Document type: Guide Practice area: Corporate — Insurance and Risk Jurisdiction: United States Last reviewed: 5 September 2026
Part one: placement
Step one: build the exposure picture
Underwriters price what they are told. A submission that presents the company well produces better terms, and the work of building it also tells the company what it is buying.
For D&O: market capitalization and volatility; recent stock movements and their causes; the shareholder base and any activist positions; the board's composition and independence; recent or pending transactions; regulatory posture; litigation history; financial restatements or material weaknesses; and the indemnification provisions in the charter and bylaws.
For cyber: the data held, by type and volume; the systems that matter and their recovery objectives; the security control set, honestly stated; the vendor and service provider dependencies; the revenue at risk from an outage, by duration; incident history; and the results of any assessment or penetration test.
Two disciplines apply to both. State the controls accurately — the application is effectively a warranty, and a control described as in place when it is in progress is a rescission argument. And quantify the exposure, because a limit chosen by reference to peer benchmarking rather than to the company's own loss scenarios is a limit chosen by accident.
Step two: model the limit
The standard approach is benchmarking against companies of similar size and sector. It is a starting point, not an answer.
For D&O, model the realistic worst case: a securities class action following a significant stock drop, with parallel derivative litigation and a regulatory investigation. Estimate defence costs over three years, settlement ranges based on the market capitalization loss and comparable resolutions, and the individual exposure if the company cannot indemnify. Then ask how much of the tower is available to individuals after the company's own claims.
For cyber, model a total operational outage: revenue per day, the realistic restoration period (measured, not assumed), incident response cost, notification cost by record volume, regulatory exposure, and third-party liability. Companies consistently underestimate the restoration period, and a business interruption limit sized to a three-day outage is inadequate for an eleven-day one.
Step three: negotiate the terms that matter
Premium is negotiated in every placement. Terms are negotiated only if somebody asks.
D&O, in priority order:
- Dedicated Side A limit, with difference-in-conditions and drop-down features.
- Conduct exclusions triggered only by final, non-appealable adjudication in the underlying proceeding.
- Non-rescindable Side A, and full severability of the application.
- Insured-versus-insured carve-outs: derivative suits, bankruptcy trustee and creditors' committee claims, former officers, whistleblowers, cross-claims.
- Pre-agreed allocation for securities claims.
- Investigation coverage, defined broadly and starting early — informal inquiries, document requests, and subpoenas, not only formal orders.
- Exhaustion language permitting the insureds to fill a gap where an underlying layer settles below its limit.
- Broad definition of claim, so that a demand letter or subpoena triggers coverage.
- Notice provisions measured by "as soon as practicable" rather than a short fixed period, and notice to a single specified address.
- Run-off terms pre-agreed, so that a transaction does not become a negotiation.
Cyber, in priority order:
- Sublimits. Identify every one and raise the ones that matter — social engineering above all.
- Social engineering coverage at a meaningful limit, covering vendor and client impersonation, with a verification condition that matches the company's actual process.
- Contingent business interruption with the critical providers scheduled by name, or on a blanket basis if available.
- Waiting period reduced, and period of restoration defined to extend until normal operations resume.
- War and hostile act exclusion narrowed: an attribution standard, a carve-back for collateral damage, and the burden on the insurer.
- Infrastructure exclusion aligned with the CBI grant rather than contradicting it.
- Panel counsel and vendors: the company's preferred firms added to the panel at placement, not negotiated during an incident.
- Regulatory coverage including fines where insurable, and PCI assessments.
- Consent provisions for extortion payments that are workable in the first twenty-four hours.
- Retroactive date as early as possible, and prior acts coverage preserved on any change of carrier.
Step four: harmonize the tower
A tower is several contracts, not one. Have the broker produce a provision-by-provision comparison across every layer, and read it.
What to check: notice provisions and addresses; the definition of claim; the definition of loss; exclusions that differ from the primary; arbitration or choice-of-law clauses; consent-to-settle requirements; exhaustion language; and any "other insurance" provision.
