Category: New Featured Post for Home Page

  • Despite Relative Inactivity on the Virtual Front in Ukraine, Russia’s Global Cyber-Attacks are Coming

    Despite Relative Inactivity on the Virtual Front in Ukraine, Russia’s Global Cyber-Attacks are Coming

    Editor

    Tom Hagy

    Tom HagyHB Founder

    Tom is HB’s Founder and Managing Director. His career in litigation content spans four decades during which he was editor, managing editor, and finally publisher at Mealey’s Litigation Reports. After Mealey’s was acquired by LexisNexis Tom became a vice president involved in creating new content and services at the legal research and services giant. He has always overseen or directly created articles, blogs, conferences, webinars, data collections, and now podcasts — all on litigation. Tom founded HB in 2008, and four years later he founded Custom Legal Content, a boutique content creation shop serving boutique and specialized legal practices and litigation services. In addition to his work at HB and CLC, Tom is Editor in Chief of the Journal on Emerging Issues in Litigation, and host of the Emerging Litigation Podcast. For years he was a leader in an international specialized publishing association, frequently speaking and writing about publishing, and is now active in an open community of content and event producers called Renewd. Sometime during the last millennium Tom proudly graduated with a B.A. in Communications from Bethany College in West Virginia.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Despite Relative Inactivity on the Virtual Front in Ukraine, Russia’s Global Cyber-Attacks are Coming

    Cyber WarSince his cyber-war capabilities seem to have worked well for him, why isn’t Vladimir Putin launching more cyber-attacks against Ukraine and its allies? Reports suggest he didn’t think he’d need them, plus they take time to execute. Other reports suggest he is trying to get some cyber damage on the scoreboard. Maybe the actual disruption to Ukraine from tanks and bombs, even though the Ukrainians aren’t giving him the satisfaction of a clean and easy parade-style invasion, could be redundant.

    But many experts did think that much of Russia’s invasion – and Ukraine’s defense –  would take place in cyberspace. Some of that is happening, but there are reasons Russia hasn’t launched large-scale attacks. Kyle Fendorf and Jessie Miller wrote for the Council on Foreign Relations on March 24, 2022, that reasons include “the higher efficacy of kinetic attacks and difficulties in planning and executing massive cyberattacks in a short timeline.” Ukraine, meanwhile, has taken a novel approach: “attempting to mobilize international sentiment” to “create an army of cybersecurity professionals to attack military and critical infrastructure targets in Russia.” Fendorf and Miller list several Russian efforts, including DDoS attacks on Ukrainian banking and defense websites. And hackers like Anonymous have “declared war” on Russia. The group has taken credit for several successes, including interrupting television broadcasts with clips from the war and leaking thousands of confidential government files.

    According to Reuters, the pro-Ukraine cyber assaults are hitting their targets, saying Russian government websites are facing “unprecedented cyber-attacks.” Relying on the Russian news agency TASS, websites for the Aeroflot airline, the Sberbank bank, and the Kremlin itself have experienced “outages and temporary access.” The Kremlin, facing greater isolation from global financial systems and supply chains, is taking steps to bolster its IT sector, such as tax breaks and easier access to lending, Reuters reports.

    President Biden has warned U.S. organizations to “lock their digital doors” for fear of a Russian cyber-attack, adding that “evolving intelligence” indicates attacks are coming.

    As quoted in Politico, Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, told 13,000 participants on a recent call that we should “assume that disruptive cyber activity will occur: and “we should consider every sector vulnerable.”

    On March 24, the Department of Justice Department unsealed two indictments charging four Russian nationals working for the Kremlin with “attempting, supporting and conducting” cyber-attacks on the global energy sector between 2012 and 2018. The targets were hundreds of organizations in 135 countries, including the U.S. Nuclear Regulatory Commission and a Kansas power plant.  “The potential of cyberattacks to disrupt, if not paralyze, the delivery of critical energy services to hospitals, homes, businesses and other locations essential to sustaining our communities is a reality in today’s world,” said U.S. Attorney Duston Slinkard for the District of Kansas.

    BBC News reported that Ukraine “has remained relatively untroubled” by Russia’s cyber weapons, but “experts now fear that Russia may go on a cyber-offensive against Ukraine’s allies. The BBC News article reminds us of the three types of Russian cyber-attacks “the West fears most,” detailing Russia’s takedown of Ukraine’s electricity grid in 2015 in an attack called BlackEnergy; the “most costly” attack in cyber history called NotPetya, a worldwide computer killer that caused $10 billion in damage, followed by WannaCry which scrambled data in 150 countries; and the one executed by a Russian criminal organization called DarkSide which caused a state of emergency in the U.S. in May 2021 when their ransomware strike shut down the vital Colonial Pipeline.

    The insurance industry, which is always impacted by any global calamity, man-made or natural, is also worried about a parallel cyberwar. Ben Dyson, a reporter for S&P Global Market Intelligence, wrote on March 28, 2022, that while the industry’s direct exposures to Russian and Ukrainian cyberrisk “is likely small,” the larger risk is the “potential for spillover” to networks in other countries. “The insurance industry can look back to at least one precedent for a cyberattack related to the wider conflict between Ukraine and Russia having global implications: the 2017 NotPetya malware attack. NotPetya spread to thousands of companies globally, handing the insurance industry a $3 billion claims bill and its first taste of a cyber catastrophe. NotPetya occurred in relative peacetime and was largely covered by cyber-specific policies.”

