Document type: Article Practice area: Corporate — Insurance and Risk Jurisdiction: United States Last reviewed: 5 September 2026
Why these two policies
Most corporate insurance is about property and liability that behaves predictably. Two programmes are different, because they respond to events that can end a company or bankrupt an individual, and because the coverage questions they raise are decided by conditions rather than by whether the loss occurred.
Directors and officers liability protects individuals from personal exposure for their conduct in office, and protects the company for its indemnification obligations and for its own securities liability. It is the reason competent people are willing to serve on boards.
Cyber responds to an event category that did not exist when the standard commercial general liability form was written, and that the CGL form has been progressively amended to exclude.
Both are claims-made. Both have notice provisions that forfeit coverage when missed. Both are placed in towers with multiple insurers whose obligations differ in ways nobody examines until a claim. And both are bought by people who read the premium and the limit and not the fifty pages in between.
The three sides of a D&O policy
A modern D&O policy contains three insuring agreements, and understanding what each does is the beginning of everything.
Side A — non-indemnifiable loss. Pays on behalf of individual directors and officers where the company cannot or does not indemnify them. It responds when the company is insolvent, when indemnification is legally prohibited (notably for derivative settlements in most jurisdictions), or when the company refuses. Side A is the coverage that exists for the individual rather than for the company, and there is no retention.
Side B — company reimbursement. Reimburses the company for amounts it has paid to indemnify individuals. Subject to a retention, often substantial. This is where most ordinary claims are paid.
Side C — entity securities coverage. For a public company, covers the company itself for securities claims. For a private company, entity coverage is usually broader.
The critical structural point: Sides B and C protect the company's balance sheet, and they share the same limit as Side A unless the programme is structured otherwise. In a catastrophic event — a securities class action, a derivative suit, and an investigation running together, with the company insolvent — the company's own claims can exhaust the tower before the individuals' non-indemnifiable exposure is reached.
The answer, and it is why sophisticated programmes are built this way, is dedicated Side A coverage: a separate limit, sitting above or alongside the traditional tower, available only for non-indemnifiable loss, and usually written on a broader form with fewer exclusions and a "difference in conditions" feature that drops down if an underlying insurer refuses to pay or becomes insolvent. Directors who ask one question about the company's D&O programme should ask about the dedicated Side A limit.
Claims-made, and the notice problem
A D&O policy responds to claims first made during the policy period (or an extended reporting period) and reported in accordance with the policy's notice provisions. Two distinct requirements, and both are conditions.
What is a claim. Modern definitions are broad: a written demand for monetary or non-monetary relief; a civil, criminal, administrative, or arbitral proceeding; a formal investigation; sometimes a subpoena or a request to toll. The definition matters enormously because it determines when the clock starts. A litigation hold letter, a books and records demand, an SEC subpoena, a shareholder demand letter — each may be a claim.
When notice is due. Typically "as soon as practicable" and in any event within a stated period after the end of the policy period. Some policies require notice within a specified number of days. Late notice is one of the two most common reasons D&O coverage fails.
Notice of circumstances. This is the provision most companies misunderstand and the one that most often saves them. A policy generally permits the insured to notify the insurer, during the policy period, of circumstances that may reasonably be expected to give rise to a claim. If a claim later arises from those circumstances, it relates back to the policy in which notice was given.
The value is obvious at renewal: an event occurs in year one, the claim is filed in year two, and by then the insurer has added an exclusion or the company has changed carriers. A circumstance notice locks the coverage into the year-one policy.
The risk is equally real: a circumstance notice may be treated by the year-two insurer as a known circumstance, excluded from the new policy under a prior-knowledge or prior-notice exclusion. Give too many circumstance notices and the company builds a wall of exclusions around itself.
