Showing posts with label #DigitalInsurance. Show all posts
Showing posts with label #DigitalInsurance. Show all posts

Tuesday, June 24, 2014

Part I. Some Cyber Policies: Structure and Organization: Comparisons


Michael Sean Quinn, Ph.D, J.D., Etc.

1300 West Lynn St. #208

Austin, Texas 78703

(o) 512-296-2594

(c) 512-656-0503

mquinn@msqlaw.com


I.                  Claims-Made Policies In General
There is no substantial difference between these requirements in cyber policies and real world policies. All claims-made liability policies—including excess policies—begin with similar concepts. Some liability claims-made policies as originally written require that (i) the alleged injury asserted by the alleged victim against the insured and (ii) the claim for compensation against the insured must all occur during the policy period. In addition, the insured’s claim notification to the insurer must also occur during the policy period.  The requirement that the insured’s claim or notification to the insurer be in writing is often waived.
·         Most claims-made policies have a policy period lasting a year.  Some of the policies require that the injury causing event occurred during the policy period, along with the alleged injury, the claims against the insured, and notification to the insurer. This is a very difficult set of criteria to meetSeldom do that many things occur during a short period of time.
·         A second way a system specified in the contract might work is that the claim is something made by the person or entity asserting injury against the insured and the insured’s making that assertion known to the insurer within the policy period.  In this system, there is no requirement that the injury occur during the policy period. The injury would be required to occur during a specified retroactive period.  In other ways the date of the beginning of the policy period would remain the same. Retroactive periods are an add-on to a given policy that would be sold to the insurer to modify the base policy by lengthening it.
·         A third way for a policy to work is that the injury and the notice must both occur during the  policy period.  If this were the way the system worked, no claim would have to be filed during the policy period. The insured would simply be notifying the insurer of claims, which it believes may arise.
·         A fourth way for the contract-created system to work is that there is an extension period during which the claim and/or the reporting can happen after the policy period ends. This extension comes after the termination date of the basic policy.
·         A fifth way it might work is that there is an extension period “backward in time” so that at least one of the three events required—the injury, the claim, and the notice--can occur during that extension period.  Usually that is the alleged injury. 
A sixth way that the system might work is that there are extensions moving in both directions on the same policy. 
These time limits and specifications are common in both real-world policies and in the cyber-world. The expense is, obviously, to some extent at least, determined by the length of times specified in the extensions. Different extensions can involve different costs, and that can happen on the same policy.
Often in real-world policies the temporal size of the extensions is prima facie fixed by standard, antecedently existing forms. These do not exist in the cyber world, but each insurer will have its own forms. Of course, the extensions in real world appear in endorsements, and they can be further extended.   Extensions deviating from the generally received extension temporal specs found in the standard forms is on the rare side.
Something similar is true in cyber policies even without any industry-wide standardized forms. You would expect there to be more deviation here regarding extensions in policies, but that is not happening. The most reasonable guess is that there are not actuarial statistics to make assorted extensions more reasonably acceptable. The same standardized arrangements regarding extensions will, in the future, will likely evolve in the context of cyber-insurance as it already appears in the real world.  For one thing, most of the insurers producing cyber insurance policies also already produce real world policies, e.g., Chubb, St. Paul, some AIG companies, Travelers, Liberty Mutual, and others.
A carrier can refuse to extend any claims-made policy, just like any other policy. They can also renew the policy and refuse to renew either or both of the extension periods.  Sometimes contracts of insurance, whether real or cyber world, can impose contractual obligations on the insurer to renew coverage.  Obviously, all sorts of insurance policies, including cyber policies, have monetary policy limits; some reduce policy limits by defense costs; some have deductions; others have self-insured retentions, and there are yet other commonalities. (I have never seen an insurance policy of any kind without either deductions or self insured retentions.  I cannot recall running across a policy with both, but in theory that is possible.)