Then negotiate the outliers into conformity. Where a carrier will not conform, know it — because at claim time the company must satisfy every layer's requirements, which means satisfying the strictest.
One practical measure worth insisting on: a single notice address and method that satisfies every layer, recorded in the claims runbook. In the week a claim arrives, nobody should be reading six policies to find out where to send a letter.
Step five: document the placement
Keep, in one place: every policy in full, including endorsements; the application and all supporting materials; the broker's placement report and the tower comparison; the limit modelling; and a one-page summary of each policy.
The summary is what gets used. For D&O: limits by layer and carrier, retentions, dedicated Side A, notice requirements and addresses, key exclusions and their triggers, allocation, and the run-off terms. For cyber: grants and sublimits, retention, waiting period, panel vendors, notice, extortion consent process, and scheduled providers.
Part two: the claim
Step six: recognize the claim
Coverage is most often lost because nobody recognized that something was a claim.
Things that are usually claims under a modern D&O policy: a complaint; a written demand for monetary or non-monetary relief; a shareholder demand letter; a books and records demand; a subpoena; a formal order of investigation; a Wells notice; a request to toll a limitations period; an arbitration notice; a criminal indictment or information.
Things that are often claims under a cyber policy or that trigger a first-party grant: a ransom demand; a regulator's inquiry; a demand letter from a business partner; notification of a breach at a service provider; a card brand assessment; and — for first-party coverage — the incident itself.
The rule to implement: anyone in the company who receives any of the above forwards it to legal the same day, and legal assesses it against every policy within seventy-two hours. Put the list in a one-page notice, distribute it to the executive team, the finance function, and anyone who opens the company's mail.
Step seven: give notice properly
To every layer. Not just the primary. Excess carriers' notice provisions are independent conditions.
In the manner the policy specifies. Email if permitted, courier if required, to the address in the policy or in a notice endorsement — which may not be the address the broker uses for correspondence.
Promptly. "As soon as practicable" is not a licence to wait for the litigation strategy to settle. Give notice first; the analysis can follow.
With enough content. Identify the claim, the insureds involved, the alleged wrongful acts, the date first made, and how the company learned of it. Attach the document. Reserve rights.
Through the broker and directly. The broker's transmittal is helpful; it is not a substitute for the insured's own notice unless the policy says so.
And document it. Date, method, recipient, and proof of delivery, filed.
Step eight: the notice of circumstances judgment
Where an event has occurred that may generate a claim later, the company can notify circumstances and lock coverage into the current policy year.
Notify circumstances when: a significant adverse event has occurred with a plausible path to litigation; a regulator has begun looking; an internal investigation has found something serious; a whistleblower complaint has substance; a restatement is coming; or a transaction has attracted shareholder objection.
Do not notify every internal complaint, every routine employment grievance, or every speculative concern. A wall of circumstance notices produces a renewal in which everything the company knows about is excluded.
How to draft one. Describe the circumstances with enough specificity to identify what is being noticed, and enough breadth to capture the claims that may follow — the potential claimants, the potential wrongful acts, and the insureds who may be involved. A notice too narrow will not capture the claim that eventually arrives.
Manage the renewal. Tell the broker, and expect the incoming carrier to exclude the noticed matter. That is the trade, and it is usually the right one: locked coverage in the old year beats speculative coverage in the new one.
Step nine: manage defence
Panel counsel. Cyber policies and many D&O policies require counsel from an approved panel, or the insurer's consent. Negotiate the company's preferred firms onto the panel at placement. If a claim arrives and the firm the company wants is not on the panel, ask immediately — insurers usually consent, but they consent more readily before fees have been incurred.
Rates. Insurers negotiate panel rates. Where the company's chosen counsel bills above them, address the differential explicitly: some insurers will pay full rates for a significant matter, some will pay the panel rate with the company funding the gap, and some will not consent at all. Resolve it in writing at the outset rather than discovering it in month four when invoices are cut.
