How the Merck Case Shapes the Future of Cyber Insurance episode artwork

EPISODE · Jan 11, 2024

How the Merck Case Shapes the Future of Cyber Insurance

from Info Risk Today Podcast · host InfoRiskToday.com

Merck & Co.'s proposed settlement with insurers over a $1.4 billion claim related to the NotPetya attack will change the language the insurance industry uses to exclude acts of war in its policies, and organizations need to consider how those changes affect risk, said attorney Peter Halprin.

Episode metadata supplied by the publisher feed · Published Jan 11, 2024

Embed this episode

NOW PLAYING

How the Merck Case Shapes the Future of Cyber Insurance

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolpasek McGee, executive editor and information security media group. Today I'm speaking with insurance attorney, Peter Halpern, a partner at LawForm Haines Boone. We're going to be discussing recent cyber-related insurance developments and trends. So Peter, let's start the conversation with a discussion about the recent developments regarding a real dispute between pharmaceutical giant Merck and company and some of its insurers that wanted to deny coverage of Merck's $1.4 billion claim related to expenses incurred in the 2017 Nacht-Petya cyber attack.

Now, the insurers, as we know, wanted to deny payment under Merck's all-risk coverage, saying that the attack fell under the policies' war exclusions, and contending that the attack was launched basically by Russia as part of its conflict with Ukraine. But last May, a appellate court agreed with a lower court's ruling that said that the hostile war-like exclusions do not apply to Merck's losses, and so the insurers were all set for oral arguments in an appeal of the case in the New Jersey Supreme Court on January 5th. But at the last minute, the insurers dropped their appeal and decided to settle with Merck. So with that said, at this point, what do we know about the settlement terms, if anything, and how would you describe the overall significance of the Merck settlement in the context of insurance coverage for cyber attacks?

Well, first of all, thank you again for having me, and that was a great summary of kind of where we are. So jumping into your summary, several years ago, this issue was before the trial court, and on a dueling motions for summary judgment, the trial court looked at the wording of the particular exclusion. It looked at the history of war exclusions and how they've been interpreted in property policies going back many years, and looked at the nature of the risk, which as you noted is an all-risk policy. And lastly, it looked at the rules of interpretation and kind of taking all of those things together.

What it essentially said is the insurers were aware of and knew of the risk of cyber incidents, and yet the language of the particular war exclusion in this policy may no reference to cyber attacks, cyber wars, cyber crime. And because of that, the exclusion should be interpreted as traditional war exclusions and property policies are, which is to reflect kinetic conflict or a shooting war, essentially. That decision was then appealed by the insurers to the trial, to the appellate court, and this is the intermediate appellate court, New Jersey's intermediate appellate court heard argument and read the briefs, and ultimately agreed with the trial court and held that the insurers had they wished to avoid coverage should have drafted a clear exclusion, making reference to exactly what they were hoping to exclude. The insurers, of course, did not like that, and further appealed to New Jersey's highest court, the New Jersey Supreme Court.

And it was a much-weighted, much-anticipated appeal, everyone in kind of the cyber space and cyber insurance space was waiting to see what the New Jersey Supreme Court would do. Several days before an argument was supposed to take place, the news came out that the party's reached a settlement, averting argument and essentially putting an end to an appeal of the lower court decision. So as it stands now, the lower court decision stand, and this is kind of the most prominent and important, I'd say, pronouncement on war exclusion issues right now. So if you know what that said, how does this case contribute to establishing legal president regarding insurance coverage for cyber attacks and how hostile or war-like exclusions might or might not apply?

I think it parries on kind of the theme in lesson of 80 to 90 years of war exclusion case law, which says you have to have a shooting war. And to the extent that insurers want to broaden these exclusions so that they include non-shooting wars and cyber risks, the onus is on insurers to clearly do so. So with that said, do you think that this Merck settlement or the case in general will prompt some insurers to change their coverage provisions for cyber-related incidents and their policies? Will they change or sort of tweak the war exclusions or what sort of changes do you think you might see?

You know, I think the interesting thing is that this comes at a time where the insurance market was shifting and where, you know, going back to, I believe, November of 2022, when Lloyd's came out with a bulletin and set forth guidelines for the Lloyd's market in terms of what types of war exclusions and specifically cyber war exclusions should be utilized by the market. You then had in the year and a half or so since, you then had other insurers bringing new products to market, really focused on new cyber exclusions, really focused on war. And the key issue arising out of most of the new exclusionary language is this concept of attribution and whether or not a cyber attack can be attributed to a nation state that would make it more akin to traditional war than perhaps, you know, a criminal gang or an independent actor. So with that said, we see, you know, many cyber attacks sort of linked with nation state sponsored groups or, you know, sometimes it's a little sketchy but, you know, there's often demands by cyber criminals that are known to be linked with certain countries.

