Insurance & Protection

Cyber Risk Exposure in General Liability Policies

The landscape of digital risk is constantly evolving, and businesses must be aware of the potential gaps in their general liability (GL) policies. For years, many companies have assumed that their GL policies would provide a safety net for the physical consequences of a cyber event. However, this assumption is no longer valid, as the insurance market has been shifting to eliminate ‘silent cyber’ coverage.

Understanding the Shift in Cyber Risk Coverage

The standard approach in the past was to exclude liability for most data breaches from GL policies. However, insurers often ‘carved back’ coverage for resulting bodily injury. This meant that if a cyber-related failure led to physical harm, for instance, a hacked industrial control system causing an injury, the GL policy could still respond. This provided a limited, but necessary, scope of coverage.

However, the majority of carriers have now adopted exclusionary Cyber Incident wording, such as the Insurance Services Office (ISO) form CG 40 35 12 23. This endorsement fundamentally alters standard GL policies by shifting the focus from the type of information lost to the cause of the loss itself. Using a wide-ranging definition of a ‘Cyber Incident’ including unauthorized access, viruses, or denial-of-service attacks, this form seeks to exclude all resulting Bodily Injury, Property Damage, and Personal and Advertising Injury.

🌿You might also enjoy reading this article.  Trucordia's California Expansion: A Deep Dive into Insurance Acquisition Strategy

The Impact of the Cyber Incident Exclusion

The underwriting intent is no longer just to manage data risk, but to isolate and remove cyber-related losses from the GL policy entirely, establishing a clear boundary that potentially leaves businesses with a gap in cover. This means that companies must proactively assess their operations for contingent physical damage scenarios and conduct a thorough review of their GL, Property, and Cyber policies.

If this review highlights meaningful coverage gaps, partnering with a broker is a proven strategy for securing tailored underwriting solutions. Businesses must be aware of the potential risks and take steps to mitigate them, rather than relying solely on their GL policy. The shift in cyber risk coverage is a wake-up call for companies to re-evaluate their risk management strategies and ensure they have adequate coverage in place.

The Future of Cyber Risk: Generative AI and Emerging Exposures

In much the same way that carriers introduced exclusionary language to define the boundaries around cyber incidents, underwriters are now adopting a similar framework to address a distinct, rapidly emerging exposure: Generative AI. To clarify that standard GL policies are not intended to cover these novel liabilities, ISO has introduced new terminology and exclusions.

As the use of Generative AI becomes more widespread, businesses must be aware of the potential risks and take steps to mitigate them. This includes assessing their operations for potential AI-related risks and ensuring they have adequate coverage in place. The future of cyber risk is uncertain, but one thing is clear: businesses must be proactive in managing their risk and ensuring they have the necessary coverage to protect themselves.

🌿You might also enjoy reading this article.  Connecticut Confronts Exploding Nonprofit Liability Insurance Costs?

What Should You Do About Cyber Risk Exposure?

Given the shift in cyber risk coverage, businesses must take immediate action to assess their risk and ensure they have adequate coverage in place. This includes reviewing their GL, Property, and Cyber policies, as well as assessing their operations for contingent physical damage scenarios. Partnering with a broker is a proven strategy for securing tailored underwriting solutions and ensuring that businesses have the necessary coverage to protect themselves.

Companies must also be aware of the emerging risks associated with Generative AI and take steps to mitigate them. This includes assessing their operations for potential AI-related risks and ensuring they have adequate coverage in place. By being proactive and taking a comprehensive approach to risk management, businesses can protect themselves from the evolving landscape of digital risk.

As the digital risk landscape continues to evolve, businesses must be vigilant in managing their risk and ensuring they have adequate coverage in place. The shift in cyber risk coverage is a wake-up call for companies to re-evaluate their risk management strategies and take proactive steps to protect themselves.

What does this mean for businesses? It means that they must be proactive in managing their risk and ensuring they have the necessary coverage to protect themselves. It means that they must be aware of the emerging risks associated with Generative AI and take steps to mitigate them. And it means that they must work with their brokers and insurers to ensure they have tailored underwriting solutions that meet their specific needs.

Can businesses afford to wait and see how the landscape of digital risk evolves? The answer is no. The shift in cyber risk coverage is a clear indication that businesses must take immediate action to protect themselves. By being proactive and taking a comprehensive approach to risk management, businesses can ensure they have the necessary coverage to protect themselves from the evolving landscape of digital risk.

🌿You might also enjoy reading this article.  Texas Chemical Spill Exposes Systemic Worker Safety Violations

Final Thoughts on Cyber Risk Exposure

Taken together, these developments show, the shift in cyber risk coverage is a wake-up call for businesses to re-evaluate their risk management strategies and ensure they have adequate coverage in place. The emerging risks associated with Generative AI are a clear indication that businesses must be proactive in managing their risk and taking steps to mitigate them. By working with their brokers and insurers, businesses can ensure they have tailored underwriting solutions that meet their specific needs and protect them from the evolving landscape of digital risk.

Cyber Risk Exposure – Disclaimer

This article is for informational purposes only and does not constitute professional advice. Businesses should consult with a qualified insurance professional to determine their specific cyber risk exposure and ensure they have adequate coverage in place. Outcomes may vary depending on individual circumstances.

Frequently Asked Questions

What is cyber risk exposure?

Cyber risk exposure refers to the potential risks and losses associated with cyber-related events, such as data breaches and cyber attacks.

How has the shift in cyber risk coverage affected businesses?

The shift in cyber risk coverage has left many businesses vulnerable, as their general liability policies may no longer provide adequate coverage for cyber-related events.

What can businesses do to protect themselves from cyber risk exposure?

Businesses can protect themselves by reviewing their GL, Property, and Cyber policies, assessing their operations for contingent physical damage scenarios, and partnering with a broker to secure tailored underwriting solutions.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button