Cyber Insurance and Your Data Ted Claypoole, Partner, Womble Carlyle and Jack Freund, PhD, InfoSec Mgr, TIAA-CREF



Similar documents
Joe A. Ramirez Catherine Crane

Second Annual Conference September 16, 2015 to September 18, 2015 Chicago, IL

Cyber Risk, Legal And Regulatory Issues, And Insurance Mitigation ISACA Pittsburgh Information Security Awareness Day

Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements

Cyberinsurance: Insuring for Data Breach Risk

IN THE COURT OF COMMON PLEAS OF PHILADELPHIA COUNTY FIRST JUDICIAL DISTRICT OF PENNSYLVANIA CIVIL TRIAL DIVISION

Insurance for Cyber Risks: Coverage Under CGL and Cyber Policies

FILED: NEW YORK COUNTY CLERK 07/20/2011 INDEX NO /2011 NYSCEF DOC. NO. 1 RECEIVED NYSCEF: 07/20/2011

STATE OF OHIO ) IN THE COURT OF COMMON PLEAS )SS:

Data Privacy, Security, and Risk Management in the Cloud

Insurance Coverage Law Report

2014 IL App (5th) U NO IN THE APPELLATE COURT OF ILLINOIS FIFTH DISTRICT

GALLAGHER CYBER LIABILITY PRACTICE. Tailored Solutions for Cyber Liability and Professional Liability

Cyber-insurance: Understanding Your Risks

Insuring Innovation. CyberFirst Coverage for Technology Companies

Cyber and CGL Insurance Coverage for Data Breach Claims

Privacy Liability & Data Breach Management Nikos Georgopoulos Cyber Risks Advisor cyrm October 2014

CLASS ACTION. Westlaw Journal. Expert Analysis The State of Coverage Disputes Concerning Advertising And Privacy Claims

CYBER RISKS AND COVERAGE: QUESTIONS TO CONSIDER

IN THE UNITED STATES COURT OF APPEALS FOR THE FIFTH CIRCUIT

Reverse and Render in part; Affirm in part; Opinion Filed December 29, In The Court of Appeals Fifth District of Texas at Dallas

IDC Member Insurance Program brought to you by LMS PROLINK Ltd.

Cyber Risk State of the Art

Black Hats, Firewalls, and Data Loss: Insurers Confront Data Breach Litigation

PUBLIC ENTITY POLICY LAW ENFORCEMENT LIABILITY COVERAGE FORM OCCURRENCE COVERAGE

Understanding Professional Liability Insurance

Tools Conference Toronto November 26, 2014 Insurance for NFP s. Presented by Paul Spark HUB International HKMB Limited

Cyber and data Policy wording

United States Court of Appeals For the Eighth Circuit

Aon & DLA Piper s 2014 Network Security & Privacy Symposium. September 2014

2015 IL App (1st) U. No IN THE APPELLATE COURT OF ILLINOIS FIRST JUDICIAL DISTRICT

That s A Wrap What Every Claims And Construction Professional Needs To Know About Wrap-up Insurance Programs

INSURANCE INDUSTRY PROFESSIONAL LIABILITY COVERAGE UNIT THIS IS A CLAIMS MADE POLICY. PLEASE READ CAREFULLY.

CYBER INSURANCE. Cyber Insurance and Gaps in Traditional Insurance. Cyber and E&O Team Willis FINEX North America

DATA BREACH, NETWORK SECURITY, CYBER LIABILITY, PRIVACY PROTECTION: ARE YOU INSURED?

Understanding the Business Risk

(1) Commercial Crime Insurance or Employee Fidelity Bond

Case 4:14-cv Document 39 Filed in TXSD on 07/08/15 Page 1 of 7 UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF TEXAS HOUSTON DIVISION ORDER

cyber invasions cyber risk insurance AFP Exchange

2014 IL App (1st)

ISO COVERAGE FORM & ENDORSEMENT CHANGES DIGGING THROUGH THE DETAILS APRIL 9, 2013

UNITED STATES DISTRICT COURT EASTERN DISTRICT OF MISSOURI EASTERN DIVISION

UNITED STATES COURT OF APPEALS

INSURANCE COVERAGE FOR CYBER RISKS AND REALITIES September 24, 2013

Introduction to Directors and Offi cers Liability Insurance

Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for?

