BankThink

Your bank's cyber insurance policies are a minefield of uncertainty

  • Key insight: The policies most community banks rely on for cyber liability, fidelity bonds and directors and officers insurance are full of overlapping exclusions, restrictive coverage sublimits and vague specifications.
  • Supporting data: In a case decided in Minnesota in 2022, the insurer only paid the $100,000 social engineering sublimit on a $600,000 loss and denied access to the larger computer fraud limit.
  • Forward look: Banks should know what their insurance covers well before a claim gets denied.

Community banks typically hold three insurance policies that come into play after a cyber incident: a cyber liability policy; a fidelity bond; and a directors and officers, or D&O, policy. A data breach triggers the cyber policy, and, if a regulatory investigation or a class action follows, the D&O policy. A wire transfer fraud is typically passed to the fidelity bond, with minimal coverage on the cyber policy.

Processing Content

These three policies are full of contradictions. The carriers know it.

I spent 20 years on the carrier and managing general agent side of insurance. I know how policies are structured to reduce a carrier's exposure to the highest risks through sublimits and exclusions. These caps are not obvious to a community bank buying a program, and only show up when a claim gets denied.

Let's look at this scenario: A bank employee gets tricked into wiring funds to a fraudster. How much does the insurance pay? That comes down to the forensic investigation and the cause of loss.

Let's say, the fraudster hacked into the bank's email system and manipulated a wire instruction. That would be covered by the bond's computer fraud coverage, up to the full limit of $5 million in one program I recently reviewed.

But what if the fraudster didn't hack the email system? What if he just spoofed an email address to trick the bank's employee into sending the wire? Insurance classifies that as social engineering. The issue is that social engineering endorsements are often sublimited. That sublimit was $250,000 in the program I reviewed.

Depending on the forensic classification, something the bank has no control over, the wire fraud recovery can swing by $4.75 million.

A federal court upheld this outcome. In a case decided in Minnesota in 2022, the insurer only paid the $100,000 social engineering sublimit on a $600,000 loss and denied access to the larger computer fraud limit.

So, the wire fraud happens, and the bank files the claim. Here is where this gets worse.

The cyber carrier calls it a crime loss, and refers to bond. The bond carrier on the other hand will say: "The claim originated from a cyber event, so that's a cyber policy problem."

Both policies contain "other insurance" clauses. The bond says it applies "only as excess over any valid and collectible insurance." The cyber policy has the same language. That means both carriers claim excess, and nobody goes first.

The community bank has two policies, the cyber policy and the fidelity bond, but zero coverage.

In five programs I reviewed earlier this year, every bank had some version of this wire fraud gap. Sometimes, carriers were pointing fingers. Sometimes, an exclusion killed the claim before it got to that point.

The cyber liability policy covers the regulatory defense for the entity. The D&O policy is supposed to cover claims against individual directors. But all five policies I reviewed exclude claims "arising from" any cyber event. What does that mean? Courts have read "arising from" very broadly.

Read more:

Now imagine the following scenario: After a data breach, the regulator starts an investigation into the board oversight of the bank's cyber governance.

How does the insurance respond? The cyber liability policy says: "That's a governance issue," and points to the D&O. The D&O policy says: "That's a cyber issue."

No carrier pays. And the bank's directors face personal liability.

The New York Department of Financial Services cybersecurity regulation already makes senior leadership personally sign off on compliance. Other states are likely to follow. At the same time, insurance coverage is narrowing.

Cyber, bond and D&O underwriters work in silos, and don't often talk to each other. Each team manages their own loss ratio. The contradictions among these policies are the bank's problem.

Many community banks buy insurance programs, where carriers package three policies together. This makes administration easier. But don't confuse packaging with coordination. When you open the program, you still see separate forms and separate exclusions.

Brokers typically review each policy at renewal against its own benchmarks. I don't know any broker who maps out how the full program responds to a scenario of likely incidents.

Regulators keep raising the bar on board cyber oversight. The insurance that's supposed to protect board members? Going in the opposite direction.

Talk to your broker and ask him to map out all three policies against likely cyber incidents, including wire fraud, ransomware, vendor outage, data breach, and regulatory investigation.
At your next renewal, push your broker on three things:

First, what is your social engineering sublimit? Does it match your transaction size?

Second, which policy pays first on a wire fraud claim? The cyber policy, or the bond?

Finally, can you add an endorsement to remove, or at least narrow the cyber exclusion on your D&O policy?

Every one of these is available in the market. Most banks just never bring them up. But no bank should find out what their insurance actually covers after a claim gets denied.

The carriers won't fix this. Their incentives run in the wrong direction. Banks need to start asking the right questions to make these contradictions visible.

Any broker who cannot answer these questions is not reviewing your program. They are just renewing it.


For reprint and licensing requests for this article, click here.
Community banking Cyber Security Insurance
MORE FROM AMERICAN BANKER
Load More