navigating a cybersecurity insurance policy webinar ppt...aug 24, 2016  · the court held that fear...

76
© Copyright 2015 by K&L Gates LLP. All rights reserved. NAVIGATING A CYBERSECURITY INSURANCE POLICY August 24, 2016

Upload: others

Post on 31-May-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

© Copyright 2015 by K&L Gates LLP. All rights reserved.

NAVIGATING A CYBERSECURITY

INSURANCE POLICY

August 24, 2016

Page 2: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Introduction

Practical Risk and Exposure

Coverage Under “Cyber” Insurance Products

What the insurance policies typically cover

Pitfalls to avoid when purchasing "cyber" insurance

How to approach a successful "cyber" insurance placement

How to negotiate to enhance the coverage provided under "cyber" insurance

policies

Potential Coverage Under “Traditional” Policies

Potential CGL coverage

Potential coverage under other "traditional" policies

Potential limitations of “traditional” policies

How to Maximize Coverage in the Event of a Claim

AGENDA

9

Page 3: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

rdardardarrrrr

Roberta D. Anderson

Insurance Coverage /

Data Privacy & Cybersecurity

Partner

INTRODUCTION rdardardarrrrr

10

Page 4: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

PRACTICAL RISK AND EXPOSURE

Page 5: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

PRACTICAL RISK AND EXPOSURE

12

• Malicious Attacks

– Advanced Persistent Threats

– Social Engineering

– Viruses, Trojans, DDoS attacks

– Ransomware

• Data Breach/Unauthorized Access

• Software Vulnerability

(Heartbleed)

• System Glitches

• Employee Mobility

• Lost or Stolen Mobile and Other

Portable Devices

• Vendors/Outsourcing

(Function, Not the Liability)

• The Internet Of Things

• Human Error

Page 6: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

klgates.com 13

Page 7: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

14

Page 8: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Source: 2016 Cost of Data Breach Study:

Global Analysis

PRACTICAL RISK AND EXPOSURE

15

Page 9: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

16

Source:

Ponemon Institute LLC

2016 Cost of Data Breach Study:

Global Analysis

Page 12: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

LEGAL AND REGULATORY FRAMEWORK

19

• Federal Cybersecurity/Data Privacy Laws

– HIPAA/HITECH

– GLBA

– FTC Act

• State Cybersecurity/Data Privacy Laws/Consumer Protection Statutes

– 47 States, D.C., & U.S. Territories Breach Notification Laws

– State Security Standards (MA, CA, CT, RI, OR, MD, NV)

• Foreign Laws

• Cross-Border Issues

– Securing data is complicated by cross-border transfer issues and the

differences in Worldwide privacy laws

– Laws are complex and can impose conflicting obligations to a multinational

enterprise.

• NIST Cybersecurity Framework

• Industry Standards, e.g., PCI DSS

• SEC Cybersecurity Risk Factor Guidance

– FCC Act

– FCRA/FACTA

Page 13: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

NIST Cybersecurity Framework—provides a common taxonomy and

mechanism for organizations to:

Describe their current cybersecurity posture;

Describe their target state for cybersecurity;

Identify and prioritize opportunities for improvement within the

context of a continuous and repeatable process;

Assess progress toward the target state;

Communicate among internal and external stakeholders about

cybersecurity risk.

The Framework is voluntary (for now)

NIST CYBERSECURITY FRAMEWORK

20

Page 15: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

“PCI DSS provides a baseline of technical and operational

requirements designed to protect cardholder data.”

PCI-DSS

22

Page 16: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

“[A]ppropriate disclosures may include”:

“Discussion of aspects of the registrant’s business or operations that give rise to

material cybersecurity risks and the potential costs and consequences”;

“To the extent the registrant outsources functions that have material cybersecurity

risks, description of those functions and how the registrant addresses those risks”;

“Description of cyber incidents experienced by the registrant that are individually, or

in the aggregate, material, including a description of the costs and other

consequences”;

“Risks related to cyber incidents that may remain undetected for an extended

period”; and

“Description of relevant insurance coverage.”

SEC CYBERSECURITY

Cybersecurity: Five Tips to Consider When Any Public Company Might be the Next Target,

http://media.klgates.com/klgatesmedia/epubs/GBR_July2014/

23

Page 17: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

SEC CYBERSECURITY

“We note that your network-security insurance coverage is

subject to a $10 million deductible. Please tell us whether

this coverage has any other significant limitations. In

addition, please describe for us the ‘certain other coverage’

that may reduce your exposure to Data Breach losses”

Target Form 10-K (March 2014)

24

Page 18: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

SEC CYBERSECURITY

“We note your disclosure that an unauthorized party was

able to gain access to your computer network ‘in a prior

fiscal year.’ So that an investor is better able to understand

the materiality of this cybersecurity incident, please revise

your disclosure to identify when the cyber incident occurred

and describe any material costs or consequences to you as

a result of the incident. Please also further describe your

cyber security insurance policy, including any material limits

on coverage.”

Alion Science and Technology Corp. S-1 filing (March 2014)

25

Page 19: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

SEC CYBERSECURITY

“Given the significant cyber-attacks that are occurring with

disturbing frequency, and the mounting evidence that

companies of all shapes and sizes are increasingly under a

constant threat of potentially disastrous cyber-attacks,

ensuring the adequacy of a company’s cybersecurity

measures needs to be a critical part of a board of director’s

risk oversight responsibilities . . . .

Thus, boards that choose to ignore, or minimize, the

importance of cybersecurity oversight responsibility, do so

at their own peril.”

Luis Aguilar, SEC Commissioner, speech given at NYSE June 10, 2014

26

Page 20: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

27

FTC CYBERSECURITY

Page 21: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

28

FTC CYBERSECURITY

Page 22: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

29

FTC CYBERSECURITY

Page 23: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

• Sony - January 21, 2014 - Standing. The court held that allegations that Sony collected

data and then it was wrongfully disclosed were sufficient to confer

standing

• Galaria - Feb. 10, 2014 - No Standing. The court stated that potential identity

theft could “hardly be said to be certainly impending” where there was

“less than a 20% chance of it occurring,” and the harm depended entirely on

what, if anything, third-party criminals would do with the plaintiffs’ information

• SAIC - May 9, 2014 - No Standing. The court held that fear of identity theft was insufficient

to confer standing

• Michael’s - July 14, 2014 - Standing. The court held that an elevated risk of

identity theft was sufficient to confer standing, but dismissed the case because

the plaintiffs failed to allege any actual damages.

• Adobe - September 4, 2014 - Standing. The court held that the risk that the plaintiffs’

information would be misused was sufficient to confer standing.

• Neiman Marcus - September 16, 2014 - No Standing. “Plaintiffs have not

alleged that any of the fraudulent charges were unreimbursed. On these

pleadings, I am not persuaded that unauthorized credit card charges for

which none of the plaintiffs are financially responsible qualify as ‘concrete’ injuries.”

STANDING TREND – TARGET

30

Page 24: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

STANDING TREND – SONY

31

Page 25: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

STANDING TREND – MICHAELS

32

Page 26: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

STANDING TREND – ADOBE

33

Page 27: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

STANDING TREND – TARGET

34

Page 28: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

COVERAGE UNDER “CYBER”

INSURANCE PRODUCTS

Page 29: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

klgates.com back

REMEMBER THE

SNOWFLAKE

Page 30: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Privacy and Network Security

Generally Covers Third-Party Liability Arising from Data Breaches and Other Failures to

Protect Confidential, Protected Information, as well as Liability Arising from Security

Threats to Networks, e.g., Transmission of Malicious Code

Regulatory Liability

Generally Covers Amounts Payable in Connection with Administrative or Regulatory

Investigations

PCI-DSS Liability

Generally Covers Amounts Payable in Connection with PCI Demands for Assessments,

Including Contractual Files and Penalties, for Alleged Non-compliance with PCI Data

Security Standards

Media Liability

Generally Covers Third-Party Liability Arising From Infringement of Copyright and Other

Intellectual Property Rights, and Torts Such as Libel, Slander, and Defamation Arising

From the Insured's Media Activities, e.g., Broadcasting and Advertising

THIRD-PARTY COVERAGE

37

Page 31: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Crisis Management

Generally Covers “Crisis Management” Expenses That Typically Follow in the Wake of a

Breach Incident, e.g., Breach Notification Costs, Credit Monitoring, Call Center Services,

Forensic Investigations, and Public Relations

Network Interruption

Generally Covers First-Party Business Income Loss Associated with the Interruption of

the Insured’s Business Caused by the Failure of Computer Systems

Digital Asset

Generally Covers First-Party Cost Associated with Replacing, Recreating, Restoring and

Repairing Damaged or Destroyed Programs, Software or Electronic Data

Extortion

Generally Covers Losses Resulting From Extortion, e.g., Payment of an Extortionist’s

Demand to Prevent a Cybersecurity Incident

Reputational Harm

FIRST-PARTY COVERAGE

38

Page 32: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

First-Party Property Damage and Business Interruption

Third-Party Bodily Injury and Property Damage

[T]his policy will drop down and pay Loss caused by a Security Failure [a failure or

violation of the security of a Computer System that: (A) results in, facilitates or fails

to mitigate any: (i) unauthorized access or use; (ii) denial of service attack; or (iii)

receipt, transmission or behavior of a malicious code] that would have been covered

within an Underlying Policy, as of the inception date of this policy, had one or more

of the following not applied:

