber” Policies

Scott Godes, Esq.
[formerly] Dickstein Shapiro LLP

Washington, DC

Jennifer G. Smith, Esq.
Lockton Companies

Washington, DC

THE RISE IN CYBER RISKS

It may seem like a few years ago, every firm had a Y2K practice, and was prepared to provide advice and counseling about how to handle the anticipated end of the world.  Luckily for society at large, the worst case scenario was not realized.  Just a few years later, the focus on liability and risks as related to computers and network security has changed to another, but far more real, issue:  the risk of data breaches, hacks, network interruptions, and other cyber risks.  The number of data breaches and cyber attacks that companies and other entities have faced has been so widespread and expensive that 2011 was dubbed “the year of the cyber attack.”  A recent PricewaterhouseCoopers report characterized “Cybercrime . . . as one of the top four economic crimes.”

Two of the most well-known cyber risks are cyber attacks and data breaches.  One form of cyber attack is a denial of service incident.  Denial of service attacks may be designed to bring a website or service down, preventing customers from accessing the site or the company’s products or services.  One research and development center has explained that denial of service attacks come in a variety of forms.  The three basic types of denial of service attacks are:

  • consumption of scarce, limited, or non-renewable resources;
  • destruction or alteration of configuration information;
  • and physical destruction or alteration of network components.

Some attacks are comparable to “tak[ing] an ax to a piece of hardware” and may be called “permanent denial-of-service (PDOS) attack[s].”  If a system suffers such an attack, which also has been called “pure hardware sabotage,” it “requires replacement or reinstallation of hardware.”

Another cyber risk, perhaps more widely discussed in the news, is a data breach.  The term data breach is used broadly, usually to describe incidents in which hackers, rogue current or former employees, or others steal or otherwise gain access to personally identifiable information or personal health information.  For example, in Anderson v. Hannaford Brothers Co., the court described a data breach against “a national grocery chain whose electronic payment processing system was breached by hackers . . . [with] hackers [having] stole[n] up to 4.2 million credit and debit card numbers, expiration dates, and security codes . . . .”

In the context of personal health information, “[U.S. Department of Health and Human Services] HHS issued regulations requiring health care providers, health plans, and other entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals when their health information is breached.”  HIPAA imposes liability immediately for breaches of certain information by certain parties; the requirements state that the entity “shall” provide notice, and do not make reference to a letter from the government or a lawsuit to enforce the law.  When a “violation is not corrected . . . a penalty” may be imposed that is $50,000 for each violation, up to $1,500,000 in a calendar year, rather than $10,000 and a cap of $250,000.

Setting the legal and enforcement issues aside, consider certain business issues that may motivate an organization to choose  insurance as a risk transfer solution:

  • Loss of assets, brand, and reputation.
  • Investor fallout from uncovered losses with large claim and class action potential.
  • Many functions are conducted by outside vendors and contractors who may lack insurance and assets to respond. What if the vendor makes a systemic mistake? What if they fail to purchase insurance or keep it? What if they are located in a country where this insurance cannot be obtained? What if the policy they purchased denies coverage or has inadequate limits?
  • PCI (credit card industry security standards) compliant companies have had their security compromised from processes lapse, human error, or criminal insider.
  • No system can be designed to eliminate the potential for loss, as people and processes failures cannot be eliminated. Insiders may be perpetrators.
  • Responsibility rests with the data owner from a legal, regulatory perspective, and credit card association operating regulations.
  • Insurance companies have become more aggressive in asserting (even if wrongfully so) that “traditional” insurance may not cover security liability or adequately cover privacy risks.

COVERAGE UNDER CGL POLICIES

Policyholders and insureds facing cyber risks and liabilities would be well served to analyze their entire slate of insurance policies to determine what coverages might apply to such risks.  Indeed, the Division of Corporation Finance of the U.S. Securities and Exchange Commission recently released “CF Disclosure Guidance:  Topic No. 2 – Cybersecurity.”  That guidance, in the context of cyber risks, notes insurance coverage for such risks, stating:  “Depending on the registrant’s particular facts and circumstances, and to the extent material, appropriate disclosures may include: . . . [a d]escription of relevant insurance coverage.”