Billing. Insurers apply litigation guidelines: staffing limits, block billing prohibitions, restrictions on internal conferences and legal research. Give the guidelines to counsel at the start. A firm that bills without regard to them will have invoices reduced, and the reduction usually falls on the company.
Advancement. For individuals, advancement flows from the charter and bylaws, with the policy reimbursing. Obtain undertakings, set up the review process, and do not let the mechanics delay payment — individuals whose fees are not being paid become uncooperative and, eventually, adverse.
Cooperation. Policies require it. Keep the insurer informed, respond to reasonable requests, and do not settle without consent.
Step ten: respond to the reservation of rights
Insurers issue reservation of rights letters as a matter of course. They are not a denial, and they should not be ignored.
Read it for what is reserved, not the boilerplate. Identify each specific ground: a definitional argument, an exclusion, a notice issue, an allocation position.
Respond in writing. A short, factual letter addressing each reserved ground preserves the record and frequently narrows the reservation. Silence is read as acquiescence.
Track the reservations through the life of the claim, and require the insurer to withdraw those that facts have overtaken.
Watch for conflicts. Where an insurer reserves on a ground that would allow it to control the defence in a direction adverse to the insured, independent counsel may be required, and in some jurisdictions at the insurer's expense.
Escalate a coverage denial promptly. A denial letter starts clocks — for suit, for appraisal, for regulatory complaint — and some are short.
Step eleven: prove a first-party loss
Cyber first-party claims are paid on documentation, and the documentation has to be built while the incident is being managed.
From day one: a separate cost centre or project code for all incident costs; contemporaneous logs of the outage — systems affected, times down, times restored, functions available; preservation of forensic reports and vendor invoices; and a record of operational decisions and their commercial consequences.
For business interruption: the revenue baseline, drawn from a defensible period; the actual revenue during the interruption; orders lost versus orders delayed; extra expense incurred to mitigate; and saved expenses to be deducted. Engage a forensic accountant early — ideally one pre-identified at placement — because the insurer will have one and the claim will be resolved between them.
For data restoration: the cost of recreation, with time records for internal effort.
Proof of loss. Prepare it properly: a narrative of the event, the coverage grants invoked, the loss by category with supporting documents indexed, and the amount claimed. A well-organized proof of loss is paid faster and reduced less.
Step twelve: settle across a tower
A settlement requiring consent from five or six carriers is a project.
Start early. Give carriers information as the case develops, so that a mediation is not the first time an excess carrier hears the exposure.
Get them in the room, or on the line. Mediators experienced in insurance-funded settlements manage this well; carriers who participate settle more readily than those presented with a demand.
Understand each carrier's position. The primary wants to cap its exposure; the first excess wants the primary to pay its full limit; the high excess may believe it is never reached and will not fund. The negotiation is as much among the carriers as with the plaintiff.
Watch exhaustion. If the primary settles below its limit, confirm in writing with each excess carrier that attachment is not prejudiced, or fund the gap in a way the policy permits.
Document consent from every layer, in writing, before signing.
Step thirteen: the renewal after a loss
A company that has had a claim will face a harder renewal, and how it presents itself determines how much harder.
Lead with remediation. What failed, what changed, what evidence exists that it changed. Underwriters price uncertainty; a documented remediation programme reduces it.
Bring the people. A renewal meeting attended by the CISO or the general counsel, who can answer questions directly, produces better outcomes than a submission.
Start early. Ninety to one hundred twenty days, with a market strategy rather than a single incumbent conversation.
Protect prior acts. On any change of carrier, preserve the retroactive date and address the noticed matters explicitly. A new policy with a fresh retroactive date leaves a gap that no premium saving justifies.
Step fourteen: know when to bring in coverage counsel
Brokers are advocates and they are good at what they do. They are not lawyers, and there are moments when the company needs one.
Bring in coverage counsel when:
- A denial or a substantial reservation of rights arrives.
