Showing posts with label computing. Show all posts
Showing posts with label computing. Show all posts

Monday, September 9, 2013

An Ironshore Cyber Policy--Part IV--Ins Ag I.C


TechDefender

Tech E&O, Network Security, Internet Media and MPL Insurance Policy 

Insuring Agreement I.C--Privacy Liability Coverage
__________________________________________________
 
Remember: This Blog is organized around insuring agreements, definitions and exclusions. Conditions, etc., may be remarked upon briefly, but they often resemble not only each other but those found in currently existing policies.
 
This is Part IV of a series of blogs about the above named policy.  Part I was an introduction and a discussion of Insuring Agreement insofar as it closely resembled "physical-world" policies, as opposed to "cyber-world" policies.  The topic pertained to D & O insurance.  Part II was a discussion of the substantive content of the Insuring agreement Ins Ag I.B, again regarding a type of D & O liability insurance.  I.A. pertained to network security and privacy wrongful acts, both of which are extensively discussed in society.  Ins. Ag. I.B concerns the same range of problems and is a broader D & O liability policy.   As already set forth in Part I, what is written here is nothing more than a sketch and the observations are not guaranteed.

I.C. Privacy Liability Coverage
This Insuring Agreement sets forth liability insurance for Damages the Insured is legally obligated to pay for losses directly resulting from any covered claim alleging a Privacy Wrongful Act  against the Insured. (The last term includes not only the Company, plus directors and officers, but a variety of others, e.g.,  employees of various sorts, among others.)  [This passage is a bit confusing.  It  might apply to a duty to defend, or something like it, but it well not apply to actual damages suffered.  The idea in the claim is that if an insured has a legal obligation to pay something that is damages, the insurer will pay it on its behalf.
The substantive components of this Insuring Agreement are, first, the idea of Privacy Wrongful Act (PWA), second,  the idea of Privacy Incident, and third, the idea of  Damages (D).  

First we examine PWA, since the term "privacy" is not independently defined, so we start with PWA.
This is a blessed definition since it is short and direct.  PWA "means any actual or alleged act, unintentional error, omission, neglect or breach of duty by an Insured or a Service Provider that results in a" PI. 

PI--and now we arrive at the crucial part of the insuring agreement--is, roughly speaking (1) the unpermitted disclosures of Non-Public Personal Information or Confidential Corporate Information that "is in the care, custody, or control of any Insured or Service Provider, ad defined., or (2[a]) it is a violation of any Privacy Regulation or (2[b]) or is a "failure to comply with the  Company's own privacy policy."

Privacy Regulation is a concept of extraordinary significance.  It includes a number of named federal and state statutes "associated with the control and use of personally identifiable financial, medical, or other sensitive information," plus "any similar, state federal or foreign identity theft or privacy protection statute."


 
DEFINITIONS

Damages of course, is a crucial idea in all insurance policies.  The definition of Damages in this policy is a complex one, to say the least. There are 4 components of what the term means, and there are 9 lines setting forth what the terms does not mean, and the 9th line contains at least 13 different concepts which the term does not cover.

Here is that which the term applies.  It resembles traditional lists of damages in some "so-called" real world policy:
  • that for which the insured is legally obligated to pay as the result of a covered judgment, award or settlement
  • monies the  court victorious victim has been able to impose on the insured, e.g., attorney fees and so forth
  • pre- and post-judgment interest (with exceptions)
  • punitive, exemplary or multiple damages to the extent that an state law applies and to the extent more that one applies, the one which is most favorable to the insurer if insurable.
Defense costs are usually covered else where in the policy; they are usually not found in the definitions of damages.
An apparent complexity in the definition of Damages is to be found in a list of that to which the term does not refer.  The positive side of the definition is straight forward and relatively simple.  Most of its components resemble the definition or characterizations of Damages found in so-called "real-world" policies, except for defense costs.  That matter is usually set forth else where in at least most policies. The "Damages do not include" section explicitly sets forth a number of situations to which the term Damages does not apply. These matters are usually found in exclusionary sections.

There are several special components "added" on, as it were, to the definition of Damages, which are "not included" in the definition section or other sections of so called, "real-world" policies--as already stated, one would expect these to be in an exclusion section. The following are included among the not included:

#6. nearly 5 lines of activities which might have to be undertaken, including "Computer System of the Company, [its] security system and Electronic Publishing."  Significantly,  Electronic Publishing includes Electronic Data, and other things, objects, events and activities.  [MSQ:  Obviously this definition of what is not included in the a covered definition is enormously complex.] 

