Cyber Coverage Pitfalls

Institutional data breaches are, unfortunately, more common (and more costly) than ever. Cybersecurity insurance can help—but is your firm’s policy really as ironclad as you think?

Digital lock shatters into pieces

Robert W. Wilkins

November 2, 2022 04:00 PM

An oft-repeated mantra in business and technology is that it’s not a question of if a data breach will happen, but when. The average cost of a corporate data breach in the United States is nearly $9.5 million, according to an IBM report published in 2022. Without adequate cybersecurity insurance, companies (and law firms) might find themselves facing a double threat: being the victim of a breach and then having to contend with the denial of their cyber insurance claim. This article addresses the risks of failing to implement and follow all of the policies and procedures required by the cyber insurance policy.

Given the exponential growth in breaches and their high costs, insurance providers are raising premiums and increasingly investigating whether the practices, as represented by the insured when it applied for coverage at the outset, were implemented and regularly tested and updated as needed. Failure to do so has resulted, and will continue to result, in denial of coverage.

The Expanding Litigation Threat

The biggest risk of this kind that businesses face is not from individual plaintiffs asserting damages from a data breach—it’s a class action brought on behalf of all those similarly situated. In the past, Article III standing cases have generally held that plaintiffs could not establish the requisite “injury in fact” based on the mere risk of future harm because their personally identifiable information or protected health information was exposed.

For years, class-action data breach cases have foundered on that basis. However, a growing body of case law provides guidance on what constitutes “concrete harm,” and the number of class-action cases finding a concrete injury is on the rise. For a good summary of the law on this critical issue, see TransUnion LLC v. Ramirez (2021) and Hunstein v. Preferred Collection and Management Services, Inc. (2022).

Loss of Insurance Coverage

Recent reports have shown that an insured party’s perception of its security versus reality often differ greatly. One of the biggest reasons for coverage denial concerns misrepresentations in the company’s application and/or the failure to maintain security practices amid the ever-changing threat environment. Most cyber insurance policies provide broad coverage for cyber extortion, data restoration, public relations, computer fraud, business interruption, regulatory compliance and related elements. However, the coverage under a policy depends on the representations the insured made in its application, and its subsequent compliance with them.

A typical application for cybersecurity insurance will contain a privacy and security liability questionnaire, as well as a portion about information security. Key items insurance providers require for such policies, according to an August 2022 FitchRatings report, include the use of multifactor authentication, employee training on phishing and other types of cyberattacks, strength-of-password requirements, regulatory reporting obligations, an assessment of the quality of one’s incident-response plan and penetration testing. In addition, all 50 states have data-breach notification laws, and law firms or clients must comply with the requirements of each state in which they do business.

Companies must regularly monitor, update and test all cybersecurity requirements mandated in their policy.”

The hole in the cyber insurance net stems from the insured’s potential misrepresentations in its application and its failure to adjust to the changes in the methods by which bad actors gain illegal access to data. Recently, one insured business that suffered an enormous data breach was denied coverage and had its policy rescinded. See Travelers Property Casualty Company v. International Control Services, Inc. (2022).

Travelers’ success was based on the fact that International Control Services, in its policy application, stated (and signed a separate attestation) that it required multifactor authentication to gain administrative access to its data. Upon investigation, Travelers determined that ICS misrepresented the scope of its authentication process, resulting in the breach.

A business’s failure to follow the policies and procedures claimed in its application is dire. In fact, most insurance policies have a specific exclusion that precludes coverage for claims arising from the policyholder’s failure to maintain adequate security standards. Companies must regularly monitor, update and test all cybersecurity requirements mandated in their policy. The same is true for policies regarding cyber extortion and ransomware attacks.

It’s not just insurance companies that require businesses to have solid procedures and policies to prevent and contain data breaches. Banks, corporate clients and a multitude of others require similar assurances from law firms they deal with that the firms have, comply with and regularly test, update and monitor a written information-security policy and incident-response plan.


The increase in data breaches, the costs resulting from them (which can include potential criminal and regulatory liability), the representations required by clients and insurance companies and the need to meet constantly changing threats in this data-driven age demand that law firms and their clients implement and closely monitor cybersecurity policies and practices. To that end:

  • Read your cybersecurity insurance policy application and representations to confirm each representation is accurate.
  • Update your policies and practices to stay on top of changes and innovations in data security.
  • Train and test your employees in data security practices and potential breaches, especially phishing schemes.
  • Keep an open line of communication with your insurance provider and follow its recommendations regarding cybersecurity.
  • Consider having an outside vendor run penetration tests of your data security systems.

