Cyber Coverage Pitfalls

Institutional data breaches are, unfortunately, more common (and more costly) than ever. Cybersecurity insurance can help—but is your firm’s policy really as ironclad as you think?

Digital lock shatters into pieces

Robert W. Wilkins

November 2, 2022 04:00 PM

An oft-repeated mantra in business and technology is that it’s not a question of if a data breach will happen, but when. The average cost of a corporate data breach in the United States is nearly $9.5 million, according to an IBM report published in 2022. Without adequate cybersecurity insurance, companies (and law firms) might find themselves facing a double threat: being the victim of a breach and then having to contend with the denial of their cyber insurance claim. This article addresses the risks of failing to implement and follow all of the policies and procedures required by the cyber insurance policy.

Given the exponential growth in breaches and their high costs, insurance providers are raising premiums and increasingly investigating whether the practices, as represented by the insured when it applied for coverage at the outset, were implemented and regularly tested and updated as needed. Failure to do so has resulted, and will continue to result, in denial of coverage.

The Expanding Litigation Threat

The biggest risk of this kind that businesses face is not from individual plaintiffs asserting damages from a data breach—it’s a class action brought on behalf of all those similarly situated. In the past, Article III standing cases have generally held that plaintiffs could not establish the requisite “injury in fact” based on the mere risk of future harm because their personally identifiable information or protected health information was exposed.

For years, class-action data breach cases have foundered on that basis. However, a growing body of case law provides guidance on what constitutes “concrete harm,” and the number of class-action cases finding a concrete injury is on the rise. For a good summary of the law on this critical issue, see TransUnion LLC v. Ramirez (2021) and Hunstein v. Preferred Collection and Management Services, Inc. (2022).

Loss of Insurance Coverage

Recent reports have shown that an insured party’s perception of its security versus reality often differ greatly. One of the biggest reasons for coverage denial concerns misrepresentations in the company’s application and/or the failure to maintain security practices amid the ever-changing threat environment. Most cyber insurance policies provide broad coverage for cyber extortion, data restoration, public relations, computer fraud, business interruption, regulatory compliance and related elements. However, the coverage under a policy depends on the representations the insured made in its application, and its subsequent compliance with them.

A typical application for cybersecurity insurance will contain a privacy and security liability questionnaire, as well as a portion about information security. Key items insurance providers require for such policies, according to an August 2022 FitchRatings report, include the use of multifactor authentication, employee training on phishing and other types of cyberattacks, strength-of-password requirements, regulatory reporting obligations, an assessment of the quality of one’s incident-response plan and penetration testing. In addition, all 50 states have data-breach notification laws, and law firms or clients must comply with the requirements of each state in which they do business.

Companies must regularly monitor, update and test all cybersecurity requirements mandated in their policy.”

The hole in the cyber insurance net stems from the insured’s potential misrepresentations in its application and its failure to adjust to the changes in the methods by which bad actors gain illegal access to data. Recently, one insured business that suffered an enormous data breach was denied coverage and had its policy rescinded. See Travelers Property Casualty Company v. International Control Services, Inc. (2022).

Travelers’ success was based on the fact that International Control Services, in its policy application, stated (and signed a separate attestation) that it required multifactor authentication to gain administrative access to its data. Upon investigation, Travelers determined that ICS misrepresented the scope of its authentication process, resulting in the breach.

A business’s failure to follow the policies and procedures claimed in its application is dire. In fact, most insurance policies have a specific exclusion that precludes coverage for claims arising from the policyholder’s failure to maintain adequate security standards. Companies must regularly monitor, update and test all cybersecurity requirements mandated in their policy. The same is true for policies regarding cyber extortion and ransomware attacks.

It’s not just insurance companies that require businesses to have solid procedures and policies to prevent and contain data breaches. Banks, corporate clients and a multitude of others require similar assurances from law firms they deal with that the firms have, comply with and regularly test, update and monitor a written information-security policy and incident-response plan.


The increase in data breaches, the costs resulting from them (which can include potential criminal and regulatory liability), the representations required by clients and insurance companies and the need to meet constantly changing threats in this data-driven age demand that law firms and their clients implement and closely monitor cybersecurity policies and practices. To that end:

  • Read your cybersecurity insurance policy application and representations to confirm each representation is accurate.
  • Update your policies and practices to stay on top of changes and innovations in data security.
  • Train and test your employees in data security practices and potential breaches, especially phishing schemes.
  • Keep an open line of communication with your insurance provider and follow its recommendations regarding cybersecurity.
  • Consider having an outside vendor run penetration tests of your data security systems.