    Attorney Vincent Vitkowsky, in an article for the Insurance Journal posted on March 25, 2022, agreed that Russia may try to turn up the stress of other countries if the war drags on. “After the conflict ends, however it ends, Russia will be the object of extreme resentment and suspicion. It may launch cyberattacks to increase disorder, believing that an environment of disorder would be serve its position as a significant power.” Vitkowsky said new cyber weapons will only make the threats worse, such as “zero click vulnerabilities” which don’t even need the help of an unsuspecting employee to click on a link, and the so-called HermeticWizard, “a new strain of software designed to autonomously spread another strain, HermeticWipe, to computers in a network.”  He writes that carriers face exposure to losses from direct or indirect cyberattacks against their insureds globally, but says the so-called War Exclusions “may mitigate that exposure,” then goes on to explain how in his article. [Vince is a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.]

    FT technology correspondent Hannah Murphy asked Kevin Mandia, the founder of cyber security company Mandiant (which was just acquired by Google for $5.4 billion) about the current state of the cyber conflict between nations.

    The current state feels like, Mandia said, “braced for impact.”

    The cybersecurity expert noted operation “Shields Up” by the Cybersecurity and Infrastructure Security Agency, plus all of the private and public players in the West and NATO, “all watching the cyber domain waiting for what happens.” He sees the war in Ukraine as “an opportunity for us to figure out what is the new normal because we’re used to conflict being air, land, sea, maybe a little bit of space . . . but a cyber domain is part of that conflict, too.” He went on to say, however, he’s “not sure everyone’s got fully fleshed-out strategies for how to do warfare in the cyber domain, and when to bring it to bear.”

    He predicted that if Russia wants to retaliate against sanctions and embargoes, a cyber-attack is “probably the first tool that might be chosen.”

    What do you think?

  • Tanks and Banks: What Fintechs Must Know About Sanctions on Russia

    Tanks and Banks: What Fintechs Must Know About Sanctions on Russia

    The Guest

    Brad Rustin

    Brad RustinPartner | Nelson Mullins Riley & Scarborough

    A highly regarded attorney and much-sought-after speaker for his expertise on the laws and operations of the technology-driven global financial system. Also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    The Journal on Emerging Issues in Litigation

    Tanks and Banks: What Fintechs Must Know About Sanctions on Russia

    Tom Hagy Interviews Brad Rustin of Nelson, Mullins, Riley & Scarborough

    Click below to get the complete article.

    Tanks and Banks: an interview with Brad Rustin on Russian Sanctions and Fintechs

  • Cybersecurity and Data Privacy Year in Review 2021

    Cybersecurity and Data Privacy Year in Review 2021

    The Authors

    The authors are all attorneys with the Kennedys law firm (kennedyslaw.com). Joshua Mooney (joshua.mooney@kennedyslaw) and Judy Selby (judy.selby@kennedyslaw.com) are partners. Tracey Kline (tracey.kline@kennedyslaw.com) and Alexis Childs (alexis.childs@kennedyslaw.com) are associates. Bridget Mead, associate, and Javier Vijil, senior associate, also contributed to this article.

    Judy Selby is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.

    The Journal on Emerging Issues in Litigation

    Cybersecurity and Data Privacy 2021 in Review

    By Joshua Mooney, Judy Selby, Tracey Kline, and Alexis Childs

    Abstract:

    As the world emerged from lockdown, it should come as no surprise that cybersecurity and data privacy remained dominant topics in the media and legal industry. Some of 2021 was much like 2020—ransomware attacks continued to fill the headlines, and in the aggregate, constituted significant loss paid under cyber insurance policies. OFAC reminded victim companies and incident response firms (and cyber carriers) that it remains unlawful to pay ransom payments to designated organizations. Comprehensive federal legislation addressing cyber defenses and notification requirements never materialized. Yet in 2021, we saw new and significant developments. U.S. law continued its drift toward comprehensive privacy regulation with two new significant pieces of privacy legislation and California’s enforcement of the California Consumer Privacy Act. In the absence of federal legislation, federal agencies either stepped up enforcement actions or signaled that they intend to do so within their realms of governance. Litigation under the Illinois Biometric Information Privacy Act continued its surge while the Illinois high courts rendered two impactful decisions and a circuit court punted to Illinois’s highest court. This review provides a brief synopsis of many events and developments that made the authors’ list.  

    Perhaps one of the most significant developments in U.S. privacy law for 2021 was the enactment of comprehensive data privacy laws in Virginia and Colorado. Both pieces of legislation, which go into effect in 2023, adopt frameworks resembling those in the EU General Data Protection Regulation 2016/679 (GDPR) and the California Consumer Privacy Act (CCPA). Both laws also grant consumers significant rights with respect to their personal data, but neither contains a private right of action. 

    Get the article now!

  • Climate Change, ESG, and D&O Insurance: Collision or Cooperation?

