Cyber and Privacy Breach Insurance

Size: px
Start display at page:

Download "Cyber and Privacy Breach Insurance"

Transcription

1 Aon Risk Solutions Financial Services Group Cyber and Privacy Breach Insurance A Risk Transfer Solution for a Growing Liability January 2015 Risk. Reinsurance. Human Resources.

2 Introduction The frequency and severity of cyber and privacy breaches are on the rise. New breaches are being reported worldwide on almost a weekly basis, with over 600 million records in the U.S. containing personal information being reported as involved in a security breach since The Ponemon Institute assessed the average cost of a data breach to U.S. companies at more than $200 per compromised record in Although there is a growing awareness of cyber and privacy data risks, and many companies are taking steps to update their IT security systems, the number of data breaches that remain undiscovered for six months or more continues to increase every year 3. As a result, cyber and privacy security has moved to the forefront of corporate risk concerns. The statistics indicate, and a growing number of organizations are recognizing, that even state-ofthe-art security systems are not failsafe. Therefore, organizations are also looking to cyber and privacy insurance policies to assist in transferring their risk. There are a number of different cyber and privacy policies available in the market and each varies in its wording and sometimes in the coverage provided. The following discussion outlines the type of coverage available to an organization purchasing cyber and privacy insurance, including which matters will likely not be covered by these policies, as well as some policy issues to watch out for. 1. A Chronology of Data Breaches, Privacy Rights Clearinghouse, June U.S. Cost of a Data Breach Study, Ponemon Institute, Data Breach Investigations Report (DBIR), Verizon Business, April 2013

3 Basic cyber and privacy coverage First party coverage Cyber and privacy policies will usually provide coverage for an insured s first party losses associated with the loss, theft or unauthorized disclosure of confidential information. This coverage would include expenses related to breach notification, public relations, credit monitoring, call centre and forensic investigation. In reviewing the first party coverage provided by a cyber and privacy policy, an insured should pay close attention to the language that triggers the coverage. It is not uncommon for cyber policies to require that an insured be legally obligated to notify individuals of a privacy data breach before coverage is available. However, this language could be problematic in Canada, as the majority of provincial privacy statutes do not yet contain a mandatory breach notification requirement. In order for cyber policy coverage to be consistent with Canadian legislation, first party coverage should be provided where an insured chooses to notify individuals of a data breach, even if not legally required to do so. Third party coverage Cyber and privacy insurance policies will also typically contain coverage for an insured s third party losses. This would generally include defence costs and the costs of judgments or settlements. Often network security events that result in third party losses involve hacking, intrusions of malware, malicious code or Trojan software. Yet, there have also been documented cases where an insured has faced a claim for third party damages when a USB key, laptop or other device containing confidential information has been lost. In order to capture all of these scenarios, a policy should provide coverage for third party losses where an insured failed to protect confidential information. Policy coverage that is triggered by unauthorized access to confidential information is not adequate, as it may not capture a scenario where a device containing confidential information is lost or paper records are stolen. Additional cyber and privacy policy features Business interruption coverage Some cyber and privacy policies may provide business interruption coverage for losses that result from the disruption or shutdown of the insured s computer system following a network or security breach. This coverage is sometimes subject to a separate retention. In the alternative, some policies will delay coverage until a certain amount of time has passed following the security or network failure. Ideally, an insured will not be subject to both a retention and a waiting period before business interruption coverage is provided. While the length of the coverage period will vary from policy to policy (60 to 90 days is common) better policies will provide coverage until the insured s computer system is fully restored with an outside time limit of up to a year. The key variables to look for in business interruption coverage include the length of the waiting period, the amount of any retention and the period of coverage. The basic business interruption coverage provided in cyber and privacy policies does not include contingent business interruption, which provides coverage for losses that result when an insured suffers a disruption in their business operations because of a breach to a third party service provider s computer system. Some insurers may offer this added coverage as an option, but it generally requires the payment of an additional premium. This coverage is also usually sublimited and can be difficult and/or expensive to obtain because of the risk to insurers that a breach to a large service provider will impact a number of insureds at the same time. Cyber terrorism State-sponsored cyber attacks are one of the fastest growing sources of external cyber and privacy breaches facing corporations today. Unfortunately, not all cyber and privacy policies have evolved to recognize this growing source of risk and many policies still contain war and terrorism exclusions which might impact coverage for losses resulting from these attacks. Where an insured has experienced a breach and suffered losses that fall within the intended areas of coverage of the policy, it should not matter who launched the attack or whether there were ideological goals behind it. 1 Cyber and Privacy Breach Insurance: A Risk Transfer Solution for a Growing Liability

