Showing 1 - 10 of 0 results
Page 1 of 1 | Results 1 - 10 of 0
Podcast

Coverage Before the Crisis: Claims, Retro Dates and the Quantum Threat

By Alliant Specialty Claims & Legal

From complex coverage disputes to the emerging threat of quantum computing, today’s risks demand careful policy analysis and forward-looking preparation.

In this episode, Peter Kelly and David Finz, Alliant Specialty Claims & Legal, examine two court decisions involving the definition of a claim and retroactive date exclusions under E&O and D&O policies. They also explore how quantum computing could transform cyber risk, influence future underwriting criteria and expose sensitive data that organizations believe is protected today.

Tune in for insights on policy wording, claims strategy and the steps organizations can take now to prepare for evolving cyber threats.

Welcome (00:00):

Welcome to the Alliant Specialty Podcast, your source for insights on emerging risks, market trends, and specialty insurance solutions.

Peter Kelly (00:09):

Hi everybody. It's Peter Kelly. Thanks for joining us for today's episode of Alliant Specialties Claims and Legal Podcast, where we highlight important legal developments in the financial alliant insurance world. I'm joined by our resident cyber expert and attorney, David Finz. I'm going to be going through a couple cases that we will be reporting on in Alliant Executive Liability Insights monthly newsletter, concerning the definition of claim and retroactive date exclusions. And then David is going to talk to us about the White House's recent executive order on quantum computing. So the first case that I'll be sharing concerns a civil investigative demand or CID and an E&O policy's definition of claim. Here, a technology company sought coverage for costs it had incurred after federal and regulator investigated its privacy and security practices, which had then spawned several related consumer lawsuits. The initial CID stated that its purpose was to determine whether the company engaged in any wrongdoing and requested answers to interrogatories and documents related to potential violations.

Peter Kelly (01:27):

The company, after seeking coverage, settled its coverage dispute with its primary carrier and all excess carriers but one. The holdout excess carrier challenged whether the CID constituted a claim under the followed policy. That followed policy defined claim in part as demand for non-monetary relief or a regulatory proceeding and defined regulatory proceeding in turn as a civil investigation by a regulatory authority based on an alleged or potential violation of privacy or cyber laws as a result of a cyber incident. Now, the excess carrier holdout argued that the CID was not a demand for non-monetary relief because it only sought documents and responses to interrogatories. And it was also not a regulatory proceeding because it did not allege a violation of a cyber or privacy law. Rather, it was just seeking information regarding whether a violation had actually occurred. And while the court agreed, stating, agreed with the excess carrier stating that, non-monetary relief cannot be construed to include mere demands for information or documents sought by a civil investigation, and also that the definition of claim was not broad enough to include demands for information absent any allegation of wrongdoing.

Peter Kelly (02:54):

So although the insured was able to negotiate for coverage with its primary and a majority of its excess layers, this loan holdout was able to successfully avoid covering the matter. The next case, I'm going be highlighting concerns D&O policy and its retroactive date exclusion. In this matter, an EV, an electric vehicle manufacturer, and certain directors and officers were investigated by the SEC for misrepresenting vehicle orders, the number of vehicle orders they had received, which then later spawned litigation. The insured's Zeno carrier denied coverage, arguing that the claims were all related to conduct that occurred prior to the inception date of the policy and thus fell within the policy's retroactive date exclusion. The exclusion barred coverage for any claim that arose out of a wrongful act occurring before the policy's effective date or conduct wrongful acts that occurred during the policy period that were related to or shared a common nexus with wrongful dates occurring prior.

Peter Kelly (04:00):

Here the court disagreed. They found that not all the allegations in the underlying complaints related back to the misrepresentations that sparked the SEC investigation. The additional allegations in the litigation included insider trading, concealment of testing failures, corporate mismanagement and unjust enrichment. These stemmed from wrongful acts occurring after the retro date and the carrier failed to demonstrate that they were related to the prior conduct that had occurred prior to that effective date. Court emphasized here that the applicability of a retro date exclusion had to be analyzed on a claim by claim basis. So you know, the carrier couldn't just lump them all together without really establishing more of a, that common nexus, that connection. So while some of the allegations were for wrongful acts submitted prior to the policy's retroactive date and therefore subject to the exclusion, since at least some of the claims potentially arose from conduct outside the exclusion, court held the insured remained entitled to advancement of defense costs.

Peter Kelly (05:06):

Now I'm going turn it over to my colleague, Mr. David Finz.