II.                Policy Structures: Cyber and Otherwise

For hundreds of years, contracts of insurance have had the same structures. They have not always been divided up in the same way, but they have been for maybe 100-150 years or more. Most of what is written here is as applicable to excess policies, of whatever level, as it is to primary policies. The structure of policies is quite simple:
(1)               Declarations. One or more sections explicitly stating what coverages are included in the policy, e.g., what perils are insured, who is insured, the upper limits on the policy, as already said, the deductible, i.e., how much will be taken off what the insurer will pay) or the self-insured retention (i.e., how much the insured must pay before the insurer has any obligations),[i] the price of the policy, the size of the policy, sometimes the name of the intermediary, and various miscellaneous information, e.g., email addresses, normal usable phone numbers, emergency numbers, and so forth, for the insured providing notice to the insurer.  In English language lingo, they are called “dec sheets” or “dec pages.”  
There is one substantively important point mentioned here; it concerns what professionals are insured under a policy.  Sometimes on dec sheets there are lists of what or who is insured. In cyber world policies, various kinds of classes of professionals insured are set forth. This can be very important for lawyers.
(2)               Insuring Agreements. There are one or more specifications as to what is insured, e.g., an insuring agreement, with a fully complete panoply of coverages, or a number of different insuring agreements, each with one or very few insured perils listed. The purpose of some of these insuring agreements is, as it were, to provide the insurance customer with a shopping basket. These divisions make no difference to the substance of the policy.
 Sometimes, real world policies, usually first party policies, are “all risk” policies, and others name the perils insured under the policy; sometimes there is one such peril, sometimes more.  In the universally established lingo of insurance, the latter type is called a “named peril policy.” This linguistic fact comes as a surprise to no one, nor does it matter. All cyber-policies are named peril policies; none of them purport to be an all risk policy, whether first-party or third party.
(3)               Package Policies, Another way in which cyber-policies are like real-world policies is that they can be “package” policies. In other words, they can list several insured perils, and the insured may be purchasing all of them, some of them, or some combination of them.  There might be some for liability coverage, and some for first-party coverage, or they might divide between first and third party in given policies but then have different first party perils in one of them and different third-party perils in the other. Cyber policies are now, at least quite often, package policies to some degree.
One bit of information found in the insuring agreements of cyber policies concerns how the insurer will compensate the insured. (i) Some parts of some cyber policies are “pay on behalf of” policies, e.g., when it comes to the costs of defense, but not other parts of the policy. This obligation can stretch out over a whole policy and sometimes it is restricted. (ii) Some sections of the same policy are reimbursement sections and some may be reimbursement policies all the way through.  There is no reason to doubt that some cyber-liability-policies are and will be formulated in terms of reimbursement even as to the duty to defend. Sometimes this is a good thing. If the insured has plenty of money, can afford paying for a defense, and wants to keep all of the policy limits for damages if they have to be paid at some time in the unpredictable future, then a reimbursement arrangement for the duty to defend may be rational. One can easily imagine such things applying to cyber-world liability policies. (iii) “We-will-pay” terms for setting forth the insurer’s duties are different yet; they may simply say the insurer “will pay” for XYZ, but it is not said when.
(4)               Definitions. All insuring agreements in cyber insurance policies use definitions. The amount and complexity of policy definitions is a distinguishable feature of cyber policies. Partly this is true because they are named policies, but there are other reasons, as well. As we shall see in the next bullet point all definitions used in insuring agreements are stacked.  To expand the point, in the last 100-150 years, all the policies I can remember, have used definitions.  As the decades have gone by, more and more definitions get used. Thus, as of now, absolutely all insurance policies are filled with and heavily depend upon definitions. Different signals in the insuring agreement call attention to them: bold letters, underlining, quote marks, italic, and perhaps others.  Cyber policies work the same way without exception.
  In cyber contracts of insurance, there are many more definitions than are usually found in real world policies—sometimes there are as many as 50 or more. These definitions are often quite complex, difficult to understand, and structured as stacks. Stacking means that one starts with the signaled definition; it is connected to one or more other definitions which define that definition; and those definitions are linked to even more definitions. This stacking can be very extensive.  Of course, there can be (and are) stacks in real-world policies, but there are not so many definitions in given stacks.  Fortunately, not all definitions are stacked or stacked to serious depths, but the definitions are always complex.
(5)                Exclusions. All insurance policies contain exclusions. In many 19th century policies, they were there but not named such.  Sometimes they were built into the description of the peril and that is still done; sometimes they were built into the definitions and that is still done. Like definitions, the use of exclusions is more lengthy and more numerous in cyber-policies than in real-world policies. By my observation, there may be as many as 50±, and the definitions used in them are often stacked.  As one might expect, some of the definitions found in cyber-policies are also found in real-world policies; this is true of both claims-made policies and others.  Here are several examples:
o   Deliberate conduct where the injury is itself intended
o   Serious criminal conduct
o   Pollution causation
o   Wartime injuries, and more.
(6)               Conditions. There is always a section for conditions.  Significantly, in the long existing common law of contract conditions are distinct from other provisions in insurance policies. They are not really statements of promised rights and duties.  They are simply descriptions of acts the insured must perform in order to qualify for coverage. It is not a breach of contract for an insured not to perform one of the requirements; the insurer has no right to performance; and the insured has no duty to perform.  Nevertheless, setting aside subtleties, conditions are often treated as covenants.  This is not necessarily a bad thing, since breaches of immaterial covenants by the insured do not end the insurer’s duty to perform.  This change has proved especially helpful in dealing with the most notable policy condition, the as-soon-as-practicable notice-to-the-insurer requirement.
            In any case, here are some conditions to be found in cyber policies. They may differ a bit from policy to policy, but not much, and many of them resemble the conditions to be found in real-world policies:
ü  Notice requirements explanations as to how to provide notice,
ü  information as to how losses of business income/profits (business interruption) are to be calculated,
ü  the conduct of legal actions against the insured,
ü  bankruptcy problems,
ü  subrogation matters,
ü  dispute resolutions clause (usually arbitration),
ü  requirement of mediation,
ü  mandatory appraisal (triggered more often by insureds that insurers),
ü  facts to be disclosed to the insurer by the insured during policy period,
ü  assignment matters, permissible waivers (usually none),
ü  cancellation (how-to + consequences),
ü  renewal matters,
ü  other insurance matters,
ü  that the application is to be included in the policy and
ü  is warranted to be truthful and so forth.
It is important to see that none of these conditions in a cyber policy is significantly different from that found in a conditions section in real-world policies. None is conceptually different.  Instructions on how to give notice in a complex high-tech case may be different from a simple requirement to give simple notice, but the basic ideas are the same. Though conceptually similar, specifications regarding the measurement of business interruption are different. That is quite often left unstated in detail; the foundation of that type of claim is different from most first-party contracts of insurance in the real world, where the foundation for all such claims is physical injury to tangible property, unlike what is required in the cyber world. 
Conditions are usually regulations of behavior. They do not usually say anything about the substance of the policy. They are probably not intended to do that.  Sometimes substantive matters can be “hidden” there, and often procedural matters have implications for substantive matters.
(7)               Extra Section(s). Sometimes there are extra sections. In one cyber-liability-policy I studied recently, there was an extra section devoted to the insurer’s duty to defend, emphasizing limits and exclusions, or what were in effect exclusions. These sections are nearly always found in liability policies, although they are sometimes formulated in terms of reimbursement rather than the insurer paying for the defense “on behalf of” the insured. That section of the policy was not to be found in the insuring agreement where it usually is, nor was there anything about that duty in the section containing definitions. I was and am puzzled by this organization.
Another matter which often occurs in a separate section is how loss adjustment is to be conducted.  These sections identify what insureds are to do about cooperating with adjusters and those on whom they depend, e.g., forensic types, accountants. 
Sometimes, instead of finding the duty to remediate, as much as reasonably possible, mentioned in the conditions section, it is to be found here. These clauses are usually quite brief, even in cyber policies.  This is true even though remediation may well be much more esoteric in dealing with cyber losses than with most real-world cases, even those involving complex physical destruction. 
Historically, there have been a considerable number of disputes about remediation matters; insureds are well advised to provide remediation plans to their insurers and try to get approval.  Often they will be neither approved nor rejected, and it will be said that it is for the insurer to determine what to do and how to do it.  The insured’s, having submitted a remediation plan to the insurer, can have later significant implications.
Yet another important matter that is often to be found in a separate section, if not the conditions section, is how to count the number of causes of loss, and how to think about situations when there are groups of different causes.  The reason this is important is that most cyber policies require that the relationship between cause and effect be “direct.”  Some try to count this as the cause being the sole cause of the effect.  This is nonsense, of course; the word “direct” has no such meaning.  Significantly, the word “direct” and “directness,” “result directly from,” and so forth are often not defined in cyber policies.


