45
Cyber Liability Graeme Newman, CFC Underwriting

Cyber Liability Insurance

Embed Size (px)

DESCRIPTION

Cyber liability training course delivered on behalf of the California Surplus Lines Association in May 2013 in San Francisco and Los Angeles.

Citation preview

Page 1: Cyber Liability Insurance

Cyber LiabilityGraeme Newman, CFC Underwriting

Page 2: Cyber Liability Insurance

“The Internet? We’re not interested.”

Bill Gates, Microsoft Founder, 1993

Page 3: Cyber Liability Insurance

Percentage of Americanswho are online

Average number of hoursspent online each day

Number of years it took theInternet to reach 50 million users.It took radio 38 and television 13.

78%

4+4

Percentage of the world’spopulation now using Facebook16%

Number of US married couples who met online1 in 8

Page 4: Cyber Liability Insurance
Page 5: Cyber Liability Insurance

10 Things the Internet Has Killed or Ruined…

7. Nigeria’s Reputation

PCWorld.com

Page 6: Cyber Liability Insurance
Page 7: Cyber Liability Insurance

1,000,000,000,000,000,000

Bytes

1 Exabyte =

Page 8: Cyber Liability Insurance
Page 9: Cyber Liability Insurance

File storage through time…

The 1950s…

=1GB of information

Page 10: Cyber Liability Insurance

The 1970s…

=2GB of information

Page 11: Cyber Liability Insurance

Today…

=64GB of information(or 5,000 filing cabinets)

Page 12: Cyber Liability Insurance

Ronnie BiggsThe Great Train Robbery, 1963

Page 13: Cyber Liability Insurance

Albert GonzalesHeartland Hack, 2007

Page 14: Cyber Liability Insurance
Page 15: Cyber Liability Insurance
Page 16: Cyber Liability Insurance
Page 17: Cyber Liability Insurance

2011

1995

2000

2002 2007

2012

2009

2010

Page 18: Cyber Liability Insurance
Page 19: Cyber Liability Insurance
Page 20: Cyber Liability Insurance

• Pure play internet business models• Privacy related regulations• High fraud / crime risk• Large customer bases• Storage of very sensitive data• High profile targets

• Blended online / offline• Storage of sensitive data• Highly connected• Heavy reliance upon systems

• Incidental exposure• Brochure websites• Office-based• Sensitive data

Social Networks

Banks

Hospitals Gambling

Travel Agents

Universities / CollegesRetailers

Movie Theaters

Charities

Accountants Recruitment Consultants

Logisitics

ManufacturingLawyers

Insurance Agents

High Risk

Medium Risk

Low Risk

Payment Processors

Energy / Utility Companies Hotels

Restaurants Medical Clinics

Public Entities

Financial Advisors

Airlines MSP / ASP / ISP

IT Consultants

DistributionArchitects Engineers

Page 21: Cyber Liability Insurance

Quiz

Page 22: Cyber Liability Insurance
Page 23: Cyber Liability Insurance

Cyber & Privacy

CommercialGeneralLiability

ProfessionalLiability Crime

Property

ManagementLiability

Page 24: Cyber Liability Insurance

“All animals are equal,but some are more equalthan others.”

George Orwell, Animal Farm

cyber policies

Page 25: Cyber Liability Insurance

• Privacy liability

• Virus / hacking liability (cyber liability)

• IP infringement / defamation (media liability)

• Content liability / Errors & Omissions

• Privacy breach notification

• System damage

• Business interruption

• Cyber crime

• Brand protection / crisis management

Third party

liability

First party

loss

Page 26: Cyber Liability Insurance

Virus / hacking (cyber) liability

Extends to cover contractors, vendors and hosting

providers

Covers a computer virus “in the wild”, not just specific

Avoid “other insurance” provisions

Page 27: Cyber Liability Insurance

Privacy Liability

Avoid sub-limits for regulatory actions

Full worldwide jurisdictional cover

No contractual liability exclusion

Avoid hard-coded definitions of PII or sensitive data

Include cover for fines and penalties (where insurable)

Page 28: Cyber Liability Insurance

Privacy breach notification

Full voluntary breach notification

Separate limit available for breach notification

24/7 expert claims response

Coverage for credit monitoring, forensic consultants, call center

Type of breach covered: paper / electronic, fault / no-fault

Page 29: Cyber Liability Insurance

Multimedia liability

Ensure not restricted to just the insured’s website and

email

Cover for social media liability and “corporate” blogging

Cover for digital content, regardless of distribution

channel

Seek cover on an “all risks” basis (except patent)

Page 30: Cyber Liability Insurance

System damage

“All risks basis” not just named perils

Avoid “security breach” trigger

Include staff overtime and additional cost of working

No exclusion for lack of risk management

Extends to cover perils at an outsourced or cloud

provider

Page 31: Cyber Liability Insurance

Business interruption

Financial retention v time retention

Scope of perils covered

Extends to cover perils at an outsourced or cloud provider

At least a three month indemnity period

Coverage for contingent loss of future sales

Page 32: Cyber Liability Insurance

Business interruption

Time

Revenue

Security Breach

Indemnity Period (max 3 months)

Contingent Period (max 12 months)

Direct Loss

Reputational Loss

Wait period

Page 33: Cyber Liability Insurance

Cyber crime

Employee crime or third party crime

Cover for cyber threats and extortion

Third party theft of electronic funds

Cover for telephone hacking

Cover for phishing scams

Page 34: Cyber Liability Insurance

Other key considerations

Retroactive date and cover for prior acts

“Pay on behalf of” v “Reimbursement” language

War and terrorism exclusions

Extent of encryption warranties

Risk management conditions

Page 35: Cyber Liability Insurance

Future trends

Page 36: Cyber Liability Insurance

Underwriting cyber

Page 37: Cyber Liability Insurance

Underwriting cyber

Page 38: Cyber Liability Insurance

Quiz

Page 39: Cyber Liability Insurance
Page 40: Cyber Liability Insurance

Security Breach: Hospital

Page 41: Cyber Liability Insurance

Denial of Service: Hotel

Page 42: Cyber Liability Insurance

“Spear-phishing”: Charity

Page 43: Cyber Liability Insurance

Quiz

Page 44: Cyber Liability Insurance
Page 45: Cyber Liability Insurance

CFC Underwriting Ltd.

85 Gracechurch St

London EC3V 0AA

+44 (0) 207 220 8500

[email protected]

www.cfcunderwriting.com

www.technologyinsuranceblog.com

www.mediainsuranceblog.com

www.twitter.com/cfcunderwriting

www.linkedin.com/company/cfc-underwriting-ltd.

Contact us