Assignment

profileBfh
Assignment4-Instructions_CyberInsurancePolicyReviewWorksheet.docx

Fall 2022 Assignment 4

Cyber Insurance Policy Review

Your Name:

Cyber Insurance Policy Review Instructions

Assignment Overview: For this assignment all students will be using the same materials. The type of organization you have been working with will not have a major bearing on your analysis or responses. The goal of this assignment is to apply the policy review analysis strategies and techniques we have been discussing during lectures. Analyzing cyber insurance policies and understanding how coverage applies to claims takes direct experience and practice reviewing many different types of policies. This assignment is designed to give you some practice examining a full cyber insurance policy in the context of a simulated real-world example.

Assignment Structure

1. Documentation – Each student will be provided the following documents to complete the assignment:

a. Assignment Instructions & Cyber Insurance Policy Review Worksheet (this document)

b. Sample Cyber Insurance Declarations Page – “UBTech CySure Declarations Page”

c. Sample Travelers Cyber Insurance Policy – “Travelers Cyber Risk Policy Form Sample”

2. Grading – This assignment will be graded on a 100 point scale with 50 points per section.

a. The first 10 questions have a right or wrong answer and all answers can be found in the Sample Cyber Insurance Declarations Page. This section is worth a total of 50 points.

b. The second set of 6 questions are a bit more challenging and are based on your interpretation of policy language Insuring Agreements, Definitions and Exclusions. These questions will be graded based on level of effort, accuracy and thought put into your responses. This section is worth a total of 50 points.

Guidance

1. Resources – All questions are based on topics we covered in sessions 7 & 8 and will align with the slides presented during these lectures. I recommend you use the slides from these lectures as guidance as you are completing this assignment.

2. Sample responses – Each section of the Cyber Insurance Policy Review Worksheet will include sample questions and answers. I will indicate where these sample answers can be found in the documentation provided.

3. Questions and Concerns – We will dedicate time during class on October 27th to walking through this assignment and answer any questions. Please bring any questions with you to class on 10/27. You can also contact me via email [email protected] for any other questions or assistance.

4. If time permits, I will do my best to provide feedback on early submissions but you must email me requesting feedback if desired. For this assignment I will not be able to provide detailed feedback prior to submission. Instead, I will highlight answers or areas that need to be reviewed or corrected.

Section 1: Policy Declarations Review

#

Question

Your Response

Reviewer Notes (Leave Blank)

0

SAMPLE: What is the name of the insurer writing this policy?

UBTech CySure

I found this on page 1 of the Declarations where the Insurer is listed. As a note we will use UBTech CySure as the Insurer for this exercise even though we are reviewing Travelers documents.

1

Is the carrier providing this policy Admitted or Non-Admitted?

2

Who is the Named Insured?

3

What is the total cost of this policy?

4

What is the policy aggregate limit?

5

How long is the policy period?

6

Does this policy provide coverage for unknown prior acts that may have occurred prior to the policy inception date?

(Yes or No)

7

Do all coverages share the policy aggregate limit or are any coverages provided outside the policy aggregate limit?

8

How long does an organization have to wait before filing a Business Interruption Claim

9

Is Cyber Extortion coverage provided at full limits or is coverage sublimited? If sublimited, please provide available limit.

10

Are there any coverages listed on the declarations page that are not being offered to this Insured? If so, please list coverage(s) not provided.

Note: Use the document titled “UBTech CySure Declarations Page” to answer questions in this section.

Section 2: Insuring Agreement, Definitions & Exclusion

#

Question

Your Response

Reviewer Notes (Leave Blank)

0

SAMPLE: The Coverage Trigger for the Privacy and Security insuring agreement is a Privacy and Security Act. Does the definition of Privacy and Security act include more than just a Privacy Breach? Based on your interpretation of this definition does this allow the coverage to be triggered by both a Privacy Breach as well as a Security Failure/Breach?

Yes, the definition of Privacy And Security act includes both failure to prevent at Privacy Breach and failure to prevent a Security Breach.

For this response I looked at the definition of “Privacy and Security Act” in the Travelers policy to confirm the definition covers both Privacy Brach and Security Failure.

1

Does the Privacy Breach Notification insuring agreement cover Voluntary Notification costs? If so, please identify the definition in this insuring agreement includes Voluntary Notification costs?

2

The Computer and Legal Expert insuring agreement covers many of the First Party Cyber Event Expenses we have been discussing in lectures. Can this coverage be triggered by failure to prevent a privacy breach as well as a failure to prevent a security breach?

3

Do you think this policy provides coverage for an employee of the Insured organization being tricked into making a fraudulent payment because they are mislead by a cybercriminal? If so, what insuring agreement best covers this type of loss.

4

If an IT Provider the Insured Organization uses to conduct business is taken down by a cyberattack, does this policy cover the lost income during time of disruption? If yes, please identify the insuring agreement that best covers this type of loss.

5

Does the definition of “Computer System” apply to systems that are owned, operated and controlled by the Insured organization as well as any type outsourced cloud or hosted IT services they may use?

6

This policy EXCLUDES losses triggered by War. Based on your review of exclusions do you think some losses related to actual or alleged cyberterrorism events would be considered?

Note: Use the document titled “Travelers Cyber Risk Policy Form Sample” to answer questions in this section.

1

1

1