[If  enough is enough, perhaps there has already been a bit too much.  Still the reader should please keep in mind that Quinn Blogs are intended to be thought-stimulating [or, thought-provoking] tools only.  The are not intended to be perfected essays.  They are in-progress disquisitions only.  They are not essays polished to completion. Maybe another time.]





[i] Robin Pearson, INSURING THE INDUSTRIAL REVOLUTION: FIRE INSURANCE IN GREAT BRITAIN, 1700-1850 (2004). (Note in wrong place.)0

Thursday, January 16, 2014

Cyber World Insurance and "Kidnap Ransom & Extortion" (KRE) Policies



Cyber World Insurance and "Kidnap Ransom & Extortion" (KRE) Policies


Michael Sean Quinn, Ph.D., J.D., c.p.c.u. . . .
The Law Firm of Michael Sean Quinn et
Quinn and Quinn
                                 1300 West Lynn Street, Suite 208
                                             Austin, Texas 78703
                                                 (512) 296-2594
                                            (512) 344-9466 - Fax

                                E-mail:  mquinn@msquinnlaw.com



The Chubb Group of Insurance Companies has put out a KRE policy that covers both the so-called "real world" and the "cyber world." As readers well know, I hold distinction in contempt; there is one world and various dimensions. Of course, there are a variety of ways in which the cyber dimension of the world can present its self, video games being a prominent one.  Of course, video games are that; they are games; and they are videos of the game.  They are not "eyes" into a separate reality. Nevertheless, I will use the phrases "cyber world," "cyber space" and "virtual world" because of their popular use.

In any case, Chubb has classified this policy as part of a system of policies that it has named "FOREFRONT PORTFOLIO 3.0sm." I will focus on the parts of this policy which cyber coverages are important. The use of computers, digital languages, etc. making ransom demands, dealing with them, communicating about them are not topics here.

Nothing will be said about real-world kidnapping coverages.  There will be no reference to the seizure of real children. At the same time, in this policy, there is no explicit distinction built into this coverage when used in the cyber-world or used in the real-world.  In both cases, some "bad guy(s)," as they are now called on television (and therefore elsewhere, as well) have captured a person and are demanding money for his/her return in exchange for something valuable, usually money.  (Of course, there may be peculiar forms of ransom-demands arising out of cyber-world  and real-world interactions. Exchanging networks for people, exchanging networks for networks, exchanging the life of a child for a pledge of no-more-hacking, a demand that bitcoins be used to pay the ransom, and so forth.)

Background 


This the prose and organization of this type of policy is of the same format, organization, and to some extent the vocabulary as those policies that are typically in this category but conceived only for the real world. It is a "claims-made policy" with purchasable extensions, either or both, (1) back in time for including more insured events for which there may coverage causes and (1)coverage continuing forward in time for including more filing claims, repairing damages, accomplishing restoration, etc., but not new covered causing damage.

Claims-made insurance policies come in many forms. The basic idea of them, however, is quite simple. In a claims-made policy the right to coverage is tied  in time to when the covered event causing damage or injury occurred.  That period of time is often one year, but it could be different. Policies that are not claims-made policies do not tie injury-causing events and making claims arising out of them together in time.  A covered event and the injury it causes can be years apart.

The temporal  tie between injurious event, the injury, and the claim(s) can take different forms. Here is an example. Medical malpractice insurance is to be found in claims-made policy.  If Doctor Diogenes, an amputation surgeon, slices off Larry's left arm, when it should be the right, then the covered negligence and the injury occur at the same time.  After that, Diogenes must make a claim to  Isabella Insurance Inc. during the same policy period.

Of course, claims-made policies and fact patterns can become vastly more complex, e.g., when the injury is subtle and is not noticed for longer than the policy period.  But none of that applies here. Extortion policies and person-napping policies involve very quick successions of time.

First-party coverage is about losses sustained by the insured.  A helpful analogy when thinking about first-party policies are policies covering tangible property.  There are other sorts of first-party policies, but this is a simple and easily understandable  starting point. Obviously, the kinds of policies discussed here are first party policies.

