Privacy Breach Coverage
Commercial Lines
Privacy Breach Coverage Commercial Lines 2 Agenda Evolving Need - - PowerPoint PPT Presentation
Privacy Breach Coverage Commercial Lines 2 Agenda Evolving Need for Insurance Enhanced Privacy Breach Endorsements New Privacy Breach Liability Coverage Ease of Underwriting Value Added Services Whats Next?
Commercial Lines
2
3
Privacy Breach
4
to protect it
2017 Stats from Breachlevelindex.com by Gemalto
Privacy Breach
5
Decreased revenue
37%
Small businesses
40%
Lost customers
49%
Damage to the brand
43%
Privacy Breach
6
Third party liability coverage
defence expense
Enhanced New Existing first party endorsements
expenses
interruption
7
Privacy Breach
8
Effective August 2018
Cyber Expense Endorsement – Form E127
Existing
Cyber Legal Expense Endorsement – Form E128 Privacy Breach Expense Endorsement – Form E127 Privacy Breach Legal Expense Endorsement – Form E128
Privacy Breach
9
unauthorized access to data that are non-public and personal information as established by Canadian law and that are possessed, managed, entrusted to or held by the Named Insured
Privacy Breach
10
information
medications
Privacy Breach
11
Privacy Breach Expense Endorsement Form E127 Privacy Breach Legal Expense Endorsement Form E128 Privacy Breach Expense Coverage
Insuring Agreement A
Business Interruption Coverage
Insuring Agreement B
Coverage Remediation Expenses
Services
(includes computer forensic service expenses)
defence expense that are made necessary by a civil proceeding in regard to a covered privacy breach Value Added Services Access to CyberScout services without being subject to conditions, exclusions,
Privacy Breach
12
Business Interruption
Waiting period reduced from 48 hours to 24 hours
✓ Faster relief for the customer
Indemnity period increased from 30 days to 60 days
✓ Longer relief for the customer
Privacy Breach Expense Endorsement
Privacy Breach
13
The breach is proven:
hour versus 48th hour
income
up to 60 days versus 30 days
covered for an additional 20 days
Claim: Computer systems were hacked and they could not access computers or operate POS machines. Business was shut down for three days to prevent any damage to customer records while forensic work was done. It took 50 days to return to prior level of income.
Retail Company
Privacy Breach
14
Privacy Breach Expense Endorsement
Worldwide coverage up to 60 days
If a privacy breach arises from business activities outside Canada
✓ More employees travel worldwide and for longer period ✓ Wider scope and longer indemnity for the customer
Privacy Breach
15
Privacy Breach Expense Endorsement
Privacy breach coverage is extended to smart phones as part
✓ Peace of mind to customer as privacy breach attacks to smart phones are on the rise
Smart phones
Privacy Breach
16
customer for money or something in value in exchange for not carrying out a threat to commit privacy breach
authorization, data that are non-public and personal information or to deny, to impede, to make unavailable or to otherwise disrupt access to such data
Privacy Breach
17
documentation for, computer or computing equipment by a certified individual or
services can also be provided by an IT employee of the customer
Privacy Breach
18
Cyber Extortion
privacy breach, approved in writing by Intact beforehand
directly by cyber extortion
directly by cyber extortion
✓ Mitigates or prevents the cyber extortion ✓ Relieves customer of additional expenses while dealing with extortion
Privacy Breach Expense Endorsement
Payments towards ransom, extortion or blackmail payments are excluded
Exclusion for cloud storage is removed
✓ Benefits customers who are increasingly using cloud services for data storage
“Cloud Storage Market is projected to witness a compound annual growth rate of 29.73% to reach a total market size of US$92.488 billion by 2022, from US$25.171 billion in 2017.”
Research and Markets Report
Cloud Storage
Privacy Breach
19
Privacy Breach Expense Endorsement
Privacy Breach
20
Remediation Expenses includes
Required notification of a privacy breach to a governmental entity with authority to regulate the privacy of non-public and personal information of Canadians
✓ Support customers to comply with mandatory reporting of Breach of Security Safeguards Regulations (BSSR) of PIPEDA and European Union General Data Protection Regulation (GDPR)
Privacy Breach Expense Endorsement
Fines, penalties or assessments of any nature including those related to Payment Card Industry (PCI) Standards are excluded
Privacy Breach
21
Expenses arising from any fact or circumstance known prior to the effective date of coverage Prior Knowledge Third Party Liability Loss, damage, expense or costs arising out of liability to a third party Information Technology Security Privacy breach from failure to diligently deploy updated functional security software Computer Forensic Services
Privacy Breach
22
if agreed in writing by Intact for cyber extortion If breach is proven, covers:
notification to authorities and clients
Claim: Customer experienced a ransonware attack and a ransom
include European guests.