#7. "any discount, coupon, prize, award, redemption or other incentive;"

#8. "Bodily Injury or "Property Damage;"  [MSQ: It is easy to see why they are let's say excluded, by definition, they are two of the principal coverages under some significant "real world" insurance policies, e.g., the Commercial General Liability.

#9. Business Interruption Income Loss, Claim. . . . Regulatory Proceeding.  [In total, there are 13 separate categories included in this "not included in the definition of Damages" category.]

 And so forth. Significantly, all definitions found in the definition section are used throughout the policy.  In many "real world" policies, different sections may have at least some different definitions
EXCLUSIONS
 
The list of exclusions is a long, long one, so not many of them can be addressed.  Some are repetitions of what is in the definition or the "not included" definition of Damages and perhaps elsewhere to boot. Many of them resemble, or are analogues of exclusions found in so-called "real world" policies.
For example, there is an exclusion for Losses resulting from various causes, most of them contract based (or likely contract based).  It is more complex than the usual exclusion of that sort; it takes up 7 lengthy subsections. Perhaps what is happening here is that given the "new-ness" of this type of policy, the insurer is trying to make sure nothing is left out. Perhaps it believes that details cut exposure. Of course, this may be wrong. It may be that all they do is create new exposures.
Here are some other exclusions:
  • based on actions brought by some trade associations, particularly an international array of those from the IP sector
  • based on violations of various statutes
  • resulting from various kinds of discrimination
  • resulting from various types of unsolicited cyber misconduct
  • thefts of various sorts
  • IP misconducts of various sorts related to thefts  [Some of these pertain to the proposition that there is no insurance for many types of intentional acts and especially for those involving crimes.]
  • mechanical and electrical faults
  • gambling, etc. 
Thus, this insurance policy in general and perhaps this section in particular resemble "real world" insurance policies, but in vastly more important ways, they are a new species--one filled with new ideas, new definitions, and new coverages. Interestingly, most of the new coverages are, in one way or another, topics widely discussed in various media.
Now, for Insuring Agreement I.D Privacy Breach Expenses Coverage.  See Part V.






 

 

An Ironshore Cyber Policy--Part III



I should have mentioned this point before, but the policy is not typical of at least some other important cyber policies, or--more accurately--other groups of cyber policies. (There is just too much in this one to be typical of the simpler or narrower ones.  Several simple ones have been blogged earlier in this blog string.)

Remember: This Blog is organized around insuring agreements, definitions and exclusions. Conditions, etc., may be remarked upon briefly, but they often resemble not only each other but those found in currently existing policies.

__________________________________________________________________________________

TechDefender

Tech E&O, Network Security, Internet Media and MPL Insurance Policy 

 

Insuring Agreement: I.B Network Security Liability Coverage

_________________________________________________________________________________



This part will focus on the Insurance Agreement to be found in I.B.  It is entitled Network Security Liability Coverage.  The phrase Network Security and Network Security Wrongful Act have already been sketched in Part II.

The difference between I.A and I.B is that the word Insured plays a key role in the insurance agreement.  What is crucial in I.A is that it covers only Individual Director[s] or Officer[s] and not the Company.  I.B covers both the individuals and the Company and other Individual Insureds. The third category of insured includes:
  • certain past, present, or future employees acting within their scopes of employment and/or their "functional equivalents," [The idea of future employees having liability is entreating.]
  • an independent contractor working for the Company (on its behalf and for its "benefit") and committing a Wrongful Action while within the scope of his retention, which must be in writing.
Thus, this is not a "Side Excess" policy, and so individuals who are directors or officer (or both) do not have as much coverage.

As yourself whether the responsibilities of an Insurer to provide a defense for its Insured is the same as in I.A.

Keep in mind, there is a duty to defend. There is a separate section in which the duty to defend liability cases is set forth.  This fact may be confusing even to the more experienced reader.  The reason is that the duty to defend it usually set forth in the insuring agreement section of a policy. Here the opposite is true.  That duty  gets its own section,  The insurer's duty to defend in this policy may be weaker than in many so-called real "world policy."  Most policies of the so-called "real world" require a liability insurer to defend its insured if the plaintiff's pleading states--or, probably in many jurisdictions, sketches  a covered claim; it does not require that the claim actually be covered.  The plaintiff (and possible victim) can be wrong about what is asserted in the pleading or even lying, and there still be a duty to defend. The liability sections of this policy don't appear to say that.  It at least appears that the claim must actually be covered.  I don't see how that can be true, but if I have understood the language, that is what is says.