Various first party policies have a variety different provision regarding how and when they are obligated to pay covered damages.  A few will pay in advance for work that has to be done.  Others pay on behalf of the insured for such work. Some will receive the invoices from vendors and pay those.  The far more common provisions obligation that the insurer need pay the insurer for covered losses the insured has paid form.  For example, if the insurer's building tipped over, the carrier would be obligated to pay only if the loss was covered; the insured has paid to repair or replace at least some of it; and the payments are reasonable. These are called, naturally enough, "reimbursement policies."  Sometimes the insurer is not obligated to pay any reimbursement costs until the job is through, but it is far more common for the insurer to monitor the work of the vendor, or of the insured itself, a pay a bit at a time.

The Chubb Policy


This point having been made, it is important to note that all of the coverage in the first-party portions of the Chubb policy (with one exception not relevant here) pay only on a reimbursement basis.  This means that the insured must pay his own way down the path of covered situations and then the insurer will pay him for the reasonable expenses it has spent.  Obviously, this is invariably an area of sharp controversy in all sorts of reimbursement policies.


In cyber policies, the definitions are often crucial. This because much of the terminology if "foreign" users of common English.  The central definition in this policy is of the phrase Extortion Threat.  (In this policy, words and phrases defined in the policy are in bold.) It is discussed here only in so far as it applies to cyber states of affairs.  I am leaving out threats made about doing something injurious to solid objects.

There are no insured kidnappings in the cyber world. Executives of  Microsoft might get kidnapped, but that is a real world. Would it be of any interest in the "world" of insurance coverage if a video game got hacked and some character in the game, some avatar named "Schmuck" was "kidnapped"?  For the same reason, it is hard to see how there could be actual, real demands to pay ransom.  For what?  "I've got your avatar, Archangela, and if you don't pay me a bunch of bits, she will disappear into far cyberspace galaxies a long way away, where you will never find her"?

The idea of extortion, however, works in the cyber world, just fine. "Pay a gazillion dollars into a trust fund at Credit Swiss named "Hackers' Delight" and do it tomorrow between 1:00PM and 2:00PM.  The person in charge of the account is Jack Bauer, ask for him by name."

I will be concentrating on some of the substantive parts of this policy, in particular the part that specified what the coverages are, the portion that consists of definitions, and the part setting forth explicit exclusions. There will be little here about conditions, portions of the policy related to conditions, or the declarations pages.

Insuring Agreements

In any case, here are the subtitles of the "Insuring Clauses," often called "Insuring Agreements." The provide a good start for developing an idea of what is covered:

A. Kidnapping, Extortion Threat and Express Kidnapping Coverage.
B. Custody Coverage
C. Expense Coverage
D. Accidental Loss Coverage
E. Legal Liability Costs Coverage
F. Emergency Political Repatriation Expense Coverage
G. Disappearance Investigation Expense Coverage [&]
H. Express Kidnap Cost Coverage Hostage Crisis Costs Coverage
I. Hostage crisis Costs Coverage

Definitions

Cyber policies often have many more definitions that real-word policies do. This one is not very different, except that most of the definitions are easier to understand. In any case, this policy  It has  
approximately 42 definitions, some of which have quite a large number of sub-parts and only approximately 12 of them have components have parts that are important to grasp to understand the cyber components of the coverage.

The key definitions that are noticeably cyber-related are:
"Insured Person," which I will petty much  ignore
"Extortion Threat," which is extremely important when formulated in terms of cyber matters
"Computer System"
"Computer Violation"
"Contaminate" [here applied only to the physical parts of  "Computer Systems"]
"Expenses," in part [This is by far the longest of the definitions, 18 subparts, though not all of them apply to cyber situations.]
"Extortion Threat," [Probably the most central of all the definitions though applicable only to cyber situations involving one or more Insured(s).]
"Independent Contractor," [In the cyber realm.]
"Insured Event," [Applying only, for our purposes, to cyber matters.]
"Merchandise," [Relevant but not discussed here.]
"Propriety Information," [In the cyber realm.]
See immediately below.

Now for a look at what I find the most interesting definitions of all, the one for the Exportation Threat.  The list of covered expenses for extortion threats is mixed together with  other covered states of affairs that result from such a threat.  Most of these are expenses an insured company (an Organization, as the company called it) has to deal with when there has been an Extortion Threat, or kidnapping, etc.:  Of course, those expenses must be reasonable.  In any case here are some of them:

  • security consultant,
  • public relation consultant,
  • cost of relevant advice,
  • temporary security measures,
  • forensic analyst,
  • security consulted who can analyse the Extortion Threat,
  • fees for retraining relevant employees,
  • &c.
I find this exciting because there are few real world policies have this sort of coverage, some D & O policies being exceptions.  I especially enjoy reflecting on all the adjustment problems which would arises out of the spending on the expenses.  Imagine a controversy over whether the fees of the independent security consultant were reasonable.  Imagine having to deal will controversies about all the expenses at once. 

As already stated these definitions, at least in theory, have some limited applicability to cyber situations, but not all of them are relevant to every such situation, or even most of them.  I am being overly cautious, perhaps, when I say this definition probably does not do much work, if any, in the cyber world.  There is little precedent, if any, in this field, and lawyers involved in coverage litigation on these type of issues can be very inventive and subtle.

Perhaps the central definition in the list is Computer System. That phrase means "any computer or network of computers of an Organization including its input, output, processing, storage and communication facilities, and shall include off-line media libraries..."  Obviously, this phrase as defined includes both solid object, such as the one at which I am working from on this blog and the one you may be using to read what I have written, and would at least appear not to be solid object, e.g., data, its "location, its structure, internal directions and so forth."

The phrase Computer Violation  is just as important. It is divided into three sections.  It means "unauthorized"
(A) "entry into or deletion of data in the Computer System;"
(B) "changes of data elements or program logic. . .kept in machine readable format;" or
(C) "introduction of instructions, programmatic or otherwise, which propagate themselves through a Computer System," where any of these are "directly against any Organization."