4 Additional cyber and privacy policy features Some insurers are willing to provide a carveback to these exclusions to clarify that they do not exclude coverage for cyber terrorism. This type of carveback should be included on every cyber and privacy policy containing war, terrorism or other similar exclusions. Sensitive corporate information In the course of business, an insured may store a number of different types of confidential information. This may not be limited to customer and employee personal information and will often include confidential corporate information of the insured s business partners as well. Yet, some cyber and privacy policies will only include personal information in the definition of confidential information. This restrictive definition would preclude an insured from coverage if the sensitive corporate information of third parties is lost. It should be noted that a cyber and privacy policy does not provide first party coverage for losses resulting from the unauthorized disclosure of the insured s own confidential corporate information. Further, it is often a perquisite to coverage that an insured have a contractual obligation to protect third party confidential corporate information (i.e., by way of a non-disclosure agreement). Ideally, policy language will include coverage for confidential corporate information as well as personal information. However, it is common for cyber and privacy policies to contain an exclusion for losses arising from the disclosure of third-party trade secrets, which would act to restrict the scope of confidential corporate information that is covered. Bodily injury and property damage Almost all cyber and privacy policies will contain an exclusion for bodily injury and property damage (BI/PD) related to cyber and privacy breach claims. In some cases, this will exclude coverage for claims arising from, or for, mental anguish and emotional distress. This broad BI/PD exclusion is potentially problematic, as a plaintiff bringing an action against an insured for unauthorized disclosure of personal information might request damages on a number of grounds, including damages for mental anguish and emotional distress. Therefore, it is important that the language in any BI/PD exclusion be worded to provide coverage for mental anguish and emotional distress where it is directly caused by the breach and there is no intervening physical peril. Coverage for regulatory proceedings Some cyber and privacy policies will provide coverage for regulatory investigations and proceedings, but policy language is not consistent, with the result that coverage is more robust under some policies as opposed to others. The majority of policies will include defence costs for regulatory proceedings, typically with a sublimit on these costs. More comprehensive cyber and privacy policies will also provide coverage for fines and penalties, subject to their insurability under the law. The definition of regulatory action often varies among policies and some policies contain a narrow definition that ties the proceedings to a civil lawsuit. Yet, an insured may face a variety of regulatory proceedings under provincial privacy legislation. The powers of the Privacy Commissioner vary from province to province, but in most cases, in addition to bringing a civil lawsuit on behalf of the victims, the Privacy Commissioner can carry out investigations, request documents, conduct audits and make orders that require an insured to improve their technology and security systems or pay money into a consumer redress fund. Policies containing a narrow definition of regulatory action will not likely provide coverage for all of the legal costs that an insured may incur to defend against a regulatory investigation or other measures that the Privacy Commissioner might undertake. In addition, there is often a misconception that coverage for a regulatory action will capture losses resulting from an investigation or enforcement actions related to compliance with payment card industry (PCI) standards. However, associations ensuring PCI compliance derive their authority through contract and would not likely meet the definition of regulator. Coverage for fines, assessments and other expenses that result from compliance with PCI standards must be provided for separately in the policy. 2 Cyber and Privacy Breach Insurance: A Risk Transfer Solution for a Growing Liability

5 Items not included in coverage Cyber and privacy insurance policies are drafted to provide coverage in a number of different privacy and data breach scenarios, but there are some situations and types of losses that these policies generally do not cover. For example, if an insured suffers a breach of its network security system that leads to physical damage, losses related to the physical damage will not likely be covered. Further, computer fraud and fraudulent transfers of funds or money and securities that take place by way of a network security breach will not typically be covered under a cyber and privacy policy. This is a matter that is more likely to be addressed through fidelity insurance coverage. Finally, other items normally excluded from coverage include the cost of installing, upgrading or maintaining a computer system and associated security programs, any consideration owed or paid in connection with an insured s goods, products or services, including the return of payments, any taxes, fines, penalties and liquidated damages, loss resulting from a mechanical failure or errors in programming and loss as a result of controlling, creating, developing or providing content on any third party s website. Although the latter risk could be addressed with the purchase of media liability coverage. 3 Cyber and Privacy Breach Insurance: A Risk Transfer Solution for a Growing Liability

6 Prepared by Jennifer Drake LL.B Financial Services Group Legal and Research Practice 20 Bay St., Toronto, Ontario M5J 2N9 t jennifer.drake@aon.ca Contacts Brian Rosenbaum LL.B and National Director Financial Services Group Legal and Research Practice 20 Bay St., Toronto, Ontario M5J 2N9 t brian.rosenbaum@aon.ca Kathleen R. Cook, MBA, CPCU 400, st Street SE Calgary, Alberta T2S 1B1 t m kathleen.cook@aon.ca Marie-Frédérique Senécal 700, rue De La Gauchetière Ouest, bureau 1800 Montréal, Québec H3B 0A4 t marie-frederique.senecal@aon.ca Denise Hall 20 Bay St., Toronto, Ontario M5J 2N9 t m denise.hall@aon.ca Catherine Richmond, LL.B., CRM and Account Manager 900 Howe St., Vancouver, British Columbia V6B 3X8 t m catherine.richmond@aon.ca Aon Risk Solutions Cyber and Privacy Breach Insurance: A Risk Transfer Solution for a Growing Liability 4

7 About Aon Aon plc (NYSE:AON) is the leading global provider of risk management, insurance and reinsurance brokerage, and human resources solutions and outsourcing services. Through its more than 66,000 colleagues worldwide, Aon unites to empower results for clients in over 120 countries via innovative and effective risk and people solutions and through industry-leading global resources and technical expertise. Aon has been named repeatedly as the world s best broker, best insurance intermediary, best reinsurance intermediary, best captives manager, and best employee benefits consulting firm by multiple industry sources. Visit aon.com for more information on Aon and aon.com/ manchesterunited to learn about Aon s global partnership with Manchester United. Aon Reed Stenhouse All rights reserved. The information contained herein and the statements expressed are of a general nature and are not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information and use sources we consider reliable, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act on such information without appropriate professional advice after a thorough examination of the particular situation. Risk. Reinsurance. Human Resources.

Considerations for Financial Advisors Regarding Corporate E&O Insurance Coverage

Considerations for Financial Advisors Regarding Corporate E&O Insurance Coverage Aon Risk Solutions Considerations for Financial Advisors Regarding Corporate E&O Insurance Coverage January 2015 Risk. Reinsurance. Human Resources. Introduction Recent statistics indicate that the number

More information

Executive Liability Insurance

Executive Liability Insurance Aon Risk Solutions Financial Services Group Life Sciences Industry Practice Executive Liability Insurance Solutions from Experts in the Life Sciences Industry Challenges on the Rise for Life Sciences Companies

More information

Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements

Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements Greater New York Chapter Association of Corporate Counsel November 19, 2015 Stephen D. Becker, Executive Vice President

More information

Cyber and data Policy wording

Cyber and data Policy wording Please read the schedule to see whether Breach costs, Cyber business interruption, Hacker damage, Cyber extortion, Privacy protection or Media liability are covered by this section. The General terms and