The judgment required is genuine, and the standard is worth getting right. The formulation many policies use — circumstances that may reasonably be expected to give rise to a claim — is objective, and a company that sits on a serious problem because it hopes nothing will come of it is making a bad bet. The practical rule: notice circumstances that a reasonable person would expect to produce a claim; do not notice every internal complaint. And where the judgment is close, notice, and manage the renewal consequence with the broker.
Related claims. Policies aggregate claims arising from the same or related wrongful acts and treat them as a single claim, first made when the earliest was made. This can be favourable — one retention, one limit — or catastrophic, where a claim in year four relates back to year one and the year-one limit has been eroded. The definition of "related" is heavily litigated and the language varies substantially.
The excess tower
D&O limits are built in layers: a primary policy, then excess layers, each attaching above the one below. Several things go wrong here.
Follow form, and its limits. Excess policies typically follow the terms of the primary, subject to their own provisions. Those provisions frequently differ in ways that matter: different notice requirements, different definitions of claim, different arbitration or choice-of-law clauses, and sometimes different exclusions. A tower assembled from six carriers' forms without a careful comparison is a tower with six different contracts in it.
Exhaustion. Excess policies attach after the underlying limits are exhausted, and the language varies. The traditional formulation requires payment of the full underlying limits by the underlying insurers. If the primary settles for less than its limit and the insured funds the gap, a strictly worded excess policy may take the position that it never attached.
Courts have divided. Some have enforced the exhaustion requirement literally, holding that the insured's own payment does not satisfy a condition requiring payment by the underlying insurer. Others have permitted the insured to fill the gap where the excess insurer suffers no prejudice. Delaware, whose law governs many of these disputes because so many issuers are incorporated there, has taken a functional approach in decisions addressing whether an excess insurer may avoid attachment when the underlying layer settled below its limit — but the outcome remains language-dependent, and the reliable answer is to negotiate the point at placement rather than litigate it later.
The provisions to seek: exhaustion by payment of the underlying limits by the underlying insurers, by the insureds, or on their behalf; and an express statement that a below-limits settlement of an underlying layer does not prejudice the excess insurer provided the excess insurer is notified.
Drop-down. Where an underlying insurer is insolvent or refuses to pay, does the excess drop down? Traditionally no. A dedicated Side A policy with a difference-in-conditions feature is written to do exactly this, and it is one of the principal reasons to buy one.
Consent and cooperation. Each layer typically requires its consent to settlement. In a tower with six carriers, obtaining consent from all of them to a mediated settlement, in a room, on a Friday, is a real logistical problem. Mediation provisions and consent-to-settle language should be reviewed with that scenario in mind.
Allocation
When a claim involves covered and uncovered parties, or covered and uncovered matters, the loss must be allocated. This is the second most common reason D&O coverage disappoints.
The problem. A securities class action names the company and five officers. The company's Side C coverage responds to securities claims; but the complaint also asserts non-securities claims, and the company's own conduct may be uncovered. Defence costs are incurred jointly and cannot be attributed cleanly.
The historical approaches. "Relative exposure" allocates by reference to the potential liability of covered and uncovered parties and claims. "Larger settlement rule" allocates to the insureds only the amount by which the settlement was increased by the presence of uncovered parties — which, where the individuals and the company are sued for the same conduct, is often nothing, so the insurer pays it all.
The modern solution. Most public company D&O policies now contain a pre-agreed allocation for securities claims — commonly 100% of defence costs and settlements allocated to covered loss where the company and insured persons are both defendants. This eliminates the fight entirely and is the single most valuable allocation provision available. Confirm it is in the policy; do not assume.
For non-securities claims, or for private company policies, the allocation provision should at minimum specify a method, provide for an interim allocation pending final determination, and require the insurer to advance defence costs during any allocation dispute.
Conduct exclusions and the final adjudication qualifier
Every D&O policy excludes loss arising from fraud, dishonesty, wilful violation of law, and personal profit to which the insured was not legally entitled. Without these exclusions the policy would insure deliberate wrongdoing, which public policy in most states does not permit.