[The term Organization is not explicitly defined, but it is probably intended to mean objections that are not natural persons that are insured, e.g, a corporation and a subsidiary limited partnership, or an entity not connected to another Organization that is party of a business system involving "artificial" entities but which has some special status. For example, it might belong to an owner of the central Organization.]

The phrase Extortion Threat is also central. Its essence is that of being a threat, and that  means the damaging state of affairs has not yet occurred.  The extortion is a new though related event. Here are at least some of its relevant parts.  Not all of the threats concern cyber situations; here are some that may:

In any case, here are some cyber-relevant parts of the definition:
(C) threaten to disseminate, divulge or utilize Proprietary Information;
(D) threaten to "disseminate or make negative information regarding the [insured's] Merchandise; or
(E) threat [made by various sorts of persons with various intents and purposes] to "adulterate or destroy any Computer System by a Computer Violation. . ." but to seek payment(s) for not following through. 
the definition further provides.

Built into the idea of Extortion Threats is the idea of Proprietary Information.  This is extremely important to cyber coverage is general, since intellectual property is one of the most difficult and financially significant areas for coverage.  Some violation of the privacy rights of customers of Target, for example, may be awkward, irritating, worrisome, and reputation-reductive for a short time, but actual serious financial losses have heretofore proved unlikely, and their probability may be diminishing further as time goes by.  IP is a different matter' both individuals and business fact tremendous financial losses.

Consequently, the terms of the definition are "all important," as popular slang would have it, and here it is: "Proprietary Information means any confidential, private or secret information unique to the [Insured's] business including client lists, drawings, negatives, microfilm, tapes, transparencies, manuscripts, prints, computer discs, or other records of a similar nature which are protected by physical or electronic control or other reasonable efforts to maintain nondisclosure of such information."

[Interestingly, coverage for Proprietary Information is not created by an insuring agreement.  It is through an insuring agreement for Extortion Threats and then Proprietary Information being central to the definition of Extortion Threat.

[There will be controversies coming out of this definition.  Significantly, the term "copyright" does not appear in this definition, and the title of phrase being defined includes the word "information."  Copyrights are not necessarily information.  A new novel or a new poem may be copyrighted, but they may contain no information at all.  The same point applies to other art works as well.  Abstract painting of Jackson Pollock? One by Hopper? A concerto by John Cage? A painting by Balthus?  (Paradoxically, there are exceptions: works of art which are not copyrighted but which contain information.  What did Machiavelli look like?
What about music that contains codes with information in them which can be understood by the few?  Can allegory every count as information?  What about metaphor?  A novel that contains a fictional character but one which "everyone" knows is really a deep literary portrait of Bathsheba Finkelstein {an actual friend of mine from graduate school}, and many people know that this is who being portrayed.

[Another area of likely conflict is whether that which is being insured is something belongs of the insured? Does that insured have an ownership interest in that information?  Must  that insured have an ownership interest in that which contains the information?  A place that might arise is in cyber insurance for law firms.
The Quincy, Quiggley, Quinn Firm has "tons" of information on all sorts devices, and none of it or them belong to the law firm.

[Or suppose the owner of the Proprietary Information has 100 devices upon which some of it is stored, but half of them have no information at all, or material, like abstract art, which may or may not have information. . . . .Notice that the list of definition does not contain one for what counts as information.  Can a proposition that is false count as "information"?  What if the client lists contained one falsehood?  Surely the list would be information.  Now consider the document entitled "Client List" where all but one of the entries is false.  Surely that would not be information.  Obviously, there is such a thing as "alleged information" which is not information. Some might think that this is what litigation is all about.

Thus the idea of Proprietary Information is not like all that is found in the idea of intellectual property.  However, the notion of Propriety Information might be just as good when it comes to trademark and similar matters.]

Obviously, there is much more to say, but at this point the discussion here may be enough for now.

Exclusions

Most of the "Exclusions" are common to kidnap, etc. policies.  They do not fit with cyber extortations, so they will be ignored, for now.

********************************************************************************
p.s. Keep in mind that in the cyber world, the use of this policy is very limited when it comes to Extortion Threats.  I shall return to this topic in another blog.




Friday, October 4, 2013

An Ironshore Cyber Policy--Part IX: I.H: Business Interruption Income Loss--Part IX

TechDefender

Tech E&O, Network Security, Internet Media and MPL Insurance Policy 

Insuring Agreement I.H: Regulatory Proceeding Coverage
Remember: This Blog is organized around insuring agreements, definitions and exclusions. Conditions, etc., may be remarked upon briefly, but they often resemble not only each other but those found in currently existing policies. It also ignores policy limits, retention matters, notice requirements, time intervals for coverage, etc., important as these are. As usual, the discussion of everything in this blog is tentative, partial, and perhaps mistaken here and there.  It is a new and relatively uncharted ocean.
__________________________________________________

BUSINESS INTERRUPTION INCOME LOSS AND DEPENDENT BUSINESS INTERURUPTION INCOME COVERAGE is the title of this insuring agreement, I.H. 
A good part of this title is familiar from commercial first-party (often property) policies, where the idea of property damage begins with the idea of physical injury to tangible property.  Obviously, that will not be the beginning of BI*or DBI coverage in cyber-policies.  Still, in terms of purpose this insuring agreement corresponds to the similar insuring agreements found in so-called "real world" policies.

