Tag: Data Breach

  • Analysis of Target Decision that Loss-of-Use Damages Included Card Replacement Costs Post-Data Breach | By Joshua Mooney, Judy Selby, and Tracey Kline | Kennedys Law

    Analysis of Target Decision that Loss-of-Use Damages Included Card Replacement Costs Post-Data Breach | By Joshua Mooney, Judy Selby, and Tracey Kline | Kennedys Law

    A Significant Deviation:
    Target v. Ace Finds Loss-of-Use Damages Included Post-Breach Card Replacement

    Analysis

    On March 22, 2022, the United States District Court for the District of Minnesota ruled that two ACE insurers were obligated to indemnify Target Corporation (“Target”) for the amounts it paid to settle claims related to replacement of payment cards impacted in a data breach, vacating an earlier decision in which the court found that Target was not entitled to coverage. Target Corp. v. ACE Am. Ins. Co., No. 19-CV-2916 (WMW/DTS), 2022 WL 848095 (D. Minn. Mar. 22, 2022), vacating 517 F. Supp. 3d 798 (D. Minn. 2021). The new decision deviates from how other courts have evaluated general liability coverage for damages because of “loss of use of tangible property that is not physically injured.” Insurers would do well to take notice.

    Background

    In 2013, Target was the victim of a massive data breach that occurred after hackers installed malicious software on its computer network, which enabled them to steal the payment card data and personal contact information of an estimated 110 million individuals with Target payment cards (the “Data Breach”). Multiple lawsuits were brought against Target, including suits by financial institutions (the “Issuing Banks”) that had issued debit and credit cards (the “Payment Cards”) affected by the Data Breach. The Issuing Banks filed class action lawsuits against Target, which were consolidated, along with various consumer suits, in the United States District Court for the District of Minnesota, in In re: Target Corporation Customer Data Security Breach Litigation, All Financial Institutions Cases, MDL No. 14-2522 (the “Issuing Banks Litigation”). In their Consolidated Class Action Complaint, the Issuing Banks asserted various causes of action against Target, including a claim for negligence by which they alleged that Target breached its duty to implement adequate technical systems or security practices that could have prevented the loss of customers’ sensitive personal and financial information. The Issuing Banks alleged that, because of Target’s failures, they incurred various losses, including costs associated with cancelling and reissuing Payment Cards that were compromised in the Data Breach. In May 2016, Target reached a settlement in the Issuing Banks Litigation for approximately $58 million, which the district court approved.

    In addition to settling the Issuing Bank Litigation, Target reached confidential settlements with the major card issuers, including Visa, MasterCard, American Express, and Discover, as well as numerous individual Issuing Banks. In total, Target settled all of the claims for approximately $138 million. Of that amount, according to Target, at least $74 million was paid to settle the Issuing Banks’ claims for the costs associated with replacing Payment Cards that they alleged had been compromised as a result of the Data Breach (the “Payment Card Claims”).

    Target gave notice of the Data Breach to its commercial general liability (“CGL”) insurers, including ACE American Insurance Company and ACE Property & Casualty Insurance Company (collectively, “ACE”), which had issued two CGL policies to Target that were in effect at the time of the Data Breach (the “ACE Policies”). In relevant part, the ACE Policies provided coverage for “‘ultimate net loss’ . . . because of ‘property damage’.” The policies defined “occurrence” as an “accident, including continuous or repeated exposure to substantially the same general harmful conditions.” They defined “property damage” to include “[l]oss of use of tangible property that is not physically injured,” and provided that “[a]ll such loss of use shall be deemed to occur at the time of the ‘occurrence’ that caused it.” The policies expressly stated that “electronic data” was “not tangible property.”

    ACE denied coverage. Subsequently, Target sued ACE, seeking indemnification exclusively for the payments Target made to settle the Payment Card Claims. Target and ACE agreed that the duty to defend was not at issue. At their Rule 26(f) conference, the parties agreed that they would file cross-motions for summary judgment on the sole issue of coverage and, if the court found coverage, the issue of the amount of damages would be resolved at trial.

    The Motions for Summary Judgment

    Target moved for partial summary judgment, seeking a declaration that the ACE Policies covered the costs Target incurred settling the Payment Card Claims. ACE cross-moved for summary judgment, arguing that Target had failed to satisfy its burden of establishing the elements required to trigger coverage under the ACE Policies—namely, that its settlement satisfied a legal obligation to pay “damages because of loss of use of tangible property” caused by an “occurrence.”

    In their motions, Target and ACE disputed a number of issues related to the question of whether the Issuing Banks claimed “damages because of loss of use of tangible property.” Among other things, the parties proffered contrasting explanations of what was compromised by the Data Breach. Target contended that the physical Payment Cards were compromised. By contrast, ACE argued that it was the intangible data embedded in the Payment Cards, not the Payment Cards themselves, that was compromised in the Data Breach.

    Relatedly, the parties disputed whether the Payment Cards lost their use as a result of the Data Breach. Relying heavily on the Eighth Circuit’s decision in Eyeblaster, Inc. v. Federal Insurance Co., 613 F.3d 797 (8th Cir. 2010),[1] Target argued that the Data Breach caused a loss of use of the Payment Cards because it resulted in the cards’ inability to function as intended. In particular, Target contended that an essential function of the Payment Cards was that each card applied exclusively to the cardholder’s own debts (i.e., the charges the cardholder made) and not to the fraudulent charges of some third person. When the data connected to accounts was compromised in the Data Breach, Target maintained, the physical Payment Cards associated with those compromised accounts could no longer be safely used without the risk of fraud. Accordingly, Target argued that the Payment Cards associated with the hacked accounts immediately lost their ability to function as intended—i.e., to provide secure access only to the cardholder.

    ACE disputed that the Data Breach resulted in loss of use of the Payment Cards. Among other things, ACE disagreed with Target’s contention that the function of the Payment Cards was to make payment transactions “safe and secure.” ACE argued that such a security function was the function not of the Payment Cards but, rather, of the merchant’s computer system. ACE maintained that the function of the Payment Cards was only to facilitate efficient point-of-sale purchases by carrying data and permitting that data to be transmitted to a merchant’s computer network via a “swipe” or “insert.” ACE then contended that the Payment Cards continued to have the ability to perform their function of carrying and transmitting data after the Data Breach. Because of this, and because the Data Breach did not result in the Payment Cards being physically removed from any cardholder’s possession, ACE argued that there was no loss of use of the cards.

