Zurich lawsuit against Sony highlights cyber insurance shortcomings
Zurich Insurance's argument that it isn't responsible for Sony's data breach losses holds a lesson for others
Computerworld - A brewing legal dispute between Sony and one of its insurers over data breach liability claims highlights the challenges that companies can sometimes face in getting insurance providers to cover expenses arising from cybersecurity incidents.
Zurich American Insurance Co. asked the New York State Supreme Court last week to absolve it of any responsibility for defending or indemnifying Sony against claims arising from the recent data breaches at the company.
The data breaches at Sony's PlayStation Network, Sony Entertainment Online and Sony Pictures resulted in account data on close to 100 million individuals becoming exposed and over 12 million credit and debit cards being compromised.
The breaches have so far resulted in at least 55 putative class-action lawsuits being filed against Sony in the U.S and another three lawsuits filed against it in Canada. Sony expects to spend close to $180 million in the next year alone on breach-related costs.
But the company's attempts to get Zurich to defend it against the claims have run into a roadblock.
According to Zurich Insurance, the commercial general liability insurance policy it has with Sony Computer Entertainment America does not cover damages arising from cyber incidents. The policy only covers "bodily injury" and "property damage" caused by occurrences other than the kind of cyberattacks Sony experienced.
The lawsuit is similar to one filed last year by the Colorado Casualty Insurance Co. against the University of Utah in another data breach incident. In its lawsuit, Colorado Casualty, like Zurich, argued that it wasn't responsible for reimbursing the university for $3.3 million in costs related to a 2008 data breach caused by a third-party service provider.
In that case, however, Colorado Casualty offered no reasons for its position, which later resulted in a motion for dismissal by the third-party service provider.
The position that Zurich has taken in its lawsuit is likely to be substantiated by the court, predicted Dana Coates, a cyber liability insurance specialist with United Agencies, an insurance brokerage company based in California.
"Personal and advertising injury liability coverage, as provided by typical General Liability policies, is specifically intended to cover resulting bodily injury and property damage liability," Coates said. Cyber attacks and data breaches are not defined or considered as bodily injury or property damage, he said via email.
Quite often, cyber incidents are specifically excluded by some policies to underscore the carrier's intention to not consider such allegations as being covered, Coates said. Sony needed to have specifically purchased cyber liability coverage for its claims to be considered, Coates said.
Part of the problem is that companies sometimes mistakenly assume that any general insurance coverage they have also offers protection against cyber incidents, said Alan Paller, director of research at the SANS Institute.
Companies, for instance, sometimes assume that the insurance coverage they have in place to compensate them in case financial or business records get destroyed also protects them in the event of a cyber breach. In reality, such business records insurance coverage does not extend to data losses stemming from cyber incidents, though it might have in the past, he said.
Now if a company wants business records coverage that includes protection against data breaches, it needs to buy a separate cyber insurance policy, Paller said.
- Arrests made after international cyber-ring targets StubHub
- International police operation disrupts Shylock banking Trojan
- Spamhaus pushes for arrests of alleged DDoS participants
- Accused Russian point-of-sale hacker arrested, will face U.S. charges
- No-IP regains control of some domains wrested by Microsoft
- Microsoft legal action cramping other hacking campaigns, Kaspersky says
- Microsoft admits technical error in IP takeover, but No-IP still down
- QuickPoll: Why hasn't Windows XP come under attack from hackers?
- Cybercrime losses top $400 billion worldwide
- U.S., foreign agents disrupt Gamover Zeus botnet
- Server-side Caching for the VMware Admin vExpert David Davis weights in on how best-in-class server-side caching solutions can drastically improve storage performance and reduce latency without the addition of...
- Top 5 Reasons for Cloud-Based Disaster Recovery There is no question that every business wants to protect their operations from downtime and loss of data. But many companies don't have...
- 5 Things You Didn't Know About Cloud Backup IT departments are embracing cloud backup, but there's a lot you need to know before choosing a service provider. Learn all the critical...
- Case Study: Extending DR Protection for Apps W/O Fixed Costs/Fees Find out how the city of Asheville, NC won the Global City on a Cloud Grand Prize from Amazon AWS for Best Practices...
- Introducing Cloud-Based Disaster Recovery From VMware Cost-effectively protect your business applications in the case of a local disaster or disruptive event. VMware is excited to introduce vCloud Hybrid Service...
- Why Purpose-Built Backup Appliances? Seeking cost-effective data protection solutions that can handle the ever-growing expansion of data, organizations are frequently turning to purpose-built backup appliances (PBBAs). All Disaster Recovery White Papers | Webcasts