More information

Data Breach and Senior Living Communities May 29, 2015

Data Breach and Senior Living Communities May 29, 2015 Data Breach and Senior Living Communities May 29, 2015 Todays Objectives: 1. Discuss Current Data Breach Trends & Issues 2. Understanding Why The Senior Living Industry May Be A Target 3. Data Breach Costs

More information

Joe A. Ramirez Catherine Crane

Joe A. Ramirez Catherine Crane RIMS/RMAFP PRESENTATION Joe A. Ramirez Catherine Crane RISK TRANSFER VIA INSURANCE Most Common Method Involves Assessment of Risk and Loss Potential Risk of Loss Transferred For a Premium Insurance Contract

More information

Cyber Risks Management. Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor

Cyber Risks Management. Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor Cyber Risks Management Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor 1 Contents Corporate Assets Data Breach Costs Time from Earliest Evidence of Compromise to Discovery of Compromise The Data Protection

More information

Cyber Insurance Presentation

Cyber Insurance Presentation Cyber Insurance Presentation Presentation Outline Introduction General overview of Insurance About us Cyber loss statistics Cyber Insurance product coverage Loss examples Q & A About Us A- Rated reinsurance

More information

Aon commentary - draft Property, Stock and Business Agents Amendment (Professional Indemnity Insurance) Regulation 2012

Aon commentary - draft Property, Stock and Business Agents Amendment (Professional Indemnity Insurance) Regulation 2012 Aon commentary - draft Property, Stock and Business Agents Amendment (Professional Indemnity Insurance) Regulation 2012 NSW Fair Trading 5 October 2012 1. Introduction This document has been prepared in

More information

Cyber-Crime Protection

Cyber-Crime Protection Cyber-Crime Protection A program of cyber-crime prevention, data breach remedies and data risk liability insurance for houses of worship, camps, schools, denominational/association offices and senior living

More information

Managing Your Cyber & Data Risk 2010 NTA Convention Montreal, Quebec

Managing Your Cyber & Data Risk 2010 NTA Convention Montreal, Quebec Managing Your Cyber & Data Risk 2010 NTA Convention Montreal, Quebec Jeremy Ong Divisional Vice-President Great American Insurance Company November 13, 2010 1 Agenda Overview of data breach statistics

More information

Real Estate Practice. Fact-Based Solutions for Real Estate Risk Management. Risk. Reinsurance. Human Resources.

Real Estate Practice. Fact-Based Solutions for Real Estate Risk Management. Risk. Reinsurance. Human Resources. Aon Risk Solutions Real Estate Practice Real Estate Practice Fact-Based Solutions for Real Estate Risk Management Risk. Reinsurance. Human Resources. Today s Real Estate Risk Trends and Priorities Our

More information

THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS

THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS Read the Marsh Risk Management Research Briefing: Cyber Risks Extend Beyond Data and Privacy Exposures To access the report, visit www.marsh.com.

More information

Cyber Risk State of the Art

Cyber Risk State of the Art Proudly presents Cyber Risk State of the Art Matthew Davies, Chubb Insurance Catherine Dowdall, Canada Post Mike Petersen, Marsh 1 Agenda 1. Who is At Risk? 2. New/Emerging Risk and Trends 3. Canada Post

More information

RISKY BUSINESS SEMINAR CYBER LIABILITY DISCUSSION

RISKY BUSINESS SEMINAR CYBER LIABILITY DISCUSSION RISKY BUSINESS SEMINAR CYBER LIABILITY DISCUSSION October 23, 2015 THREAT ENVIRONMENT Growing incentive for insiders to abuse access to sensitive data for financial gain Disgruntled current and former

More information

Managing Cyber & Privacy Risks

Managing Cyber & Privacy Risks Managing Cyber & Privacy Risks NAATP Conference 2013 NSM Insurance Group Sean Conaboy Rich Willetts SEAN CONABOY INSURANCE BROKER NSM INSURANCE GROUP o Sean has been with NSM Insurance Group for the past

More information

Mitigating and managing cyber risk: ten issues to consider

Mitigating and managing cyber risk: ten issues to consider Mitigating and managing cyber risk: ten issues to consider The board of directors is responsible for managing and mitigating risk exposure. A recent study conducted by the Ponemon Institute 1 revealed

More information

Data breach, cyber and privacy risks. Brian Wright Lloyd Wright Consultants Ltd

Data breach, cyber and privacy risks. Brian Wright Lloyd Wright Consultants Ltd Data breach, cyber and privacy risks Brian Wright Lloyd Wright Consultants Ltd Contents Data definitions and facts Understanding how a breach occurs How insurance can help to manage potential exposures

More information

Cyber-insurance: Understanding Your Risks

Cyber-insurance: Understanding Your Risks Cyber-insurance: Understanding Your Risks Cyber-insurance represents a complete paradigm shift. The assessment of real risks becomes a critical part of the analysis. This article will seek to provide some

More information

Cyber Liability. AlaHA Annual Meeting 2013

Cyber Liability. AlaHA Annual Meeting 2013 Cyber Liability AlaHA Annual Meeting 2013 Disclaimer We are not providing legal advise. This Presentation is a broad overview of health care cyber loss exposures, the process in the event of loss and coverages

More information

Privacy / Network Security Liability Insurance Discussion. January 30, 2013. Kevin Violette RT ProExec

Privacy / Network Security Liability Insurance Discussion. January 30, 2013. Kevin Violette RT ProExec Privacy / Network Security Liability Insurance Discussion January 30, 2013 Kevin Violette RT ProExec 1 Irrefutable Laws of Information Security 1) Information wants to be free People want to talk, post,

More information

Discussion on Network Security & Privacy Liability Exposures and Insurance

Discussion on Network Security & Privacy Liability Exposures and Insurance Discussion on Network Security & Privacy Liability Exposures and Insurance Presented By: Kevin Violette Errors & Omissions Senior Broker, R.T. Specialty, LLC February, 25 2014 HFMA Washington-Alaska Chapter