Almost certainly I.B can be removed by endorsement.

Monday, September 2, 2013

An Ironshore Cyber Policy--Part #1

Michael Sean Quinn, Ph.D, J.D., Etc.
1300 West Lynn #208
Austin, Texas 78703
(o) 512-296-2594
(c) 512-656-0503

TechDefender

Tech E&O, Network Security, Internet Media and MPL Insurance Policy 

Part One (i):  Introduction

In previous parsing of cyber policies, I have tried to do whole policies all at once. That approach won't work for this policy; it may have been a bad idea as all times and across the board. With regard to this policy, I am going to divide it up, so that the individual blogs are much, much shorter. The attempt will be to do, where possible, one insuring agreement per part. In addition, there will be not attempt to spell out in detail each relevant provision: insuring agreement, definition, condition, and/or what have you. This may lead to subtleties being left out and/or other errors, but I will probably come pretty close
I will include one small  substantive thing in this introductory section.  It is a concept taken over from standard, tangible Director & Officer policies, and since the D&O insuring agreement in this policy comes first in the discussions--it is, after all, the A insuring agreement--that order makes sense, at least for now.
This Ironshore contract of insurance is a complex--very complicated--blanket cyber policy concentrating mainly on liability insurance. It contains 11 different insuring agreements (A-K), 60 "primary" definitions and a great many "included" definitions" (A-LLL).  All the insuring agreements contained at least one primary definition, and many of the primary definitions are to be found in more one.  Many of the definition parts, at least, are really exclusions in disguise, though courts do not pay attention to that obvious truth. 
In addition, there are 22 exclusions, some containing subparts, some of which take more than half a page, and--of course--almost all of them use at least one of the definitions.
Taken as a whole, the policy is 34 pages long. The application takes up 13 pages, and it becomes part of the policy. 
*******************************************************************************
 Part One (ii): Close to an Introduction
Preliminary Observation Regarding Insuring Agreement I.A

Insuring Agreement: "SIDE A" D&O LIABILITY COVERAGE

"Side A" is the first phrase in the first insurance agreement.  Many readers will not recognize it, so let's start there.  The locution "Side A" is not the same as the designation of Insuring Agreement I.A.
So, what is "Side A"?  The directors of corporations won't serve without some sort of protection from liability.  The same thing is true for "senior" officers, e.g., CEO, COO, some VIPs--roughly, whoever is named in the bylaws of the company as an officer: "Big Deal Administrators Capable of Large Decisions." 

Such protection--indemnify protection--can be provided by the entities themselves. Then again, consider Enron. Nobody wants that.

Or consider what might happen if the company went bankrupt.  The directors and perhaps the officers might  get dragged into the pit. Consider the failure of Dewey LaBoeuf.

Now consider a financial liability policy on the corporation, as well as the directors and officers. In this situation the company might take care of its self and throw the directors and officers "under the bus," as they say.

It's better for the directors and officers to have their own policy, and its better for there to be separate policy limits for each of them built into the same policy. These policies are called "Side A" policies. They are called excess policies because they quite often stand above other policies and funds. If the company can pay on behalf of a director, the Side A policy is never triggered. If the insurance on both the company the individual directors and   officers pays, then the directors and officers are protected. Only when neither the company itself nor the insurance policy covering  the company, the directors and the officers can pay all owed is the insurance that directly covers only the directors and officers, i.e., the Side A policy, ever triggered. Only if the underlying policies cannot pay will the Side Excess policy step up to the plate.

Of course, there is always the possibility--even if--it is extremely unlikely and not the sort of thing normal business persons and insurance underwriters would ever think will occur.  This would happen when neither the company nor the "together-we-stand D&O policy" actually has coverage. Maybe the individualized Side A policy would provide coverage.  If so, then the Side A policy wouldn't be just an excess policy but an umbrella policy as well.

Make sure you have read the immediately preceding blog in "Wrongful Acts, Claims, and Responses."

Now for some cyber insurance policy discussion focusing on one very complex policy.  It will involve at least 12 parts, all keyed to different insuring agreements.