    Climate Change, ESG, and D&O Insurance: Collision or Cooperation?

    The Authors

    Robert D. Chesler (rchesler@andersonkill.com) is a shareholder in Anderson Kill’s New Jersey office and is a member of the firm’s Cyber Insurance Recovery Group. Bob represents policyholders in a broad variety of coverage claims against their insurers and advises companies with respect to their insurance programs. Dennis J. Artese (dartese@andersonkill.com) is a shareholder in Anderson Kill’s New York office and chairs the firm’s Climate Change and Disaster Recovery Group. Joseph Vila (jvila@andersonkill.com) is an insurance recovery attorney in Anderson Kill’s New Jersey office.

    Journal on Emerging Issues in Litigation

    Climate Change, ESG, and D&O Insurance: Collision or Cooperation?

    By Robert D. Chesler, Dennis J. Artese, and Joseph Villa

    Abstract:
    Climate change has been tied to the recent increase in catastrophic weather events. Insurance coverage for often billions of dollars in damage becomes a source of argument between insurers, who want to limit their exposure, and policyholders, who want the coverage they argue the carriers are contractually obligated to pay. The authors discuss the nature of the underlying suits and the potential coverage issues; the types of policies implicated; cases that have addressed these issues; the rising societal concern over climate change that have played a role in the new corporate emphasis on environmental, social, and governance, or ESG, and the insurance industry’s response to this trend.

    Excerpts:
    Directors and Officers (D&O) policies [are] directly affected by climate change. Two types of suits are already happening. First, there are at least 1,375 climate change–related suits pending in the United States, about two dozen of which have been filed by local municipalities and states seeking damages because of climate change. For example, the attorneys general of New York, Massachusetts, and the U.S. Virgin Islands launched investigations to determine whether Exxon Mobil Corporation misrepresented to investors the risks of how climate change might impact its business. Although the U.S. Virgin Islands attorney general terminated its investigation, the New York and Massachusetts attorneys general filed separate suits against Exxon.

    In the seminal case People of the State of New York, By Letitia James v. Exxon Mobil Corporation, 119 N.Y.S.3d 829 (N.Y. Sup. Ct. 2019), the State of New York sued Exxon, alleging that it violated the state’s securities act by making materially false and misleading statements to the public and investors about how the company manages risks of climate change and the cost of carbon in assessing demand for its products. The state dropped its common law fraud claims prior to trial, but proceeded with a claim under New York’s Martin Act, which permits the attorney general to sue for fraud in connection with the marketing of securities without requiring proof of scienter, reliance, and damages, as well as under New York’s Executive Law, which prohibits persistent fraudulent acts. After a trial, the New York Supreme Court held that the state failed to demonstrate by a preponderance of the evidence that Exxon made any material misrepresentations to investors ….

    As regulatory activity and private litigation activity surrounding climate change issues continue to increase, liabilities likely will follow. D&O insurance companies will be called on to address those liabilities with increasing frequency.

    Those claims will present complex coverage issues of first impression, and policyholders can expect a fight. Policyholders also should be on the lookout for more restrictive coverage terms on D&O renewals. Policyholders should work with their brokers to obtain the broadest coverage available, and consult with sophisticated coverage counsel in the event that they are faced with climate change–related claims. 

    Get the article now!

    Explore more from Bob Chesler and contributing specialists!

    Journal on Emerging Issues, Editorial Board of Advisors

    The Use and Abuse of the Pollution Exclusion. By Dennis Artese, Jamie O’Neil, Robert Chesler

    The Environmental, Social, and Governance Police Have Arrived: Is your Insurance Ready. Authors: Dennis Artese, Bob Chesler.

    PFAS Insurance Coverage with Jaana Pietari and Jim Fenstermacher and Litigation with Bob Chesler: Part 1 of 2 Podcasts

    PFAS Insurance Coverage with Robert D. Chesler of Anderson Kill. Part 2 of 2 Podcasts

    How Insurance Companies Defraud Their Policyholders, and What Courts and Legislators Should Do About It

    Climate Change, ESG, D&O Insurance: Collision or Cooperation? By Robert D. Chesler, Dennis J. Artese and Joseph Villa

    Remediating, Insuring, and Litigating PFAS Claims. By Dr. Jaana Pietari, PhD, MBA, PE, Jim Fenstermacher, PE, Dr. Michael Bock, PhD, MS, Robert D. Chesler and Nicholas M. Insua, Sheila Mulrennan, Robin Kelliher, Jason R. Waters

  • The Shifting Gun Liability Landscape: Plaintiffs Say Companies are Marketing Illegally, Insurers End Up Paying

    The Shifting Gun Liability Landscape: Plaintiffs Say Companies are Marketing Illegally, Insurers End Up Paying

    The Author

    Charlie Kingdollar

    Charlie KingdollarInsurance Industry Expert

    Charlie spent more than four decades with General Reinsurance, three-quarters of which as the company’s Emerging Issues Officer. One colleague described him as “one of the most prescient and gifted industry futurists I have met in my 36 year professional career within the insurance industry. Entertaining and insightful, his ability to digest and communicate complex issues, many before they are readily apparent, is both a gift and a talent.” Charlie is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.