More information

GALLAGHER CYBER LIABILITY PRACTICE. Tailored Solutions for Cyber Liability and Professional Liability

GALLAGHER CYBER LIABILITY PRACTICE. Tailored Solutions for Cyber Liability and Professional Liability GALLAGHER CYBER LIABILITY PRACTICE Tailored Solutions for Cyber Liability and Professional Liability Are you exposed to cyber risk? Like nearly every other business, you have probably capitalized on the

More information

Data Breach Cost. Risks, costs and mitigation strategies for data breaches

Data Breach Cost. Risks, costs and mitigation strategies for data breaches Data Breach Cost Risks, costs and mitigation strategies for data breaches Tim Stapleton, CIPP/US Deputy Global Head of Professional Liability Zurich General Insurance Data Breaches: Greater frequency,

More information

Managing Cyber Risk through Insurance

Managing Cyber Risk through Insurance Managing Cyber Risk through Insurance Eric Lowenstein Aon Risk Solutions This presentation has been prepared for the Actuaries Institute 2015 ASTIN and AFIR/ERM Colloquium. The Institute Council wishes

More information

Canadian Social Workers & Professional Liability Insurance

Canadian Social Workers & Professional Liability Insurance Canadian Social Workers & Professional Liability Insurance Understanding How it Works & Why You Need it March 1, 2016 Prepared by Aon Risk Solutions Presenter CASW is pleased to welcome the expertise of

More information

Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for?

Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for? Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for? Authored by Neeraj Sahni and Tim Stapleton Neeraj Sahni is Director, Insurance Channel at Kroll Cyber Investigations

More information

Coverage is subject to a Deductible

Coverage is subject to a Deductible Frank Cowan Company Limited 75 Main Street North, Princeton, ON N0J 1V0 Phone: 519-458-4331 Fax: 519-458-4366 Toll Free: 1-800-265-4000 www.frankcowan.com CYBER RISK INSURANCE DETAILED APPLICATION Notes:

More information

Don t Wait Until It s Too Late: Top 10 Recommendations for Negotiating Your Cyber Insurance Policy

Don t Wait Until It s Too Late: Top 10 Recommendations for Negotiating Your Cyber Insurance Policy Privacy, Data Security & Information Use Insurance Recovery & Advisory Cyber Insurance June 17, 2015 Don t Wait Until It s Too Late: Top 10 Recommendations for Negotiating Your Cyber Insurance Policy By

More information

Cyber Risk and the Utility Industry

Cyber Risk and the Utility Industry Cyber Risk and the Utility Industry Imran Ahmad Lawyer, Cassels Brock & Blackwell LLP Canadian Legal Landscape Personal Information Protection and Electronic Documents Act (PIPEDA) Federal legislation

More information

CYBER RISK SECURITY, NETWORK & PRIVACY

CYBER RISK SECURITY, NETWORK & PRIVACY CYBER RISK SECURITY, NETWORK & PRIVACY CYBER SECURITY, NETWORK & PRIVACY In the ever-evolving technological landscape in which we live, our lives are dominated by technology. The development and widespread

More information

CyberEdge. Desired Coverages. Application Form. Covers Required. Financial Information. Company or Trading Name: Address: Post Code: Telephone:

CyberEdge. Desired Coverages. Application Form. Covers Required. Financial Information. Company or Trading Name: Address: Post Code: Telephone: Company or Trading Name: Address: Post Code: Telephone: E-mail: Website: Date Business Established Number of Employees Do you have a Chief Privacy Officer (or Chief Information Officer) who is assigned

More information

MANAGING Cybersecurity Risk AND DISCLOSURE OBLIGATIONS

MANAGING Cybersecurity Risk AND DISCLOSURE OBLIGATIONS MANAGING Cybersecurity Risk AND DISCLOSURE OBLIGATIONS RRD Donnelley SEC Hot Topics Institute May 21, 2014 1 MANAGING CYBERSECURITY RISK AND DISCLOSURE OBLIGATIONS Patrick J. Schultheis Partner Wilson

More information

Data breach! cyber and privacy risks. Brian Wright Michael Guidry Lloyd Guidry LLC

Data breach! cyber and privacy risks. Brian Wright Michael Guidry Lloyd Guidry LLC Data breach! cyber and privacy risks Brian Wright Michael Guidry Lloyd Guidry LLC Collaborative approach Objective: To develop your understanding of a data breach, and risk transfer options to help you

More information

Insurance Journal. Defending Until the End When Does the Duty to. Volume 1, Issue 3 Editor Keoni Norgren. May 1, 2013

Insurance Journal. Defending Until the End When Does the Duty to. Volume 1, Issue 3 Editor Keoni Norgren. May 1, 2013 Insurance Journal May 1, 2013 In this Issue Volume 1, Issue 3 Editor Keoni Norgren Defending Until the End When Does the Duty to Defend End? Cyber Liability Laws in Canada Dolden Wallace Folick Welcomes

More information

Cyber/ Network Security. FINEX Global

Cyber/ Network Security. FINEX Global Cyber/ Network Security FINEX Global ABOUT US >> We are one of the largest insurance brokers in the world >> We have over 180 years of history and experience in insurance; we currently operate in over

More information

DATA BREACH, NETWORK SECURITY, CYBER LIABILITY, PRIVACY PROTECTION: ARE YOU INSURED?