 [*BI is a standard appreciation used to denote Business Income Losses in todays so-called "real world" policies.  Previously, BI referred to Business Interpretation Losses.  Many do not know why the terminology changed, and I am one of the many.  Maybe it was to accentuate the fact that there had to be an income loss; I suspect that was always true.]
Here is the verbatim quotation of  insuring agreement of I.H:
The Insurer will pay the Company any Business Interruption Income Loss [BI], Dependent Business Interruption Income Loss [DBI] and Extra Expense the Company sustains during the Period of Restoration as the direct result of an Interruption in Services, provided that such Interruption in Services first occurs during the Policy Period. 
Before turning the central substantive definitions, several matters need to be discussed.
First, only the Company really covered; only its losses  are to be paid.
Second, under this insuring agreement, the Insurer "will pay" is a key obligation of the Insurer.  This is more flexible that "will reimburse.  Interestingly, there is no restriction of when the Insurer is obligated to pay. Probably all cyber-insurer that use this language are governed by the law--a more or less general law across at least most states in the U.S.--that requires the insurer to pay promptly, once it has the information, etc., it reasonable needs to calculate what it owes.
Third, the Period of Restoration is defined (pretty much) as the reasonable length of time it takes the Company to get its cyber operation up and running again, measured starting with the time there was covered Interruption in Services, but lasting no more than 30 days.

 Obviously, the Period of Recovery to reach out beyond the end date of coverage under the policy This topic is often a matter of dispute.  One of the principal topics of dispute is  whether the insured made is snappy to get the fix completed.  An enormous number of facts and therefore components of an (or more than one) investigation are involved in any relevant adjustment and/or adjustment dispute.  As a general rule, periods of restoration can be extended by endorsement, like lots of things in insurance policies.
Fourth, the term "direct result" again serves a crucial role. For more on  this matter, see Part VIII: I.G, for example.  The ideas of direct and indirect is illustrated nicely by the workings of "Silk Road."  Some of it is direct, I think, in particular,  the mailing of the "goods."  Some of it indirect, I believe, namely, the modes of purchasing the "goods."
Fifth, the Company's Computer System is an obvious term the meaning of which is intuitively obvious at a surface level.  Of course different companies what have different systems used for different purposes.  In this definition, an insured system is one restricted to working solely for the Company's benefit
We now arrive at what might be called the crucial topical definitions.
The definition of Interruption in Services [IS], the covered train of events which do covered injury or damage to the Company.  Which ISs are covered and which are not is to be found in this definition.  IS "means the actual and measurable interruption, suspension, failure, degradation or delay in the performances of the Company's Computer System, if directly caused by a Network Security Incident.  [Notice that the idea of being direct is a necessary condition of being an IS and therefor of coverage.  Given the general terms--one is "measurable"--one can bet that there will be disputes grounded on this idea.]
BI and  DBI are the crucial definitions for describing the types of  injuries/damages for which the Insurer will pay.

BI means, roughly speaking,  the Company's loss of "net profits before income tax" that the Company is prevented from earning as the result of IS and its normal expenses, e.g., payroll,  that "must continue" during the Period of Restoration had there been no IS

 [This is a relatively standard surface formulation of BI for a very long time.  Extra-help that has to be brought in to straighten thing out is an Extra Expense, not a loss.  Notice that the general BI can be brought about by an assortment of causes of the IS, and that the cause of the IS might actually involve more than one cause, so that the IS need not directly result from a single cause.]

DBI is one of those components of this insurance policy that contains of "direct;" once is "direct result of" and the other it is "caused directly by."  It is even more complicated than passages where there is a double occurrence of the word; for this reason it is necessary to quote some of it.  It is a BI loss "as the direct result of an IS[, and it] is caused directly by a Network Security Incident to the
Service Provider's Computer System  but only if such Network Security Incident would have been covered under the Policy had the Service Provider been entitled to insurance in accordance with the terms, conditions and other provisions of the Policy."

This is a very complicated provision.
The place to begin is with the word "dependent.  The point is that this form of BI must be triggered  by an injury to something upon which the Company depends, and--if anything--will be the Service Provider. The surface idea of a Service Provider is easy enough to understand, though it must be understood that it is a separate company, a vendor, and there is a forma contract with the Company.  It's computer system is simply a Computer System somehow and/or to some extent belongs to it, as the term is defined in the policy.  It is the Service Provider's Computer System that must be subjected to a Network Security Incident.  

That is a defined term in the policy. It, very roughly, means some sort affliction is directly imposed upon the Service Provider's Computer System, such improper use of it and/or the introduction of a Malicious Code, that directly results in specified injuries/damages to the Company's Computer System so that it is subject to IS or a "corruption or deletion" of Digital Assets."  However, under the definition of DBI there is a necessary condition:  the Service Provider must be such the Network Incident "would have been covered under [this] Policy had the Service Provider been entitled to insurance in accordance with the terms, conditions and other provision of the Policy."

One thing this means is that the insurance of the Service Provider must been equivalent to the Company's policy in terms of strength and scope for the Company to have coverage.  If the Service Provider has weaker or no coverage, the Company will have no coverage for DBI.  Something it might mean is that the Company's Digital Asserts have been "corrupted."  Unfortunately, that is not a defined term, although the term is commonly used in cyber-circles.
 So far as exclusions are concerned, there do not appear to be any that apply uniquely to this insuring agreement, and if so there are none that are prepared for it.  Plenty of exclusions that are to be found in so-called "real world" policies apply to it and to the rest of this policy, and lots of new fangled exclusions for the "virtual world" also apply to it.  Still, there is nothing further that needs to be said about this exclusionary matter just now. 