The critical question is what triggers the exclusion. Three formulations, in descending order of insured-friendliness:
- "Final, non-appealable adjudication in the underlying proceeding" establishing the conduct. This is the standard to insist on. Settlements do not trigger it. Findings in a coverage action do not trigger it. Only a judgment, in the underlying case, after appeals.
- "Final adjudication" without the "non-appealable" qualifier or the "underlying proceeding" limitation, which permits the insurer to establish the conduct in a separate coverage action.
- "In fact" — the conduct occurred, however established. This is the worst formulation and should be resisted absolutely.
Severability. The exclusion should apply only to the insured who committed the conduct, and the knowledge of one insured should not be imputed to others. For the application, the knowledge of the signing officers only should be imputed to the company, and to no individual other than the one who knew.
The related provisions: a non-rescindable Side A; an express statement that the policy will not be rescinded as to any insured who did not know of the misstatement; and severability of the application.
The insured versus insured exclusion
D&O policies exclude claims brought by one insured against another, to prevent the policy from funding intramural disputes and collusive suits. The exclusion is necessary and, in its unmodified form, dangerous.
The carve-outs to require:
- Derivative suits brought by a shareholder without the assistance or participation of an insured person. Without this, the D&O policy does not cover derivative litigation, which is a substantial part of the reason it exists. The carve-out is standard; verify it.
- Bankruptcy — claims brought by a trustee, examiner, receiver, liquidator, creditors' committee, or debtor in possession. This is the carve-out that matters most, because insolvency is precisely when Side A is needed and precisely when the claimant will be an entity standing in the company's shoes. An unmodified insured-versus-insured exclusion can eliminate coverage in the scenario the policy was bought for.
- Former officers and directors who left more than a stated period before the claim.
- Whistleblower claims and employment claims brought by an insured person.
- Claims brought outside the United States by a foreign representative.
- Cross-claims and third-party claims brought in a covered proceeding.
Many policies have replaced the traditional exclusion with an "entity versus insured" exclusion, which is narrower and preferable.
Run-off and the transaction
A change of control terminates most D&O programmes prospectively: the policy continues to cover claims made during the remaining period for pre-transaction wrongful acts, but coverage for post-closing conduct ends.
The instrument that protects the target's former directors and officers is a run-off or tail policy: typically six years, purchased at closing, covering claims first made during the run-off period arising from pre-closing wrongful acts.
Points that matter:
- Six years is the market standard and matches the outer limit of most applicable limitations periods.
- Purchase it at closing. A merger agreement covenant to maintain coverage is not the same as a bound policy, and the obligation to buy the tail should sit with a party that will actually perform it.
- Non-cancellable and fully earned — the run-off cannot be terminated by the acquirer.
- The limit is fixed and finite for six years of claims. Size it accordingly.
- Dedicated Side A within the run-off is worth buying.
- Check the merger agreement's indemnification and insurance covenants against the actual policy purchased. They frequently do not match.
Cyber insurance: what the coverage grants actually do
A cyber policy is a bundle of distinct coverages, and companies routinely buy one without understanding which parts respond to which events. The usual grants:
First-party coverages — for the insured's own loss:
- Incident response. Forensics, legal, notification, credit monitoring, call centre, public relations. Usually the most-used coverage, often subject to a panel of approved vendors, and frequently the coverage that determines how the whole incident is handled because the panel firm arrives first.
- Business interruption. Lost income and extra expense from a network interruption caused by a covered event. Subject to a waiting period — commonly eight to twelve hours — and a period of restoration. The waiting period is a deductible measured in time, and for a short outage it can eliminate the claim entirely.
- Contingent business interruption. The same, for an interruption at a service provider. This is the coverage that responds when a cloud provider or a critical vendor goes down, and it is the one most often either not purchased or purchased with a scope too narrow to reach the provider that actually failed. Check whether it requires the provider to be scheduled by name.
- Data restoration. The cost of recreating or restoring damaged data. Note that it typically covers restoration cost, not the value of data that cannot be restored.
- Cyber extortion. Ransom payments and the cost of response. Subject to consent requirements and to sanctions compliance, which has become a live constraint.
- Funds transfer fraud and social engineering. Discussed below, and the source of more coverage disputes than any other cyber grant.
- Bricking. Replacement of hardware rendered unusable.
- Reputational harm. Lost income following publication of a breach. Narrow and hard to prove.
Third-party coverages — for liability to others:
- Privacy and network security liability. Claims by individuals or businesses arising from a breach or a security failure.
- Regulatory defence and penalties. Investigations by data protection and other regulators, and fines where insurable under applicable law — which varies, and the policy usually says it pays "where insurable."
- PCI assessments. Card brand fines and assessments, which are contractual rather than regulatory and are excluded by some forms.
- Media liability. Defamation, infringement, and similar claims arising from the insured's content.
The two questions to ask of any cyber programme: which of these grants do we have, and at what sublimit? Cyber policies are riddled with sublimits, and a $10 million policy may carry a $250,000 sublimit on social engineering and a $1 million sublimit on regulatory defence. The headline limit is frequently not the operative number.
Social engineering and funds transfer fraud
The most common cyber loss at most companies is not ransomware. It is a payment sent to a criminal because someone believed an email.
The coverage question turns on how the loss occurred and how the policy is worded, and courts have reached different results on similar facts.
American Tooling Center, Inc. v. Travelers Casualty & Surety Co., 895 F.3d 455 (6th Cir. 2018), found coverage under a computer fraud provision where an employee, deceived by spoofed emails, wired funds to a fraudster. The court read "direct" causation to permit the intervening employee action, holding that the fraudulent emails were the direct cause of the loss.
Apache Corp. v. Great American Insurance Co., 662 F. App'x 252 (5th Cir. 2016), reached the opposite result on similar facts, holding that the computer use was too attenuated: the fraudulent email was "merely incidental" to a chain of events in which the employee's independent verification failure was the operative cause.
Universal American Corp. v. National Union Fire Insurance Co., 37 N.E.3d 78 (N.Y. 2015), construed a computer systems fraud rider covering losses from "fraudulent entry of electronic data" as reaching unauthorized access to the system, not authorized users entering false data — narrowing the coverage significantly.
The practical lesson is that generic computer fraud and crime coverages were written for a different problem and produce unpredictable results. The answer is a dedicated social engineering fraud coverage grant, expressly covering loss resulting from an employee being fraudulently induced to transfer funds, with:
- an adequate sublimit — often the default is far too low;
- clear coverage for vendor and client impersonation, not only executive impersonation;
- coverage for inadvertent disclosure of credentials as well as direct transfers;
- a verification condition that is achievable — some policies require callback verification to a pre-established number, and if the company's actual process does not match, the claim fails; and
- coordination with the crime policy, so that the two do not each point at the other.
Check the verification condition against the company's actual accounts payable procedure. If they do not match, either change the procedure or negotiate the condition, and do it before the loss rather than after.
War, infrastructure, and the exclusions that grew
Two exclusion categories have expanded significantly in cyber policies and deserve specific attention.
War and hostile act exclusions. Cyber operations attributed to states have prompted insurers to invoke war exclusions, and the resulting litigation — most prominently over losses from a destructive malware event widely attributed to a state actor — has driven substantial redrafting. Newer forms contain cyber-specific war exclusions that attempt to define state-sponsored activity, attribution, and the treatment of collateral damage to entities not themselves targets.
What to look for: a definition of war and hostile act that does not sweep in ordinary criminal activity by actors who happen to be located in a particular country; an attribution standard that requires something more than a government statement or a press report; a carve-back for collateral or unintended damage to an insured that was not the target; and a burden of proof expressly on the insurer.
Infrastructure and utility exclusions. Many cyber forms exclude loss arising from failure of infrastructure not under the insured's control — power, telecommunications, satellite, internet. Read against the contingent business interruption grant, these exclusions can eliminate the coverage the insured thought it bought. Negotiate a carve-back for failures caused by a covered cyber event, and align the exclusion with the CBI grant so that the two are not in direct conflict.
Widespread event and systemic risk provisions. A newer category, permitting insurers to limit or exclude losses arising from a single event affecting a large number of insureds. These are commercially understandable and materially reduce coverage for precisely the scenario a large company most fears.
Worked example one: the securities claim
Priya Anand is general counsel of Larkspur Diagnostics, a public company. On a Tuesday the company announces that a clinical endpoint was missed; the stock falls 41%. Within three weeks there are two securities class actions, a books and records demand, and a derivative complaint. Six weeks later the SEC issues a formal order of investigation.
Notice. Priya's first act is not to read the policy — it is to give notice, to every layer, of everything. The stock drop itself may not be a claim, but the class actions plainly are, and the books and records demand and the SEC order both fall within the policy's definition. She gives notice within days, by the method the policy specifies, to the addresses the policy specifies, with a copy to the broker. She also gives a notice of circumstances describing the announcement and the potential for further claims, which will lock later-filed related actions into this policy year.
The tower. Larkspur has $50 million: a $15 million primary, three excess layers, and a $10 million dedicated Side A above. Priya's broker produces a comparison of the six forms, which is when she learns that the third excess layer has a different notice provision and a different definition of "claim." She gives notice under both definitions to be safe.
Allocation. The primary policy contains a pre-agreed 100% allocation for securities claims where both the company and insured persons are defendants. That provision saves months of dispute and is the reason the defence costs are being paid in full rather than fought over.
Advancement. The individuals need defence costs advanced. Larkspur's bylaws provide mandatory advancement, and Side B reimburses the company. Priya obtains undertakings from each individual and sets up the process before the first invoice.
The SEC investigation. Coverage for investigations is narrower than for litigation and varies by form. Larkspur's policy covers formal investigations of insured persons after a formal order, but not the pre-order informal inquiry, and not the company's own investigation costs. Priya identifies this gap and raises it at renewal.
The independent investigation. The board forms a special committee. Its costs are generally not covered by D&O — a point boards routinely discover late — although some forms include a limited derivative demand investigation sublimit. Priya checks and finds a $500,000 sublimit, which will be exhausted quickly.
Consent. Eighteen months later, a mediated settlement is reached at $34 million, requiring consent from four carriers. The first excess carrier initially declines, and the negotiation to bring it along consumes two weeks. This is normal and should be anticipated.
What Priya changes at renewal. Broader investigation coverage; a larger derivative investigation sublimit; harmonized notice provisions across the tower; and an exhaustion provision permitting the insureds to fill a gap if an underlying layer settles below its limit.
Worked example two: the wire
On a Thursday afternoon, Colby Rutherford, controller at Vance Materials, approves a $2.4 million payment to a long-standing supplier whose banking details changed by email. The email came from a domain one character different from the supplier's. The money is gone within two hours.
The first six hours matter most. Vance's bank is called immediately and initiates a recall; law enforcement is notified, which can sometimes freeze funds in a domestic receiving account; and the incident response retainer is activated. Roughly $400,000 is recovered.
The coverage analysis is where it gets complicated.
Vance has a crime policy with computer fraud and funds transfer fraud coverages, and a cyber policy with a social engineering endorsement subject to a $250,000 sublimit.
The crime policy's computer fraud grant covers loss resulting directly from the use of a computer to fraudulently cause a transfer of property. The insurer's initial position is that the loss resulted from Colby's authorized instruction to the bank, not directly from any computer use — the Apache argument. Vance's coverage counsel responds with the American Tooling line of authority and the specific facts: the spoofed emails were the direct cause, there was no intervening independent investigation, and the authorization was procured by the fraud itself.
The crime policy's funds transfer fraud grant covers transfers made without the insured's knowledge or consent, which does not fit — Vance consented, having been deceived.
The social engineering endorsement fits precisely, and is sublimited at $250,000.
The resolution is a negotiated settlement at $1.1 million after a coverage mediation, reflecting the litigation risk on the computer fraud grant.
What Vance changes. The social engineering sublimit is raised to the full policy limit at renewal. The verification condition is reviewed against the actual accounts payable procedure and found to require callback to a number on file — which Vance's procedure did not do. The procedure is changed, documented, and trained. And a dual-authorization requirement is imposed for any change of banking details, with the callback made to a number from the vendor master file rather than from the email.
The insurance fix and the process fix are both necessary. The process fix is worth more.
Worked example three: ransomware and a coverage fight
Marguerite Okonkwo is CFO of Hallward Foods when ransomware encrypts the production and warehouse management systems on a Sunday night. Operations stop across eleven distribution centres.
Days one to four. Incident response through the panel; forensic containment; restoration from backups, which are partially usable. Hallward does not pay the ransom. Production resumes progressively over eleven days.
The claim. Incident response costs of $3.1 million. Business interruption loss assessed by Hallward at $18.4 million. Data restoration $900,000. Third-party liability minimal, since no personal data was exfiltrated.
Three coverage disputes emerge.
The waiting period. The policy has a twelve-hour waiting period. The insurer takes the position that the period of restoration began when systems were restored to functionality, not when Hallward returned to normal operating levels — a difference of six days and roughly $9 million. The policy's definition of "period of restoration" is the battleground, and Hallward's position rests on language extending the period until operations are restored to the condition that would have existed but for the event.
The contingent business interruption question. Part of Hallward's loss arose because a third-party logistics provider could not receive Hallward's data. The CBI grant requires the provider to be scheduled, and this one is not. That portion of the claim fails, and it is a placement failure rather than a claims failure.
The forensic accounting. The insurer's accountant computes the business interruption loss at $7.2 million against Hallward's $18.4 million, differing on the revenue trend used as the baseline, the treatment of orders eventually fulfilled late, and the deduction of saved expenses. This is the ordinary shape of a BI dispute and it is resolved, as most are, by two accountants and a mediator.
The resolution. $14.6 million against a $25 million limit, eleven months after the event.
What Marguerite changes. All material service providers scheduled for CBI. The waiting period reduced from twelve hours to eight. The definition of period of restoration negotiated with an express extension to restoration of normal operations. A forensic accounting firm pre-identified and retained on standby. And — the change that matters most operationally — a documented, tested restoration procedure with the recovery time objective actually measured, because the eleven days were longer than anyone had assumed and the insurance conversation was easier than the operational one.
The application, and rescission
Both D&O and cyber applications ask questions whose answers, if wrong, can void the policy.
D&O applications incorporate the company's public filings and ask about known circumstances. A material misstatement can support rescission, which unwinds the policy entirely.
The protections to negotiate:
- Severability of the application, so that one person's knowledge is not imputed to others.
- Non-rescindable Side A, so that the individuals' protection survives whatever the company did.
- Knowledge limited to named signatories, and a statement that no other insured's knowledge is imputed.
- Incorporation limited to specified documents, so that every statement in years of filings does not become a warranty.
Cyber applications increasingly ask detailed security control questions: multifactor authentication coverage, endpoint detection, backup architecture and testing, privileged access management, patching cadence, email filtering, and employee training. These answers are warranties in substance, and insurers have declined claims where controls represented as in place were not.
The discipline required is unglamorous and important: the person who signs the cyber application must be the person who actually knows, the answers must be verified against reality rather than against intention, and any control described as "in progress" must be described that way. An application saying MFA is deployed on all remote access, signed by a CFO relying on a project plan, is a rescission argument waiting for an incident.
Where a control is genuinely partial, disclose the scope. Insurers price it; they do not usually decline for it. What they do decline for is discovering, in a forensic report, that the answer was wrong.
Coordination between policies, and the gaps between them
A large company's programme includes D&O, cyber, crime, professional liability, general liability, property, and often technology errors and omissions. Events do not respect these boundaries, and the gaps between policies are where losses fall.
D&O and cyber. A breach produces both first-party loss (cyber) and shareholder litigation alleging that management misrepresented the company's security posture (D&O). Both policies respond to different parts of the same event. Notice both.
Cyber and crime. Social engineering losses sit at the boundary, and both insurers may point at the other. The fix is an "other insurance" analysis at placement and, ideally, placement of both with the same carrier or with an agreed priority.
Cyber and property. Physical damage caused by a cyber event — damaged equipment, a manufacturing incident — may fall outside a cyber policy's coverage of intangible loss and outside a property policy's cyber exclusion. Bricking coverage addresses part of this; the rest needs a deliberate look.
Cyber and technology E&O. For a company that provides technology services, a breach affecting customers implicates both. Coordination and shared limits should be understood.
Cyber and contingent business interruption. A vendor's outage may be covered by the cyber policy's CBI grant, by a property policy's contingent business interruption extension, or by neither. The provider must usually be scheduled somewhere.
D&O and employment practices. Employment claims against officers may sit in either, and the retention and defence arrangements differ.
The exercise worth doing annually is a gap analysis across the whole programme, run by the broker but reviewed by counsel, mapping a set of realistic scenarios against the policies and identifying which responds, at what limit, subject to what retention, and where nothing responds at all. It takes a day and it regularly finds something.
What a director should ask
Directors are not expected to underwrite the programme, but a handful of questions asked once a year would prevent most of the failures described above.
- What is the total D&O limit, and how much of it is dedicated Side A?
- Does the insured-versus-insured exclusion carve out derivative suits and claims by a bankruptcy trustee, examiner, or creditors' committee?
- What triggers the conduct exclusions — final non-appealable adjudication in the underlying action, or something less?
- Is Side A non-rescindable, and is the application severable?
- Is there a pre-agreed allocation for securities claims?
- Do all layers in the tower have the same notice provisions and the same definition of claim?
- Can the insureds fill a gap if an underlying layer settles below its limit without prejudicing attachment?
- What does the policy cover in an investigation, and from what point?
- If we are acquired, who buys the six-year run-off, when, and at what limit?
- Has anyone read the excess policies, or only the primary?
For cyber, the parallel list is shorter: what are the sublimits, is social engineering covered at a meaningful limit, are our critical service providers scheduled for contingent business interruption, what is the waiting period, how is the war exclusion worded, and do the answers on our application match reality.
A board that receives written answers to those questions has done more for its own protection than one that approves a premium.
A closing observation
Insurance coverage disputes are rarely about whether the loss happened. They are about notice given late, a claim reported under the wrong policy year, an excess layer that never attached, an allocation nobody agreed in advance, an exclusion drafted more broadly than anyone noticed, a sublimit set at a fraction of the exposure, a vendor not scheduled, and an application answered optimistically.
Every one of those is a placement problem or a process problem, and every one is fixable in the eight weeks before renewal at a cost of a few days' attention. The alternative is discovering the problem in the month after the event, when the company has no leverage, the individuals are personally exposed, and the only remaining question is how much of the loss the insurer will pay to avoid litigating.
The programme is worth reading. Not the summary the broker prepares — the policies, including the excess forms, once a year, by someone who will have to use them.
Related documents
- Placing and tendering a D&O or cyber claim: a practical guide
- D&O and cyber insurance review checklist
- Executive and cyber coverage toolkit: policy comparisons, notice letters, and allocation analyses
- Indemnification and advancement for directors and officers: the fight that starts before the merits
- Books and records demands: section 220, proper purpose, and the documents you actually get