TABLE OF CONTENTS
CYBERSECURITY & DATA PRIVACY

Below, we highlight some key trends companies can expect as they consider how insurance both cyber and general policies could help to mitigate cybersecurity risks.

Coverage Disputes and Uncertainty
One constant in the insurance market that is likely to persist for the foreseeable future is uncertainty with respect to coverage for losses arising from cyber incidents. Historical data about the scope and scale of losses are limited, and there can be a lack of clarity as to what is covered by new policy terms such as cyberterrorism. Multiple reports from government and industry sources attest to the lack of clarity around how key terms that set the scope of coverage are or should be defined, reducing predictability for both insureds and insurers. It is reasonable to expect continued dispute and litigation over the proper scope of coverage as companies face previously unanticipated threats to their businesses, such as nation-state cyber attacks.

For example, one recent case in a New Jersey state court resolved a coverage dispute arising out of the 2017 NotPetya cyber attack in favor of an insured, finding that its property insurance policy covered the $1.4 billion in damages it experienced. The insurer had disputed coverage based on the US governments attribution of NotPetya to the Russian military. The insurers argued that the relevant policys Hostile/Warlike Action Exclusion Language applied to the losses arising from the attack because the malware had been attributed to the Russian government and was linked to Russias ongoing conflict with Ukraine. The court disagreed, writing that the insurers had failed to update the policy to account for this type of event and that such exclusions had historically only ever applied to traditional forms of warfare. Notably, the court highlighted that when policy language creates ambiguity, the policy should be interpreted to conform to the reasonable expectations of the insured.

This case is unlikely to be the last word on this topic. At a time of rising international tensions and increasing use of cyber operations to accompany or replace traditional uses of armed force, questions around the scope and extent of policy coverage and exclusions in cases of nation-state sponsored cyber attacks are likely to remain contentious and significant.

Expanded Coverage Limitations
In response to the risk of unanticipated losses, some insurers are taking steps to clarify and limit the scope of policy coverage through new policy exclusions that could significantly limit the prospect of coverage for insureds at a time of increasing cybersecurity threats.

For example, one insurance association issued new, apparently first-of-their-kind, war and cyber war clauses in November 2021 that contain significant limitations in the scope of coverage for cyber operations that would not meet the threshold of traditional understandings of warfare. One such clause expressly excludes coverage for losses related to a cyber operation that has a major detrimental impact upon essential services in a given state. Cyber operations are defined to include cyber attacks by one state against the computer systems or information of another, and essential services include a range of critical infrastructure functions from financial