DATA BREACH, NETWORK SECURITY, CYBER LIABILITY, PRIVACY PROTECTION: ARE YOU INSURED? DATA BREACH, NETWORK SECURITY, CYBER LIABILITY, PRIVACY PROTECTION: ARE YOU INSURED? February 3, 2012 Steve Brown, Agency Manager West Virginia Medical Insurance Agency How many in the audience today will

More information

Property Insurance Market Report United States. Summary and Forecast Q1 14

Property Insurance Market Report United States. Summary and Forecast Q1 14 Property Insurance Market Report United States Summary and Forecast Q1 14 Property Summary Property underwriters enjoyed a profitable 2013 due to lower losses and higher rates, which followed two-plus

More information

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance Today s agenda Introductions Cyber exposure overview Cyber insurance market and coverages Captive cyber insurance

More information

CYBER BRIEF A SEMI-ANNUAL PUBLICATION FROM YOUR WNA FINEX CLAIM & LEGAL GROUP

CYBER BRIEF A SEMI-ANNUAL PUBLICATION FROM YOUR WNA FINEX CLAIM & LEGAL GROUP www.willis.com CYBER BRIEF A SEMI-ANNUAL PUBLICATION FROM YOUR WNA FINEX CLAIM & LEGAL GROUP INSIDE THIS EDITION... CYBER CLAIMS LANDSCAPE A SAMPLING OF LARGE CYBER SETTLEMENTS LEGAL SPOTLIGHT, PRIVILEGE

More information

Cyber Security Issues - Brief Business Report

Cyber Security Issues - Brief Business Report Cyber Security: Are You Prepared? This briefing provides a high-level overview of the cyber security issues that businesses should be aware of. You should talk to a lawyer and an IT specialist for a complete

More information

Aon Risk Solutions Global Risk Consulting Captive & Insurance Management. Cyber risk and the captive market - a match made in the cloud?

Aon Risk Solutions Global Risk Consulting Captive & Insurance Management. Cyber risk and the captive market - a match made in the cloud? Aon Risk Solutions Global Risk Consulting Captive & Insurance Management Cyber risk and the captive market - a match made in the cloud? With increasing news coverage of cyber-attacks and despite indications

More information

Network Security & Privacy Landscape

Network Security & Privacy Landscape Network Security & Privacy Landscape Presented By: Pam Townley, AVP / Eastern Zonal Manager AIG Professional Liability Division Jennifer Bolling, Account Executive Gallagher Management Liability Division

More information

Cyber Liability & Data Breach Insurance Claims

Cyber Liability & Data Breach Insurance Claims Cyber Liability & Data Breach Insurance Claims A Study of Actual Payouts for Covered Data Breaches Mark Greisiger President NetDiligence June 2011 Last year, privacy breaches ran about 1-2 per week. This

More information

Network Security and Data Privacy Insurance for Physician Groups

Network Security and Data Privacy Insurance for Physician Groups Network Security and Data Privacy Insurance for Physician Groups February 2014 Lockton Companies While exposure to medical malpractice remains a principal risk MIKE EGAN, CPCU Senior Vice President Unit

More information

Internet Gaming: The New Face of Cyber Liability. Presented by John M. Link, CPCU Cottingham & Butler

Internet Gaming: The New Face of Cyber Liability. Presented by John M. Link, CPCU Cottingham & Butler Internet Gaming: The New Face of Cyber Liability Presented by John M. Link, CPCU Cottingham & Butler 1 Presenter John M. Link, Vice President jlink@cottinghambutler.com 2 What s at Risk? $300 billion in

More information

Is Your Financial Institutions' Insurance Policy vulnerable to a cyber claim? Joan D Ambrosio, James Cooper and Kim West 22 January 2014

Is Your Financial Institutions' Insurance Policy vulnerable to a cyber claim? Joan D Ambrosio, James Cooper and Kim West 22 January 2014 Is Your Financial Institutions' Insurance Policy vulnerable to a cyber claim? Joan D Ambrosio, James Cooper and Kim West 22 January 2014 Cyber Exposures Joan D Ambrosio Reported data breaches continue

More information

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder Ten Questions Your Board Should be asking about Cyber Security Eric M. Wright, Shareholder Eric Wright, CPA, CITP Started my career with Schneider Downs in 1983. Responsible for all IT audit and system

More information

What would you do if your agency had a data breach?

What would you do if your agency had a data breach? What would you do if your agency had a data breach? 80% of businesses fail to recover from a breach because they do not know this answer. Responding to a breach is a complicated process that requires the

More information

CAGNY Spring 2015 Meeting Fundamentals of Cyber Risk. Brad Gow June 9th, 2015 Endurance

CAGNY Spring 2015 Meeting Fundamentals of Cyber Risk. Brad Gow June 9th, 2015 Endurance Fundamentals of Cyber Risk Brad Gow June 9th, 2015 Endurance But consider the kickoff chuckle to a speech given to the Wharton School in March 1977 by Sidney Homer of Salomon Brothers, the leading bond

More information

APPLICATION FOR TECHNOLOGY & PRIVACY PROFESSIONAL LIABILITY

APPLICATION FOR TECHNOLOGY & PRIVACY PROFESSIONAL LIABILITY APPLICATION FOR TECHNOLOGY & PRIVACY PROFESSIONAL LIABILITY GENERAL INFORMATION 1. APPLICANT NAME: 2. PHONE: 3. MAILING ADDRESS: 4. WEB ADDRESS: 5. The following officer of the Applicant is designated

More information

Cyber Liability Insurance: It May Surprise You

Cyber Liability Insurance: It May Surprise You Cyber Liability Insurance: It May Surprise You Moderator Eugene Montgomery, President & CEO Community Financial Insurance Center Panelists Antonio Trotta, Senior Claim Counsel, CNA Specialty William Heinbokel,

More information

Top Ten Technology Risks Facing Colleges and Universities

Top Ten Technology Risks Facing Colleges and Universities Top Ten Technology Risks Facing Colleges and Universities Chris Watson, MBA, CISA, CRISC Manager, Internal Audit and Risk Advisory Services cwatson@schneiderdowns.com April 23, 2012 Overview Technology

More information

ISO? ISO? ISO? LTD ISO?