    The Shifting Gun Liability Landscape: Plaintiffs Say Companies are Marketing Illegally, Insurers End Up Paying

    By Charlie Kingdollar

    On Feb. 15, 2022, Remington Arms, manufacturer of the Bushmaster AR15-style rifle agreed to pay $73 million to settle a lawsuit filed by the families of nine of the victims of the Dec. 14, 2012, Sandy Hook Elementary School shooting. The $73 million will be paid by four of Remington’s insurers (and likely their reinsurers).[i]

    Why is this a big deal? Insurers and reinsurers providing liability coverage for gun manufacturers did so believing that federal law protected gun manufacturers from liability arising from shootings under the federal Protection of Lawful Commerce in Arms Act (PLCAA). It seems likely that policy terms and conditions as well as pricing of the risk reflected that perceived liability protection.

    Things have changed. The Connecticut plaintiffs filed their suit under the Connecticut Fair Trade Practices Act. The plaintiffs alleged that the Bushmaster was a combat weapon and that Remington improperly marketed it to civilians – particularly trying to reach young men. In 2019, the Connecticut Supreme Court ruled that the federal PLCAA did have some carve-outs for state laws and subsequently declined Remington’s request to dismiss the lawsuit. It seems a safe bet that the families of other Connecticut gun violence victims will file similar suits over past and/or future incidents.

    Okay, so this is Connecticut. But it seems likely that this lawsuit will be used as a template by plaintiffs in other states that have similar statutes – and many do. This lawsuit and settlement could result in burgeoning litigation against gun manufacturers.

    Presumably, even a single victim shot with a Bushmaster, or any gun that could be argued is a combat weapon, could file a similar suit under a state’s Fair Trade Practices Act.

    Which other guns could be deemed “combat weapons” and therefore unfit for civilian populations? Only time and future litigation will tell. One possible example is the WEE1 Tactical, the manufacturer of the AR-15, which is similar to the Bushmaster, may find itself facing litigation. A look at AR-15-style guns on Wikipedia results in a list of 27 guns by 26 manufacturers – and I doubt this is a comprehensive list.[ii] Would a machine pistol be considered a “combat weapon”? How many other types of firearms might be deemed “combat weapons”?

    WEE1 Tactical has recently begun advertising the JR-15 – a smaller, lighter version of the AR-15 that fires smaller .22 caliber rounds for use by children. WEE1’s website states: “The JR-15 is the first in a line of shooting platforms that will safely help adults introduce children to the shooting sports.”[iii] Given that the plaintiffs in the Sandy hook case stressed the firm was specifically marketing the Bushmaster to young men it will be interesting to see how this marketing strategy will play out in any future similar litigation.

    There’s been another crack in the perceived liability protection afforded to gun manufacturers in the U.S.  Last year the State of New York enacted a law that “would classify the illegal or improper marketing or sale of guns as a nuisance…that supporters said would bolster litigation against gun companies.”[iv]

    Will other states follow? If even a few enact similar statutes, the defense and indemnity costs could be significant to the gun manufacturers and their insurers and reinsurers.

    Bushmaster has settled once before with the families of victims shot by one of its guns. In 2004, the company agreed to pay $2.5 million to settle with the families of victims shot by the D.C. sniper.[v] Not much changed after that settlement. It may be different this time.

    What about other entities in the gun liability chain? If the gun manufacturer can be held libel for marketing a combat weapon to civilians, can wholesalers and retailers also be found liable?  Could courts find that these companies also played a role in putting “combat weapons” into the hands of civilians?  If so, the costs to the Property/Casualty insurance industry will be greater.

    Unfortunately, mass shootings and gun violence are on the rise in the United States. The number of mass shootings (defined as 4 or more people shot – killed or wounded) have increased every year except one from 2014 to 2021. In 2014 there were 269 mass shootings in the U.S.  By 2021, this increased to 691 mass shootings. There have been 2,402 mass shootings in the U.S. in the past five years. And we’ve only mentioned mass shootings incidents.[vi]

    Gun violence generally continues to rise. “Guns were involved in 75% of all homicides and 91% of homicides involving youths between 2018 and 2019 … those new numbers represent a significant and troubling uptick from a decade before.”[vii]

    I suspect insurers and reinsurers providing liability for companies that manufacture and sell guns find themselves as defendants in an increasing number of lawsuits.

    [i] https://www.washingtonpost.com/nation/2022/02/15/remington-sandy-hook-settlement/

    [ii] https://en.wikipedia.org/wiki/AR-15_style_rifle

    [iii] https://en.wikipedia.org/wiki/AR-15_style_rifle

    [iv] https://www.nytimes.com/2022/02/15/nyregion/sandy-hook-families-settlement.html?referringSource=articleShare

    [v] https://www.washingtonpost.com/nation/2022/02/15/remington-sandy-hook-settlement/

    [vi]   https://www.gunviolencearchive.org/

    [vii]   “Gun Deaths Continue to Rise In American Cities,” U.S. News, 1/10/22

  • Going Viral or Going Nuclear: Social Inflation’s Impact on Jury Verdicts …

    Going Viral or Going Nuclear: Social Inflation’s Impact on Jury Verdicts …

    The Authors

    All three authors are with the law firm of Hall Booth Smith, P.C., and concentrate on various aspects of healthcare defense.  Lindsay A. Nishan (lnishan@hallboothsmith.com) is an Associate in the HBS Charleston office. Samantha Bowen Myers (smyers@hallboothsmith.com) is an Associate in their West Palm Beach, Florida, office. Sandra Mekita Cianflone (scianflone@hallboothsmith.com) is a Partner in the firm’s Atlanta office. She is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation, and a frequent contributor to the Emerging Litigation Podcast.