    The parties also disputed whether there was a relevant distinction between “loss of use” and “loss of value.” ACE argued that the Supreme Court of Minnesota’s decision in Federated Mutual Insurance Co. v. Concrete Units, Inc., 363 N.W.2d 751 (Minn. 1985) created a distinction between “loss of use” and “loss of value,” holding that “diminution in value” was not “property damage” when the latter was defined as either “physical injury to . . . tangible property” or as “loss of use of tangible property.” Concrete Units, 363 N.W.2d at 756. Relying on Concrete Units, ACE contended that the Data Breach caused the Payment Cards to lose their value, not their use, and therefore Target’s settlement liability arising from the Issuing Banks’ replacement of the Payment Cards did not constitute loss-of-use damages.

    Target countered that Concrete Units did not draw the distinction between losses that ACE claimed it did. Target further asserted that the Issuing Banks did not allege that the Payment Cards merely became less valuable—and did not seek to recoup the economic loss they suffered because the cards’ market value decreased—as a result of the Data Breach. Instead, Target claimed, the Issuing Banks were forced to cancel and reissue the Payment Cards because the cards could no longer effectively or safely be used to perform their intended function.

    The parties further disputed whether the ACE Policies’ loss-of-use coverage applied only to time-based damages. ACE contended that was the case, and argued that loss-of-use damages under the policies should be measured by the losses a claimant incurred because of, and during, the tangible property’s temporary down time. Target countered that no such temporal limitation appeared in the policies or was recognized by, or consistent with, Minnesota case law.

    In addition, the parties disputed whether Target’s liability for the Payment Cards’ replacement costs was caused by a covered “occurrence” (which, as noted above, the ACE Policies defined, in part, as an “accident”). The parties’ dispute in this regard concerned, among other things, from whose perspective an “accident” was determined. Targeted maintained that an accident was determined from the perspective of the policyholder (i.e., Target). Target then argued that, because the Data Breach was an unexpected and unintended happening from its standpoint, its losses stemmed from an accidental “occurrence.”

    ACE counter-argued that an accident had to be determined from the standpoint of the actor who caused the “property damage.” ACE then contended that the relevant actors for purposes of the accident inquiry were the Issuing Banks that deactivated and replaced the Payment Cards. In addition, ACE maintained that the Issuing Banks knowingly, intentionally, and purposefully deactivated and replaced the Payment Cards so as to mitigate future economic losses incurred through fraudulent transactions. ACE argued that, as a result, Target’s liability did not arise out of an accidental “occurrence.”

    The February 8, 2021 Decision

    On February 8, 2021, the Minnesota federal district court, applying Minnesota law, denied Target’s motion for partial summary judgment and granted ACE’s motion for summary judgment, holding that Target had not met its burden of establishing that its settlement liability arising out of the Payment Card Claims was covered under the ACE Policies. Target, 517 F. Supp. 3d at 806 (the “2021 Decision”) Specifically, the court determined that there was an insufficient causal connection between Target’s claimed damages arising out of the Payment Card Claims and the alleged loss of use of the Payment Cards to trigger coverage. Id.

    In arriving at that conclusion, the court initially observed that Target’s theory appeared to be that, because the Payment Cards allegedly lost their use and Target resolved the Payment Card Claims by paying a settlement, the settlement of that liability necessarily constituted damages because of a loss of use. Id. at 804. The court stated that this was, “in essence, a but-for theory of loss-of-use damages.” Id. at 804-05. The court then cited—and seemingly agreed with—several decisions wherein courts rejected a “but-for” test for loss-of-use damages. Id. at 805 (citing Vicor Corp. v. Vigilant Ins. Co., 674 F.3d 1, 13 (1st Cir. 2012); Atmel Corp. v. St. Paul Fire & Marine Ins. Co., 430 F. Supp. 2d 989, 994 (N.D. Cal. 2006)). The court determined that, for loss-of-use damages to be “based on” alleged loss of use under Minnesota law, the damages had to “have some connection to the value of the use of the now-damaged property when it previously was unimpaired.” Id. The court explained that “[a] ‘commonly used measure of loss-of-use’ damages—reasonable rental value—illustrates this point.” Id. (quoting Jacobs v. Rosemount Dodge-Winnebago South, 310 N.W.2d 71, 78 (Minn. 1981)). “Renting a vehicle,” the court added, “allows for use of a vehicle when another vehicle has been rendered unusable and, as such, vehicle-rental costs typically are recognized as loss-of-use damages.” Id. (italics in original, underline added) (citing Barbarossa & Sons, Inc. v. Iten Chevrolet, Inc., 265 N.W.2d 655, 662-63 (Minn. 1978)).

    The court then observed that “the record [was] devoid of any allegation or evidence as to what the value of the use of the payment cards [was], either to Target’s customers or to the payment card companies.” Id. (emphasis in original). Because “the value of the use [was] not established or even approximated,” the court determined that “damages [could not] . . . be ‘based on’ the loss of use because there [was] no nexus between the damages and the loss of use.” Id. (emphasis in original) (citations omitted). The court concluded that Target had “not established a connection between the damages incurred for settling claims related to replacing the payment cards and the value of the use of those cards, either to the payment-card holders or issuers.” Id. For that reason, the court found that “the connection between the damages claimed and the loss of use of the payment cards [was] insufficiently direct and, therefore, the damages claimed [were] not loss-of-use damages covered under the [ACE] Policies.” Id. at 806.

    Before arriving at this conclusion, the court stated that Target’s reliance on the Eighth Circuit’s decision in Eyeblaster was “misplaced” because Eyeblaster involved the duty to defend, which was “distinct” from and “broader” than the duty to indemnify that was at issue. Id. at 803. The court explained:

    “Because the duty to defend is broader in scope than the duty to indemnify, some losses covered under a duty to defend fall outside of the narrower duty to indemnify. As such, it is not necessarily so that the loss covered under the insurer’s duty to defend in Eyeblaster is covered under ACE’s duty to indemnify in this case. For this reason, Eyeblaster does not confirm that coverage is available for Target’s loss.”

    Target filed a motion to alter or amend the court’s 2021 Decision pursuant to Federal Rule of Civil Procedure 59(e). In its motion, Target argued that the court’s decision was in error for two reasons.

    First, Target argued that ACE never raised the legal theory on which the court resolved the summary judgment motions—i.e., that Target had not established “a connection between the damages incurred for settling [the Payment Card Claims] . . . and the value of the use of those cards.” Target contended that the court likewise did not raise that argument at the hearing on the motions. Target claimed that, as a result, it did not have notice of and a reasonable time to respond to the argument, which constituted a violation of Federal Rule of Civil Procedure 56(f)(2).

    Second, Target argued that the 2021 Decision represented a “manifest error of the law” justifying alteration or amendment under Rule 59(e). Target contended that, to obtain coverage under a CGL policy for damages because of “loss of use,” Minnesota law requires the policyholder to demonstrate only that the damages be “causally related” to the loss of use. Target argued that the court “went further and imposed an additional requirement on Target to establish a connection between such damages and the value of the use of the property when it was unimpaired.” Target argued that this additional requirement had never been imposed by a Minnesota court and, furthermore, was incompatible with the Eighth Circuit’s decision in Eyeblaster.

    Target asked the court to (1) vacate its 2021 Decision and entry of judgment to permit additional briefing, evidentiary submissions, and (potentially) discovery; or, in the alternative, (2) alter or amend the judgment to grant summary judgment for Target; or, in the alternative, (3) alter or amend the judgment to deny both Target’s and ACE’s motions for summary judgment, which would permit the case to move forward into discovery and, ultimately, to trial.

    The March 22, 2022 Decision

    On March 22, 2022, the district court granted Target’s motion to alter or amend the 2021 Decision, vacated the court’s 2021 Decision, denied ACE’s motion for summary judgment, and granted Target’s motion for partial summary judgment. Target, 2022 WL 848095, at *4-5 (the “2022 Decision”). The court determined that the expenses Target incurred in settling the Issuing Banks’ Payment Card Claims were covered under the terms of the ACE Policies and that ACE was obligated to indemnify. Id. at *4. The court stated that it had “erred in its prior judgment” when it found that Target’s claim was not covered. Id.

    The court began by explaining that, to establish coverage under the ACE Policies for the costs it incurred settling the Payment Card Claims, Target needed to establish: (1) that its losses were the result of an “occurrence”; (2) that the “occurrence” resulted in the “loss of use” of property; and (3) that the property lacking use was “tangible property that [was] not physically injured.” Id. at *2. The court addressed each requirement and concluded that each was satisfied. Id. at *2-4.

    The court first found that Target satisfied its burden of demonstrating that its losses resulted from an “occurrence.” Id. at *2-3. The court reasoned:

    “The parties do not dispute that Target neither expected nor intended the Data Breach. The Data Breach was an accident, which is an “occurrence” within the terms of the Policies. Under Minnesota law, an accident includes the acts of the insured and “the consequences of the insured’s acts.” [Am. Fam. Ins. Co. v. Walser, 628 N.W.2d 605, 609 (Minn. 2001).] . . . The cancellation and resulting inoperability of the payment cards were the consequences of Target’s discovery of the accident, the Data Breach. For this reason, the Court concludes that the inoperability of the payment cards—necessitated by the Data Breach—is an “occurrence” within the terms of the Policies.”

    Id. at *3.

    Next, the court determined that Target met its burden of establishing that the Data Breach resulted in “loss of use” of the Payment Cards. Id. In doing so, the court favorably cited the Eight Circuit’s decision in Eyeblaster, which the court described as presenting a “factually analogous loss of use” issue—without discussing its previous determination that Target’s reliance on Eyeblaster was “misplaced” or explaining why the court no longer found that to be the case. See id. The court reasoned:

    “Here, the Data Breach compromised Target’s payment cards. By compromising the payment information listed on and associated with the payment cards, the Data Breach caused the Issuing Banks to cancel the compromised payment cards and issue replacement payment cards. Cancellation of the compromised payment cards rendered the payment cards inoperable. The payment cards lost their use. Although the compromised payment cards still existed, like the consumer’s computer in Eyeblaster, they could no longer serve their function. . . . The expense that Target incurred to settle claims brought by the Issuing Banks for the costs of replacing the compromised payment cards was a cost incurred due to the loss of use of the payment cards. As such, Target meets the second requirement for establishing coverage pursuant to the Policies.”

    Id. (citation and footnote omitted).

    The court briefly discussed, in a footnote, the causation issue that formed the basis for the 2021 Decision, stating:

    The parties and this Court’s prior order discuss the connection that must exist between the loss of use of the payment cards and the settlement of the Issuing Banks’ claims against Target. The Court need not repeat that analysis here as Minnesota case law clearly states that the insured’s claims “must be causally related to . . . the lost use.” Federated Mut. Ins. Co. v. Concrete Units, Inc., 363 N.W.2d 751, 757 (Minn. 1985). Target’s insurance claim is for the expense Target incurred settling the Issuing Banks’ legal claims demanding compensation for the cost of replacing the payment cards that lost their use following the Data Breach. There is a sufficient causal connection between Target’s claim for coverage and the payment cards’ loss of use so as to satisfy the causation requirement of Minnesota law.

    Id. at *3 n.3.

    Finally, the court concluded that Target satisfied its burden of showing that its claim was for property damage to “tangible property that [was] not physically injured.” Id. at *4. The court reasoned:

    ACE contends that Target is actually seeking compensation for the missing data, not the payment cards. But the parties do not dispute that the payment cards, the damaged property for which Target seeks coverage, are “tangible property that is not physically injured.” And it is the use of the payment cards, not the use of electronic data, that was lost. Because the payment cards are tangible property and the payment cards are not physically injured, Target has met the third requirement to establish a basis for its claim for coverage.

    Id. (emphasis in original).

    For those reasons, the court concluded that the costs of replacing the Payment Cards affected by the Data Breach were covered under the ACE Policies. Id. Subsequently, the court held that ACE was obligated to indemnify Target for Target’s settlement with the Issuing Banks for those costs. Id.

    The 2022 Decision represents a significant deviation from how other courts have viewed CGL coverage for damages because of “loss of use of tangible property that is not physically injured.” Of particular note is the court’s unexplained change in opinion with respect to whether Target’s claimed damages were sufficiently tied to the alleged loss of use of the Target Payment Cards.

    Courts have often couched loss-of-use damages in terms of consequential damages. See, e.g., J & D Towing, LLC v. Am. Alternative Ins. Corp., 478 S.W.3d 649, 655 (Tex. 2016); see also generally IRMI, Loss of Use as Property Damage, https://www.irmi.com/articles/expert-commentary/loss-of-use-as-property-damage (last visited Apr. 20, 2022). In doing so, courts have determined that, to constitute damages because of “loss of use of tangible property,” the claimed loss-of-use damages must be directly traceable to the loss of use of the tangible property. See, e.g., J & D Towing, 478 S.W.3d at 677.

    Consistent with the foregoing, many courts have determined that loss-of-use damages are not replacement costs. See, e.g., Advanced Network, Inc. v. Peerless Ins. Co., 119 Cal. Rptr. 3d 17, 25 (Cal. Ct. App. 2010) (“Coverage for ‘loss of use’ does not apply to an underlying action in which the claimant seeks only the replacement value of converted property.”). Atmel Corp. v. St. Paul Fire & Marine Insurance Co., 430 F. Supp. 2d 989, supra is illustrative. There, the insured, Atmel, manufactured and sold to Seagate electronic chips, which Seagate incorporated into disk drives that it later sold to its customers. Atmel, 430 F. Supp. 2d at 991. The Atmel chips were allegedly defective and caused Seagate’s disk drives to fail. Id. As a result, Seagate had to repair or replace the defective disk drives. Id. Seagate subsequently sued Atmel, and Atmel ultimately settled the lawsuit by agreeing to pay Seagate millions of dollars. Id. at 991-92.

    In ensuing coverage litigation between Atmel and its CGL insurers, the United States District Court for the Northern District of California held that Atmel’s settlement liability in the Seagate action did not trigger the at-issue CGL policies’ coverage for “loss of use of tangible property of others that isn’t physically damaged.” Id. at 994. The court reasoned:

    Seagate’s damages primarily consisted of costs associated with repairing and replacing the Atmel chips. Although Atmel is correct that these damages would not have been incurred but for the failure of the Atmel chips, that does not compel a finding that these damages are “loss of use” damages. Atmel’s expansive definition of “loss of use” damages includes any and all damages related to the failure of the Atmel chips in the Seagate drives, and does not require a nexus with Seagate’s (or its customers’) inability to use the drives. The Court does not hold . . . that loss of use damages can only consist of rental value or its equivalent. However, the Court holds that the damages alleged by Seagate at the time of the settlement were too attenuated from a “loss of use,” and there must be a more direct connection between the damages claimed and the loss of use of the property in order to establish coverage under the CGL policies.

    The 2021 Decision was largely in accord with Atmel and other decisions finding that costs to repair or replace property are too remote from a loss of use of the property to constitute loss-of-use damages. See Target, 517 F. Supp. 3d at 805. But in its 2022 Decision, the court reversed course, concluding that there was “a sufficient causal connection between Target’s claim for coverage and the payment cards’ loss of use so as to satisfy the causation requirement of Minnesota law.” Target, 2022 WL 848095, at *3 n.2. It is unclear what led to this change in heart by the court. In particular, it is unclear if the court was accepting the but-for theory of loss-of-use damages the court had seemingly rejected in its 2021 Decision.

    The 2022 Decision also raises questions concerning the court’s change of position as to the import of the Eight Circuit’s Eyeblaster decision. It is also unclear to what extent, if at all, the court’s decision was informed by the “loss of use” versus “loss of value” distinction urged by ACE.

    In light of the issues left unresolved by the 2022 Decision, it remains to be seen how the decision will impact courts’ evaluation of similar claims going forward. It will be particularly interesting to see how Target factors into the Home Depot, Inc. v. Steadfast Insurance Co. case, which is currently pending in the United States District Court for the Southern District of Ohio, under docket number 1:21-cv-00242.

    Home Depot involves facts that, at least as alleged by Home Depot, appear to be materially identical to those in Target—with the exception that Home Depot involves alleged breaches of both the duty to indemnify and the duty to defend (whereas Target involved just the former). Specifically, Home Depot was the victim of a data breach that allegedly compromised the payment cards of millions of Home Depot customers. Subsequent to the data breach, credit card issuers that were allegedly forced to cancel the compromised cards and issue replacement cards to customers sued Home Depot, seeking to recover, among other things, the costs they incurred in replacing the cards. Home Depot ultimately reached a settlement with the card issuers. It then sued its CGL insurers, alleging that they wrongfully denied coverage under policies that provided coverage for, in relevant part, “property damage” caused by an “occurrence.”

    Like the policies at issue in Target, the policies at issue in Home Depot define “property damage” to include “[l]oss of use of tangible property that is not physically injured,” and define “occurrence” to mean “an accident, including continuous or repeated exposure to substantially the same general harmful conditions.” Unlike the policies at issue in Target, however, the policies at issue in Home Depot—according to Home Depot, at least—are governed by Georgia law.

    We expect that Home Depot will point to the Target court’s 2022 Decision in an attempt to support an argument that it is entitled to coverage.[2] It is uncertain how the Home Depot court would in that instance evaluate the merits or persuasiveness of the Target decision, which we would expect to be appealed at the appropriate time. We are actively monitoring both the Target and Home Depot cases and will report on any developments.

    [1] In Eyeblaster, the insured, Eyeblaster, was an online marketing campaign management company. Eyeblaster, 613 F.3d at 799. A computer user sued Eyeblaster, alleging that Eyeblaster injured his computer, software, and data after he visited an Eyeblaster website. Id. Specifically, the plaintiff alleged, in pertinent part, that his computer was infected with a spyware program from Eyeblaster, which caused his computer to immediately freeze up and to operate so slowly that it essentially became inoperable. Id. at 799, 802. The plaintiff also alleged that he experienced “a hijacked browser” and “slowed computer performance, sometimes resulting in crashes.” Id. at 802. Additionally, he asserted that his computer had three years of client tax returns that he could not transfer because he believed the spyware files would also be transferred, and he therefore had to reconstruct those records on a new computer. Id. The plaintiff argued that his computer was no longer usable, and claimed among his losses “the cost of his existing computer.” Id.

    In coverage litigation between Eyeblaster and its insurers concerning whether the insurers breached their duties to defend and indemnify Eyeblaster in the underlying action, one of the issues was whether the allegations in the underlying action triggered coverage under a general liability policy that defined “property damage” to include “loss of use of tangible property that is not physically injured.” See id. at 802-03. The Eighth Circuit, applying Minnesota law, held that the allegations triggered coverage, reasoning that “[t]he plain meaning of tangible property include[d] computers, and the [underlying] complaint allege[d] repeatedly the ‘loss of use’ of [the plaintiff’s] computer.” Id. at 802.

    [2] No doubt cognizant of the Target court’s 2021 Decision, Home Depot appeared to craft the allegations in its complaint (which it filed two months after that decision was rendered) to address the standards articulated in the 2021 Decision. For instance, Home Depot alleged in its complaint that the ability to use the payment cards “had significant value” to the card issuers. Complaint ¶ 39, Home Depot, Inc. v. Steadfast Ins. Co., No. 1:21-cv-00242 (S.D. Ohio filed April 8, 2021). Home Depot further alleged that, as a result of the data breach, the card issuers “incurred costs including the cost to replace the compromised plastic payment cards as well as lost interest and transaction fees due to reduced card usage.” Id. ¶ 46. “Alternatively,” Home Depot asserted, “the cost to replace the compromised plastic payment cards approximates the value to the Issuing Banks of the loss of use of these cards.” Id.

    Id. at 994-95 (emphasis in original) (footnote omitted).

    The Authors

    Joshua Mooney

    Joshua MooneyKennedys

    Josh is a partner and head of the firm’s U.S. Cyber and Data Privacy practice. Based in Philadelphia, he advises clients on a wide array of data privacy and security issues, including breach response, compliance under such laws as CCPA, HIPAA, New York’s DFS Cyber Regulation and the SHIELD Act, and BIPA, and big data usage and licensing. Josh also advises on cross-border data transfers and implementation of privacy and security protocols. In addition, Josh represents insurers in media and cyber liability coverage matters.

    Judy Selby

    Judy SelbyKennedys

    Judith Selby is a partner in the firm’s New York office where she focuses on insurance coverage matters. Judy represents clients in all phases of large scale, complex first- and third-party insurance issues. She has extensive experience handling insurance coverage trials in the U.S. and international arbitrations in London. In addition to cyber security and privacy coverage, her experience includes matters involving underlying claims relating to environmental damage, toxic torts, TCPA, business interruption, bad faith, pharmaceutical products, and COVID-19 exposures. She also provides insurance due diligence advice in connection with mergers and acquisitions, run offs, and adverse development cover transactions.

    Judy is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.

    Tracey Kline

    Tracey KlineKennedys

    Tracey is an associate in the firm’s Philadelphia office. Her practice focuses primarily on insurance coverage litigation and cyber matters. Tracey represents and advises clients with respect to a variety of complex insurance coverage matters involving a variety of insurance policies, including general liability, directors and officers liability, cyber, and first-party property policies, among others. She has experience conducting depositions, leading arbitrations, and drafting pleadings and motions at all stages of litigation, and has worked on cases in courts throughout the United States.

    More about the firm.

  • The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar
    Now on-demand at the West LegalEdcenter
    THE COMMERCIAL DRONE INDUSTRY
    Privacy, Security, Threats, and Mitigation of Risk

    Drones have become an increasingly valuable tool for businesses of all types and sizes.

    Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical.

    Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle.

    Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology.

    Topics:

    • Defining drones.
    • Current and future applications.
    • FAA Modernization and Reform Act of 2012.
    • FAA Part 107 Regulations and waivers.
    • Resources, e.g. the FAA Drone Zone and LAANC Portal.
    • Penalties for violations.
    • Privacy implications.
    • Drones as weapons.
    • Vulnerability to cyber attacks.

    Take it now!

    What you get:

    1+ CLE credits (subject to bar rules).

    Insights from an experienced professional who specializes in this area of the law.

    The complete PowerPoint presentation.

    Continued access to the complete recording for later use.

    Answers to your questions.

    Fee:

    No additional charge to subscribers to the West LegalEdcenter.

    Non-subscribers may take the course for $170.

    Meet the Speaker

    Kathryn Rattigan
    Robinson & Cole LLP

    Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and vendor management. She represents clients across all industries, such as manufacturing, insurance, health care, education, energy, and construction.

    Kathryn helps clients comply with all state and federal regulations related to data privacy and cybersecurity. She is also a member of the firm’s Drone Compliance Team. As such, she advises clients on all legal issues surrounding the use of commercial drones, including navigation of Federal Aviation Administration regulations, commercial registration requirements, and Part 107 waivers.

    She is committed to doing pro bono work and being involved in the community. Her recent efforts include assisting Inner Explorer, a non-profit which works to help students focus and succeed through mindfulness practice in the classroom, and College Visions, which helps low-income students pursue a college education.

    She writes for two of the firm’s blogs, Data Privacy + Security Insider and Health Law Diagnosis.

    More about Kathryn

    Also, listen to my interview with Kathryn for the the Emerging Litigation Podcast!

    –Tom Hagy

  • The Cyber Insurance Market Has Problems: A Conversation With Tom Johansmeyer

    The Cyber Insurance Market Has Problems: A Conversation With Tom Johansmeyer

    The Cyber Insurance Market Has Problems: A Conversation With Tom Johansmeyer

    The author of the piece is my guest on our latest episode. He is Tom Johansmeyer, ARM, is head of PCS, a Verisk business. PCS investigates and provide, independent loss estimates on catastrophes and large individual losses to the benefit of the global risk and capital supply chain. Tom has focused on the broad and rapid expansion of PCS, leading the team into Japan, New Zealand, and other APAC regions in 2019 – as well as Mexico. Tom is the architect of the PCS entry into global specialty lines, most recently adding large risk loss reporting to the group’s portfolio. Previously, Tom held insurance industry roles at Guy Carpenter (where he launched the first corporate blog in the reinsurance sector) and Deloitte. Personally, I like his LinkedIn description: “Aspiring cyclist and distance swimmer, former soldier. Leading the global charge at PCS. Haven’t driven anything with a motor since 2007.” Excellent.

    This podcast is the audio companion to the Journal on Emerging Issues in Litigation, a collaborative project between HB Litigation Conferences and the legal news folks at Law Street Media, and the Fastcase legal research family, which includes Docket Alarm and Judicata. If you have comments or wish to participate in one our projects, or want to tell me how insightful our guests are, please drop me a note at Editor@LitigationConferences.com.

    You might notice that I misused a commonly used term, one specifically common in the world of insurance, or maybe you weren’t paying that much attention. That would make two of us. Also, Tom J. was just a fun interview and I hope to get him back! I like the way he explained his candor at the end. He suffers from an infliction that I wish were a pandemic. I hope you enjoy it.

    Tom Hagy
    Host of the Emerging Litigation Podcast

    “Facing the prospect of major financial fallout from an attack, C-suites around the world have turned to cyber insurance. Insurers are issuing more policies, and the amounts of protection available are increasing.

    “In 2020, according to data proprietary to the team I lead, the global insurance community saw the first cyber insurance program to exceed $1 billion — and the second. However, the momentum that has propelled the sector this far may be running out. The cyber insurance sector may still be in its infancy, but there are signs that it’s hit a (hopefully temporary) plateau.”

    From a Jan. 11, 2021, article in the Harvard Business Review titled “Cybersecurity Insurance Has a Big Problem.”

  • To Pay or Not to Pay: Does Your Insurance Policy Cover Ransomware Losses? | By Pamela Hans | Anderson Kill

    To Pay or Not to Pay: Does Your Insurance Policy Cover Ransomware Losses? | By Pamela Hans | Anderson Kill

    To Pay or Not to Pay: Does Your Insurance Policy Cover Ransomware Losses?

    Abstract

    Ransomware attacks are a rapidly growing threat against organizations. Paying ransom demands is a risky proposition and may even lead to sanctions against the targeted company. Either way, the damage to a company’s operation and integrity can be cripplingly severe. Should a company suffer losses from cyber extortion, its insurance company will be one of the resources it turns to for relief. But with cyber
    coverage increasingly out of reach for some, policyholders may find coverage in more traditional coverages. In this article, the author evaluates the potential for coverage under several policy types, and underscores the importance of understanding policy language, the relevant law, and the potential regulatory ramifications of meeting ransom demands.

    Author

    Pamela D. Hans (phans@andersonkill.com) is the managing shareholder of Anderson Kill’s Philadelphia office. Her practice concentrates on insurance coverage exclusively on behalf of policyholders. Pam is also a member of the firm’s COVID Task Group and Cyber Recovery Group.

    About
    The Journal on Emerging Issues in Litigation is a co-production of HB, Fastcase, and Law Street Media. You can also hear the complementary (and complimentary) Emerging Litigation Podcast wherever podcasts appear. For questions, contact Tom Hagy, Editor in Chief, at Editor@LitigationConferences.com.

    Loading Viewer…

  • Data Security for Small Law Firms with Ondrej Krehel and Gaspare Marturano

    Data Security for Small Law Firms with Ondrej Krehel and Gaspare Marturano

    Data Security for Small Law Firms with Ondrej Krehel and Gaspare Marturano

    Joining me to discuss this important issue is Ondrej Krehel, CEO & Founder of LIFARS, a New York-based incident response and digital forensics firm specializing in cybersecurity protection.
    Ondrej is recognized for his digital forensic expertise and ethical hacking skills. He participates in high-profile engagements around the world using his proprietary methodology to achieve the most rapid root-cause analysis and remediation. He is a former lecturer at FBI Training Academy who has led forensic investigations and cybersecurity involving the U.S. government, including military cyber special operations. He holds a Ph.D. in Computer Forensics from Police Academy in Bratislava, Slovakia, an M.S. degree in Mathematical Physics from Comenius University in Bratislava, and an Engineering Diploma from Technical University in Zvolen, Slovakia.
    Joining Ondrej and me is Gaspare J. Marturano, Chief Marketing Officer at LIFARS. Gaspare is a former Director of Information Systems for a large Connecticut law firm and has consulted on these issues with a number of other law firms.
    This podcast is the audio companion to the Journal on Emerging Issues in Litigation, a collaborative project between HB Litigation Conferences and the Fastcase legal research family, which includes Full Court Press, Law Street Media, and Docket Alarm. If you have comments or wish to participate in one our projects, or want to tell me how insightful and informative Ondrej and Gaspare are, please drop me a note at Editor@LitigationConferences.com.
    I particularly enjoyed hearing about what one kid was doing at 17, an age when I was certain I would be sought out for my rock drumming artistry. Of course, that kid was operating a criminal enterprise. I was just trying to impress girls.
    Tom Hagy

    Law firms are sweet targets for hackers given the rich data they store, from intellectual property to confidential merger details to personal and health information.

    The last decade is rife with headlines about data hacks and ransomware attacks at even the most sophisticated global law firms.

    Yet, according to the 2020 Legal Technology Survey Report conducted by the American Bar Association’s Legal Technology Resource Center fewer than half of the firms polled employ some of the most basic security measures, such as email and file encryption.

    What can smaller firms do to protect their data and that of their clients?

  • Policyholders Hit With Ransomware, Then Strike Insurance Coverage Oil in Indiana

    Policyholders Hit With Ransomware, Then Strike Insurance Coverage Oil in Indiana

    Policyholders Hit With Ransomware, Then Strike Insurance Coverage Oil in Indiana

    Abstract

    The cost of ransomware to businesses is estimated to have doubled since 2019 to $20 billion, according to Coveware. Policyholders turn to their insurance policies to recover losses that average more than $230,000 per incident. In the case discussed, the carrier denied a policyholder’s claim as being outside the computer fraud provisions of the commercial crime portion of the policy. Two lower courts sided with the carrier, but the

    Indiana Supreme Court ruled in favor of coverage. This is a significant win for policyholders seeking coverage for losses under policies not sold as “cyber insurance.” The article discusses the decision and the precedents cited in an area of litigation that only promises to expand as ransomware and similar digital crimes proliferate.

    Author

    Scott Godes and Andy Detherage were counsel to United Policy-holders, which submitted an amicus brief in favor of granting transfer and reversing the lower court decision, in the Indiana Supreme Court decision referenced in this article. Messrs. Godes and Detherage are partners in Barnes & Thornburg LLP.

    About
    The Journal on Emerging Issues in Litigation is a co-production of HB, Fastcase, and Law Street Media. You can also hear the complementary (and complimentary) Emerging Litigation Podcast wherever podcasts appear. For questions, contact Tom Hagy, Editor in Chief, at Editor@LitigationConferences.com.

    Loading Viewer…

  • Myriah Jaworski on Arbitration as Defense Against Data Breach Class Actions

    Myriah Jaworski on Arbitration as Defense Against Data Breach Class Actions

    Myriah Jaworski on Individual Arbitration as a Defense Strategy Against Data Breach Class Actions

    Abstract
    Data privacy class actions are proliferating. Defendant companies may find an effective defense strategy is moving to compel individual arbitration. Not all contracts have the appropriate language, however, and, even if they do, they may not succeed. This article, which will appear in the forthcoming issue of the Journal on Emerging Issues in Litigation, discusses U.S. privacy litigation and case law on compelling arbitration of class claims in the privacy law context, with recommendations for businesses to improve their chances of securing court orders that enforce arbitration language in their agreements.

    Author
    Myriah V. Jaworski, Esq. (mjaworski@beckage.com), is a member with the Beckage, a law firm specializing in technology, data security and privacy. She is a Certified Information Privacy Professional, United States (CIPP/US) and Certified Information Privacy Professional, Europe (CIPP/E). She leads Beckage’s Privacy Litigation Practice Group where she represents clients in data breach actions, technology vendor disputes, and the defense of consumer class actions and related regulatory investigations. Myriah is also a former Trial Attorney with the Department of Justice.

    About
    The Journal on Emerging Issues in Litigation is a co-production of HB, Fastcase, and Law Street Media. You can also hear the complementary (and complimentary) Emerging Litigation Podcast wherever podcasts appear. For questions, contact Tom Hagy, Editor in Chief, at Editor@LitigationConferences.com.

    Loading Viewer…

    Safeguarding Against Financial Exploitation

    An on-demand CLE-eligible webinar Safeguarding Against Financial Exploitation   America’s senior population is growing. Nearly one in five U.S. residents will be 65 or older in 2030. Which means the average age of U.S. investors is climbing too. With that comes the risk that they will be exploited by people with access – or gain access through nefarious methods – to their investment portfolio. Seniors and vulnerable persons lose billions of dollars each year. Remarkably, 90% of the people to take advantage of senior investors are members of their own family. Attorneys who represent senior clients need to know the signs of vulnerability, red flags that their clients are being exploited, what laws apply, and rules lawyers must follow in these matters.   Questions our speakers answer: What is senior / vulnerable investor exploitation?   Who is protected by state and federal laws?   How prevalent is senior financial exploitation? What do the numbers tell us?  What is the pace of financial abuse SAR filings by securities firms?  What are the most popular scams?   What is diminished capacity?  What are the red flags indicating possible exploitation?  What are the laws, rules, and regulations governing law firms?  What are some best practices for law firms?  How can firms best protect their senior clients?   On Demand CLE Webinar What You Get PowerPoint and supplemental materials. Complete recording for later review. Answers to your questions via email. Invitation to contact speakers. 1.5 CLE credits (for licensed attorneys). CLE assistance.* *Subject to state bar rules. For licensed attorneys.  Register Meet the Speakers Joseph Calabrese Bressler, Amery & Ross, P.C. A 1991 Graduate of St. John’s University Law School, Mr. Calabrese brings 30 years of practice and 18 years of Securities Litigation/Regulatory experience to his role as principal in the New York office of  Bressler, Amery & Ross’s Financial Institutions Group. He began his career as a Wall Street litigator as an associate general counsel for Citigroup’s Smith Barney and […]

    Lien Resolution: Government & Private Plans Get Aggressive (Against Attorneys)

    Includes Nearly 75 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. What can you do to settle personal injury suits cleanly and avoid costly litigation and penalties? What recent cases can inform you about protecting your settlements and, as attorneys, yourselves, from post-settlement federal lawsuits? How can your firm set itself up to meet government expectations? What role might experts play in navigating these pitfalls? Medicare Advantage (42 USC § 1395w-22) Federal Medical Care Recovery Act (FMCRA) (42 USC § 2651) Armed Forces Act (10 USC §1095) Veterans’ Benefits (38 USC §1729) Third-Party Collection Rules (32 CFR 537.24; 38 CFR 17.101, etc.) Set-Asides under the Medicare Secondary Payer Act (42 USC § 1395y(b)(2)] On Demand Registration Lien Resolution Government & Private Plans Get Aggressive (Against Attorneys!) On Demand | Recorded September 2020 It is increasingly common these days. Personal injury attorneys settle a case, only to find themselves sued by a U.S. Attorney for failing to reimburse Medicare for conditional payments as required by the Medicare Secondary Payer Act. In some cases the attorney may be required to pay fines in addition to the reimbursements and interest, a costly proposition. Are you up to speed on issues surrounding Medicare Advantage, TRICARE, veterans’ claims, and Medicare set-asides? Join nationally recognized healthcare lien and resolution expert Franklin P. Solomon and go-to lien resolution provider Brett Newman as they offer a practical, in-depth CLE presentation. Franklin P. Solomon, Esq. Attorney & Founder, Solomon Law Firm  A graduate of Rutgers University School of Law at Camden, Franklin Solomon is based in Cherry Hill, NJ, with a practice focused on evaluation, litigation and resolution of healthcare “liens” and reimbursement claims. Mr. Solomon represents personal injury victims and their attorneys […]

    Telepsychiatry: Mitigating the Risks

    REGISTER Registration Includes Nearly 90 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. Understand the risks associated with telepsychiatry and how to manage them.  Telemedicine has emerged as an important solution for healthcare in general and psychiatric medicine specifically during the current global pandemic. Remote access for sub-practices including addiction counseling have been commonly used. Our panel of psychiatric professionals who have served as expert witnesses and attorneys who counsel and represent physicians have prepared a 90-minute session to share insights with attorneys, physicians, healthcare providers, risk professionals, and more. Agenda Examining procedures and best practices that exist for ensuring confidentiality in a telemedicine practice How do you draft a telepsychiatric consent form? What is the emerging standard of care for telemedicine? Will the standard of care for telemedicine become a national standard? (Should it?) Review the case law addressing telemedicine or telepsychiatry How do the HIPAA regulations and HITECH privacy laws impact telemedicine? How have the HIPAA regulations and HITECH privacy laws been relaxed during the pandemic? Will the relaxed HIPAA and HITECH regulations impacting telemedicine continue past the pandemic? Which technical platforms are preferred? Which ones to avoid? Panelists Mark Levy, M.D., Medical Director at fpamed David Kan, M.D., UCSF Psychiatry Department and the California Society for Substance Abuse Medicine Ayesha Ashai, M.D., associated with fpamed Stephen M. Fatum, J.D., Partner, Barnes & Thornburg LLP Angela W. Russell, J.D., Partner, Wilson Elser Moskowitz Edelman & Dicker LLP Meet our physician and attorney panelists. Mark Levy MD Medical Director fpamed Dr. Levy is a graduate of Columbia College (A.B. 1967) and the Columbia University College of Physicians and Surgeons (M.D. 1971) in New York. He is a Physician […]

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar Now on-demand at the West LegalEdcenter THE COMMERCIAL DRONE INDUSTRY Privacy, Security, Threats, and Mitigation of Risk Drones have become an increasingly valuable tool for businesses of all types and sizes. Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical. Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle. Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology. Topics: Defining drones. Current and future applications. FAA Modernization and Reform Act of 2012. FAA Part 107 Regulations and waivers. Resources, e.g. the FAA Drone Zone and LAANC Portal. Penalties for violations. Privacy implications. Drones as weapons. Vulnerability to cyber attacks. Take it now! What you get: 1+ CLE credits (subject to bar rules). Insights from an experienced professional who specializes in this area of the law. The complete PowerPoint presentation. Continued access to the complete recording for later use. Answers to your questions. Fee: No additional charge to subscribers to the West LegalEdcenter. Non-subscribers may take the course for $170. Meet the Speaker Kathryn Rattigan Robinson & Cole LLP Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and […]

    The Intersection of Privacy and Antitrust Webinar Now Available On-Demand on the West LegalEdcenter

    Available as part of your subscription to The Thomson Reuters West LegalEdcenter®. Don’t subscribe to the West LegalEdcenter? This webinar is still available directly from HB. Take it now! Questions for speakers Questions@LitigationConferences.com CLE questions CLE@LitigationConferences.com Check out the MoginRubin blog for more insights on antitrust and privacy law. What attorneys and companies need to know about the increasing interplay between these critical areas of the law.  Highly publicized cases and investigations in the U.S. and Europe of big technology, e-commerce, and social media companies demonstrate how anti-competition laws are being used to scrutinize and challenge not only how these corporations conduct themselves in the marketplace, but the very core of their colossal success: the mass collection and utilization of user data. Are the privacy and antitrust worlds beginning to cross over? Or do they simply run parallel while addressing entirely different types of conduct? Whatever the answer, data is the raw material that drives the likes of Google, Facebook, Apple and Amazon, so how it is handled is a critical question when counseling clients on mergers and acquisitions. Moderator Daniel J.  Mogin | Managing Partner, MoginRubin LLP Speakers Jennifer M. Oliver, CIPP/US | Partner, MoginRubin LLP Thomas N. Dahdouh | Director, Western Region, Federal Trade Commission Franklin M. Rubinstein | Partner, Wilson Sonsini Goodrich & Rosati Randi W. Singer, CIPP/US, CIPT | Partner, Weil, Gotshal & Manges Contributor Dina Srinivasan | Independent Researcher & Author of The Antitrust Case Against Facebook Dina was unable to present but we thank her for her content contributions.  Agenda Who should regulate privacy violations in the U.S.? Which antitrust issues implicate privacy concerns? What role does machine learning play on the competitive landscape? What is big data really? How is it different from “data”? What are the elements of effective merger reviews? What are the appropriate remedies? What are “notice-and-choice” versus “harms-based” approaches? Plus answers to your questions. Send them to Questions@LitigationConferences.com.

  • The Dark Net:  Anonymity, Infrastructure, and the Future

    The Dark Net: Anonymity, Infrastructure, and the Future

    Register

    Webinar Info

    Wednesday, Aug. 5, 2020

    United States
    8am PT | 10am CT | 11am ET

    United Kingdom
    4pm BST

    Get CLE or CPE, a complete set of materials, and answers to your questions!

    Email us your:
    Speaker questions
    CLE questions

    Topics Covered

    Physical and Logical Topology and Method of Data Transmission

    Using the Dark Net for Threat Hunting

    Hacking Groups and Malicious Hackers  

    The Future of The Dark Net and Anonymity

    The Dark Net: Anonymity, Infrastructure, and the Future
    Is the Dark Web Getting Darker? 

    Wed., Aug. 5, 2020 | Produced for Access Data by HB Litigation Conferences

    The web, however singular it may seem from behind an everyday user’s computer or smartphone screen, comprises three distinctive parts: the public net (or web), the deep net, and the dark net. Though the dark net contains some innocuous content and is used for legitimate purposes, it also operates as a platform for illegal marketplaces. These offer almost anything a criminal or cybercriminal might want to buy or sell like malware, exploits, hackers-for-hire, information lifted from data breaches, censored content, and goods like drugs, guns, and other contraband.

    Observers report that the dark web is getting darker, meaning hardcore criminals make up a greater percentage of its user base. Exploits and other hacking tools and techniques used to disrupt business, critical infrastructure, and misappropriate confidential information are continually diversifying and becoming more complex. According to Cyber Defense Magazine, the annual cost of cybercrime damages to users, online businesses, and nations is expected to hit $5 trillion this year, with some estimates ranging as high as $10 trillion.

    Join two highly experienced data security professionals – Mary T. Frantz of Enterprise Knowledge Partners and Frank Krahn of Burdock Consulting – as they discuss how cybercrime fighters must overcome a variety of challenges as they threat-hunt on the dark net: detecting, monitoring, and gathering intelligence on cybercrimes and the actors behind them. Frantz and Krahn will discuss how the cybersecurity community will address emerging threats, what changes the web may undergo as a result, and more. The session will be moderated by the head of international training at AccessData, Sarah Hargreaves, who brings her own experience in forensics to the discussion.

    Meet our panelists.


    Frank Krahn
    Co-Founder, Burdock Consulting, LLC

    Before co-founding Burdock Consulting, Frank had a long tenure with the Mayo Clinic, where he served as the Director of Operational Risk Management. He holds various specialist certificates in information security and computer crime investigation and forensics. Frank has taught classes and consulted for law enforcement agencies on computer crime-related matters, and has worked with the FBI. He is also an e-discovery specialist.


    Mary T. Frantz

    Founder & Managing Partner, Enterprise Knowledge Partners, LLC

    Mary is a technology and strategy professional with more than 25 years’ experience as a corporate and consulting firm executive. Her expertise includes IT strategy, e-discovery, compliance, enterprise risk, information security, and enterprise architecture. Mary has served as a legal expert on a variety of cyber security topics. She is also an author, keynote speaker, and adjunct professor.


    moderator

    Sarah Hargreaves ACI, ACE
    Director of Training – International
    AccessData, United Kingdom

    Sarah started her career in digital forensics in 2003.  Previously working in a criminal law practice, Sarah moved over to forensics after working on a number of investigations which inspired her to change career path.  Her journey continued with a number of roles in Digital Forensic Laboratories, primarily supporting law enforcement in Child Sexual Exploitation investigation and general crime.  Sarah progressed to Laboratory Management and later into Training Management.

    Sarah is experienced in digital investigation, laboratory management, ISO17025 and evidential process.

    Sarah lives in the North West of England and is a mum to two young children.  She enjoys days out with her family and traveling.

  • Setting the record straight on cyber insurance claim denials and the ‘war exclusion’

    Is insurance coverage for cyber claims barred by a war exclusion?  Judy Selby and Peter McLaughlin asked this question in a recent post for IAPP.

    Two corporate giants, Mondelez International and Merck, made the headlines recently as they sustained serious damage as a result of a NotPetya infection, an encrypting ransomware. They have each filed declaratory judgments after their carriers denied their claims. Reports of these insurance disputes have led to concerns that cyber incidents involving state actors would not be covered by cyber policies with war exclusions.

    The Verizon 2019 Data Breach Investigations Report attributes 23% of breaches  to nation-states or state-affiliated players. “These state-sponsored attacks typically range from theft or espionage to financial gain; however, some attacks appear to have been driven by grudge or by swatting a neighbor,” Selby and McLaughlin write.

    “[P]erhaps we are viewing this through an old lens. Insurance has often been purchased to address hazards. Specifically, an organization obtains a policy to counter the slim risk of a fire, flood or other catastrophe. Fred Kaplan wrote an article for Slate in April in which he argues the inevitability of attacks – state-sponsored or otherwise – means that we should view cyber insurance more like we do health insurance: coverage against the inevitable, rather than against a hazard risk.”

    Read on for what else Selby and McLaughlin had to say here.

  • Cyber Captive Survey 2019 — AON

    Aon’s Cyber Captive Survey 2019 says that the rapid growth in the captive market of cyber-specific policies underscores that cyber is one of the primary risks for organizations across the world driven by an increasingly complex operational, technological and regulatory environment.

    Key findings include:

    • Healthcare and energy industries are leading the way, with 19% and 15% of organizations in these industries utilizing captives for cyber coverage respectively.

    • 41% of captives surveyed are incubating cyber risk.

    • The range in limits of cover taken out is up to USD$100 million.

    • An estimated 34% of all captives will be writing cyber in five years’ time.

    Read the complete report here!