ISO? ISO? ISO? LTD ISO? Property NetProtect 360 SM and NetProtect Essential SM Which one is right for your client? Do your clients Use e-mail? Rely on networks, computers and electronic data to conduct business? Browse the Internet

More information

Directors and Officers Liability Indemnification and Insurance. Richard Berrow, LL.B. Brian Rosenbaum, LL.B.

Directors and Officers Liability Indemnification and Insurance. Richard Berrow, LL.B. Brian Rosenbaum, LL.B. Directors and Officers Liability Indemnification and Insurance Richard Berrow, LL.B. Brian Rosenbaum, LL.B. Introduction Richard Berrow, LL.B. Partner, Fasken Martineau DuMoulin LLP Brian Rosenbaum, LL.B.

More information

Privacy Liability & Data Breach Management Nikos Georgopoulos Cyber Risks Advisor cyrm October 2014

Privacy Liability & Data Breach Management Nikos Georgopoulos Cyber Risks Advisor cyrm October 2014 Privacy Liability & Data Breach Management Nikos Georgopoulos Cyber Risks Advisor cyrm October 2014 Nikos Georgopoulos Privacy Liability & Data Breach Management wwww.privacyrisksadvisors.com October 2014

More information

Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance

Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance About Canada Dispute Resolution Forms of Business Organization Aboriginal Law Competition Law Real Estate Securities and Corporate Finance Foreign Investment Public- Private Partnerships Restructuring

More information

PROFESSIONAL RISK PRIVACY CLAIMS SCENARIOS

PROFESSIONAL RISK PRIVACY CLAIMS SCENARIOS PROFESSIONAL RISK PRIVACY CLAIMS SCENARIOS The following claim scenarios are hypothetical and are offered solely to illustrate the types of situations that may result in claims. Although sorted by industry,

More information

8 WAYS TO SAVE MONEY ON BUSINESS INSURANCE. Reduce Your Risk While Saving Money

8 WAYS TO SAVE MONEY ON BUSINESS INSURANCE. Reduce Your Risk While Saving Money 8 WAYS TO SAVE MONEY ON BUSINESS INSURANCE Reduce Your Risk While Saving Money Reduce Your Risk While Saving Money Few businesses have the financial resources to self-insure against large risks, such as

More information

THE ANATOMY OF A CYBER POLICY. Jamie Monck-Mason & Andrew Hill

THE ANATOMY OF A CYBER POLICY. Jamie Monck-Mason & Andrew Hill THE ANATOMY OF A CYBER POLICY Jamie Monck-Mason & Andrew Hill What s in a name? Lack of uniformity in policies: Cyber Cyber liability Data protection Tech PI The scope of cyber insurance First party coverage

More information

Network Security & Privacy Landscape

Network Security & Privacy Landscape Network Security & Privacy Landscape Presented By: Greg Garijanian Senior Underwriter Professional Liability 1 Agenda Network Security Overview -Latest Threats - Exposure Trends - Regulations Case Studies

More information

Understanding Professional Liability Insurance

Understanding Professional Liability Insurance Understanding Professional Liability Insurance Definition Professional liability is more commonly known as errors & omissions (E&O) and is a form of liability insurance that helps protect professional

More information

Demystifying Cyber Insurance. Jamie Monck-Mason & Andrew Hill. Introduction. What is cyber? Nomenclature

Demystifying Cyber Insurance. Jamie Monck-Mason & Andrew Hill. Introduction. What is cyber? Nomenclature Demystifying Cyber Insurance Jamie Monck-Mason & Andrew Hill Introduction What is cyber? Nomenclature 1 What specific risks does cyber insurance cover? First party risks - losses arising from a data breach

More information

Cyber Risk in Healthcare AOHC, 3 June 2015

Cyber Risk in Healthcare AOHC, 3 June 2015 Cyber Risk in Healthcare AOHC, 3 June 2015 Kopiha Nathan, Senior Healthcare Risk Management and Data Specialist James Penafiel, Underwriting Supervisor, Insurance Operations CFPC Conflict of Interest -

More information

Business Insurance Application For Canadian Counsellors

Business Insurance Application For Canadian Counsellors New Business Insurance Application for Canadian Counsellors Français disponible sur demande. Name: Mailing Address: City: Prov.: Postal Code: Are you the Business Owner? If yes, Name of Business: Number

More information

THE QUÉBEC PRIVATE SECURITY ACT

THE QUÉBEC PRIVATE SECURITY ACT AUGUST 2010 THE QUÉBEC PRIVATE SECURITY ACT AND ITS APPLICATION TO ELECTRONIC SECURITY FIRMS Construction, Engineering, Surety and Fidelity Group CONSTRUCTION LAW BULLETIN www.blgcanada.com In 2004 the

More information

YOUR TRUSTED PARTNER IN A DIGITAL AGE. A guide to Hiscox Cyber and Data Insurance

YOUR TRUSTED PARTNER IN A DIGITAL AGE. A guide to Hiscox Cyber and Data Insurance YOUR TRUSTED PARTNER IN A DIGITAL AGE A guide to Hiscox Cyber and Data Insurance 2 THE CYBER AND DATA RISK TO YOUR BUSINESS This digital guide will help you find out more about the potential cyber and

More information

Reducing Risk. Raising Expectations. CyberRisk and Professional Liability

Reducing Risk. Raising Expectations. CyberRisk and Professional Liability Reducing Risk. Raising Expectations. CyberRisk and Professional Liability Are you exposed to CyberRisk? Like nearly every other business, you have likely capitalized on the advancements in technology today

More information

Cyber Risks in Italian market

Cyber Risks in Italian market Cyber Risks in Italian market Milano, 01.10.2014 Forum Ri&Assicurativo Gianmarco Capannini Agenda 1 Cyber Risk - USA 2 Cyber Risk Europe experience trends Market size and trends Market size and trends