Wednesday, April 24, 2013

Cyber Insurance Policy--Sample #2: A Liability Policy--Chubb




Michael Sean Quinn, Ph.D., J.D., c.p.c.u. . . .
The Law Firm of Michael Sean Quinn et
Quinn and Quinn
         1300 West Lynn Street, Suite 208
                     Austin, Texas 78703
                          (512) 296-2594
                         (512) 344-9466 - Fax


                     E-mail:  mquinn@msquinnlaw.com


Preface

This blog discusses the insurance policy listed below. There are more than several cyber insurance policies available these days, but there is no real literature about them.  There are one or two pieces in law reviews, but there is no real discussion of what the policies contain or  how they work.  This is an attempt to do just that.  This policy is narrower than others and it is not a paradigm of cyber liability insurance policies. 
There are not (or few and hard to find) judicial decisions on cyber insurance policies/contracts, e.g., treating coverage matters. There may be a few out there, but they are not reported, and I have found no real references. One of the propositions that the forgoing implies is that, I do not believe that I am giving a comprehensive account of this policy, or others I have discussed and will discuss. In addition, I do not so much as suggest that what I am saying can be taken as gospel. That sort of thing, if it comes at all, is far off in the future.  If you are inclined to think I am a prophet, I am flattered, and while you may be right, do not bet large sums on it, although you have my permission to cite me in coverage opinions, law review or magazine articles,  court briefs--or, for that matter, judicial opinions.
I will not be  giving a full explication of the policy; much of it is left out. The main concentration is on the insuring agreement, the definitions, and the exclusions. Not even all of them are discussed.  The main reason for this is that many of the components of not only of the exclusion section, but  the conditions and the miscellaneous sections, are not really very interesting in studying and thinking about cyber policies. One reason for this is that they are quite similar to what has been characteristic of insurance policies for many years.
My comments on the policy, immediately below, will be enclosed in brackets, "[   ]."
This insurance policy--or a predecessor--was issued for the first time in 2000. The following comes from a 2006 version.  It is a liability policy--a third party policy.

Chubb Group of Insurance Companies

SAFETY’NET INTERNET
LIABILITY POLICY


1. Insuring Clause [Insuring Agreement]

The Company shall pay on behalf of each Insured all Loss on account of any Claim first made during the Policy Period arising out of the Insured's Internet Activities which occurred on or after the Retroactive Date set forth in ITEM 7 of the Declarations.

[This insuring agreement cannot be understood without grasping the relevant definitions, at least to some extent.  One important thing about it is characteristic of many policies that have been in use for many years, e.g., Directors and Officers Liability Policies.  Policies like that have a certain period of coverage, and or more event must happen during that interval.  These include (1) events giving rise to a claim against the insured, (2) the claim against the insured, (3) claims by the insured "against" the insurer seeking coverage, or (3) up to all of them.   In this case, that which gives rise to the claim-again-the-insured must occur during the policy period, as must the claim against the insured itself, as well as the insured's claim against the insurer. Because of this ostensible fixed schedule, the insurer offers extension periods.  They can be retroactive or for the future.  Thus if a claim-against-the-insured is originally required to be submitted  the policy period, that time interval can be increased by an interval of time back into the past, or it can be stretched out into the future.  The insurer may or may not have a right to refuse these extensions.  In any case, extensions demand payment of an additional premium.]

[On items on a Declarations Page/Sheet, see the discussion of definition (f) and (g).]

2. Definitions

(b) Defense Costs means that part of Loss consisting of reasonable costs, charges, fees (including       but   not limited to attorneys' fees and experts' fees) and expenses (other than regular or overtime wages, salaries or fees of the directors, officers or employees of the Named Insured) incurred in defending Claims, and the premium for appeal, attachment or similar bonds.

[The language of this definition entails that the insurer's costs of defense will diminish the amount available to compensate the complainant against the insured.  This proposition is reinforced elsewhere in the policy.]
(f) Internet Activities means
          (i) display or use of other Matter on an Internet Site;
          (ii)  transmission of Matter via an Internet Site; or
          (iii) the disseminating of Matter by any other means of publication or communication shown
                 in Item 8 of the Declarations.
(g) Internet Site means an Internet site shown in Item 8 of the Declarations.

(h)  Loss means any amount which an Insured becomes legally obligated to pay on account of any Claim, including but not limited to damages (including punitive and exemplary damages, where insurable by law), judgments, settlements, costs and Defense Costs. . . .
[Remember: Defense costs are part of the loss, so that the expenditure of defense costs reduces the amount that is available to pay the indemnity part of the claim.]
(i) Matter means printed, verbal, numerical, audio or visual expression, or an other expression, regardless of the medium upon which such expression is fixed.
3. Exclusions

The Company shall not be liable for Loss on account of any Claim made against any Insured:

Anti-Trust:  (d) arising out of allegations of price fixing, restraint of trade, monopolization, unfair trade practices, or any actual or alleged violation. . . .

Patent Infringement  (h) arising out of any actual or alleged infringement, contribution to infringement, or inducement of infringement of any patent[.]

Governmental Actions:  (i) brought by any federal, state or local regulatory agency or other administrative body alleging the violation of any federal, state or local laws or regulations.


[So far as I can tell, the rest of the 14 or so exclusions, depending on how they are counted, are not very interesting either because they are part of commosense, because they are not uniquely related to cyber insurance situations, or because they or some close variation of them, are well known from other types of currently existing commercial liability policies.

Reporting and Notice 5.  Insureds must give Chubb written notice of a claim against it "as soon as practicable" but within 60 days and no longer. This demand is described as a, "condition precedent to their exercising their rights hereunder. . . ."  In addition, it is also a "condition precedent" of an insured exercising any of its rights that it provide the insurer (Chubb) with such information and cooperation as it may reasonably require.

[This clause is common all over the industry. The first part is commonly called the "Late Notice Requirement" or the "Late Notice Condition," while the second half is often called the "Duty to Cooperate Clause."  Insurers usually describe these requirements as conditions, but a number of courses have ruled against this understanding of the clauses. The reason is that the clauses, as set forth in the policies, are held not actually  to be conditions for various reasons; instead those courts treat them as covenants, meaning simple promises in the contract. This distinction can make a lot of difference in litigation, but it is easiest for the insured to act in accordance with the language of the insurance contract, and avoid that dispute even if the law is "on his side."]