How does this get all get washed out when it comes to the cyber insurance or whether or not your exclusion is applied? Well, I'm going to give you the lawyerly answer and say it depends. I think that the insurers are eager to bring some of these new exclusions to market and the market's response has been, you know, to question it. And I think in many cases, you know, brokers and policy holders are hostile to some of the proposed changes and are rejecting some of the proposed changes.

I know in some instances, insurers have held off on introducing new language because of the backlash that they've received. So I don't know exactly how it's going to shake out also because we don't know what what language will ultimately be utilized by most of these carriers. The other issue though is really defining attribution. You gave an example and I think that the reality is that it's often very complicated.

Yes, there may be instances where you know that it's a government hacking group and that that is what they're doing. But sometimes in some countries you have criminal gangs that are kind of, you know, tolerated by the government or, you know, loosely affiliated because, again, they know that they're, you know, stealing money from Americans and it's kind of a common enemy. But it's not necessarily directed by the nation's state itself. And that's where I think the attribution issue becomes so complicated.

The attribution issue also becomes complicated because it's a political issue in many cases, right? It's aware that Iran is directing cyber attacks against the United States, but it doesn't want to have to initiate some kind of cyber war or just want to have to initiate, you know, some kind of diplomatic or military response. And so rather than identifying something as, you know, state-based and focuses elsewhere or it doesn't make that attribution. So then the question is, okay, well, if, you know, governments aren't making the attributions, who is making the attributions?

You know, are we looking to private corporations and experts and all these things to sort that out? And if you're thinking about how does that play out in the claim process or the claim setting, that's messy, right? Then just lead to a cottage industry of dueling experts where, you know, the insured has an expert who explains why the threat actor is not related to a nation's state, was not directed by the nation's state. And then you have dueling expert on the other side who makes the opposite case.

So I think that attribution issues in some ways will not clarify this and will actually make it even messier. But ultimately, I think until there's litigation over these exclusions, it's really going to be unclear as to how this all shakes out. So given the global fallout of the not-petch attack, which impacted many companies worldwide, do you think this settlement might influence international discussions on cybersecurity insurance standards or practices or, you know, promote changes that are, you know, universities or the dressed? I think that there's already a movement toward improved cyber defenses and cyber capabilities in connection with the underwriting of cyber insurance risks.

So the application process is pretty arduous. Clients are being asked, you know, 20 pages or even more of questions to try to address or assess the risk that they may pose the insurer before the insurer can underwrite the risk. And sometimes the insurers are kind of looking under the hood and seeing what systems are in place and they may require the client to bring their systems up to a certain level before they'll even agree to underwrite. You know, it's been bandied about a lot in the trade press, but, you know, multi-factor authentication in some cases is the deal breaker for cyber insurance.

If you don't have it, the underwriters aren't going to underwrite it. So I think there is a movement that is helpful to companies and will force them to improve their cyber hygiene and their cyber defenses just going through the underwriting process. But I think as the exclusionary language, I don't think that's going to alter the risk profiles. I just think it's something that clients are going to really scrutinize in tandem with their brokers when they get new insurance policies and it may be a place where there's dispute, discussion, negotiation, even on the underwriting side or even at the time of, you know, the place of the policy.

So the details of this settlement haven't been disclosed at least at, not at this point. But what are the potential elements or conditions in the settlement that you think might have influenced both parties to reach an agreement rather than to go ahead with an appeal? Well, I mean, you have to think that with kind of the wind at their sails from winning at the trial and the intermediate appellate court, you know, that the policy holders are feeling pretty good about their prospects. And, you know, the insurers were fighting a little bit of an uphill battle, you know, given the rulings below.

So I have to think that the insurers assessed the risks and felt that, you know, as unhappy as they may have been with the intermediate appellate court decision, better not to have the New Jersey Supreme Court also rule against them. So I think they took into account the legal risks. I'm sure there was some, you know, financial component to this as well. But you know, ultimately, I think that given the rulings below probably the insurance on the writing on the wall.

So are there specific recommendations for companies to consider when reviewing their insurance policies at this point in light of the Merck case, especially regarding the language related to cyber incidents, war exclusions, and, you know, similar provisions? Yeah, so I would say, you know, I work with a lot of clients on reviewing their policies and it's something that I didn't traditionally do, but now I do very often, particularly in the cyber realm. And we look for a lot of different things. It's not just the war exclusion, but, you know, decisions like Merck really raise the profile of this issue and have brokers and clients really, you know, kind of focused in on that language.

And, you know, the insurers have worked very hard to try and develop language that they think will insulate them against the risks that they're concerned about. But, you know, at a certain point, if you're overly broad in your exclusionary language, you know, it nullifies much of the benefit of the policy. So, you know, one of the things I see clients is, you know, insurance is not just the kind of thing that you should get and put on your shelf and, you know, only open or only use in case of emergency. It's something where, you know, you should carefully scrutinize the terms of the policy to get an understanding of what is and is uncovered and, you know, you should have discussions with the underwriters at the time of, you know, purchasing of the policy to really understand what are they trying to do by virtue of this exclusion?

What is in and what is out? And if it's ambiguous or unclear, I think the Merck decision shows that courts will hold that against the insurer and say, okay, well, you know, you knew what the risks were. You write the policies. You know, I think that's a really good obligation to the public to write, you know, clearly and to exclude clearly.

And if you fail to satisfy that responsibility, then we're going to find against you. Besides the war exclusion, are there any other top sort of hot button exclusions that you suggest companies that are looking for cyber insurance or, you know, insurance to cover cyber attacks to look carefully at that could also cause problems, maybe in the future if they do have an incident? It's a great question. I think there are probably some people who have kind of a checklist that they use when they look at policies, but I don't do that.

I look at every policy, you know, with a specific thought in mind toward that client and their risks and the issues that they're going through. I had a situation recently where I was looking at a cyber policy for a client and it had some exclusionary language that really didn't make sense in the context of their business. It might have made sense in the context of other businesses, but it was so broad that it basically would have knocked out any loss they could ever expect to have in the event of a cyber incident. And so we went back to the insurer and, you know, sure enough, they had an industry specific form that we were able to, you know, at least bring into the picture so that they didn't have that kind of broad exclusionary wording affecting them.

And I think that's why, you know, you don't want to kind of make a one-size-fits-all recommendation you really want to look specifically at what that particular client's concerns would be in the event of cyber attack. Peter, what advice would you give to other companies facing similar situations regarding insurance claims after a cyber attack, considering the lessons learned from this Merck case? I would start on the front end, which is I think Merck is really a lesson in policy wording and language. And so it's really important that, especially as these new work solutions come to the market, that clients and the brokers work collaboratively with the insurers to try to ensure that there is going to be some kind of exclusionary language in relation to cyber warfare.

It was really narrowly drafted and really limited and targeted and focused on, you know, a narrow set of risks so that the client doesn't inadvertently end up in a situation where a criminal gang is, you know, hitting them up for a ransom and the insurer is able to kind of use overly broad language to say, oh, wait, wait, we don't, we don't cover that. I mean, it seems almost preposterous that you would buy a cyber insurance policy that specifically covers ransomware only to find out that it's not covered because, you know, a red actor has a tangential relationship to a nation's sake. And one last question. What are you keeping your eye on for 2024 in terms of the hottest sort of cyber insurance issues that organizations should really be paying close attention to?

That's an excellent question. I think the development of work solutions is absolutely an important area and people should continue to keep their eye on the ball there. I think generative AI is one where I'm getting a lot of client questions and inquiries clients really want to understand the implications of using AI in their businesses and how that will impact the insurance coverage that they have going forward. You know, we have new privacy laws coming out from, you know, new states in the new year.

And, you know, if the BIPA legislation in Illinois and the subsequent litigation over it and the subsequent coverage litigation over it hasn't scared everyone, you know, we could probably expect more of that as more states, you know, get into the regulation of privacy risks. So I think those are really kind of the big three areas. I can also tell you that from the reports that have come out from brokers and others, it seems like ransomware and business email compromise schemes continue to kind of fuel claims. And so, you know, the extent companies are thinking about their cybersecurity readiness.

You know, those are two things to really focus on, much of which involve kind of cyber hygiene and just making sure that people within an organization are prepared and know what to do when they get a suspicious email. Well, thank you so much, Peter. I've been speaking to attorney Peter Halpern. I'm Mary Ann Goldissette McGee of Information Security Media Group.

Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 11, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!