Is there coverage for cyber risks under a “standard form” commercial general liability (“CGL”) insurance policy, one with insuring agreements drafted by the Insurance Services Office (“ISO”)?  That question is at issue at the time of this writing between Zurich (among other insurance companies) and various Sony entities in litigation.  In 2011, Sony allegedly suffered various cyber attacks and data breaches, with the events allegedly costing Sony nine figures, and leading to multiple putative class action lawsuits against various Sony entities.  Seeking to avoid defending or indemnifying Sony, Zurich filed an action against Sony, seeking declarations that there is no coverage under various CGL policies, among other requests for rulings.

Zurich itself had recognized, in at least one article, that “[t]hird-party liability policies such as Commercial General Liability (CGL) policies provide coverage to a company . . . for data security breaches.”

Standard form CGL policies often provide coverage for personal and advertising injury, bodily injury, and property damage.  “Personal and advertising injury” has several definitions; but for purposes of data breaches and cyber risks, one relevant definition is “[o]ral or written publication, in any manner, of material that violates a person’s right of privacy.”  The term “bodily injury” often is defined as including “bodily injury, sickness or disease . . . including death resulting . . . at any time.”  When analyzing the scope of bodily injury coverage in the context of cyber risks, however, consider whether the definition of “bodily injury” has been expanded to include mental anguish, mental injury, shock, fright, or similar terms.  “Property damage” in standard form CGL policies often includes “[p]hysical injury to tangible property, including all resulting loss of use of that property” and “[l]oss of use of tangible property that is not physically injured,” but often states that “electronic data is not tangible property.”

The leading case addressing these issues held that personal and advertising injury coverage was available for computer- and internet-based class action claims.  In Netscape Communications Corp. v. Federal Insurance Co., the U.S. Court of Appeals for the Ninth Circuit’s brief (and unpublished) opinion, along with the earlier trial court opinion that the Ninth Circuit reversed, illustrates that Netscape Communications Corporation (“Netscape”) was sued in putative class action lawsuits regarding a software program that provided Netscape with information about users’ internet activities and which Netscape used for targeted advertising.  The claimants alleged that Netscape’s program violated the Electronic Communications Privacy Act (“ECPA”) and the Computer Fraud and Abuse Act (“CFAA”).  The court held that “[a]lthough the underlying claims against AOL were not traditional breach of privacy claims, given that coverage provisions are broadly construed, the underlying complaints sufficiently alleged that AOL had intercepted and internally disseminated private online communications.”

With a dearth of cases interpreting publication in the cybersecurity context, it is helpful to consider analogous cases.  In Zurich American Insurance Co. v. Fieldstone Mortgage Co., a leading case on the issue, the insurance company argued “that in order to constitute a publication, the information that violates the right to privacy must be divulged to a third party.”  The court correctly rejected that argument, explaining that “the majority [of circuits] have found that the publication need not be to a third party.”  Other courts have followed the well-reasoned Fieldstone decision, finding that unauthorized access of credit reports meets the publication requirement under the relevant personal and advertising injury provisions.

Those holdings are critical in the context of data breaches.  Data breaches, as noted above, consist of situations in which private information has been publicized to third parties.  Therefore, the basic insuring agreement relating to personal and advertising injury should be considered broad enough to encompass a data breach.

To the extent that CGL policies have broadened definitions of bodily injury, there may be an argument that bodily injury coverage applies to, or (at a minimum) provides a defense for, data breach claims.  For example, one of the class action complaints filed against Sony alleges that “plaintiff and the Class have suffered damages, including, but not limited to, . . . fear and apprehension of fraud . . . .”  Such an allegation could be read as falling within an expanded definition of “bodily injury,” depending on how broadly the definition is written and whether it is construed as being tied to a physical bodily injury from the rest of the definition of the term.

The potential application of property damage coverage may be a more fact specific inquiry in the context of cyber risks.  For those policies excluding “electronic data” from the definition of “property damage,” convincing an insurer that a data breach alone caused covered property damage, or gives rise to a duty to defend under property damage coverage, will be challenging for policyholders and insureds.  Nonetheless, certain cyber attacks may result in property damage in the form of physical damage to tangible property.  For example, certain denial-of-service attacks cause physical destruction or alteration of network components.  If an insured can demonstrate that there were allegations of such damage, or actual evidence of such damage, property damage coverage should apply, as the claim does not implicate software and data alone.