- The claim will approach or exceed a layer's limit.
- An allocation dispute is live.
- An exhaustion question arises because an underlying layer is settling below its limit.
- An insurer asserts a conduct exclusion or threatens rescission.
- A first-party loss is being reduced by more than a modest amount on methodology grounds.
- Two policies are pointing at each other.
- A settlement requires consent from multiple carriers who are not aligned.
What coverage counsel adds that a broker cannot: the applicable law, which varies substantially by state on nearly every question in this area; the ability to make a demand that carries litigation risk; privilege over the analysis; and — often most valuable — knowledge of how a particular carrier behaves when pressed, which is real and not written down anywhere.
Who pays. Coverage counsel's fees are generally the insured's own cost, not a covered defence expense. That is a reason to engage deliberately rather than reflexively, and a reason to use the broker first on questions the broker can resolve.
Choice of law matters more than most people expect. Whether an excess policy attaches when the primary settles below its limit, whether an insurer must show prejudice from late notice, whether fines are insurable, whether an insurer may recoup defence costs after a coverage determination, and how allocation is performed are all questions on which states differ. A policy's choice-of-law clause, or its absence, may be the most consequential provision in the document. Check it at placement.
Step fifteen: build the claims runbook
The week a serious claim arrives is the wrong week to work out the process. Write it down in advance, on two pages.
What it contains:
- The trigger list. What is a claim under each policy, in plain language, distributed to everyone who might receive one.
- The notice matrix. For each policy and each layer: carrier, policy number, limit, attachment point, notice address, notice method, and the deadline. One table.
- Who does what. Who assesses, who drafts the notice, who sends it, who tells the broker, who tells the board.
- Panel counsel and vendors, pre-approved, with contacts.
- The forensic accountant, pre-identified for first-party claims.
- Coverage counsel, pre-identified, with conflicts pre-cleared.
- The documentation protocol for a first-party loss: cost centre, logging requirements, preservation.
- Board notification thresholds and process.
- The one-page policy summaries.
Test it. Run a tabletop once a year against a realistic scenario, with the broker present. The exercise reliably finds a wrong notice address, a policy nobody has read, and a vendor who is no longer on the panel.
Step sixteen: manage the retention and the cash
Insurance is not only a coverage question; it is a cash flow question, and the finance function needs to understand the shape of it.
Retentions are paid first, in cash. A $2.5 million D&O Side B retention means the company funds the first $2.5 million of indemnified defence costs before any insurance money arrives. In a matter that runs three years, that money leaves in the first six months.
Reimbursement lags. Side B reimburses the company after it has indemnified. Invoices are submitted, reviewed against litigation guidelines, sometimes reduced, and paid on the insurer's cycle. Ninety days from invoice to payment is common. Model the working capital effect.
First-party cyber claims pay in stages. Incident response costs are often advanced quickly, because the panel vendors bill the insurer directly. Business interruption is paid at the end, after the accountants agree, which can be a year. Ask for interim payments — most policies permit them and most insurers will make them on undisputed amounts, but only if asked.
Sublimits erode the aggregate. Payments under a sublimited grant usually reduce the overall limit as well. A programme that pays $2 million on incident response has $2 million less available for the liability claim that follows.
Retentions may be eroded by defence costs, or may not, depending on the form. Check which.
Deductible versus retention. With a deductible the insurer pays and seeks reimbursement; with a retention the insured pays first. The distinction matters for cash flow and occasionally for who controls the defence within the retention.
Give finance the numbers at placement: the retention by coverage part, the expected reimbursement cycle, and the cash requirement in a modelled claim. A CFO who learns during a crisis that the company must fund $2.5 million before insurance responds is a CFO who will ask why nobody mentioned it.
Worked example one: the first placement
Thandiwe Molefe is general counsel of Ardent Robotics, approaching an initial public offering with no D&O programme beyond a small private company policy.
