Information To Protect What You Grow

Watch For Contractual Liability Exclusions In Cyber Policies

Written by Jeffrey Forbes | Aug 18, 2016 12:30:00 PM

Contractual Liability exclusions have found their way into many different types of insurance policies over the years, and cybersecurity insurance has proven no exception.  These exclusions operate to prevent insureds from recovering for losses that result from the insured willingly agreeing to assume a liability or risk in a contract.  In the field of cyber insurance, these types of contractual liabilities can take many forms.  When companies contract out information technology work, cloud storage, or other data services, they may sign contracts assigning liability to them without realizing it.

What Happened?

The issue of contractual liability exclusion arose recently with regards to P.F. Chang’s data breach.  The breach affected the credit card information of 60,000 P.F. Chang’s customers.  P.F. Chang’s had purchased a cyber insurance policy through Chubb that purported to cover the company from losses incurred as a result of a data breach. 

The insurance company paid out $1.7 million to P.F. Chang’s for various losses as a result of that breach, including forensic investigation of the breach and defense of lawsuits resulting from the breach.

Read More: 3 WAYS SAVVY BUSINESS OWNERS REDUCE CYBERSECURITY INSURANCE COSTS

Costs Continued To Grow After The Initial Claim

The insurance company and P.F. Chang’s, though, had a serious disagreement as to whether $2 million in fraud assessment fees charged by P.F. Chang’s credit card processor constituted a covered loss.  P.F. Chang’s had entered into an agreement with Bank of America Merchant Services that allowed BAMS to charge the company certain fees in the event of a data breach.  These fees were mostly calculated pursuant to a formula included in the merchant services agreement and included operational reimbursement fees and fraud recovery fees.  For the data breach P.F. Chang’s suffered, these various fees totaled $1,929,921.57.  P.F. Chang’s felt their cybersecurity policy covered these losses. 

How Could These Costs Be Excluded?

The insurance company, on the other hand, felt these fees fell under the contractual liability exclusion contained in the cyber insurance policy.  The applicable language as quoted by the Court stated, “With respect to all Insuring Clauses, [Federal] shall not be liable for any Loss on account of any Claim, or for any Expense . . . based upon, arising from or in consequence of any . . . liability assumed by any Insured under any contract or agreement." 

Translation:

Because P.F. Chang’s repeatedly agreed within the merchant services agreement to indemnify BAMS for losses suffered and to pay any resulting fines, fees, or assessments, the Court held that the exclusion prevented recovery under the cyber insurance policy for these damages.  The Court also read through the coverage provisions and determined they did not extend coverage to these types of losses either.

3 Things Businesses Should Take Away From This Case

This case holds several important lessons for companies seeking to purchase cyber insurance. 

  1. First, companies must understand the full extent of coverage they are purchasing and the types of losses excluded from coverage. 
  2. Second, companies must fully understand and be aware of what liabilities they assume under contractual relationships with the understanding that insurance may not cover many of these liabilities. 
  3. Third, while cyber insurance is itself relatively new and policies can vary significantly from one provider to the next, courts will interpret these policies within the context of other similar insurance policies with well-established case law.

 

More From ECBM's Cyber Team: