Tag: Directors & Officers

  • Am I Covered For? . . . A Discussion of Insurance Coverage Issues

    Am I Covered For? . . . A Discussion of Insurance Coverage Issues

    Am I Covered For? . . . A Discussion of Insurance Coverage Issues

    Gain a better understanding of core insurance coverages and the common challenges policyholders face when seeking recovery.

    This session provides a basic introduction to insurance coverage generally and the types of issues that typically arise when policyholders seek coverage under those policies.  We start with the basics, outlining the difference between first party and third-party claims, which provides a foundation for our discussion.  We then discuss the following insurance policies, providing a brief description of what they typically cover: commercial general liability policies; property policies; directors & officers liability policies; errors & omissions liability policies; employment practices liability policies; commercial crime or fidelity policies; cyber policies; and contamination and recall policies.  We offer real examples of challenges policyholders face in attempting to procure coverage, from the time of the loss, to providing notice, to subsequent litigation.  Our presentation then highlights some interesting cases, their facts, and the ultimate holdings.  We provide practical tips regarding the application process, providing notice, and potential alternatives to litigation.

    Learning Objectives

    By the end of this webinar, you’ll gain a solid foundation in:

    • Several different types of insurance policies;

    • What those insurance policies typically cover;

    • Examples of common issues that arise in seeking coverage under those policies;

    • How courts have dealt with certain types of insurance claims; and

    • Practical tips on common insurance-related claim issues.

    TAKE IT NOW

    Available now to CeriFi LegalEdge subscribers. Don’t subscribe? Don’t despair. Use code HB20 for 20% off. Or, HBSub20 for 20% off a full solo subscription. While supplies last.

    Speakers

    Steven J. Pudell

    Steven J. PudellManaging Shareholder | Anderson Kill Newark

    Steven J. Pudell is managing shareholder of Anderson Kill’s Newark office, focusing on insurance recovery for policyholders and commercial litigation. Recognized by Chambers USA, Best Lawyers, and The Legal 500, Steve represents clients in the food, chemical, pharmaceutical, and real estate industries. He frequently writes and speaks on insurance coverage and has held leadership roles in the ABA and New Jersey legal community.

    Christina Yousef

    Christina YousefShareholder | Anderson Kill

    Christina Yousef is a shareholder in Anderson Kill’s New Jersey office, representing policyholders in high-stakes insurance recoveries involving D&O liability, food contamination, construction defects, and environmental claims. She has litigated in courts nationwide and advises clients across the hospitality, manufacturing, and construction sectors. Christina holds a J.D. from Seton Hall and clerked at the U.S. District Court for the District of New Jersey.

    William Harrison

    William HarrisonManaging Director, Product Recall Practice | Gallagher

    Bill Harrison is a leading expert in product recall and contamination insurance. He launched the first brokerage group focused on crisis risks like product contamination, recall, K&R, and terrorism. Now with Gallagher, Bill brings decades of experience from AIG, Aon, and Marsh to help clients manage complex product risk. He is also co-author of The Executive’s Desk Book on Corporate Risks and Response for Homeland Security.

  • Biometric Privacy Laws: Companies Will Need Insurance as Protection From New and Expanding Liability

    Biometric Privacy Laws: Companies Will Need Insurance as Protection From New and Expanding Liability

    The Authors

    Cort T. Malone

    Cort T. MaloneAnderson Kill P.C.

    * Cort T. Malone (cmalone@andersonkill.com) is a shareholder
    in the New York and Stamford offices of Anderson Kill and practices
    in the Insurance Recovery and the Corporate and Commercial Litigation Departments. He represents policyholders in insurance coverage litigation and dispute resolution, with an emphasis on commercia general liability insurance, directors and officers insurance, employment practices liability insurance, advertising injury insurance, and property insurance issues.

    Jade Sobh

    Jade SobhAnderson Kill P.C.

    Jade W. Sobh (jsobh@andersonkill.com) is an attorney in Anderson Kill’s New York office. Jade focuses his practice on insurance recovery, exclusively on behalf of policyholders, as well as regulatory and complex commercial litigation matters.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Biometric Privacy Laws:  

    Companies Will Need Insurance as Protection From New and Expanding Liability

    “Businesses may look to various types of insurance policies for protection from the sudden and ever-increasing liability under present and soon to pass biometric data privacy laws, including commercial general liability insurance, employment practices liability insurance, cyber insurance, and directors & officers (D&O) insurance.”

    Abstract: As more states follow Illinois in enacting biometric privacy laws, the risk that companies will be hit with lawsuits and extensive damages awards increases. Employers are among the most active collectors of this type of data, collecting fingerprints and deploying facial recognition for timekeeping and security purposes. Several multi-million-dollar settlements have been reported for violations of biometric privacy laws. Meta, formerly Facebook, paid $650 million to resolve claims that it improperly stored face scans of its users. When companies turn to their insurance carriers, policyholders have a good track record of receiving coverage. Now that these claims are becoming more prevalent, will the insurance industry work to limit its exposure in this space? What should policyholders do in the event the industry is successful? In this article, the authors provide background on these emerging privacy laws, how they have played out in court, and what
    types of policies companies should consider to be sure they have the necessary protection.

    At least seven states have passed biometric privacy laws specifically intended to protect individuals from the collection, use, and sale of their personal biometric identifiable information. Several of these laws allow for extensive damages awards regardless of whether individuals suffered any actual harm as a result of the nonconsensual collection of biometric data. The companies facing class action lawsuits as a result should look to insurance to cover such claims, as the initial litigation with insurance companies has provided favorable results to policyholders. But insurance companies surely will seek to limit future exposure related to biometric privacy law violations, and companies either using biometrics or potentially doing so in the future would be wise to seek and maintain the broadest possible coverage.

    Biometric Identifiable Information (BII) is generally defined as any physiological or biological characteristic that is used by or on behalf of a commercial establishment to identify an individual. BII may take the form of a retina scan, a fingerprint, a voiceprint, a scan of hand or face geometry, or any other identifying characteristic.

    Download the article now!

    Read, listen, explore more content on the subject!

    Podcast: Biometric Privacy Litigation and Coverage Disputes with John Leonard and Cort Malone 

    Podcast: Autonomous Vehicles: The New Technology Driving the Litigation Conversation with Cort Malone and John Leonard

    JEIL: Litigation After Biometric Privacy Law Violations: Policyholder Victories and Their Implications with Cort Malone and Abigal Damsky

    JEIL: Autonomous Vehicles: The New Technology Driving the Litigation Conversation with Cort Malone, John Leonard, Joshua Zelen

    Tags

    Emerging Litigation & Risk Compliance Litigation & appeals Cybersecurity Data Privacy Artificial Intelligence (AI) Insurance Companies Risk Management Corporate & Securities Insurance Claims Recovery Regulations Data Breach Toxic Torts Antitrust Legal Tech Product Liability Settlements Trial Personal Injury Privacy Healthcare Per- and Polyfluoroalkyl Substances (PFAS) Data Analytics Arbitration Constitutional Law Climate Change Cannabis Labor Law Insurance Fraud Liability Claims COVID Alternative Dispute Resolution (ADR) Mediation Diversity Equity Inclusion (DEI) Claims management Professional Liability Legal Research & Writing Business Interruption Law Practice Management Trial Skills Property and Casualty Drug Laws Copyright Law Catastrophic Loss

  • Asymmetrical Combat: Bad Faith Liability in Insurance Recovery Cases

    Asymmetrical Combat: Bad Faith Liability in Insurance Recovery Cases

    The Author

    William Passannante

    William PassannanteAnderson Kill P.C.

    William G. Passannante is co-chair of Anderson Kill’s Insurance Recovery Group and is a nationally recognized authority on policyholder insurance recovery in D&O, E&O, asbestos, environmental, property, food-borne illness, and other insurance disputes, with an emphasis on insurance recovery for corporate policyholders and educational and governmental institutions.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Asymmetrical Combat: Bad Faith Liability in Insurance Recovery Cases

    “Insurance policies are a unique product that requires the policyholder perform first—by paying insurance premiums—while the insurance company’s performance—the payment of the claim amount—is delayed until the insurance company determines to do so.”

    Abstract: Policyholder counsel see claims that an insurer violated its duty of good faith and fair dealing is an essential tool in leveling the playing field in policyholder–insurer disputes, especially in high-stakes litigation. Insurance companies write the policies, employ lobbyists, exchange information with each other, and, of course, have more experience handling claims. So, the author writes, bad faith allegations bring more balance to the relationship and provide a disincentive to “the profitable breach of the insurance promise.” He discusses above-policy limits risks for insurers, as well as attorneys’ fees, interest on unpaid claims, punitive damages, and more.

    Introduction: Bad faith insurance litigation presents high-stakes risks for insurance companies in the unbalanced battle between insurance companies and their policyholders. The asymmetric nature of the insurance claims process—insurance companies draft the insurance policies, lobby legislatures as an industry repeat litigant, exchange superior information among themselves, and have more experience with claims than any policyholder—means that policyholders need a counterbalance. Insurance company liability for bad faith and related above-policy limits liabilities can act as that counterbalance. Insurance company bad faith and related doctrines prove useful because of the claims-handling calculus used to attempt to avoid coverage for a claim.

    Without more an insurance company denying a claim faces what it did at the outset—the amount of the covered claim. Insurance companies thus engage in the profitable breach of the insurance promise. Most purchasers of the insurance product would think of their insurance company as a fiduciary or trustee from whom one can expect scrupulous candor. At claims time many policyholders do not receive what they expect. Still, hornbook contract law tells policyholders that every insurance policy contains within it a duty of good faith and fair dealing enforcing that duty of good faith and fair dealing helps level the insurance claim playing field . . . .

    Download the article now!

  • Climate Change, ESG, and D&O Insurance: Collision or Cooperation?

    Climate Change, ESG, and D&O Insurance: Collision or Cooperation?

    The Authors

    Robert D. Chesler (rchesler@andersonkill.com) is a shareholder in Anderson Kill’s New Jersey office and is a member of the firm’s Cyber Insurance Recovery Group. Bob represents policyholders in a broad variety of coverage claims against their insurers and advises companies with respect to their insurance programs. Dennis J. Artese (dartese@andersonkill.com) is a shareholder in Anderson Kill’s New York office and chairs the firm’s Climate Change and Disaster Recovery Group. Joseph Vila (jvila@andersonkill.com) is an insurance recovery attorney in Anderson Kill’s New Jersey office.

    Journal on Emerging Issues in Litigation

    Climate Change, ESG, and D&O Insurance: Collision or Cooperation?

    By Robert D. Chesler, Dennis J. Artese, and Joseph Villa

    Abstract:
    Climate change has been tied to the recent increase in catastrophic weather events. Insurance coverage for often billions of dollars in damage becomes a source of argument between insurers, who want to limit their exposure, and policyholders, who want the coverage they argue the carriers are contractually obligated to pay. The authors discuss the nature of the underlying suits and the potential coverage issues; the types of policies implicated; cases that have addressed these issues; the rising societal concern over climate change that have played a role in the new corporate emphasis on environmental, social, and governance, or ESG, and the insurance industry’s response to this trend.

    Excerpts:
    Directors and Officers (D&O) policies [are] directly affected by climate change. Two types of suits are already happening. First, there are at least 1,375 climate change–related suits pending in the United States, about two dozen of which have been filed by local municipalities and states seeking damages because of climate change. For example, the attorneys general of New York, Massachusetts, and the U.S. Virgin Islands launched investigations to determine whether Exxon Mobil Corporation misrepresented to investors the risks of how climate change might impact its business. Although the U.S. Virgin Islands attorney general terminated its investigation, the New York and Massachusetts attorneys general filed separate suits against Exxon.

    In the seminal case People of the State of New York, By Letitia James v. Exxon Mobil Corporation, 119 N.Y.S.3d 829 (N.Y. Sup. Ct. 2019), the State of New York sued Exxon, alleging that it violated the state’s securities act by making materially false and misleading statements to the public and investors about how the company manages risks of climate change and the cost of carbon in assessing demand for its products. The state dropped its common law fraud claims prior to trial, but proceeded with a claim under New York’s Martin Act, which permits the attorney general to sue for fraud in connection with the marketing of securities without requiring proof of scienter, reliance, and damages, as well as under New York’s Executive Law, which prohibits persistent fraudulent acts. After a trial, the New York Supreme Court held that the state failed to demonstrate by a preponderance of the evidence that Exxon made any material misrepresentations to investors ….

    As regulatory activity and private litigation activity surrounding climate change issues continue to increase, liabilities likely will follow. D&O insurance companies will be called on to address those liabilities with increasing frequency.

    Those claims will present complex coverage issues of first impression, and policyholders can expect a fight. Policyholders also should be on the lookout for more restrictive coverage terms on D&O renewals. Policyholders should work with their brokers to obtain the broadest coverage available, and consult with sophisticated coverage counsel in the event that they are faced with climate change–related claims. 

    Get the article now!

    Explore more from Bob Chesler and contributing specialists!

    Journal on Emerging Issues, Editorial Board of Advisors

    The Use and Abuse of the Pollution Exclusion. By Dennis Artese, Jamie O’Neil, Robert Chesler

    The Environmental, Social, and Governance Police Have Arrived: Is your Insurance Ready. Authors: Dennis Artese, Bob Chesler.

    PFAS Insurance Coverage with Jaana Pietari and Jim Fenstermacher and Litigation with Bob Chesler: Part 1 of 2 Podcasts

    PFAS Insurance Coverage with Robert D. Chesler of Anderson Kill. Part 2 of 2 Podcasts

    How Insurance Companies Defraud Their Policyholders, and What Courts and Legislators Should Do About It

    Climate Change, ESG, D&O Insurance: Collision or Cooperation? By Robert D. Chesler, Dennis J. Artese and Joseph Villa

    Remediating, Insuring, and Litigating PFAS Claims. By Dr. Jaana Pietari, PhD, MBA, PE, Jim Fenstermacher, PE, Dr. Michael Bock, PhD, MS, Robert D. Chesler and Nicholas M. Insua, Sheila Mulrennan, Robin Kelliher, Jason R. Waters

  • $3M Transferred in Fraud Scheme, Law Firm Gets Sued, Says It Followed Client Instructions

    $3M Transferred in Fraud Scheme, Law Firm Gets Sued, Says It Followed Client Instructions

    $3M Transferred in Fraud Scheme, Law Firm Sued, Says It Followed Client Instructions

    Two related foundations hired a big law firm to sell stock and execute a merger via wire transfer. Cyber fraudsters had other ideas. Posing as stock seller, and intercepting a verification email, the perpetrators grabbed $3.1 million. The foundations sued the firm in state court in Utah, claiming the firm should have red-flagged certain inconsistencies and known it was being duped. The firm should also have picked up the phone to verify the source of the fraudulent emails and documents. Not so fast, the firm maintains. The plaintiff was not a client and it was only acting on wiring instructions sent via the plaintiff’s email system and provided the instructions to the paying agent. The money was sent to the account of an alleged furniture company in Hong Kong. Sorenson, et al. v.  Continental Stock Transfer, Tassel Parent, and Holland & Knight, 3rd. Jud. Dist. Ct., Salt Lake Co., Utah.

    Download

  • Aon SVP Belfiore on Corporate Cyber Risk

    Cyber Risk of Paramount Concern to Corporate Boards

    Lack of History Remains a Challenge

    “Cyber security is the most polarizing issue on the corporate board agenda these days,” says Anthony Belfiore, SVP and Chief Information Security Officer at Aon. “It has the most potential impact and the most regulatory pressure among all risks companies face. Nothing is more top of mind right now.”

    “You just have to look at the amount of media coverage and the actual realized impacts companies are experiencing. Hundreds of thousands of businesses from big to small are being affected. The entire healthcare system in the UK went down. The impact is tangible. It’s affecting day-to-day operations,” he says. “And no one is immune. Board members come from a diverse set of industries, and all are impacted.”

    Why is cyber risk such a hot button for companies versus other types of risks?

    “The risk has become more urgent as it has shifted to actual business interruption,” Belfiore says. “Historically companies were concerned with data leakage and loss, or regulatory fines, but now the actual operation itself can come to a halt. When a company goes down for three days that hits the media. Analysts notice. You can trace a specific event to a drop in stock values.”

    Aren’t fines still a concern?  

    “Yes. We are operating in a regulatory environment which can have a significant downside,” Belfiore says. “This is especially true if you are a multi-national firm with considerable operating and capital expenses. You can sustain significant and unforeseen punitive fines which can be imposed anywhere around the globe, for example, if you’re found non-compliant with GDPR.”

    What about directors themselves?  

    “Potential for board liability for failing to protect shareholders is a hot-button issue right now.  D&O liability and coverage is evolving,” says Belfiore.  “There is uncertainty as to who is protected.”

    The digitization of so many aspects of conducting business has been around for a while now. So why does cyber risk continue to present challenges for the insurance industry?

    “Historical data is a challenge for insurers because there is very little relative to other risks like those posed by fire or storms for which we have decades of statistics. This makes it difficult to qualify and quantify the risk. Models are used to gauge the potential for losses but, still,” he says, “there isn’t a lot of history to go on.”

    Aren’t companies and boards okay as long as they have insurance?  

    “Organizations who think they are covered may come to a different conclusion when they read the fine print. That’s why it’s imperative to work with an experienced broker to navigate the various coverages and nuances in policy language,” Belfiore says.

    At a high-level, what should security leaders at companies do to reduce risk and anxiety around potential cyber losses? 

    Belfiore urges companies to “set up effective governance and establish an effective governance committee. Examine how you run your operation day-to-day, consider how to best manage the expectations of the C-suite and the board. Get the most out of governance committee discussions, ensure you have alignment up and down the stack, and make sure you have installed effective risk management and risk protocols.”


    Belfiore is on “The CISO Perspective” panel at the International Cyber Risk Management Conference (ICRMC) on Dec. 6-7, 2018 in Bermuda, along with Tim Dawson, Cybersecurity Chief Technology Officer at HSBC; Tom Pageler, Chief Security Officer at BitGo, Inc.; and Derek Vadala, Chief Information Security Officer at Moody’s Corporation.  

    You will be able to hear insights like these, and updates on anything that occurs between now and December in Bermuda.

    This posted was edited by HB Founder & Managing Director Tom Hagy. In the 1990s Tom launched one of the first nationwide legal reports in this area — Mealey’s Litigation Report: Cyber Tech & E-Commerce — when he was publisher at Mealey’s, now part of LexisNexis. If you are interested in posting on this site or discussing speaking opportunities, please contact us at Editor@LitigationConferences.com.

  • Cyber Risks Enter a New and Increasingly Vicious Phase

    For anyone plotting the evolution of cyber risks, the last phase of cyber-attacks was dominated by breaches that resulted in lost or stolen personal or financial data that could then be monetized.

    The current phase is different.

    “We have observed a significant increase in the number of disruptive breaches that our clients are dealing with,” says Charles Carmakal, Vice President at Mandiant/FireEye. “These involve destruction, extortion, or public shaming.”

    How are organizations dealing with this shift?

    “It’s catching many organizations off guard. Most don’t have a playbook for dealing with extortion,” Carmakal says. “While they may have thought about a ransomware situation, that’s different from the more common type of extortion we are seeing these days, where a threat actor threatens C-level executives or corporate board members with the release of sensitive information.”

    “Many organizations assume the default is they wouldn’t give into the demands, but when in the middle of a crisis too often the decision is made to pay the threat actors,” he says.

    “So it’s important to consider what your organization will do in this situation. For example, who will be involved in the decision-making process? Organizations should play out an extortion scenario so they have a plan when faced with real demands.”

    How can organizations better test the efficacy of their security capabilities?

    Many organizations conduct penetration testing or red-teaming exercises, but they often undermine their own efforts.

    “A problem arises when an organization contracts a third-party to test their capabilities, but puts a lot of restrictions on those who are doing the testing,” Carmakal says. “For example, they will tell the testing team or red team to identify vulnerabilities, but not to exploit them, or they can exploit a vulnerability but stop there and not dig any further.  The penetration testers might be allowed to test only during a certain day of the week or certain time of day. Or they might be allowed to sample only a fraction of the organization’s IP addresses and ignore everything else.”

    “What happens is the penetration testers are not permitted access to the crown jewels,” Carmakal warns. “They can’t demonstrate business impact to the organization. This creates a false sense of security because the organization can say they had a team of qualified people try and fail to break into the network, but in reality they were unable to break through because of all the unrealistic restrictions imposed on that team.”

    This false sense of security travels to the top. “Testing results are shared with the board and the board believes that because a really good third-party was not able to get to the crown jewels that they have a much safer environment than they really do. That’s a very common theme we see across the industry,” Carmakal says.

    How do penetration testers deal with unrealistic testing parameters?

    “It’s part of the education process,” he says. “When a company wants us to do a very limited test, and we believe our reports will be shared with the leadership team or the board, then we just won’t take the engagement. We try to make it clear that this is not an exercise to make anyone look bad, but a way to leverage the lessons from all the bad guys who are breaking into organizations so you can strengthen your security.”

    In the end, he says, “It’s better we identify the vulnerabilities than have the bad guys do it.”

    What the geopolitical trends you are seeing?

    Iran – “They used to be unorganized. They even clumsily posted social media profiles of themselves,” Carmakal says. “But they have become much more organized, more structured, more technologically adept, and have affiliated with government entities.”

    “In 2017 we saw more intrusions from Iran than we had ever seen before. There was a noticeable spike in offensive intrusions coming from them. For some reason, in 2018 we really haven’t seen Iran targeting organizations in the United States. They’ve scaled back significantly in the US, but are still active in other parts of the world.”

    “What makes security professionals nervous about Iran,” Carmakal says, “is that they are a wildcard. You don’t know what they are going to do. You don’t understand the rationale behind their activity. But what we do see is a capability and a willingness to be incredibly destructive – taking down businesses and publicly shaming organizations. The fact that they’ve slowed down their attacks on U.S. organizations is interesting, but we expect that to change.”

    Russia – “Russia is not hacking the U.S. midterm elections like they were with the presidential election in 2016, but they are conducting some significant offensive operations around the world. They are very capable. They are also very good at disinformation and throwing false flags, so when you investigate them it’s difficult to tell who they really are. Russia is one of the few countries that demonstrates the willingness and capabilities to cause kinetic consequences through cyber-attacks, such as when they turned off the lights in Ukraine.”

    In March 2018 The New York Times wrote, “The Trump administration accused Russia … of engineering a series of cyber-attacks that targeted American and European nuclear power plants and water and electric systems, and could have sabotaged or shut power plants off at will.”

    When asked about this and the reporting that surrounded it, Carmakal said the story was a bit “sensationalized” and not 100% accurate. “While the intrusion was serious, we didn’t see the Russian actors getting anywhere near being able to shut off the lights,” he said, adding that they “certainly have the capability” in other parts of the world.

    China – There has been a “notable decrease” in cyber intrusions from China since the 2015 bi-lateral cyber agreement was reached between President Obama and China’s President Xi, Carmakal says. While narrow in scope, addressing economic espionage — China’s state-sponsored theft of private U.S. intellectual property and then turning it over to state-owned and private companies in China — the agreement does appear have helped, reports suggest. “They are still hacking organizations and are following a defined playbook. We’re keeping a close eye on them to see how their offensive operations evolve,” Carmakal says.

    North Korea – Except for the highly publicized attack against a major U.S.-based entertainment company, “North Korea rarely goes after Western organizations.” Given the country’s need for cash, “their focus has been more on robbing digital currency exchanges and stealing from banks digitally,” Carmakal says, adding that they, like Iran, are a bit of a “wild card.” North Korea actors have stolen more than $100 million from victims, Carmakal says.


    You will be able to hear insights like these, and updates on anything that occurs between now and December in Bermuda when Carmakal and his fellow panelists discuss important trends in global cyber risks.

    This posted was edited by HB Founder & Managing Director Tom Hagy. In the 1990s Tom launched one of the first nationwide legal reports in this area — Mealey’s Litigation Report: Cyber Tech & E-Commerce — when he was publisher at Mealey’s, now part of LexisNexis. If you are interested in posting on this site or discussing speaking opportunities, please contact us at Editor@LitigationConferences.com.

  • Willis Towers Watson: Cyber Risk Top D&O Concern

    Based on their survey, Willis Towers Watson says cyber risk continues to top the list of concerns for directors and officers (right up there with employee claims). As for coverage, while they care about price, things like their relationship with the carriers and how well they handle claims are critical elements.

    And, maybe one key reason cyber events keep happening: “Only 13% of board members feel that their organizations learn from past cyber mistakes.”

    Read the results of the Willis Towers Watson survey. 

  • Judy Selby on Improving Cyber and Privacy Board Reporting


    “While general awareness of cyber risks among corporate boards is increasing, even the most motivated and knowledgeable directors cannot effectively fulfill their duties without receiving appropriate data about the organization’s risk profile. Unfortunately, however, there appears to be a disconnect between management and boards when it comes to cyber risk reporting . . .  In order for directors to effectively discharge their duty of active, informed, and engaged oversight, the information they receive must be relevant, understandable, reliable, and objective.”

    Judy Selby, JD

    Judy Selby Consulting

    Read the full article and Judy’s tips for improving board reporting. 


    Judy Selby of Judy Selby Consulting

  • Crowell & Moring on D&O Corporate Liability for Cyber Claims

    “Although many commentators have noted the potential exposure for cyber claims in the form of shareholder actions under D&O coverage, little attention has been given to the risks of cyber exposure under Side C [D&O corporate liability] coverage,” write Laura A. Foggan and Thomas Kinney of Crowell & Moring LLP. “D&O policies contain many exclusions and coverage limitations that should protect against undue, unintended expansion of such policies to encompass cyber risks. However, as this case illustrates, courts may not always agree that those coverage limitations fully address cyber breach exposures.”