Modelling. The broker benchmarks $30 million for the sector and market capitalization. Thandiwe models the actual scenario: a significant stock drop in year one, a securities class action, and a derivative suit. Defence costs alone over three years project at $12–18 million. She buys $60 million, with $15 million of dedicated Side A.
Terms she negotiates: final non-appealable adjudication triggers on the conduct exclusions; non-rescindable Side A; full severability; insured-versus-insured carve-outs including bankruptcy claimants; pre-agreed 100% securities allocation; investigation coverage from the first document request rather than from a formal order; and exhaustion language permitting the insureds to fill a gap.
Tower harmonization. The comparison reveals that the second excess has a fourteen-day notice requirement and the fourth has a different definition of claim. She has both conformed to the primary, which costs nothing because she asked before binding.
Run-off pre-agreed. Ardent is a plausible acquisition target. She negotiates run-off terms — six years, at a stated percentage of the expiring premium — into the policy now.
Worked example two: tendering across six carriers
Bruno Hartmann is deputy general counsel at Fenwick Industrial when a whistleblower complaint becomes an SEC inquiry, then a class action, then a derivative suit, across fourteen months.
Month one. The whistleblower complaint is assessed. It is specific, credible, and concerns revenue recognition. Bruno gives a notice of circumstances describing the allegations, the potential claimants, and the insureds who may be involved. He drafts it broadly.
Month four. An SEC document request arrives. Under Fenwick's policy — negotiated to cover investigations from the first request — this is a claim. Notice to all six layers, in the manner each specifies.
Month nine. A securities class action. Notice again, with a statement that it arises from the circumstances noticed in month one and is therefore deemed first made then.
Month eleven. The incoming carrier at renewal excludes the noticed matter, as expected. The month-one notice has done its job.
Month fourteen. A derivative suit. The insured-versus-insured carve-out for shareholder derivative actions applies, and Bruno confirms in writing with each carrier that it does before defence costs mount.
Throughout. Bruno maintains a single claim file: every notice with proof of delivery; every reservation of rights and his response; a running spreadsheet of defence costs by matter and by insured; and a monthly update circulated to all carriers. When the settlement discussion comes, no carrier is hearing anything for the first time.
Worked example three: the disputed BI claim
Rosalind Achterberg is CFO of Corvine Manufacturing after a cyber event halts production for nine days.
What she does on day one, before the systems are back: opens a dedicated cost centre, instructs the plant managers to log production and shipment data hourly, notifies the cyber carrier, and calls the forensic accountant identified in the placement file.
The dispute is about the baseline. Corvine's revenue had been growing 14% year over year; the insurer's accountant proposes a trailing twelve-month average, which understates the loss by roughly $4 million. Rosalind's accountant proposes the growth-adjusted trend, supported by the order book at the time of the event.
The resolution is a negotiated baseline between the two, arrived at in three meetings over six weeks. The dispute is entirely about method, and it was going to happen regardless — but it resolves quickly because Corvine's data is contemporaneous, granular, and credible.
What would have gone badly without day-one discipline: reconstructed production data, no separation of incident costs from ordinary operating costs, and an insurer entitled to be sceptical of every number.
Placement in a transaction
A merger, acquisition, or financing changes the insurance position in ways that must be handled on a schedule set by the deal, not by the renewal cycle.
On a sale of the company. The target's programme terminates prospectively at closing. The protection for the target's former directors and officers is a six-year run-off, and the questions to resolve before signing are: who buys it, when, at what limit, and at whose expense.
The merger agreement typically contains a covenant requiring the acquirer to maintain coverage. Treat that covenant as insufficient on its own. Negotiate instead that the run-off is bound before closing, that it is non-cancellable and fully earned, and that a copy of the bound policy is delivered at closing. A covenant to buy insurance is worth what the counterparty's performance is worth; a bound policy is worth its limit.
Size the run-off against six years of claims, not one. And include dedicated Side A within it — the individuals covered by a run-off are, by definition, people the company can no longer indemnify because the company no longer exists in the same form.