The definition of property damage, in a standard form CGL policy, typically includes “[l]oss of use of tangible property that is not physically injured.”  This phrase presents an opportunity to seek coverage for loss of use of tangible property, such as the loss of use of computers or networks rendered inaccessible or inoperable as a result of a cyber attack.

A real world example is found in the Johns v. Sony complaint.  The putative class alleges that “Plaintiffs seek damages to compensate themselves and the Class for their loss (both temporary and permanent) of use of their PlayStation consoles . . . .”  Those loss of hardware use allegations should be considered loss of use of tangible property for purposes of pursuing and maximizing any insurance recovery.

In Eyeblaster, Inc. v. Federal Insurance Co., the U.S. Court of Appeals for the Eighth Circuit considered a similar set of allegations.  That dispute involved a complaint in which the claimant “alleg[ed] that Eyeblaster injured his computer, software, and data after he visited an Eyeblaster website.”  The court analyzed the scope of property damage coverage.  After determining that one prong of the property damage definition was not met, because the claimant alleged software and operating system damage, without allegations of damage to hardware, the court then considered whether the loss of use of tangible property prong of property damage was met.  The court held that alleged computer freezes, pop-up ads, hijacked browsers, random error messages, slowed performance and crashes, and ads based on past Internet surfing habits constituted property damage in the form of loss of use of tangible property sufficient for coverage under a CGL policy.  Likewise, in State Auto Property & Casualty Insurance Co. v. Midwest Computers & More, an Oklahoma federal district court held that loss of use of a computer system allegations fell within the loss of use of tangible property terms of the policy.

A final note specific to data breaches is the question of coverage for credit monitoring under CGL policies.  Policyholders and insureds should anticipate that insurance companies will assert that credit monitoring costs are not covered under CGL policies.  One such anticipated argument is that credit monitoring does not consist of “damages” “because of” personal and advertising injury, bodily injury, or property damage.  Policyholders and insureds should note that courts have rejected similar insurance company arguments in analogous contexts.  For example, class action plaintiffs have alleged that certain products (such as asbestos or lead paint) cause bodily injury at the cellular level, and, as such, they are entitled to the cost of medical monitoring that would allow said plaintiffs to know whether they will develop a cognizable injury or disease.  For those decisions recognizing the underlying claim alleges a covered claim, those decisions have recognized that medical monitoring costs are “damages” “because of” bodily injury.  That authority should be considered a persuasive basis in response to anticipated insurance company arguments that credit monitoring costs are excluded from coverage.

COVERAGE UNDER “CYBER” POLICIES

No doubt countless side-by-side coverage comparisons have been lost in the land of good intentions trying to delineate the distinctions between CGL, property, and cyber insurance solutions.  There are solid arguments that there is coverage for cyber risks under the insuring agreements within a standard ISO form CGL policy.  Likewise, policyholders have had some success in arguing that coverage may be afforded under the Computer Funds Transfer, Theft or Employee Theft/Dishonesty insuring agreements within a Fidelity and/or Commercial Crime program.  There also are solid arguments that coverage for private companies may provide coverage (specifically entity coverage) for cyber-related losses under a private company Directors & Officers Liability insurance program.  Notwithstanding those solid arguments and favorable case decisions, policyholders found themselves facing denials or in insurance coverage litigation to determine whether a CGL or other insurance policy will cover a data breach or other cyber event.

What is the solution then, for those organizations that are concerned with insurance companies taking aggressive positions as to coverage under CGL or other policies for cyber risks in the wake of a data breach or other cyber event?  Insurance companies now are marketing stand-alone, dedicated insurance policies as being designed to address information risk.  Those insurance policies should provide the solution.