Expert Analysis The Next Insurance Big Top : Emerging Issues in Personal and Advertising Injury Coverage

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance

Why Buy Cyber and Privacy Liability When You Have a Perfectly Good Commercial General Liability Program?

Cyber Liability Insurance: It May Surprise You

Fully Integrated Insurance Solutions

IN THE UNITED STATES DISTRICT COURT FOR THE WESTERN DISTRICT OF WISCONSIN

Mind the Gap Between D&O and E&O Insurance Policies

Public charities are all 501(c)(3) but have various missions. Each mission carries significant risks and innocuous risks. Amount of risk depends upon:

Fiduciary Insurance and the Board of Retirement in New York State

THE STATE OF FLORIDA...

How To Cover A Data Breach In The European Market

Data security: A growing liability threat

ARCHITECTS AND ENGINEERS PROFESSIONAL LIABILITY INSURANCE By Bruce H. Schoumacher

Cyber Insurance What is it? Should your bank purchase it? Roberta D. Anderson Partner, K&L Gates LLP

RECOGNIZING BAD FAITH CASES

How To Know If A Property Damage Claim Is Covered Under A Cgl Policy

Helping you protect your good intentions

CGL Coverage for Construction Defects in Nebraska and Iowa

Cyber Insurance Presentation

Case 8:13-cv EAK-TGW Document 145 Filed 02/12/15 Page 1 of 12 PageID 5551 UNITED STATES DISTRICT COURT MIDDLE DISTRICT OF FLORIDA TAMPA DIVISION

IN THE UNITED STATES COURT OF APPEALS FOR THE FIFTH CIRCUIT

UNITED STATES COURT OF APPEALS FIFTH CIRCUIT. No (Summary Calendar) GLEN R. GURLEY and JEAN E. GURLEY, AMERICAN STATES INSURANCE COMPANY,

INDEMNIFICATION AND INSURANCE REQUIREMENTS FOR LOS ANGELES COUNTY SERVICE AGREEMENTS

UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF INDIANA EVANSVILLE DIVISION ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) )

A&E Briefings. Indemnification Clauses: Uninsurable Contractual Liability. Structuring risk management solutions

CYBER & PRIVACY LIABILITY INSURANCE GUIDE

IN THE COURT OF COMMON PLEAS OF PHILADELPHIA COUNTY FIRST JUDICIAL DISTRICT OF PENNSYLVANIA CIVIL TRIAL DIVISION

CYBER SECURITY SPECIALREPORT

Commercial Insurance Nonprofit, Professional & Social Services

Insurance for Data Breaches in the Hospitality Industry

A REPORT BY HARVARD BUSINESS REVIEW ANALYTIC SERVICES Meeting the Cyber Risk Challenge. Sponsored by

CyberSecurity for Law Firms

Practical Cyber Law: Why the Standard of Care Requires Lawyers to Have a Basic Understanding of Cyber Insurance

Why Obtain Student Medical Malpractice Insurance?

Cyber Liability & Data Breach Insurance Claims

IN THE COURT OF COMMON PLEAS OF PHILADELPHIA COUNTY FIRST JUDICIAL DISTRICT OF PENNSYLVANIA CIVIL TRIAL DIVISION

Business Insurance. AKD Consultants Adam Dworkin CPA 188 Whiting Street Suite 10 Hingham, MA

Insurers Not Obligated to Defend in ZIP Code Coverage Suits

APPLICATION FOR LAWYERS PROFESSIONAL LIABILITY INSURANCE IMPORTANT NOTICE

Reducing Risk. Raising Expectations. CyberRisk and Professional Liability

EZ RENEWAL APPLICATION FOR LAWYERS PROFESSIONAL LIABILITY INSURANCE ABOUT THE FIRM RENEWAL INFORMATION

EMPLOYEE BENEFITS LIABILITY COVERAGE

How To Protect Yourself From Cyber Crime

Data Breach Cost. Risks, costs and mitigation strategies for data breaches

Defense of State Employees: LIABILITY AND LAWSUITS. UNCW Office of General Counsel January 2010

CAMBRIDGE PROPERTY & CASUALTY SPECIAL REPORT

Structure Tone, Inc. v Travelers Indem. Co NY Slip Op 30706(U) April 29, 2015 Supreme Court, New York County Docket Number: /2014 Judge:

COVERAGE UNDER A CGL POLICY. A. CGL coverage is Commercial General Liability Coverage.

Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re

IN THE UNITED STATES COURT OF APPEALS FOR THE ELEVENTH CIRCUIT. No D.C. Docket No. 8:10-cv JSM-TGW

Cyber Liability. AlaHA Annual Meeting 2013

Don t Wait Until It s Too Late: Top 10 Recommendations for Negotiating Your Cyber Insurance Policy

Sterling Education Seminar. Liability Insurance: How Insurance is Written and Why You Need to Know. Alexandrea L. Isaac Hartford, CT Sept.

Hope Is Not a Strategy: Manage Risk Before False Claims Act Claims Are Made

Transcription:

Cyber Insurance and Your Data Ted Claypoole, Partner, Womble Carlyle and Jack Freund, PhD, InfoSec Mgr, TIAA-CREF October 9, 2013 1

Cyber Insurance Why? United States Department of Commerce: Cyber Insurance is an effective, market driven way of increasing Cybersecurity. United States Department of Homeland Security: Cyber Insurance may help reduce the number of successful cyber attacks by promoting widespread adoption of preventative measures; encouraging the implementation of best practices by basing premiums on an insured s level of self-protection; and limiting the level of losses that companies face following a cyber attack. 2

Cyber Insurance Discussion Topics Homeland Security Workshop Topics: Defining Insurable and Uninsurable Cyber Risks Cyber Insurance and the Human Element Cyber Liability: Who is Responsible for What Harm? Current Cyber Risk Management Strategies and Approaches Cyber Insurance: What Harms Should It Cover and What Should It Cost? Improving the Cyber Insurance Market: Stakeholder Roles and Responsibilities Sequencing Solutions: How Should the Market Move Forward? 3

Cyber Insurance History What falls under business insurance? Errors and Omissions? Business says Yes, Insurer says No Leave it to the Courts to Decide 4

Cyber Insurance History Zurich Am. Ins. v. Sony Corp. of Am., No. 651982/2011 (N.Y. Sup. Ct. filed July 20, 2011) In April 2011, hackers accessed data for one hundred million Sony PlayStation users and as a result, Sony was sued in sixty actions across the United States. Zurich brought suit seeking a declaratory judgment, claiming that it has no duty to defend or indemnify Sony against customer class actions and related matters. Sony purchased primary commercial general liability and excess liability policies from Zurich. Zurich asserts that the lawsuits arising out of the cyber attacks are not covered by the "bodily injury," "property damage" and "personal and advertising injury" coverage provided by its liability policies. 5

Cyber Insurance History Arch Ins. Co. v. Michaels Stores Inc., 1:12-cv-00786 (N.D. Ill. filed Feb. 23, 2012) Arch brought suit seeking a declaration that it is not required to indemnify or defend Michaels under a general liability policy in connection with a recent security breach where criminals known as skimmers tampered with PIN pad terminals in Michaels stores, using them to steal customers financial information and obtain access to their bank accounts. Arch asserts that none of the underlying suits allege property damage, bodily injury, or advertising injury, as required by the policies. Moreover, Arch contends that the electronic data and breach of contract exclusions in the policies apply 6

Cyber Insurance History DSW Inc. v. National Union Fire Ins. Co. of Pittsburgh, Pa., Case No. 10-4576/5608 (Aug. 23, 2012). The U.S. Court of Appeals for the Sixth Circuit recently addressed an exclusion for loss caused by the theft of confidential information. The court found that there was coverage for first-party and third-party losses arising from the theft of customer credit card information by hackers under a crime policy s computer fraud endorsement. The Sixth Circuit found that the crime policy at issue covered third-party liability losses even though the insuring agreement limited coverage to loss resulting directly from the theft of any Insured property by Computer Fraud. The Sixth Circuit also refused to apply an exclusion barring coverage for any loss of proprietary information, Trade Secrets, Confidential Processing Methods or other confidential information of any kind. The court reasoned that, while credit card information might be considered confidential in some circumstances, it could not have been the type of confidential information envisioned by the exclusion. 7