On an acquisition. The acquirer inherits exposure for the target's pre-closing conduct in respect of the acquired entity, and its own D&O programme's definition of "subsidiary" and treatment of prior acts determines what is covered. Check the prior acts position; many programmes cover a new subsidiary only from the date of acquisition, leaving the target's history uninsured except by the run-off.
Diligence the target's insurance: current policies in full, the loss history, open claims and circumstance notices, and the applications. A target that gave circumstance notices has told its insurer about problems the acquirer should also know about.
On an IPO. A private company policy will not respond to public company securities exposure, and public company D&O must be placed before pricing. Underwriters will want the registration statement, the financials, and management access. Start ninety days out. Consider whether the pre-IPO policy needs a run-off for the private company period.
On a financing or a going-private transaction. Both attract litigation, and both may change the insured entity. Review the programme against the new structure and confirm that the entities that need coverage have it.
Working with the broker
The broker is the company's agent and, in most placements, is compensated by commission from the insurer. Understanding the relationship makes it more productive.
What a good broker does: knows which carriers will write which risks and on what terms; runs a genuine market process rather than renewing with the incumbent; produces a real tower comparison rather than a summary; advocates on a claim, forcefully, because the carrier wants the broker's future business; and tells the company what it does not want to hear about its controls or its exposures.
What to ask for, and get in writing:
- A market strategy at least ninety days before renewal, naming the carriers to be approached.
- A provision-by-provision tower comparison, not a summary.
- The specific coverage enhancements requested and each carrier's response.
- Benchmarking data, with the peer set identified.
- Full disclosure of compensation, including contingent commissions.
- A written placement report at binding.
Where to be careful. A broker's summary of coverage is a summary; the policy governs, and discrepancies between the two have been the subject of professional negligence claims. Read the policy. And a broker who has placed the account with the same carrier for eight years without a market test may be delivering continuity or may be delivering complacency; ask.
Common failures, ranked by cost
1. Late notice, or notice to fewer than all layers. Coverage forfeited for reasons entirely unrelated to the merits. The most common failure and the most preventable.
2. Not recognizing a claim. A subpoena filed in a drawer, a demand letter treated as routine correspondence, a books and records demand handled without reference to insurance.
3. Sublimits nobody read. A $10 million cyber policy that pays $250,000 on the loss that actually occurred.
4. Providers not scheduled for contingent business interruption. The vendor whose outage stopped the business is not on the list.
5. Exhaustion mismatch. The primary settles at 80% of its limit, the insured funds the gap, and the first excess says it never attached.
6. Tower provisions that differ. A notice requirement in a middle layer that nobody satisfied.
7. An application answered optimistically. Controls described as deployed that were planned.
8. An unmodified insured-versus-insured exclusion. No coverage in bankruptcy, which is when Side A is needed most.
9. Conduct exclusions triggered by "in fact" rather than final adjudication. The insurer litigates the merits in the coverage case.
10. Run-off not bound at closing. A covenant instead of a policy, and then a dispute with a counterparty who has moved on.
Every one of these is a placement or process failure, and every one costs more than the entire annual cost of the discipline that would have prevented it.
Reporting to the board
The board has a direct interest in the D&O programme — its members are the insureds — and a governance interest in cyber. An annual report, delivered once, prevents most of the surprises.
What to present, on two pages:
The D&O structure. A tower diagram: each layer, carrier, limit, attachment point, and premium. The dedicated Side A limit called out separately, with an explanation of when it responds.
The five terms that matter, with the actual policy language: the conduct exclusion trigger; the insured-versus-insured carve-outs; whether Side A is non-rescindable and the application severable; the allocation provision; and the exhaustion language.
The scenario analysis. In a securities class action with parallel derivative litigation and an investigation, how much of the tower is realistically available to individuals? If the company were insolvent, what would respond?
Run-off. What happens on a change of control, who buys the tail, and on what terms.