    Going Viral or Going Nuclear:

    Social Inflation’s Impact on Jury Verdicts and How to Safeguard Against It

    By Lindsay A. Nishan, Samantha B. Myers
    and Sandra M. Cianflone

    A juror’s perception of companies and healthcare providers is increasingly colored by TV and social media. The same is true for their understanding of the practice law or medicine, which may be as wrong as it is immovable. “Social inflation” refers to rising litigation costs and the resulting higher insurance payouts which drive up the cost of insurance. In this article the authors, each of whom represents parties in the healthcare industry, discuss the evolving social trends that lead jurors to render “nuclear verdicts,” and what attorneys should consider in mitigating the effects of this phenomenon.

    Social media feeds today are crammed with flashy advertisements from lawyers promising big-dollar settlements against “rich insurance companies.” The number of these commercials has spiked since the 1970s as the phenomenon known as “social inflation” has taken root in the legal system.

    Social inflation is a term of art that refers to rising litigation costs, the impact those costs have on insurance claim payouts, and how much the average policyholder is expected to pay for basic coverage. Recently, the term social inflation has taken on a new meaning as it has become more widely used in the general press. The phrase has come to be associated with tort reform rollbacks, litigation funding, and is most seen in references to so-called “nuclear” jury verdicts, i.e., a jury award that exceeds $10 million.

    But the question remains: What factors contribute to these exorbitantly high jury verdicts?  These outsize awards are often driven by myriad factors including sympathetic jurors, societal conceptions about income and wealth of corporations, the use of emotion-driven “Reptile Theory” tactics by plaintiff attorneys, the media spotlight on “bad apple” physicians, and numerous other social factors. A new factor that influences elevated jury verdicts is the increasing volume of information—whether true or false—that is exchanged on social media platforms.

    One of the lines most affected by this form of social inflation is the healthcare industry and the soaring costs of medical malpractice litigation. This includes lawsuits involving hospital systems, pharmaceutical companies, and their insurers.

    See what the authors have to say about mitigating the impact of social inflation. 

    Get the article now!

  • Can we rely on shareholders to compel corporations to meaningfully act on ESG issues? | By Rebecca Boon and John Rizio-Hamilton | Bernstein Litowitz Berger & Grossmann

    Can we rely on shareholders to compel corporations to meaningfully act on ESG issues? | By Rebecca Boon and John Rizio-Hamilton | Bernstein Litowitz Berger & Grossmann

    The Authors

    Rebecca Boon

    Rebecca BoonPartner | Bernstein Litowitz Berger & Grossmann

    Rebecca Boon has been litigating securities fraud and shareholder rights actions for over a decade, recovering more than $1.5 billion for the firm’s institutional investor clients. Her work at the firm expands beyond litigation. Rebecca has advanced equality in the workplace by co-founding the Beyond #MeToo working group and leading landmark recoveries that have resulted in hundreds of millions of dollars back to investors and important social change among industries.

    Contact: rebecca.Boon@blbglaw.com

    John Rizio-Hamilton

    John Rizio-HamiltonPartner | Bernstein Litowitz Berger & Grossmann

    John Rizio-Hamilton is one of America’s top shareholder litigators. He works on the most complex and high-stakes securities class action cases, and has recovered billions of dollars on behalf of institutional investor clients.

    John led the trial team that recovered $240 million for investors in In re Signet Jewelers Limited Securities Litigation, a precedent-setting case that marks the first successful resolution of a securities fraud class action based on allegations of sexual harassment.

    Contact: johnr@blbglaw.com

    Can we rely on shareholders to compel corporations to meaningfully act on ESG issues?

    By Rebecca Boon and John Rizio-Hamilton

    This article was first published in the Responsible Investor, Aug., 10th, 2021. Posted with permission of the authors. Copyright 2021 by Rebecca Boon & John Rizio-Hamilton.  All rights reserved.

    There is an ongoing debate about the role that regulators should take regarding corporate obligations and accountability for ESG issues. Earlier this year, the Ontario Capital Markets Modernization Taskforce weighed in with its long-anticipated recommendation on diversity quotas for corporate boards. After receiving significant industry feedback, the Ontario Taskforce changed its initial recommendation from a requirement that public companies meet specific diversity targets, to allowing companies to set their own targets, report them, and develop a timeline for implementation. This ‘market-based’ framework for diversity would rely on investors to push corporations and hold them accountable.