A. a Cyber Coverage Restriction [a limitation of coverage in an Underlying

Policy expressly concerning, in whole or in part, the security of a Computer

System (including Electronic Data stored within that Computer System)];

and/or

B. a Negligent Act Requirement. [a requirement in an Underlying Policy that

the event, action or conduct triggering coverage under such Underlying

Policy result from a negligent act, error or omission]

$350M Capacity First-Party

$100M Capacity Third-Party

DIC COVERAGE

39

Page 33: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

klgates.com

AVOID THE TRAPS

Page 34: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

41

Page 35: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

42

POLICY EXAMPLE 1

Page 36: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 2

43

Page 37: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

44

POLICY EXAMPLE 2

Page 38: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

45

Page 39: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 1

46

Page 40: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 1

47

Page 41: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 2

48

Page 42: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 2

49

Page 43: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 3

50

Page 44: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 3

51

Page 45: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

52

Page 46: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 1

53

Page 47: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 1

54

Page 48: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 2

55

Page 49: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 2

56

Page 50: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

57

Page 51: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE

Any member of the “Control Group.” e.g., CEO, CFO ,RM, CRO, CIO, GC

58

Page 52: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,
Page 53: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 1

60

Page 54: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 2

61

Page 55: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POLICY EXAMPLE 3

62

Page 56: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Request a “Retroactive Date”

of At Least a Year

63

Page 57: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

BEWARE THE

FINE

PRINT

64

Page 58: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

BEST PRACTICES CHECKLIST

• Embrace a Team Approach

• Understand the Risk Profile

• Review Existing Coverages

• Purchase Appropriate Other

Coverage as Needed

• Remember the “Cyber”

Misnomer

• Spotlight the “Cloud”

• Remember the Retro Date

• Selection of Counsel and Vendors

• Engage a Knowledgeable Broker

and Outside Counsel

• Carefully Review the Application

65

Page 59: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

“A well drafted policy will

reduce the likelihood that

an insurer will be able to

avoid or limit insurance

coverage in the event of a

claim.”

Roberta D. Anderson, Partner, K&L Gates LLP (August 24, 2016)

66

Page 60: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POTENTIAL COVERAGE UNDER

“TRADITIONAL” POLICIES

Page 61: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Coverage B Provides Coverage for Damages Because of

“Personal and Advertising Injury”

“Personal and Advertising Injury”: “[o]ral or written publication,

in any manner, of material that violates a person’s right of

privacy”

What is a “Person’s Right of Privacy”?

What is a “Publication”?

Does the Insured Have to “Do” Anything Affirmative And Intentional to Get

Coverage?

POTENTIAL COVERAGE

UNDER CGL POLICIES

68

Page 62: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Coverage A Provides Coverage for Damages Because of

“Property Damage”

“Property Damage”: “Loss of use of tangible property that is

not physically injured”

POTENTIAL COVERAGE

UNDER CGL POLICIES

69

Page 63: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Directors’ and Officers’ (D&O)

Errors and Omissions (E&O)/Professional Liability

Employment Practices Liability (EPL)

Fiduciary Liability

Crime

Retail Ventures, Inc. v. National Union Fire Ins. of Pittsburgh, Pa., 691 F.3d 821

(6th Cir. 2012) (DSW covered for expenses for customer communications, public

relations, lawsuits, regulatory defense costs, and fines imposed by Visa and

Mastercard under the computer fraud rider of its blanket crime policy)

Property

Commercial General Liability (CGL)

COVERAGE UNDER OTHER

“TRADITIONAL” POLICIES

70

Page 64: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POTENTIAL LIMITATIONS

71

Page 65: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POTENTIAL LIMITATIONS

72

Page 66: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

ISO states that “when this endorsement is

attached, it will result in a reduction of

coverage due to the deletion of an

exception with respect to damages

because of bodily injury arising out of loss

of, loss of use of, damage to, corruption of,

inability to access, or inability to manipulate

electronic data.”

POTENTIAL LIMITATIONS

73

Page 67: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POTENTIAL LIMITATIONS

74

Page 68: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

POTENTIAL LIMITATIONS

75

Page 69: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

cv

cv

POTENTIAL LIMITATIONS

76

Page 70: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

Zurich American Insurance Co. v. Sony Corp. of America et al.

POTENTIAL LIMITATIONS

77

Page 71: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

HOW TO MAXIMIZE COVERAGE IN

THE EVENT OF A CLAIM

Page 72: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

“Cyber” Policies Impose Time Requirements Regarding Notification

Permissive Notice of Circumstances

Compliance is Important

MANAGING A CLAIM

79

Page 73: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

“Cyber” Policies Impose “Cooperation” Requirements

MANAGING A CLAIM

80

Page 74: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

QUESTIONS

Page 75: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,

THANK YOU

Page 76: NAVIGATING A CYBERSECURITY INSURANCE POLICY webinar PPT...Aug 24, 2016  · The court held that fear of identity theft was insufficient to confer standing • Michael’s - July 14,