The cyber position. Limits and the material sublimits; what a total outage would cost against what the policy would pay; whether critical vendors are scheduled; the waiting period against the measured restoration time; and the accuracy of the application's control representations.
What changed this year, and what was asked for and not obtained.
Directors should ask about the dedicated Side A limit and the insured-versus-insured carve-outs specifically. Those two items determine whether the policy protects them in the circumstances where they most need it, and both are frequently deficient in programmes that look adequate on the summary page.
A final discipline
The single highest-return habit in this area costs an afternoon a year: read the policies.
Not the broker's summary. Not the binder. The actual forms, including every excess policy and every endorsement, once a year, by the person who will have to use them when something happens.
Every failure listed above is visible on the page. The notice address is on the page. The sublimit is on the page. The exhaustion language is on the page. The insured-versus-insured exclusion, with or without its bankruptcy carve-out, is on the page. Nobody reads them because they are long and dull and the claim is hypothetical — right up until the Tuesday when it is not.
Individual directors and their own position
A director's interest in the programme is personal and is not identical to the company's, and it is worth saying plainly what a director should do.
Get a copy of the policy. Not the summary. Directors are insureds and are entitled to see the contract that protects them. A company that will not provide it has told you something.
Confirm the indemnification position. Charter and bylaw provisions should be mandatory rather than permissive, should cover advancement, and should not be amendable to a director's detriment for prior conduct. Many are not.
Consider an individual indemnification agreement. These are common, they can be more protective than bylaws, and they are contractual rather than subject to amendment by a later board.
Ask about the dedicated Side A limit and about the insured-versus-insured carve-outs. In insolvency — the scenario where a director's personal exposure is greatest and the company's indemnity is worthless — those two provisions determine whether there is coverage at all.
Understand what happens on departure. Coverage continues for claims made during the policy period arising from acts while in office, subject to renewal and to any run-off. A director who resigns and the company that later changes carriers without preserving prior acts coverage have between them created a gap the former director will discover only when a claim arrives.
On a transaction, insist on the run-off, bound before closing, six years, with dedicated Side A, and delivered rather than promised.
None of this is adversarial. Boards that address it openly at the annual insurance review find that the questions take twenty minutes and that the answers improve the programme for everyone at the table.
The calendar
Everything above reduces to a small number of dated obligations. Put them in one place, with an owner.
120 days before renewal. Market strategy agreed with the broker. Exposure picture refreshed. Control representations verified against reality, in writing, by the people who know.
90 days before renewal. Submission prepared. Limit modelling updated against the current scenario, not last year's. Coverage enhancements requested, in a list, with the priority order.
60 days before renewal. Underwriter meetings. Quotes received. Tower comparison produced.
30 days before renewal. Terms negotiated. Outlier provisions conformed. Binding decisions made with enough time to change course.
At binding. Policies received in full, including endorsements. Placement report filed. One-page summaries updated. Notice matrix updated. Claims runbook updated.
Annually, independent of renewal. Board report. Gap analysis across the whole programme. Tabletop exercise. Policy read-through by the person who would use them.
On any transaction. Run-off terms confirmed and bound before closing. Prior acts and subsidiary definitions checked. Target's insurance diligenced.
Within 72 hours of any potential claim. Assessment against every policy. Notice given to every layer that could respond.
Quarterly. Review of circumstance notices given and their renewal implications. Review of open claims, reservations outstanding, and defence cost run rate against the retention and limit.
It is an unremarkable list. Companies that keep it have insurance that works, and companies that do not have insurance that turns out, at the worst possible moment, to have been a receipt rather than a contract.
Related documents
- Directors and officers and cyber insurance: towers, triggers, allocation, and the claim you must notice
- D&O and cyber insurance review checklist
- Executive and cyber coverage toolkit: policy comparisons, notice letters, and allocation analyses
- Obtaining or resisting advancement: a practical guide
- Responding to a data breach: the first seventy-two hours