The bottom line: Breaches may be inevitable, but diligence and preparation can mitigate both their financial and reputational impact.

Robert W. Wilkins, a Jones Foster shareholder, and the Litigation & Dispute Resolution Practice Group Chair, is double Board Certified by The Florida Bar in the areas of Business Litigation and Civil Trial. He is Co-Chair of the E-Discovery Subcommittee and the Data Security Subcommittee of the ABA Litigation Sections’ Commercial and Business Litigation Committee. He is also an active member of The Sedona Conference Working Group 1, Electronic Document Retention and Production and Working Group 11, Data Security and Privacy Liability.

Headline Image: istock/TU IS

Related Articles

New York City To Clarify Employer Artificial Intelligence Laws

by Gregory Sirico

Best Lawyer weighs in on New York City's current legislative battle to clarify the extent of artificial intelligence laws in an employment setting.

AI worker stands in front of line of people


Embedded Advantage: The Value in Partnering with Appellate Counsel

by Justin Smulison

Most litigants should expect the non-prevailing party in their case to challenge the trial court’s final judgment in post-judgment motions and/or on appeal. Robert A. Mandel discusses how aligning with a seasoned appellate lawyer can make all the difference in securing a favorable resolution.

Headshot of male lawyer with brown hair in dark suit

A New Spin on Continuing Legal Education

by Sara Collin

Attorney Humira Noorestani is launching a program for continuing legal education, one that she’s dubbed the “Netflix of CLE,” allowing lawyers in the U.S. to explore legal knowledge from prominent lawyers around the world.

Hands emerging from computer and cellphone screens

South Florida’s Legal Renaissance

by Gregory Sirico

What was once only thought of as a destination for vacation may now be the top legal market in the country, attracting talent from around the world.

Blue and orange block sections with gavels and busts

Thirteen Years of Excellence

by Best Lawyers

For the 13th consecutive year, “Best Law Firms” has awarded the most elite and talented law firms across the country through a thorough and trusted data review process.

Red, white and blue pipes and writing on black background

To Serve and To Lead

by J. Henry Walker IV

Effective teamwork is more important than ever in the modern law firm, and it’s the almost oxymoronically named “servant leaders” who make it happen. Here’s a primer.

Three people leaving a conference room

Strength in Numbers: When Partnering Up May Be Best in Whistleblower Litigation

by Justin Smulison

Whistleblower claims make headlines when they result in multimillion-dollar settlements. But the journey to the courtroom is characterized by complexity and requires time and resources. Bienert Katzman Littrell Williams partner and The Best Lawyers in America awardee Michael R. Williams discusses when and why partnerships between counsel will strengthen whistleblower litigation.

A Blue Person in the Middle of White People

California Appeals Court Reverses Workplace Arbitration Decision

by Greg Sirico

Labor Code 432.6, a newly proposed set of legislation in California, was recently met with a successful ruling, but state officials are now reversing that decision.

Two people signing documents

Florida Amends Statewide Cybersecurity and Ransomware Act

by Gregory Sirico

A closer look at a Florida act's amendments to strengthen cybersecurity and ransomware requirements across the state.

Blue human figure holding computer with abstract background

New Non-Compete Restrictions To Take Effect in D.C.

by Gregory Sirico

Best Lawyers investigates the Non-Compete Clarification Act of 2022 passed in the District of Columbia.

Woman in black dress pushing a glowing puzzle piece

ESG and Stakeholder Capitalism as Tools for Energy Transition

by Javier Cremades

The recent rise of “stakeholder capitalism” shows the way forward to solving today’s energy crisis and working toward a carbon-free future. Are companies and governments up to the challenge?

Trees fill two silhouettes shaking hands

Navigating Rough Waters

by Roberto Ovalle and Sergio Díez

Chile has a solid foundation to welcome and protect foreign investment even in turbulent times. Its strong network of international treaties helps provide stability beyond the political contingency.

Boat weathers rough waters in bottle

Caveat Sanctions and Export Controls

by Carsten Bormann and Stephan Müller

Increasingly strict global sanctions and export-control regulations add a new layer of potential peril to M&A deals. A guide to expanding due diligence to ensure that malfeasance, whether intentional or accidental, doesn’t end up scuttling the agreement.