David Finz (05:10):

Thanks, Peter. So today I'm going to be speaking about a White House executive order dealing with the issue of quantum computing. The White House actually issued a pair of executive orders on this topic, but there's one particular one that I would like to focus on today, and specifically one provision within that executive order. It states that within 180 days, the Federal Acquisition Regulatory Council, in consultation with the Secretary of Homeland Security and through the Director of the National Institute of Standards and Technology, or NIST, shall publish a proposed rule amending the federal acquisition regulation to require covered contractors to comply by December 31st of 2030 with the Federal Information Protection Standard, and to incorporate that into post-quantum cryptography compliant algorithms. Now, let me pause here for a second and explain to folks what this means. Okay? We all know that quantum computing is on the verge of becoming a reality over the next few years.

David Finz (06:18):

Quantum computing allows technology to advance to a point that computers are going to be able to work at a speed and process information at a level that even today's supercomputers are incapable of doing. There are going to be alot of great use cases for that in industry, but unfortunately, that technology is also going to be available to hackers, certainly first at the nation state level, and then potentially even in the hands of private threat actors. And so this concept of post-quantum cryptography or PQC is the idea of encrypting data to a point that even quantum computing will not be able to crack it. Now, a lot of this is a ways off. We're talking a few years down the road, but we need to start thinking about this threat today. So again, that's the first step in terms of getting these regulations out and then within 270 days, the FAR Council is going to work with the Secretary of Homeland Security, the Director of the Cybersecurity and Infrastructure Security Agency, or CISA, the Director of NIST, and they're going to publish a proposed rule requiring contract clauses for contractor vulnerability disclosure programs to ensure that covered contractors with the federal government implement vulnerability disclosure policies that are consistent with NIST guidelines and that they incorporate reports of cryptographic vulnerabilities, including test for lack of encryption and the use of non-approved algorithms.

David Finz (08:01):

Now, what does all this mean? Quite simply, the federal government is recognizing that quantum computing poses an imminent threat to the security of data that federal agencies and federal contractors may be in possession of. So if you are a government contractor working with the federal government right now, you have a contract with federal agencies, there's no time like the present to begin to get ready for the threat that is being posed by the advent of quantum computing and to get those cryptographic standards that we anticipate are going to be able to thwart those threats. Now, there's two reasons you might care about this. Obviously, if you're a federal contractor, you're going to need to be in compliance with these regulations in order to continue to do business with the federal government. But if you're elsewhere in the private sector, particularly if you work in critical infrastructure, even though this is not binding upon you, these standards that have been promulgated by NIST are considered best practices.

David Finz (09:03):

Over time, all businesses are going to be expected to be able to withstand the threat posed by quantum computing. So these best practices we can expect will also be incorporated into underwriting criteria around your cyber insurance program. So if you have records that you are either legally required to retain for a period of years, or it's just your own record retention policy as a company to do so, you need to recognize that hackers may take that data now. And when the technology allows for it, use quantum computing to decrypt that data, or at least try to decrypt that data later. Your current encryption methods may not be sufficient to be able to protect that data at some point a few years down the road when quantum computing will allow the threat actor to crack the code, so to speak. So as the technology develops, you need to begin to migrate over to this new standard of PQC, post-quantum cryptography, as soon as you are able to do so.

David Finz (10:11):

Now, admittedly, some of the data that could get compromised now might get stale a few years out. You know, credit card numbers change, that sort of thing. But biometric information, patient health information, some of that has no expiration date on it, and it's highly sensitive. So because of that, organizations, particularly around healthcare, need to understand that the data they have now, which is not based on PQC standards, could at some point, even if it's taken now and it's encrypted, get decrypted at a later date. The federal government is trying to get out in front of this as much as it is able to do so and instruct those businesses that are government contractors, or those businesses that are in critical infrastructure, that they need to get on board with this and begin to invest in PQC. For those of you who are interested in learning more about this executive order, it is publicly available on the whitehouse.gov website, but this is an area that we're going to continue to keep an eye on because we expect as these best practices get rolled out and as federal regulations continue to direct or guide government contractors into integrating this into their own information security, we're going to expect the cyber insurance underwriters to begin asking questions about it as well.

David Finz (11:35):

And with that, I'll turn it back over to you, Peter.

Peter Kelly (11:37):

Thank you, David. And glad to hear that we'll be continue to monitor all this for its impact. So thanks to our listeners for tuning in today. If you'd like more information on some of these recent developments, please reach out and definitely subscribe to our Executive Liability Insights monthly newsletter and be sure to check out Alliant.com to learn about a more rewarding way to manage risk.

This document is provided for general informational purposes only and does not constitute legal, tax, accounting, insurance, brokerage, risk management, or other professional advice. You should consult your own legal counsel or other qualified professional advisors regarding your specific circumstances, and receipt of this document does not create any client, advisory, fiduciary, brokerage, or other professional relationship with Alliant Insurance Services, Inc. This document is provided “as is” without warranty of any kind, and Alliant Insurance Services, Inc. disclaims any liability for any loss or damage arising out of or relating to reliance on this document.