More information

PROFESSIONAL INDEMNITY INSURANCE

PROFESSIONAL INDEMNITY INSURANCE ESSENTIAL BUSINESS INSURANCE COVER POLICY RISK FACT introducing FirstUnited FirstUnited is a leading insurance intermediary group operating in Malta and under Freedom of Services throughout the EU. We

More information

Administrative Procedures Memorandum A1452

Administrative Procedures Memorandum A1452 Page 1 of 11 Date of Issue February 2, 2010 Original Date of Issue Subject References February 2, 2010 PRIVACY BREACH PROTOCOL Policy 2197 Management of Personal Information APM 1450 Management of Personal

More information

cyber invasions cyber risk insurance AFP Exchange

cyber invasions cyber risk insurance AFP Exchange Cyber Risk With cyber invasions now a common place occurrence, insurance coverage isn t found in your liability policy. So many different types of computer invasions exist, but there is cyber risk insurance

More information

Protecting Your Assets: How To Safeguard Your Fund Against Cyber Security Attacks

Protecting Your Assets: How To Safeguard Your Fund Against Cyber Security Attacks Protecting Your Assets: How To Safeguard Your Fund Against Cyber Security Attacks Hacks, breaches, stolen data, trade secrets hijacked, privacy violated, ransom demands made; how can you protect your data

More information

43-700 PRIVACY LIABILITY AND INSURANCE

43-700 PRIVACY LIABILITY AND INSURANCE 43-700 PRIVACY LIABILITY AND INSURANCE Prepared by Murn Meyrick, CEO Grey Swan Advisory Inc. Reproduced with permission from the Ultimate Corporate Counsel Guide, published by CCH Canadian Limited, Toronto,

More information

Cyber/Information Security Insurance. Pros / Cons and Facts to Consider

Cyber/Information Security Insurance. Pros / Cons and Facts to Consider 1 Cyber/Information Security Insurance Pros / Cons and Facts to Consider 2 Presenters Calvin Rhodes, Georgia Chief Information Officer Ron Baldwin, Montana Chief Information Officer Ted Kobus, Partner

More information

Cyber Risk, Legal And Regulatory Issues, And Insurance Mitigation ISACA Pittsburgh Information Security Awareness Day

Cyber Risk, Legal And Regulatory Issues, And Insurance Mitigation ISACA Pittsburgh Information Security Awareness Day Lloyd s of London (Reuters) May 8, 2000 Cyber Risk, Legal And Regulatory Issues, And Insurance Mitigation ISACA Pittsburgh Information Security Awareness Day Rivers Casino, Pittsburgh November 17, 2014

More information

How to Respond When Sensitive Customer and Employee Data is Breached, Stolen or Compromised

How to Respond When Sensitive Customer and Employee Data is Breached, Stolen or Compromised ACE USA Podcast Released June 24, 2010 How to Respond When Sensitive Customer and Employee Data is Breached, Stolen or Compromised Moderator: Richard Tallo Senior Vice President, ACE North America Marketing

More information

The Intersection of 21st Century Risk Management and Data: Risk Allocation and Mitigation for Customer Data Breaches

The Intersection of 21st Century Risk Management and Data: Risk Allocation and Mitigation for Customer Data Breaches The Intersection of 21st Century Risk Management and Data: Risk Allocation and Mitigation for Customer Data Breaches Ethan D. Lenz, CPCU, and Christopher C. Cain, Foley & Lardner LLP Data. It has always

More information

Cyberinsurance: Insuring for Data Breach Risk

Cyberinsurance: Insuring for Data Breach Risk View the online version at http://us.practicallaw.com/2-588-8785 Cyberinsurance: Insuring for Data Breach Risk JUDY SELBY AND C. ZACHARY ROSENBERG, BAKER HOSTETLER LLP, WITH PRACTICAL LAW INTELLECTUAL

More information

Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re

Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re Global Warning It is a matter of time before there is a major cyber attackon the global financial system and the public needs to invest heavily in

More information

CYBER SECURITY SPECIALREPORT

CYBER SECURITY SPECIALREPORT CYBER SECURITY SPECIALREPORT 32 The RMA Journal February 2015 Copyright 2015 by RMA INSURANCE IS AN IMPORTANT TOOL IN CYBER RISK MITIGATION Shutterstock, Inc. The time to prepare for a potential cyber

More information

Insurance for Data Breaches in the Hospitality Industry

Insurance for Data Breaches in the Hospitality Industry The Academy of Hospitality Industry Attorneys The Pl Palmer House Hilton Chicago, IL April 25, 2014 Insurance for Data Breaches in the Hospitality Industry Presenters: David P. Bender, Jr. dbender@andersonkill.com

More information

Lessons Learned from Recent HIPAA and Big Data Breaches. Briar Andresen Katie Ilten Ann Ladd

Lessons Learned from Recent HIPAA and Big Data Breaches. Briar Andresen Katie Ilten Ann Ladd Lessons Learned from Recent HIPAA and Big Data Breaches Briar Andresen Katie Ilten Ann Ladd Recent health care breaches Breach reports to OCR as of February 2015 1,144 breaches involving 500 or more individual

More information

Are you a registered member of a provincial CGA Canadian affiliate? YES NO Firm #: (if applicable) NEW RENEWAL. Phone Fax E-mail:

Are you a registered member of a provincial CGA Canadian affiliate? YES NO Firm #: (if applicable) NEW RENEWAL. Phone Fax E-mail: PLEASE COMPLETE THIS APPLICATION IN FULL. THIS FORM IS THE BASIS UPON WHICH INSURANCE IS PROVIDED. IN THE EVENT OF A NON-DISCLOSURE, THE POLICY MAY BE VOIDED AT THE OPTION OF THE INSURER. USE A SEPARATE

More information

Best practices and insight to protect your firm today against tomorrow s cybersecurity breach

Best practices and insight to protect your firm today against tomorrow s cybersecurity breach Best practices and insight to protect your firm today against tomorrow s cybersecurity breach July 8, 2015 Baker Tilly Virchow Krause, LLP Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently

More information

Who s next after TalkTalk?