Small Hotel
Privacy Breach
23
Privacy Breach Expense Endorsement Form E127 Privacy Breach Legal Expense Endorsement Form E128 Privacy Breach Expense Coverage Business Interruption Coverage
$25,000 $25,000 $25,000 $50,000 $50,000 $50,000 $75,000 $75,000 $100,000 $100,000
Higher amounts introduced
$150,000 $150,000 $200,000 $200,000 $250,000 $250,000
Privacy Breach
24
Introductory Premium Deductible
Interruption exceeds the 24-hour waiting period
$25,000
Privacy Breach
25
For limits > $25,000, premium is rated based on major class’ relative degree
Common Examples
26
Effective August 2018 New coverage for third party liability
Privacy Breach
27
actions due to a breach of personal information
the first party endorsements
Privacy Breach
28
Privacy Breach Liability Form E161 Privacy Breach Liability
Insuring Agreement A
Legal Fees or Defence Expense – Liability for Privacy Breach
Insuring Agreement B
Coverage Privacy breach compensatory damages that the customer is legally obligated to pay Legal fees or defence expense Value-Added Services Access to CyberScout services without being subject to conditions, exclusions, or coverage
Privacy Breach
29
Claims made Worldwide coverage Employees, Directors & Officers covered as claimants No cloud exclusion No deductible
Privacy Breach Liability Form E161 Per Claim Limit Aggregate limit $50,000 $50,000 $75,000 $75,000 $100,000 $100,000 $250,000 $250,000 / $500,000 $500,000 $500,000 / $1,000,000 $1,000,000 $1,000,000 / $2,000.000 $2,000,000 $2,000,000 ✓ Aggregate limit must equal the 'Per Claim' limit when limit is $100,000 or less ✓ For limits of $250,000 and over, aggregate can be doubled of the 'Per claim' limit.
Privacy Breach
30
Privacy Breach
31
Bodily Injury or Property Damage Information Technology Security Privacy breach from failure to diligently deploy updated functional security software Any claim, privacy breach compensatory damages, or legal fees or defence expense, arising directly or indirectly from bodily injury or property damage Mechanical Breakdown and Service Interruption Interruption of internet or electrical service
Privacy Breach
32
Retail Company
Claim: POS machine was hacked and ransom of $4,000 bitcoin was
and they became victims of identity theft. Clients sued the retail company.
customer becomes legally obligated to pay
Privacy Breach
33
Claim: Patient records were
charges to their credit cards and two of them became victims of identity theft. They seek compensation for costs and losses.
Dental Clinic
customer become legally obligated to pay
Privacy Breach
34
Claim: Spreadsheet containing confidential personal information
mistakenly sent out to public. Several of the employees brought legal actions against the customer.
Construction Company
customer become legally obligated to pay due to affected employees
Privacy Breach
35
Claim: Laptop case is stolen. Smart phone with confidential client information was also in the
the real estate agency, submitting proof that the stolen details were used for fraudulent activities.
Real Estate Agency
customer becomes legally obligated to pay to the clients that suffered loss due to breach
Privacy Breach
36
Premium is rated based on major class’ relative degree of privacy breach exposure Common Examples
Privacy Breach
37
Low exposure: Building construction company
Base scenario Scenario 1 Scenario 2 Remediation expenses $25,000 $50,000 $100,000 Business interruption $25,000 $50,000 $100,000 Legal expense $25,000 $50,000 $50,000 Annual premium (Form E127/E128) $120 $165 $271 Privacy Breach Liability Coverage $50,000 $75,000 $100,000 Annual premium (Form E161) $77 $115 $146 Total annual premium $197 $280 $417
Privacy Breach
38
Medium exposure: Wholesaler
Base scenario Scenario 1 Scenario 2 Remediation expenses $25,000 $50,000 $100,000 Business interruption $25,000 $50,000 $100,000 Legal expense $25,000 $50,000 $50,000 Annual premium (Form E127/E128) $120 $239 $394 Privacy Breach Liability Coverage $50,000 $75,000 $100,000 Annual premium (Form E161) $100 $150 $190 Total annual premium $220 $389 $584
Privacy Breach
39
High exposure: Dental clinics
Base scenario Scenario 1 Scenario 2 Remediation expenses $25,000 $50,000 $100,000 Business interruption $25,000 $50,000 $100,000 Legal expense $25,000 $50,000 $50,000 Annual premium (Form E127/E128) $120 $359 $584 Privacy Breach Liability Coverage $50,000 $75,000 $100,000 Annual premium (Form E161) $150 $225 $285 Total annual premium $270 $584 $877
40
$100,000 Privacy Breach Liability coverage
Privacy Breach
41
Privacy Breach Legal Expense Endorsement Privacy Breach Expense Endorsement $100,000 $50,000 Amounts/Limits Coverage
✓ Ideal for small to medium sized business customers ✓ No restrictions by class ✓ No application is required
Privacy Breach
42
Privacy Breach Legal Expense Endorsement Privacy Breach Liability coverage Privacy Breach Expense Endorsement ✓ Not separable ✓ Must have property coverage ✓ No need for base CGL
✓ Recommended first party and third party coverage as a complete solution ✓ Add to entire portfolio (up to $100K) or individual customer
Amounts/Limits Coverage
$250,000 $500,000 $1,000,000 $2,000,000 Privacy Breach Liability coverage
Privacy Breach Expense Endorsement $150,000 $200,000 $250,000 Amounts/limits Coverage
✓ No change in the wordings ✓ Application is required ✓ Portfolio addition is not available
Privacy Breach
43
44
.
To guard against a data loss incident with proactive measures that mitigate risk
To defend against a breach with guidance from breach response team
Privacy Breach
45
Privacy Breach
46
✓ Crisis management ✓ Breach notification writing ✓ Documentation during remediation process ✓ Industry best practices for handling a breach
Privacy Breach
47
Global Username: Intactinsurance1 Global Password: Intactinsurance1
Privacy Breach
48
Call 24/7 Intact Insurance claims service
Intact claims collaborate with CyberScout™ experts for an effective privacy breach response
Privacy Breach
49
1.Educate to raise awareness of this growing threat 2.Explain how breaches occur 3.Help them assess their vulnerabilities 4.Focus on the extra services included as part of their coverage 5.Walk them through our coverage 6.Put the value in perspective
50
Underwriters
Business Development Consultants
Meetings Reference materials
Sheets
Privacy Breach
51
Technology.SS@intact.net
52