School of fish attack shark

The Write Stuff

by Michele M. Jochner

A series of pointers for making your legal writing clear, concise and—crucially—persuasive.

Closed laptop with woman holding pencil

Punishment and Deterrents

by David A. Yeagley

Facing a jury instruction on punitive damages? Here’s a cheat sheet to help you secure the best possible outcome for the defendant you represent.

Seated man wearing glasses and looking down

Freedom to Compete

by Alyson M. St. Pierre and Ashley C. Pack

Recent movement at the federal level regarding management-labor relations mean changes to enforcement of noncompete agreements and other covenants could be imminent.

Woman in front of open blue door

Trending Articles

The Best Lawyers in Spain™ 2023

by Best Lawyers

Announcing Spain's recognized lawyers for 2023.

Flag of Spain

Announcing the 2023 The Best Lawyers in America Honorees

by Best Lawyers

Only the top 5.3% of all practicing lawyers in the U.S. were selected by their peers for inclusion in the 29th edition of The Best Lawyers in America®.

Gold strings and dots connecting to form US map

The Best Lawyers in Chile™ 2023

by Best Lawyers

The results include an elite field of top lawyers and firms in Chile.

White star in blue box beside white box with red box on bottom

The Best Lawyers in South Africa™ 2023

by Best Lawyers

Best Lawyers proudly announces lawyers recognized in South Africa for 2023.

South African flag

The 2023 Best Lawyers in Portugal™

by Best Lawyers

Announcing the elite group of lawyers recognized in Portugal for 2023.

Green and red Portuguese flag

Announcing The Best Lawyers in Peru™ 2023

by Best Lawyers

Honoring our awarded lawyers for 2023 in Peru.

Red and white stripes with green leaf symbol

The Best Lawyers in Spain™ 2022

by Best Lawyers

The results include an elite field of top lawyers and firms.

The Best Lawyers in Spain™ 2022

Best Lawyers: Ones to Watch in America for 2023

by Best Lawyers

The third edition of Best Lawyers: Ones to Watch in America™ highlights the legal talent of lawyers who have been in practice less than 10 years.

Three arrows made of lines and dots on blue background

Thirteen Years of Excellence

by Best Lawyers

For the 13th consecutive year, “Best Law Firms” has awarded the most elite and talented law firms across the country through a thorough and trusted data review process.

Red, white and blue pipes and writing on black background

Famous Songs Unprotected by Copyright Could Mean Royalties for Some

by Michael B. Fein

A guide to navigating copyright claims on famous songs.

Can I Sing "Happy Birthday" in Public?


Rewriting 𝙃𝙀𝙍𝙨𝙩𝙤𝙧𝙮 One Verdict at a Time

by Justin Smulison

Athea Trial Lawyers was formed only a year ago by several prestigious lawyers seeking justice for their clients, and together they are making history.

Six female lawyers sitting in office

Announcing the 2022 Best Lawyers® in the United States

by Best Lawyers

The results include an elite field of top lawyers listed in the 28th Edition of The Best Lawyers in America® and in the 2nd Edition of Best Lawyers: Ones to Watch in America for 2022.

2022 Best Lawyers Listings for United States

What the Courts Say About Recording in the Classroom

by Christina Henagen Peer and Peter Zawadski

Students and parents are increasingly asking to use audio devices to record what's being said in the classroom. But is it legal? A recent ruling offer gives the answer to a question confusing parents and administrators alike.

Is It Legal for Students to Record Teachers?

Announcing the 2023 The Best Lawyers in Canada Honorees

by Best Lawyers

The Best Lawyers in Canada™ is entering its 17th edition for 2023. We highlight the elite lawyers awarded this year.

Red map of Canada with white lines and dots

Announcing the 2022 "Best Law Firms" Rankings

by Best Lawyers

The 2022 “Best Law Firms” publication includes all “Law Firm of the Year” recipients, national and metro Tier 1 ranked firms and editorial from thought leaders in the legal industry.

The 2022 Best Law Firms Awards

Announcing the 2022 Best Lawyers in South Africa™

by Best Lawyers

The results include an elite field of top lawyers and firms.

Announcing 2022 Best Lawyers in South Africa