    There was significant backlash when the Ontario Taskforce changed its initial recommendation. It was accused of not going far enough and caving to corporate pressure. However, it decided that allowing corporations to set their own quotas would avoid a ‘one size fits all’ approach, prevent corporations from simply complying with a minimum target, and limit instances of tokenism. The reporting requirement would force companies to implement material quotas and stand by them because they would be too afraid of investor reactions to do anything less than meaningful.

    In crafting governance reforms in some of the most significant derivative litigation in history, we spend considerable time thinking about how to enact meaningful and lasting social change at corporations. One key component is to get insider buy-in – because if the change is simply imposed from above, there could be internal resistance, a lack of commitment and a tendency to make only superficial progress. But the question is: can we rely on shareholders to compel corporations to meaningfully act on ESG issues? Recent history says yes. A market-based approach that incentivises good ESG practices could make a significant difference, when coupled with smart regulation.

    A recent study found that for every additional 8% of a company’s stock owned by the Big Three, the number of new women board members increased by 76%.

    For example, UK regulators just announced that London-listed companies should have at least 40% women and one non-white director on their boards. Similar to the Ontario Taskforce, the goals are not binding but if companies do not meet them, they must explain why. In the US, the Securities and Exchange Commission’s Advisory Panel also recently offered ESG and Diversity & Inclusion disclosure recommendations, designed to allow investors to understand what terms like ‘sustainable’ or ‘green’ actually mean.

    According to Chairman Gary Gensler, “investors should be able to drill down to see what’s under the hoods” at the companies and investment funds making these claims.

    The ‘Big Three’ asset management firms – BlackRock, Vanguard and State Street Global Advisors – recently made headlines when they supported Engine No.1, the Exxon activist investor that led a successful campaign to secure three board seats for its chosen candidates, in a bid to push Exxon to address long-term climate risk and move to clean energy, among other things. Exxon Director Ursula Burns acknowledged that the campaign’s success is part of a “tidal wave” of investor concerns on ESG issues. This victory would not have been possible without the support of three of the biggest investors in the US.

    In addition, big investors have committed to vote against firms that do not appoint more women directors to their boards. In January, State Street announced that it will now vote against the Chair of the Nominating & Governance Committee at companies in the S&P 500 and FTSE 100 that do not disclose the racial and ethnic composition of their boards; and in 2022, it will vote against them if they do not have at least one director from an underrepresented community.

    Similarly, Goldman Sachs will no longer take a company public without two diverse board members, one of whom must be a woman.

    The SEC has just approved a proposal by US marketplace Nasdaq for all its listed companies to disclose board-level diversity statistics and either meet the objective of 1 or 2 ‘diverse’ directors (depending on size) or explain why they have not. Some criticised the Ontario Taskforce – and others heralded it – for not taking Nasdaq’s “extreme position”.

    Are any of these initiatives enough? No. But investor pressure works. A recent study from the Kellogg School of Management at Northwestern University found that for every additional 8% of a company’s stock owned by the Big Three, the number of new women board members increased by 76%. Critically, the same study found that in response to investor pressure, women on boards get “power positions” on audit and nominating committees at even higher numbers than companies complying with mandatory quotas.

    Investors have also taken direct action by filing lawsuits alleging toxic workplace cultures of discrimination and retaliation against female executives, and racial and gender bias. And investors are no less active on environmental issues. For example, investors are currently prosecuting a securities fraud class action in Ohio against Energy Transfer, arising from the explosion of a natural gas pipeline that wreaked environmental havoc in Pennsylvania. These lawsuits are in early stages, but the pressure is on. Corporations have to address social issues because investors are demanding it.

    We have already seen what investor demands for accountability can do in US securities cases involving #MeToo issues and sexual harassment allegations. As the #MeToo movement went mainstream, we saw the first successful securities case addressing sexual harassment allegations – in a shareholder derivative lawsuit involving Fox News parent Twenty-First Century Fox. Investors were listening.

    Following a year of litigation, the lawsuit uncovered allegedly systemic problems at the network involving multiple senior executives, multiple types of discrimination and harassment, and a toxic workplace characterised by surveillance, retaliation and fear.

    Ultimately, as part of a $90m settlement, the plaintiff and the company unveiled a series of governance reforms designed to fix the broken sexual harassment culture at Fox News. The resulting Fox News Workplace Professionalism and Inclusion Council is majority-independent, but also has company participation, along with broad powers and a mandate to identify and solve the problems at the company. A critical component is investor accountability – the Council has the power to issue minority reports that Fox is mandated to post publicly for investors and the world to see. It also has a mandatory five-year term and if Fox determines to dissolve the Council, it must publicly state the reasons why. This approach set the stage for the recent high-profile settlement of a securities case against L Brands, which also settled for $90m. The firm committed to invest a further $45m over at least five years in a Diversity, Equity & Inclusion Council, and take other measures to protect employees from harassment and discrimination, requiring accountability when misconduct occurs.

    We also recently saw the first successful direct securities action certified as a class action involving allegations of sexual harassment against Signet Jewelers. When the market learned that hundreds of women had submitted declarations describing alleged sexual harassment reaching to the company’s highest levels, Signet was forced to halt trading to address them; and when trading resumed, the company’s stock price declined 13%. Again, investors were listening.  The Signet case settled for $240m in late 2020.