Who s next after TalkTalk? Who s next after TalkTalk? Frequently Asked Questions on Cyber Risk Fraud threat to millions of TalkTalk customers TalkTalk cyber-attack: website hit by significant breach These are just two of the many

More information

DATA SECURITY: A CRUCIAL TOPIC FOR CORPORATE COUNSEL AND MANAGEMENT

DATA SECURITY: A CRUCIAL TOPIC FOR CORPORATE COUNSEL AND MANAGEMENT Advisor Article DATA SECURITY: A CRUCIAL TOPIC FOR CORPORATE COUNSEL AND MANAGEMENT By James R. Carroll, David S. Clancy and Christopher G. Clark* Skadden, Arps, Slate, Meagher & Flom Customer data security

More information

Complete Professional Indemnity

Complete Professional Indemnity Allianz Insurance plc plc Complete Professional Indemnity Policy Details (including Policy Summary pages 1 4) Insurance Brokers Policy Summary This is a Policy Summary only and does not contain full terms

More information

Security & Privacy Current cover and Risk Management Services

Security & Privacy Current cover and Risk Management Services Security & Privacy Current cover and Risk Management Services Introduction Technological advancement has enabled greater working flexibility and increased methods of communications. However, new technology

More information

How To Write A Network Security Endorsement

How To Write A Network Security Endorsement THIS ENDORSEMENT CHANGES THE POLICY. PLEASE READ IT CAREFULLY. NETWORK SECURITY ENDORSEMENT INTEGRATED TECH CLAIMS MADE CLAIM EXPENSES INCLUDED WITHIN THE LIMITS OF INSURANCE This endorsement modifies

More information

Cyber and Privacy Risk What Are the Trends? Is Insurance the Answer?

Cyber and Privacy Risk What Are the Trends? Is Insurance the Answer? Minnesota Society for Healthcare Risk Management September 22, 2011 Cyber and Privacy Risk What Are the Trends? Is Insurance the Answer? Melissa Krasnow, Partner, Dorsey & Whitney, and Certified Information

More information

Practical Cyber Law: Why the Standard of Care Requires Lawyers to Have a Basic Understanding of Cyber Insurance

Practical Cyber Law: Why the Standard of Care Requires Lawyers to Have a Basic Understanding of Cyber Insurance Practical Cyber Law: Why the Standard of Care Requires Lawyers to Have a Basic Understanding of Cyber Insurance By Shawn Tuma & Katti Smith Data breaches have become far more common than most people realize.

More information

Anatomy of a Privacy and Data Breach

Anatomy of a Privacy and Data Breach Anatomy of a Privacy and Data Breach Understanding the Risk and Managing a Crisis Adam Kardash: Partner, Heenan Blaikie LLP Robert Parisi: Senior Vice President, Marsh Leadership, Knowledge, Solutions

More information

ANATOMY of a DATA BREACH DISASTER. Avoiding a Cyber Catastrophe. June, 2011. Sponsored by:

ANATOMY of a DATA BREACH DISASTER. Avoiding a Cyber Catastrophe. June, 2011. Sponsored by: ANATOMY of a DATA BREACH DISASTER Avoiding a Cyber Catastrophe June, 2011 Sponsored by: ANATOMY of a DATA BREACH DISASTER Avoiding a Cyber Catastrophe An Advisen Special Report Sponsored by Chartis Security

More information

Data Security Breaches: Learn more about two new regulations and how to help reduce your risks

Data Security Breaches: Learn more about two new regulations and how to help reduce your risks Data Security Breaches: Learn more about two new regulations and how to help reduce your risks By Susan Salpeter, Vice President, Zurich Healthcare Risk Management News stories about data security breaches

More information

Airmic Review of Recent Developments in the Cyber Insurance Market. & commentary on the increased availability of cyber insurance products GUIDE

Airmic Review of Recent Developments in the Cyber Insurance Market. & commentary on the increased availability of cyber insurance products GUIDE Airmic Review of Recent Developments in the Cyber Insurance Market & commentary on the increased availability of cyber insurance products GUIDE 1. Executive summary Airmic members have become increasingly

More information

INFORMATION SECURITY AND PRIVACY INSURANCE WITH ELECTRONIC MEDIA LIABILITY COVERAGE. I. GENERAL INFORMATION Full Name:

INFORMATION SECURITY AND PRIVACY INSURANCE WITH ELECTRONIC MEDIA LIABILITY COVERAGE. I. GENERAL INFORMATION Full Name: INFORMATION SECURITY AND PRIVACY INSURANCE WITH ELECTRONIC MEDIA LIABILITY COVERAGE NOTICE: COVERAGE UNDER THIS POLICY IS PROVIDED ON A CLAIMS MADE AND REPORTED BASIS AND APPLIES ONLY TO CLAIMS FIRST MADE

More information

Understanding the Business Risk

Understanding the Business Risk AAPA Cybersecurity Seminar Andaz Savannah Hotel March 11, 2015 10:30 am Noon Understanding the Business Risk Presenter: Joshua Gold, Esq. (212) 278-1886 jgold@andersonkill.com Disclaimer The views expressed

More information

Cyber Exposure for Credit Unions

Cyber Exposure for Credit Unions Cyber Exposure for Credit Unions What it is and how to protect yourself L O C K T O N 2 0 1 2 www.lockton.com Add Cyber Title Exposure Here Overview #1 financial risk for Credit Unions Average cost of

More information

Cloudy With a Chance Of Risk Management

Cloudy With a Chance Of Risk Management Proudly presents Cloudy With a Chance Of Risk Management Toby Merrill, ACE USA John Mullen, Nelson Levine de Luca & Hamilton Shawn Melito, Immersion Ltd. Michael Trendler, ACE INA Canada What is Cloud

More information