Showing posts with label cyber-insurance. Show all posts
Showing posts with label cyber-insurance. Show all posts

Thursday, October 10, 2013

"Wrongful Acts," "Claims Made," & "Claims Reporting"




Michael Sean Quinn, Ph.D, J.D., Etc.
2630 Exposition Blvd  #115
Austin, Texas 78703
(o) 512-296-2594
(c) 512-656-0503



Cyber- Insurance & Some Crucial Time Elements


Another thing to keep in mind is that all--or virtually all--cyber insurance policies are so-called "claims made" policies.  They fall into the pattern of D&O and professional malpractice policies to be found in the so-called "real world."   What is important is that all so-called "claims made" policies may have three very significant time elements in addition to policy limits.

In both "worlds," the phrase "claims made" is often a misleading metaphor.  A more general characteristic, which changes the policy radically, and which an insured needs to watch out for is a two or three component "claims made" period; significantly the components are all different.
 
The first one requires that the relevant covered "wrongful act" be performed during a specified length of time; often this is during the policy period; though sometimes, by agreement and an additional fee, it can be provided during a retro-active extension period; the existence of this period will usually be found on the dec sheet, though it can be found in an endorsement, for example, if it is purchased after the original purchase of the basic policy. Under some circumstances this component can cover some sections of a liability claim. 
The second one is the actual "claims made" component; this is a covered claim made against the policy holder; consequently, it is to be found in liability policies, not first party-policies, so far as I know.  The specified time for when a covered claim may be made can be extended both backwards and forward in time
The third component is the "claim reporting" requirement.  This is the time period during which the insured must report a claim to the insurer including  any claim made against it during the specified periods.  Cyber policies are new, and there  is virtually no authority as to their potentially controversial meanings. From the point of view of coverage analysis this is a new and relatively uncharted ocean. Conjecture and even guess work are required.
 In addition, it usually must also be done within a reasonable period of time, and this is described as "as soon as practicable."  If one were to look at phrases that are paradigmatically vague, this is one of them. It certainly does now and will in the future generate lots of controversy.
Again, like the other components this requirement is for liability policies. It too can be extended. These time limits can be iron clad. 
To be a covered claim, the following must be considered: (1) whether the insured received service of a lawsuit claim is required within a specified period of time; (2) whether the insured has received a demand or announcement letter (but not the lawsuit yet), and (3) whether the insurer has a reasonable belief that (1) or (2) might well happen.  #(1) is invariably a necessary condition for coverage; #(2) is usually to be found in policies; and #(3) is also to be found in policies. 
The insurance purchasing department of the insured company should make sure that those who handle risk management know this, and that all relevant management personnel are made aware of the pertinent provisions of these contract requirements. It does not matter whether they are actually there. Relevant personnel should watch all problematic acts or omissions in the company for signals of potential coverage problems.

The above discussion has concerned time requirements required by the insurance contracts. Naturally, first party policies have some similar requirements. Often the word "claim" is used in this context.  It has a different meaning.  In this context, a claim concerns the damage or potential damage to which the insured itself has or will be subjected. It's causes may involve conduct of the insured, conduct of others, damages caused (or to be caused by nature), simply adverse luck, or a combination of some or all of these. Of course, these claims must be made within specified time periods, often the policy limits, and they can include damage already occurred, or the reasonable concern that damages might occur in the future as a result of actions, omissions, or events that have occurred.

Monday, September 16, 2013

An Ironshore Cyberpolicy--Part VI: Insuring Agreement I.E.

TechDefender

Tech E&O, Network Security, Internet Media and MPL Insurance Policy 

Insuring Agreement I.E: Regulatory Proceeding Coverage
Remember: This Blog is organized around insuring agreements, definitions and exclusions. Conditions, etc., may be remarked upon briefly, they often resemble not only each other but those found in currently existing policies.
The first specific thing to notice here in I.E. is that the Insurer agrees to reimburse the Insured.  Be mindful of the fact that this concept is quite different from "pay on behalf of" or "pay for."  "Reimburse," literately understood, means that the insured pays first. There is no reason to believe that a court will not take this language literally.

Second, and very important, this entire section is attached to two concepts: Privacy Incident
and Regulatory Proceeding.  The first of these concepts was discussed in Part V, and a concept related to the second one, Privacy Regulation, was also discussed there. Much of what was written there is reprinted in the next paragraph.

The phrase Privacy Incident briefly put includes (i) the disclosure, etc., of some information or another, that is secret, or close to it; and the disclosure is in the care, custody or control of the Insured or Service Provider.  (ii) That disclosure must result from a Privacy Regulation or a failure of the Company to comply with its own privacy policies. The concept of Privacy Regulation includes a slew of  named statues, both state and federal, plus regulations under those statutes, and "any similar state, federal or foreign identity theft or privacy protecting statute." 

[MSQ:  Does the reader realize how controversial the phrase "care, custody and control" can be in insurance disputes?  And here only immaterial entities are involved. Will that complicate matters? Does the reader recognize that there may be controversies generated by the word "similar"?  Or what about this what about the word "any"?  What about when they don't apply? Are Bolivian privacy administrative rules applicable to problems in Oklahoma?  (Perhaps not; but consider the twists and turns, "New York lawyers" might generate out of these two ideas.)  Remember: the phrase "care, custody and control" has caused lots of  insurer-insured disputes for many years.

Now for the second of the two crucial concepts, Regulatory Proceeding.  This topic has not been written about in this (group of) blog(s).  The idea is pretty clear from the language.  The phrase means (1) a governmental investigation of an Insured, e.g., perhaps leading up to a adjudicative governmental hearing concerning a Privacy Incident and/or (2) an adjudicative administrative hearing on either a Privacy Wrongful Act or a Network Wrongful Act including an appeal, either of them begun by the receipt of "a subpoena, a formal investigative demand, complaint or similar document."

It seems odd to me, at least appears, that one of the types of wrongful acts is covered for investigations and the other one is not. Indeed, this seems so unlikely that I think I must have missed something.

The Insured's right to be paid for its expenses in this arena is huge. This fact indicates that the insured should make sure that everyone in its organization involved knows well the terms of the policy, consults with risk management, stays in close contact with the IT and IS departments, and ask in-house or outside counsel for advice.  (Perhaps there will be an appropriately specializing attorney included within the in-house counsel department. This is not uncommon in really large law firms.) In addition, the Insured should monitor its work on these matters carefully, make sure that accurate records are kept, make sure that confessionary, personal, and other assorted messages are not entered into the cyber-systems.  It would be a good idea for the insured to institute a special, nearly unique kind of specialized "Product Management," as it is now called.

The Insured should also make sure that it has enough coverage. The problem here is that no one really knows what is adequate coverage.  The whole field is too new; there has not been enough time to develop helpful statistical data.

On to I.F.