Thursday, June 13, 2013

Computer Clouds, Lawyers, Law Firms and Insurance


Law Firms in the Clouds

Of course, the words clouds, clouding, in-the-clouds. cloudy, and so forth, even rain cloud, apply to law firms for all sorts of reasons, so one must be clear when the discussion regards things cyber-istic, and so forth, as opposed to more established meanings. Nevertheless:

Law firms and the Clouds

"Computer Clouds" are like computer based electronic, information storage set-ups.  They are used by many types of business organizations.  Large law firms are switching over to them to approach being a Paperless Office. (See the very helpful elementary book on this topic authored by Benjamin F. Yale and published by the ABA in  2012.)  Mr. Yale was an undergraduate at Yale, did his law school studies at Northern Ohio and has spent a good part of his adult life being an agriculture lawyer with a specialty in dairy insurance.  This fact is worth mentioning because he has worked for very large organizations that store lots of data and therefore probably knows what he is talking about pp. 127-28, where Mr. Yale has created a compare-and contrast chart for "Cloud Root Storage Options" with those of the Traditional kind."

Another helpful book--a long pamphlet really, by three authors-- entitled ASTAPORE SPECIAL PROJECT: UNDERSTANDING THE LEGAL RIGHTS OF CLOUD COMPUTING--NAVIGATING THE NETWORK SECURITY AND DATA PRIVACY ISSUES ASSOCIATED WITH CLOUD SERVICES (2012).  This book lists an array of problems, components of due diligence, and some of what should be in contracts between providers and users.

Clouding Business

An astounding fact is that amongst all the huge literature on "clouding" activities there is either next to nothing (or very little) about the role of insurance in the domain of cyber-clouds and almost none of it is about the characteristics of what might be called "Cloud Policies" and related topics. Aside from an article in FORBES, which  is a dead end with regard to these topics, and maybe an ad on the Internet for Accenture, a management consulting firm, there is less than slim pic'ens 

So far as law firms are concerned, I have found no advertisements regarding their use of clouds and relevant insurance, except for a few cursory and shallow ones.  Still, there is a fairly interesting set of essays by Roberta D. Anderson,* and it contains a squiggle of material about cloud insurance.

[*Anderson is at K & L Gates, a law firm, and her essays can be found at 12 Insurance Coverage Law Bulletin ## 4-5 (2013) and on the Internet. The journal is in a private for-profit publication that costs approximately $500 a year.  In any case, Anderson cites several well-known non-cloud cases and some other secondary sources. Nevertheless, only some of her discussion are, as it were, on the clouds. [I promise  not-very-often in the future to use this type of phraseology.  For example, I promise that the title of the next short section will not be "Cloudy Insurance."]

Clouds and Insurance

I**  have located only three announced-to-be-relevant and therefore potentially relevant cyber policies and none of them are explicitly--in defined terms--about the activity in, about and around the clouds. [Alas! Failed already!]

Of course, there may be more policies and secondary sources, [I** I  just haven't found them yet.]  The three that have been found are (1) ACE DigiTech(r) Digital Technology & Professional Liability Insurance Policy, (2) XL ECLIPSE PRO(tm) 2.0, and (3) Ace Privacy Protection(r)[:] Privacy and Network Liability Insurance Policy. Perhaps I will review at least some of them later.

[**Really it is the computer savvy,office managing-paralegal, Stephanie Rodriguez who found both the policy and the Anderson articles. I get the credit for the two books. ]

Obviously, there are--or are going to be--several  different kinds of policies, as there always are. One will be the cloud provider's liability insurance (with its endorsements = amendments). The providers may also want some first party coverage.

The second type of policy will be a first party insurance policy for the user; it will cover many things.  One type of coverage will be for assorted perils damaging data already collected (analogous to wind and/or rain damage). Another will be injuries suffered from foul-ups by the user, and there will be many types of these problems covered, including virtually all of those Yale sets forth or what are to be found in the Aspatore pamphlet.

Next, there may also be liability insurance for errors on the part of the user; those errors might include: provider selection, not having performed due diligence, using the wrong outsourced helpers, not making property disclosures to clients, failing to obtain a satisfactory contract. 

Clearly the problems of lawyer liability insurance must be directed toward clients, so that potential liability should be included in legal malpractice policies, and the right people--those with the right range of knowledge, for example--should be those who select appropriate policies. This point is  applicable whether the lawyer is representing the provider, the user, or some other relevant entity.  (Of course, there may be other kinds of for-lawyer policies focused on other sources of lawyer liability.)

It should also be mentioned that the right kinds of lawyers should be advising clients as to which policies they should obtain for themselves.

I will review the lengthy and complex XL policy sometime in the future.