We recently did a market search for cyber insurance for a company with high cyber exposure – company outline below for context – and found that the variability around cyber policy terms and conditions remains high.
We thought it might be helpful to share some of our thoughts on what we found.
First, some context.
Company profile: To give a little context, the company (a Canadian company) we were searching for is highly reliant on technology; they are an information services company or, in other words, their product is information. Their value proposition puts them at the centre of a key industry and their customers include large numbers of both individuals and companies. They handle most – but not all – types of personally identifiable information – in reasonably large (but not huge) numbers. Their system is bespoke to them; it is also hosted by them. They do not rely on on-line marketing, so content isn’t a big issue for them and, though they worry their customers could sustain business interruption in the event they were disrupted by a cyber event, the company is not so concerned about business interruption for themselves.
Our search parameters: We concentrated our search in London because the local market was unable to deliver the limits we needed for this company and the coverage they were willing to offer was also too limited. Following a client visit to meet underwriters face-to-face (a trip to Europe for another reason coincided with the beginning of our search), when we met with half a dozen insurers, we obtained quotes we could have bound immediately from 3 markets. We won’t reveal who the markets were to save blushes – and because the point of this post is the importance of reading the small print!
Findings:
1. Coverage
All the policies claimed to offer comprehensive cyber insurance – and all of them had broadly the same insuring clause names. One example of the list of clauses:
A. Data Breach Incident Response
B. Network Security, Privacy & Data Breach Liability
C. Regulatory Liability
D. PCI Fines and Assessments
E. Business Interruption
F. Data Restoration
G. Cyber Extortion
H. Technology Liability
I. Media Liability
Endorsements were also available for:
Reputational Harm
Systems Failure
Contingent System Failure
Social Engineering Fraud
Bricking
The main difference between the different quotes in terms of coverage was the extent of the privacy liability. In one of the policies, privacy liability was limited only to – basically – liability for a data breach, despite the name of the insuring clause which suggested both. The issues around what a company says it is going to do with customer data and what it actually ends up doing (in a world where what we can do with data is changing so fast, makes this coverage, in our opinion, one of the principal reasons to buy cyber insurance) was not covered at all.
The insurers unwillingness to add this coverage eliminated them from further consideration.
2. Exclusions
In the early days of comparing cyber policies, it was in the exclusions (then the definitions) that we found the greatest variability. Over time, inevitably, there has been increasing similarity between different wordings but there are still big differences to look out for. For example:
Reckless or deliberate acts exclusion
We get that a deliberate acts exclusion should apply to a liability policy but to exclude a reckless act is just to exclude the most extreme forms of error that give rise to claims in the first place. And, though an act may seem perfectly reasonable in the heat of the moment, it can be all too easy to recast it as reckless with the benefit of hindsight.
‘Undersized’ security exclusion
We are amazed insures still think they can get away with this exclusion.
For one thing, it has been the subject of litigation (the insurers lost) for ‘bait and switch’ claims against insurers. The argument is that the insurer offered low cost coverage because they knew they could wheel out this exclusion whenever the security turned out not to be enough to prevent a claim.
For another thing – and it is a big issue – what constitutes ‘undersized’ is:
Subjective – clearly any security can be categorized as undersized if it fails to prevent a claim; and
Negotiable – and this is the really big issue we will come back to in another post – which means that a cyber risk manager should be able to make decisions about what to focus on in terms of event prevention, identification and mitigation based on all the tools at their disposal, including insurance. So, if a new firewall configuration is more expensive and harder to implement in operational terms than buying more insurance, the risk manager should be able to make that decision and – to be fair – the insurer should be able to charge for it. Acknowledging that this is not currently possible dynamically because of the nature and form of cyber insurance today, it is still possible to address this as an overarching issue when buying coverage.
Because these exclusions all came from the second insurer’s policy, and they were not willing to remove or edit them, they were discounted from consideration.
3. Retroactive Dates
We advocate that, with the exception of technology and media liability, retroactive dates have no place in a cyber insurance policy. The initial terms we got from all 3 insurers included retroactive date inception.
We advocated for their removal on the basis, for example, that in the event of a cyber extortion threat, where the code encrypting data is introduced some time before inception for a ransom demand made after inception, that a retroactive date of inception excludes all coverage for this demand. The same applies to most other insuring clauses and given most CIOs admit that the only reason any of them say their systems haven’t been penetrated is because they haven’t yet found the penetration, this exclusion is very material to assessing the quality and value of the policy. How long after inception will it take for all insuring clauses to come on line given pre-existing penetrations (among other things) are all excluded?
One insurer was willing to remove all the retroactive dates.
Finally, the company we were searching for has some unique features about them – we won’t go into those here for obvious reasons – but this insurer was also able to re-write their policy to accommodate these issues for us.
One example involved the insurer allowing the company to trigger coverage for data breach notification costs in the event the company decided they needed the coverage – not for legal reasons but because a data breach from their central role in their industry might cause damage to the industry itself – and even then, the insurer further agreed that the company need not actually sustain a loss of income from the data breach before pulling the trigger, which is normally a prerequisite.
Premiums
Finally, the premiums quoted also ranged broadly – from $30k to $65k for the same limit and retentions. The insurer we ended up placing the business with wasn’t the cheapest – but they weren’t the most expensive either. They were the insurer with the best base coverage and the greatest willingness to adapt that coverage to our client’s needs.