Defense and Settlement 6.  The Company shall have the right and duty to defend any Claim covered by this Policy...The Company may make any investigation it deems necessary and may, with the consent of the Named Insured, make any settlement of any Claim it deems expedient... Defense Costs are part of and not in addition to the Limits of Liability set forth in the Declarations, and the payment by the Company of Defense Costs reduces and may exhaust such Limits of Liability. 

[The "duty to defend clause" is often among the most important clauses in the insurance policy. This matter is commonly known, so nothing more needs to be said about it here and now. It must be remembered that the amount that is paid for a defense, shrinks the amount of money available to pay the plaintiff, if that is necessary. This feature is not common in ordinary commercial or personal liability policies, but it is common in malpractice policies, aka "E & O Policies," aka "Errors and Omissions policies."  Usually, these policies are for "professional" malpractice, e.g., doctors, lawyers, accountants, engineers, architects, and so on. Duty to defend clauses usually contain investigation clauses, cooperation clauses, and  clauses regarding settlement. Settlement clauses can be particularly important. They usually authorize the insurer to settle a case with the consent of the insured. However, if the insured refuses to consent, the insurer's obligation to pay damages may be restricted to the amount for which the case could have been settled.  (Sometimes, the insured also ends up being liable for attorney's fees accumulated after the case could have been settled.  That is not the case in this policy.)]

There are a number of other clauses, most of them routine, so they will not need be discussed here.  Here are their titles:
  • Allocation [as between covered and uncovered events]
  • Extended Reporting Periods
  • Spousal Liability Coverage
  • Other Insurance [sometimes other insurance policies pay first]
  • Representations and Severability [Assertions in the application must be true and are part of the policy.
  • Territory [where there is coverage]
  • Notice
  • Subrogation
  • Action Against the Company, i.e., the insure [Insured's full compliance with the terms of the contract is a condition precedent upon the insured suing the insurer.  Seldom enforced these days.]
  • Bankruptcy
  • Authorization
  • Alteration and Assignment [The insured may not do either one.  Strictly enforced.]
  • Cancellation and Non-renewal.
[Sometimes these "conditions" or "conditional clauses" or "alleged conditions," can contain what might be called "tricks."  Consider the "Late Notice Clause,"  it requires that the insured give notice no later than the 60th day.  Does this mean provide or receive? If request for coverage is sent my mail, several days may pass. So might a late night notice emailed to an insurer.  This sort of thing does not come up often and generally the reasonable insurer doesn't seek to enforce this clause over these kinds of situations, except--maybe--where fraud is plausibly thought to exist.]

______________________________________________________________________________

Essay on Coverage

This discussion will concern one aspect of coverage: that which is obviously included in or involved with the Insuring Agreement, Definition (f), and the Definitions contained therein.  

Definition (f) begins with the Definition of Matter. Generally speaking,  the defined term "Matter" refers to a concatenation of instruments of communications, and the communication they can be used for can be of any sort. The human voice, however, is not mentioned though it seems to me that it is implied.

An Internet site is a "something" by means of which communication can occur over the Internet. (n: Internet Site is any Internet site listed on the declaration page of the policy. Notice that cyber communication systems are not within the definition and therefore not insured.

[1] (f)(i)So an Internet Activity is, among other things, the display of Matter on an Internet site listed in the policy--that is an Internet Site;
[2] (f)(i)An Internet Activity, is also, among other things, other use of Matter on an Internet site listed in the policy--that is Internet Site  (I take the phrase "other use" to include a variety of other uses, and note that the term is not defined in the policy.  I think it's reasonably clear that the word "use" really means other "uses.")
[3] (f)(ii) transmission of Matter via an Internet Site; (It is unclear whether "transmission" means out, in, or both. I see no difficulty in taking that word to mean both outgoing and incoming.   
[4]  (f)(iii) dissemination of Matter by any other means of publication or communication shown in the specified place in the policy. I find (f)(iii) puzzling:

  • First, the difference between transporting and disseminating is not obvious. Either of them could be be intentional or unintentional. One can transport one thing, but the idea of dissemination seems to imply "moving" more than one thing. 
  • Second, (f)(iii) a dissemination pass through an Internet Site before can be something insured.  Of course the communications device that falls within (f)(iii) has to be listed in the specified place in the policy. Does that makes it discretionary for the underwriter for the insurer to decide how to deal with a particular disseminatrion device, say, the Wall Street Journal.  Or does is make it discretionary for the underwriter of the insurer to decide what categories of dissemination outside of Internet will trigger coverage through (f)(iii), say, newspapers, but not TV. 
    • It would not surprise me for the insurer to opt for the former, say, there must be a particular magazine listed if it is to trigger insurance through (f)(iii), e.g., The New York Review of books
    • It would not surprise me for the insured to opt for the latter, e.g., magazines or magazines containing book reviews and so forth
    • I am inclined to think that the near sentence in (f)(iii) means extra-Internet category.
    • This reasoning does not need an argument from ambiguity.  An ambiguity argument may be needed to distinguish general categories from categories that are not general and are nothing but semantic games designed to make the particular look general
  • Third, why might (f)(iii) be included in this kind of policy when (f)(iii) falls within CGL coverage, when liable, etc.from Coverage B is involved? Maybe its to deal with the insuring the insured's  passing along incoming messages  libelous information.
In any case, the fact that this is a liability policy is quite clear. We shall be examining some first party policies and other liability policies as blog-chapters go along