    It is too soon to know whether the newer cases will be successful, or whether the new regulations will have any teeth. But pressure from the Big Three and the corresponding dramatic increase in the number of women on corporate boards confirms that when investors demand diversity, companies respond. Investors have shown that they are willing and ready to compel corporations to act on important social issues. And recent securities cases involving #MeToo issues have demonstrated to the corporate world that investors can use their significant power to demand change and hold corporations accountable when they fail to act.

  • 7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation?

    By Jennifer M. Oliver

    The outcome of this case will have a dramatic impact on statutory damages.

    The Seventh Circuit U.S. Court of Appeals has certified a question to the Illinois Supreme Court over the accrual of claims under the Illinois Biometric Information Privacy Act (BIPA). The question, posed by the court in Cothron v. White Castle Systems, Inc., reads:

    “Do section 15(b) and 15(d) claims accrue each time a private entity scans a person’s biometric identifier and each time a private entity transmits such a scan to a third party, respectively, or only upon the first scan and first transmission?”

    The case was brought by an employee of the White Castle hamburger chain, which requires fingerprint scans for employees to access computer systems. The plaintiff charged that sharing her fingerprints with a third party vendor violated the law. Cothron v. White Castle Sys., No. 20-3202, 2021 U.S. App. LEXIS 37593 (7th Cir. Dec. 20, 2021).

    An accrual rule based on each collection, opponents to such a finding argue, would pose potentially existential damages — especially in the class action context — since BIPA provides for statutory damages of $1,000 or $5,000 per violation. Parties disagree on whether BIPA damages are mandatory or discretionary, however. Should the court determine that the first scan is the only scan that starts the statute of limitations clock ticking, opponents to that interpretation say,  anyone bringing a claim after five years would be out of luck, even if their private biometric data continued to be transmitted more than five years after the first occurrence.

    Preceding the federal court’s certification of this question by just five days, an Illinois appellate court ruled that, yes, claims under sections 15(a) and (b) accrue with each capture and use of a plaintiff’s biometric  information. Watson v. Legacy Healthcare Financial Services, LLC, et al., 2021 IL App (1st) 210279 No. 1-21-0279, Opinion filed Dec. 15, 2021.

    This is an important case to watch. Illinois was the first to implement such legislation, something several states have since emulated.

    Should the state Supreme Court come down in favor of an “all scans” interpretation, defendants may find themselves on the receiving end of devastating damages multipliers. Of course, the Illinois Supreme Court could determine that damage awards are at the discretion of a court, and are not mandatory under the law. Or it could rule that every scan or transmission restarts the statute of limitations clock, but that a claimant may only collect damages once for a series of transmissions of the same data, similar to how damages for defamation are not based on each publication of the same defaming remarks. Yet another possibility is that the court could determine that the clock starts to run when a claimant first learns of an alleged violation, which has precedent in litigation involving latent diseases caused by products, where individuals cannot know they were harmed until they developed a signature disease, i.e., one connected to a specific product.

    The ruling in this case is especially interesting as the COVID-19 pandemic has led to skyrocketing adoption of remote access tools that can collect biometric data for learning, court appearances, and work-from-home arrangements, and a corresponding uptick in BIPA lawsuits.

    Edited by Tom Hagy for MoginRubin LLP. Reposted with permission from the MoginRubin Blog. © 2022 MoginRubin LLP. 

    The Author

    Jennifer M. Oliver

    Jennifer M. OliverMoginRubin LLP

    Jennifer is a partner in the San Diego offices of MoginRubin LLP, where she focuses on antitrust, complex business, and investment litigation. Her experience includes active roles in several high-profile jury trials, serving as lead counsel in complex mediations, and arguing before courts at both the trial and appellate levels. Jennifer earned her B.S. (Business Administration), M.B.A., and J.D. degrees from the University at Buffalo, each with honors, where she also served as the Vice President of the undergraduate student body and was an editor of the Buffalo Law Review and Buffalo Intellectual Property Law Journal. Jennifer is also a certified information privacy professional.

    We are pleased to add that Jennifer is a member of the Board of Advisors for the Journal on Emerging Issues in Litigation and the Emerging Litigation Podcast.

    More from Jennifer and her colleagues.

  • The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The Author

    Vincent J. Vitkowsky

    Vincent J. VitkowskyPartner | Gfeller Laurie LLP

    Vince Vitkowsky is a partner in Gfeller Laurie LLP, resident in New York. He focuses on cyber risks, liabilities, insurance, and litigation. Vince assists insurers and reinsurers in product development, and in all aspects of coverage evaluation and dispute resolution in many lines of business, including cyber, CGL, property, and professional liability. He also assists in complex claim evaluations, and if necessary, the defense of insureds in complex matters.

    Vince is also a member of the Editorial Advisory Board for the Journal on Emerging Issues in Litigation.

    Contact: vvitkowsky@gllawgroup.com

    More from Vince and his colleagues.