Many refer to this solution as “cyber insurance.”  Cyber insurance is a coat of many colors, with as many product names as there are colors of the rainbow.  Other variations include:  Information Security Insurance, Network Security Insurance, Privacy Insurance, Data Breach Insurance, Network Breach Insurance, Technology Solutions, Cyber-this, Cyber-that (e.g., “plus”, “enhancement”, “solution”), Information Insurance, or, when all else fails, some iteration of Professional Liability or E&O – seemingly irrespective of the buyer’s actual services.  For the purposes of this article and to avoid calling attention to any one particular insurer, we will continue to refer to this solution as “cyber insurance.”

Although the expression “no two forms are alike” may be a stretch under other circumstances, it is painfully, tediously true in the cyber insurance context.  These forms vary vastly from the fundamental structure and scope of the policy to the retention and use of outside experts.  Certain policies are duty to defend policies; others are indemnity policies.  Certain policies have specifically delineated intentional torts drafted into the definition of “personal injury” or “wrongful act”; other policies – perhaps in an effort to avoid changing forms amid rapidly evolving regulations – leave such definitions or insuring agreements rather broadly defined.  Some might even argue “vague and ambiguous.”  Each of these issues, and the many others not listed herein, serves as a reminder to potential buyers to rely on their experts in the search for the best cyber insurance solution for that particular organization.

The core elements of cyber insurance that are unique to this particular insurance solution may include coverage in varying degrees for the following:

  • Network Security Liability
    • Claim Expenses and Damages emanating from Network and non-Network security breaches.
  • Media Liability
    • Claim Expenses and Damages emanating from Personal Injury Torts and Intellectual Property Infringement (except Patent Infringement).
    • Claim Expenses and Damages emanating from Electronic Publishing (website) and some will provide coverage for all ways in which a company can utter and disseminate matter.
  • Privacy Liability
    • Claim Expenses and Damages emanating from violation of a Privacy Tort, Law or Regulation.
    • Claim Expenses and Damages emanating from a violation of a law or regulation arising out of a Security Breach.
  • Privacy Regulatory Proceeding and Fines
    • Claim Expenses in connection with a Privacy Regulatory inquiry, investigation or proceeding.
    • Damages/Fines related to a Consumer Redress Fund.
    • Privacy Regulations Fines.
    • PCI Fines.
  • Privacy Event Expense Reimbursement
    • Expense reimbursement for third party forensics costs.
    • Public Relations costs.
    • Legal.
    • Mandatory Notification Costs (Compliance with Security Breach Notification Laws) and Voluntary Notification Costs.
    • Credit Monitoring.
    • Call Center.
    • Second Security Audits required by Financial Institutions (varies by market).
  • Data/Electronic Information Loss
    • Covers the cost of recollecting or retrieving data destroyed, damaged or corrupted due to a computer attack.
  • Business Interruption or Network Failure Expenses
    • Covers cost of lost net revenue and extra expense arising from a computer attack and other human-related perils.  Especially valuable for computer networks with high availability needs.
  • Cyber-Extortion
    • Covers both the cost of investigation and the extortion demand amount related a threat to commit a computer attack, implant a virus, etc.

Also significant, and perhaps unique to the cyber insurance market, is the rapid rate at which the underwriters have modified and/or enhanced their forms. Issues like contractual liability/indemnification, mandatory versus voluntary notification, and even the defining triggers under the policy(ies) appear to change every 18 months – with new product introductions every six months.  Again, buyers are encouraged to carefully review the different program terms and conditions, so that they can prioritize and weigh their coverage needs against the solutions offered by the underwriters.

Although sorting through various cyber insurance solutions may be a daunting task to first-time buyers, it is worth repeating that insurance companies market this solution as being designed expressly to contemplate information risk, including data privacy and network security.  A properly designed insurance solution may very well pre-empt a difficult explanation to senior management after a cyber loss, a much more favorable position to be in than explaining why the policyholder’s insurance companies have sued the policyholder, simply because the policyholder put the insurance company on notice.

Disclaimer:

This blog is for informational purposes only. This may be considered attorney advertising in some states. The opinions on this blog do not necessarily reflect those of the author’s law firm and/or the author’s past and/or present clients. By reading it, no attorney-client relationship is formed. If you want legal advice, please retain an attorney licensed in your jurisdiction. The opinions expressed here belong only the individual contributor(s). © All rights reserved. 2012.