The bottom line: Breaches may be inevitable, but diligence and preparation can mitigate both their financial and reputational impact.

Robert W. Wilkins, a Jones Foster shareholder, and the Litigation & Dispute Resolution Practice Group Chair, is double Board Certified by The Florida Bar in the areas of Business Litigation and Civil Trial. He is Co-Chair of the E-Discovery Subcommittee and the Data Security Subcommittee of the ABA Litigation Sections’ Commercial and Business Litigation Committee. He is also an active member of The Sedona Conference Working Group 1, Electronic Document Retention and Production and Working Group 11, Data Security and Privacy Liability.

Headline Image: istock/TU IS

Related Articles

Best Law Firms® Research Has Begun

by Best Lawyers

Best Law Firms® rankings are annually produced awards recognizing the top law firms across the United States. We are here to offer insight into the submission process for all eligible firms.

Black background with colorful squares and faces

Best Lawyers Voting Is Now Open

by Best Lawyers

Voting has begun in several countries across the globe, including the United States, the United Kingdom and Europe. Below we offer dates, details and answers to voting-related questions to assist with the voting process.

Hands holding smartphone with five stars above phone

Best Lawyers’ Purely Pure Voting: Authenticity and Trust Through Decades of Tradition

by Best Lawyers

Larry A. Campagna of Chamberlain Hrdlicka met with Best Lawyers CEO Phillip Greer to discuss how trust and peer-review feedback are pivotal to building authentic relationships with colleagues in the legal industry.

Hands shaking with silhouette of professionals

Honoring the Integrity of Best Lawyers’ Purely Peer Review Voting Process

by Best Lawyers

Best Lawyers CEO Phillip Greer sat down with attorney J. Keith Hyde of Provost Umphrey to discuss how peer review plays a role in building relationships and establishing accountability in the legal industry.

Five gold stars with a magnifying glass hovering over the right star

Clients with Appeal

by Michele M. Jochner

It’s frustrating to lose a case you’ve worked hard on. When considering whether to take an appeal of that ruling, here’s what to keep in mind—and how to enable your client to make that decision.

Client faces stacks of legal papers

The Evolving Reproductive Landscape

by Justin Smulison

The Supreme Court’s thunderclap Dobbs decision sent abortion policy nationwide into utterly unfamiliar terrain. The ruling also has a colossal effect on surrogates, intended parents and anyone involved in family planning given the patchwork of state laws likely to emerge. What’s a family law attorney to do?

Couple attends surrogate ultrasound

Estate Plan Implications in Divorce

by April Will and James Vedder

It’s essential that family law practitioners consult with estate planning attorneys as they guide their clients through a marital breakup. Here’s what to what to consider when there is a trust, but the parties do not trust each other.

Two figures shaking hands

The Quarter-Century Childhood

by Joseph Trotti

In recent years, proposed and enacted laws have significantly expanded parental obligation for child support, receiving little attention. Even if well-meaning, they have their flaws, beginning with reduced parental rights.

Child helping individual plant flowers

Mike Morse Law Firm’s 90-Day Digital Transformation Disrupts Status Quo

by John Georgatos

Mike Morse Law Firm's Chief Information Officer is shedding light on the firm's 90-day digital transformation.

Up close image of a multicolored eye

2023 Best Lawyers Mexican Awards

by Best Lawyers

Announcing Mexico's 2023 recognized lawyers and firms.

Green, white and red stripes with symbol in center

New York City To Clarify Employer Artificial Intelligence Laws

by Gregory Sirico

Best Lawyer weighs in on New York City's current legislative battle to clarify the extent of artificial intelligence laws in an employment setting.

AI worker stands in front of line of people


Embedded Advantage: The Value in Partnering with Appellate Counsel

by Justin Smulison

Most litigants should expect the non-prevailing party in their case to challenge the trial court’s final judgment in post-judgment motions and/or on appeal. Robert A. Mandel discusses how aligning with a seasoned appellate lawyer can make all the difference in securing a favorable resolution.

Headshot of male lawyer with brown hair in dark suit

A New Spin on Continuing Legal Education

by Sara Collin

Attorney Humira Noorestani is launching a program for continuing legal education, one that she’s dubbed the “Netflix of CLE,” allowing lawyers in the U.S. to explore legal knowledge from prominent lawyers around the world.