    Melicent Thompson

    The New LMA War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies

    By Vincent J. Vitkowsky

    On November 25, 2021, the Lloyd’s Market Association released four War, Cyber War and Cyber Operation Exclusions (“Exclusions”). The LMA Cyber Business Panel spent well over two years drafting the Exclusions, which are models for use in standalone cyber insurance policies.  Lloyd’s has agreed that they meet the requirement that all insurance and reinsurance policies written at Lloyd’s must, except in very limited circumstances, contain a clause which excludes all losses caused by war.  The Exclusions address some difficult issues troubling the cyber insurance market for several years, following cyberattacks by nation-states (“states”) and threat actors associated with them.  They attempt to reduce uncertainty for both insurers and policyholders.

    Five interrelated issues.

    • The treatment of collateral damage (borrowing a concept from the traditional Law of Armed Conflict). Some state-sponsored attacks had significant effects on many entities that were not the intended targets.
    • How attribution is to be determined, and whether the insurers have an obligation to make payments while attribution is being determined.
    • The extent to which attacks by non-state actors associated with a state are excluded.
    • The treatment of state and state-sponsored cyberattacks directed at essential services, most notably those disrupting financial institutions and the financial markets infrastructure.
    • As in war exclusions in all lines of business, attempting to limit the aggregation risk.

    The Exclusions.

    The principal innovations in the Exclusions are to introduce the concept of “cyber operation” to insurance, to set processes for determining attribution, to partially clarify the scope of essential service, and to set a structure that de facto mitigates the aggregation risk.

    The key concepts and terms are as follows.

    War.  All four Exclusions contain an identical definition of War, largely based on traditional insurance policy language dating back to the Spanish Civil War.  It is “the use of physical force by a state against another state, or as part of a civil war, rebellion, revolution, insurrection, and/or military or usurped power or confiscation or nationalisation or requisition or destruction or damage to property by or under the order of any government or public or local authority, whether war be declared or not.”  (Emphasis is added, throughout this note.)  In the context of cyber war, this would include a cyberattack with kinetic effects.

    Cyber operation.  All four Exclusions also have an identical and innovative definition of cyber operation.  It is “the use of a computer system by or on behalf of a state to disrupt, deny, degrade, manipulate or destroy information in a computer system of or in another state.”

    Attribution.  All four Exclusions also contain an identical and innovative provision on “Attribution of a cyber operation to a state.”  It provides that the “primary but not exclusive factor” in attribution “shall be whether the government of the state (including its intelligence and security services) in which the computer system affected by the cyber operation is physically located attributes the cyber operation to another state or those acting on its behalf.”  Pending attribution by a state, “the insurer may rely upon an inference which is objectively reasonable as to attribution,” and no loss shall be paid.  If the affected state “takes an unreasonable length of time to, or does not, or declares it is unable to attribute the cyber operation to another state or those acting on its behalf,” the insurer, bearing the burden of proof, must “prove attribution by reference to such other evidence as is available.”

    Specified States.  This term appears in some of the Exclusions.  The specified states are China, France, Germany, Japan, Russia, UK or USA.

    The four exclusions treat cyber operations differently.

    The first Exclusion simply provides a blanket denial of coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation.”

    The other three Exclusions deny coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation that is carried out in the course of war.”

    The second Exclusion has additional provisions denying coverage for “retaliatory cyber operations between any specified states; and/or a cyber operation that has a major detrimental impact on the functioning of a state due to the direct or indirect effect of the cyber operation on the availability, integrity, or delivery of an essential service in that state; and/or the security or defense of a state.”  Although these are excluded, the policy may grant coverage for “any other cyber operations,” with a separately negotiated limit and aggregate.

    Significantly, essential service is defined as “a service that is essential for the maintenance or vital functions of a state including without limitation: financial institutions and associated financial market infrastructure, health services or utility services.”

    The third Exclusion is identical to the second, except it does not grant coverage for “any other cyber operations,” i.e., those not carried out in the course of war, retaliatory cyber operations between specified states, or those having a major detrimental impact.

    The fourth Exclusion is identical to the third, except it introduces the concept of “impacted state,” defined as “any state where a cyber operation has had a major detrimental impact on the functioning of that state [as defined in the third Exclusion], and/or security or defense of that state.”  Moreover, it limits the Exclusion for retaliatory cyber operations to those “leading to two or more specified states becoming impacted states.”  It also provides an exception to the Exclusion for loss from a cyber operation that has a major detrimental impact, so the Exclusion “shall not apply to the direct or indirect effect of a cyber operation on a bystanding cyber asset.”  That term is defined as “a computer system used by an insured or its third party service providers that is not physically located in an impacted state but is affected by a cyber operation.”

    The complete Exclusions can be found here.

    A serious attempt to reduce uncertainty.

    These Exclusions are not perfect.  Nothing is.  There is scope for dispute about the terms “an inference which is objectively reasonable,” “reference to such other evidence as is available,” “major detrimental impact,” and “essential service,” among others, as applied to specific facts.  But the Exclusions reflect a well-reasoned, serious attempt to reduce some of the uncertainties over the scope of coverage for state and state-sponsored attacks.

    Written Dec. 9, 2021 and posted with permission with minor formatting changes. Copyright 2021 by Vincent J. Vitkowsky.  All rights reserved.