Join me at the 2012 NetDiligence® Cyber Risk & Privacy Liability Forum.

My good friends at HB Litigation Conferences present:

NetDiligence® Cyber Risk & Privacy Liability Forum
June 4-5, 2012| Hyatt at the Bellevue, Philadelphia, PA

I’ll be a speaker on a panel discussing the “State of the Cyber Nation – Cases, Theories, and Damages”:

State of the Cyber Nation – Cases, Theories, and Damages
•Is actual harm still needed?
•Statutory framework – CMIA litigation, Video Protection Privacy Act, and the Driver’s Privacy Protection Act
•Notable recent cases and their impact
•Current theories of liability and claims alleged
•How to present damages in this era
•How to minimize the chance of litigation after a breach and settlement opportunities
•More sophisticated defenses
•Identity Theft Restoration Act-suing hackers?  How federal courts may change the game
•Medical disclosure cases and how they fit into the mix
•Developments in insurance coverage for cyber and privacy risks

Theodore Kobus III, Esq., Baker & Hostetler LLP (Moderator)
John Mullen Sr., Esq., Nelson Levine de Luca & Horst, LLC
Scott Godes, Esq, [formerly] Dickstein Shapiro
Jamie Sheller, Esq.
, Sheller P.C.
Mark Camillo, Chartis Insurance
Ben Barnow, Esq., Barnow & Associates, P.C.

Take a look at the full agenda by clicking here.  And you can register online by clicking here.

Disclaimer:

This blog is for informational purposes only. This may be considered attorney advertising in some states. The opinions on this blog do not necessarily reflect those of the author’s law firm and/or the author’s past and/or present clients. By reading it, no attorney-client relationship is formed. If you want legal advice, please retain an attorney licensed in your jurisdiction. The opinions expressed here belong only the individual contributor(s). © All rights reserved. 2011.

Note:  as a speaker at the conference, I was not charged a fee to attend the remainder of the conference.
myspace profile views counter

Join me for the IRMI Cyber & Privacy Risk Conference.

IRMI Cyber & Privacy Risk Conference.  Mark your calendar to join us in Baltimore, MD on May 16-17, 2012.

Noted cybersecurity, homeland and national security expert Richard A. Clarke will deliver the keynote address.

Discussing the last IRMI Cyber & Privacy Risk Conference, IRMI notes:

This past July in San Francisco, 100 risk managers, underwriters, agents and brokers attended the first IRMI Cyber & Privacy Risk Conference.

These industry thought leaders came away with a greatly improved understanding of how to identify, contractually transfer, and insure liability risks arising from the use of technology and the Internet in business. Many networking opportunities were provided to build relationships with leaders in cyber and privacy risk management and insurance.

My session will be:

Wednesday, May 16, 10:45 a.m. – 12:15 p.m.

The Cyber Risk Regulatory and Legal HorizonAs the web of laws and regulatory requirements increases, managing the risks of cyber security becomes even more challenging. On top of the multitude of state laws, the SEC recently released reporting requirements and Congress is set to take up a number of bills during 2012. This workshop will provide an overview the range of laws and regulations in place and explore the new legislative developments affecting cyber insurance and risks, as well as the reporting requirements issued recently by the SEC.

Panelists:

  • Scott N. Godes, Counsel in the Insurance Coverage Practice, [formerly] Dickstein Shapiro LLP
  • Jacob Olcott, Principal, Cybersecurity, Good Harbor Consulting, LLC
  • Tim Stapleton, Assistant Vice President and Professional Liability Product Manager, Zurich North America
  • Other Panelists To Be Announced

Interested in attending?  Then head on over to the RIMS 2012 website to register.

Disclaimer:

This blog is for informational purposes only. This may be considered attorney advertising in some states. The opinions on this blog do not necessarily reflect those of the author’s law firm and/or the author’s past and/or present clients. By reading it, no attorney-client relationship is formed. If you want legal advice, please retain an attorney licensed in your jurisdiction. The opinions expressed here belong only the individual contributor(s). © All rights reserved. 2012.

Note:  as a speaker at the conference, I will not be charged a fee related to the conference.

myspace profile views counter

« Older Entries