Cyber Insurance History St. Paul Fire and Marine Ins. Co. v. Compaq Computer Corp., 539 F.3d 809 (8th Cir. 2008) Applying Texas law, the Eight Circuit found that the insurer had a duty to defend under a technology E&O policy because the allegations in the underlying litigation included conduct falling within the policy s definition of error. Specifically, the plaintiffs alleged the insured engaged in the unintentional incorrect act of selling defective computers. As the act was alleged to be unintentional rather than intentional, the claims fell within the scope of the policy. 8

Cyber Insurance History Union Pump Co. v. Centrifugal Tech., Inc., No. 05-0287, 2009 U.S. Dist. LEXIS 86352 (W.D. La. Sept. 18, 2009) In this case, the court found that there was no coverage under the insured s commercial general liability policy for litigation involving claims that the insured had wrongfully used and then destroyed electronic data which included plaintiff s design drawings, autocad drawings, and pump models. As to coverage for property damage, the court found that electronic data failed to meet the definition of tangible property as required by the policy and that further, coverage only applied to property damage in the event of an occurrence. Since plaintiff s claims all involved allegations of intentional acts, they were excluded under the intentional act exclusion. 9

Cyber Insurance History Early Cyber Insurance: Extended Consulting Contract. If you hire us as security consultants, and if you pay us to crawl inside your business and look for problems, and if you take all of the steps that we recommend for you, then we will insure some of your risk. 10

Other Early Cyber Coverages: Cyber Insurance History Tech E & O for consultants and tech contractors. Liability and Property Insurance aimed at big tech companies. Data breach loss Third party claim expenses Cyber-extortion coverage Crisis management/legal 11

Cyber Insurance History Game Changers: Breach Notice Laws guess what? Everybody knows now. Organized Crime discovers hacking for profit. Rise of the Cloud/SaaS/IaaS/Outsourcing 12

Cyber Insurance Now Now Risk Transfer is More Attractive. Market is Bigger/Prices are Lower More Direct Policies Customizing Coverage Increasing Complexity Increasing Attack Risk Businesses Forced to Accept Risk: Regulators/contracts SEC Guidance 13

Cyber Insurance Now First Party Coverage: Direct damages from theft of IP, Data loss or destruction, hacking, denial of service attacks. Forensics covered Third Party Coverage: Public Relations Services Co-ordinated Outreach to Affected Customers (and regulators) Legal Expenses Credit Monitoring/Fraud Resolution Services Penalties and Fines 14

So You ve Decided to Buy A Policy How much insurance do you need? What s your tolerance for loss? Insuring the first dollar is always the most expensive Will need to self-insure up to your limit (deductible) In this case, will need to be a hard threshold Pay attention to the types of losses 15

Types of Losses Privacy Notification Costs Call Center Costs Credit Monitoring Identify Theft Repair Consumer Redress and Fines Liability and Defense Expense 16

Modeling Losses to Assess Limits MIN ML MAX Response Effort No. Ppl in Response Effort 5 50 500 No. Hours Per Person 20 40 250 Hourly rate $55.00 $70.00 $90.00 No. records 10,000 250,000 1,000,000 Per record Notification Cost 10.00 7.00 5.00 Credit Monitoring Per record monitoring costs 25.00 15.00 10.00 Acceptance % 5% 10% 25% Legal Defense Costs $250,000 $750,000 $2,000,000 Fines & Judgments $500,000 $1,000,000 $5,000,000 $368,000 $3,015,000 $20,750,000 17

Modeling Losses with Monte Carlo Most Likely Losses are ~ $3M 18

Modeling Losses with Monte Carlo But we are buying cyber insurance for catastrophe scenarios Heretical Math Use Max as Mean, and Mode as Std. Dev. 3x Std. Dev gives you 99.7% Max Losses ~$16M 19

Stress Testing with Tail Analysis Most Likely Losses are ~ $17M 20

Choosing Thresholds $0 $5M $50M You Pay They Pay You Pay 21

Ted Claypoole Partner Womble Carlyle Jack Freund, PhD InfoSec Mgr TIAA-CREF riskdr.com 22