Hands emerging from computer and cellphone screens

South Florida’s Legal Renaissance

by Gregory Sirico

What was once only thought of as a destination for vacation may now be the top legal market in the country, attracting talent from around the world.

Blue and orange block sections with gavels and busts

Thirteen Years of Excellence

by Best Lawyers

For the 13th consecutive year, “Best Law Firms” has awarded the most elite and talented law firms across the country through a thorough and trusted data review process.

Red, white and blue pipes and writing on black background

To Serve and To Lead

by J. Henry Walker IV

Effective teamwork is more important than ever in the modern law firm, and it’s the almost oxymoronically named “servant leaders” who make it happen. Here’s a primer.

Three people leaving a conference room

Trending Articles

Announcing the 2023 The Best Lawyers in America Honorees

by Best Lawyers

Only the top 5.3% of all practicing lawyers in the U.S. were selected by their peers for inclusion in the 29th edition of The Best Lawyers in America®.

Gold strings and dots connecting to form US map

Best Lawyers: Ones to Watch in America for 2023

by Best Lawyers

The third edition of Best Lawyers: Ones to Watch in America™ highlights the legal talent of lawyers who have been in practice less than 10 years.

Three arrows made of lines and dots on blue background

The Best Lawyers in South Africa™ 2023

by Best Lawyers

Best Lawyers proudly announces lawyers recognized in South Africa for 2023.

South African flag

Could Reign Supreme End with the Queen?

by Sara Collin

Canada is revisiting the notion of abolishing the monarchy after Queen Elizabeth II’s passing, but many Canadians and lawmakers are questioning if Canada could, should and would follow through.

Teacup on saucer over image of Queen's eye


2022: Another Banner Year

by John Fields

Block O’Toole & Murphy continues to secure some of New York’s highest results for personal injury matters.

Three men in business suits standing in office

Famous Songs Unprotected by Copyright Could Mean Royalties for Some

by Michael B. Fein

A guide to navigating copyright claims on famous songs.

Can I Sing "Happy Birthday" in Public?

Announcing the 2023 The Best Lawyers in Canada Honorees

by Best Lawyers

The Best Lawyers in Canada™ is entering its 17th edition for 2023. We highlight the elite lawyers awarded this year.

Red map of Canada with white lines and dots

Wage and Overtime Laws for Truck Drivers

by Greg Mansell

For truck drivers nationwide, underpayment and overtime violations are just the beginning of a long list of problems. Below we explore the wages you are entitled to but may not be receiving.

Truck Driver Wage and Overtime Laws in the US

What the Courts Say About Recording in the Classroom

by Christina Henagen Peer and Peter Zawadski

Students and parents are increasingly asking to use audio devices to record what's being said in the classroom. But is it legal? A recent ruling offer gives the answer to a question confusing parents and administrators alike.

Is It Legal for Students to Record Teachers?

Thirteen Years of Excellence

by Best Lawyers

For the 13th consecutive year, “Best Law Firms” has awarded the most elite and talented law firms across the country through a thorough and trusted data review process.

Red, white and blue pipes and writing on black background

The Upcycle Conundrum

by Karen Kreider Gaunt

Laudable or litigious? What you need to know about potential copyright and trademark infringement when repurposing products.

Repurposed Products and Copyright Infringemen

Choosing a Title Company: What a Seller Should Expect

by Roy D. Oppenheim

When it comes to choosing a title company, how much power exactly does a seller have?

Choosing the Title Company As Seller

Caffeine Overload and DUI Tests

by Daniel Taylor

While it might come as a surprise, the over-consumption of caffeine could trigger a false positive on a breathalyzer test.

Can Caffeine Cause You to Fail DUI Test?

Announcing the 2022 Best Lawyers® in the United States

by Best Lawyers

The results include an elite field of top lawyers listed in the 28th Edition of The Best Lawyers in America® and in the 2nd Edition of Best Lawyers: Ones to Watch in America for 2022.

2022 Best Lawyers Listings for United States

Announcing The Best Lawyers in Australia™ 2023

by Best Lawyers

The results include an elite field of top lawyers and firms from Australia.

The Best Lawyers in Australia™ 2023

Announcing The Best Lawyers in Germany™ 2023

by Best Lawyers

The results include an elite field of top lawyers and firms from Germany.

Black, red and yellow stripes