
Companies must rethink how cyber, crime and D&O risks interact: Gallagher
Gallagher experts explain that as cyber, crime and D&O exposures converge, companies need to rethink how they structure cover and manage board-level risk.
Key points:
Shared limits can dilute D&O cover
Boards must document risk decisions
Third-party dependencies raise exposure
The boundaries between cyber, commercial crime and management liability are becoming increasingly difficult to draw as companies digitalise, automate and become more dependent on interconnected systems and third-party providers.
Gallagher experts say that convergence is making it increasingly important for companies to consider cyber, crime and D&O exposures as part of the same risk picture, while recognising that the policies themselves serve different purposes.
A single event can generate losses across several areas of a business, raising questions not only about which insurance policy should respond, but also about the decisions management made before and after an incident.
“There could be an incident involving a cyber intrusion into an IT system that leads to a transfer of funds, creating a bridge into the cover that a crime insurance policy would provide,” said Aldo Borsani, head of financial lines & cyber, Europe, at Gallagher.
If questions then arise over how management assessed, mitigated or transferred that exposure, the same incident could potentially develop into a D&O claim.
“When an intrusion into an IT system could lead to loss of funds, a standard cyber policy would then exclude the actual loss of money or securities. However, the loss of money itself can then potentially be covered by the commercial crime policy instead hence the importance to analyse and assess all scenarios at once,” Borsani said.
Social engineering, business email compromise, phishing and fraudulent payments can further blur those boundaries, leaving companies to determine where a loss sits and which policy should respond.
“A crime or cyber policy should be used as a first line of defence, keeping claims as far away from management as possible.”
Connected risks
For major European companies, however, recognising those connections does not necessarily mean combining the insurance protection itself.
Harald Köberich, managing director of Köberich Financial Lines and head of carrier management at Gallagher in Europe, cautioned against placing cyber, crime and D&O protection within a single aggregate limit for major clients.
“This is particularly relevant to large business and I would not recommend it, especially in Germany, because you would combine, within one limit, cover for the individual liability of directors and board members with pure asset or balance-sheet protection, such as crime or cyber insurance,” he said.
“You could erode the directors’ limit with a claim under the crime policy, so I wouldn’t recommend that.”
The appropriate structure will depend partly on the jurisdiction and the size and complexity of the client. Shared-limit packages are more established in parts of the US SME market, Köberich said, where directors’ indemnification differs from Germany and other European jurisdictions.
For larger companies, that distinction matters because the policies perform different roles. But Köberich stressed that the exposures themselves should not be considered in isolation.
“My preference is always to have a crime or cyber policy as a first line of defence, keeping claims as far away from management as possible,” he said. “It therefore makes sense to take a holistic view of the three lines.”
Governance in focus
That holistic view extends beyond insurance purchasing. Whether a cyber incident develops into a management liability issue will depend less on whether a company bought a particular policy and more on how the board assessed and responded to the underlying exposure.
“There is no direct link between not buying or not buying sufficient cover and management liability,” Köberich said. Instead, a claimant would need to allege that management had failed in the way it assessed the risk.
For boards, that puts greater emphasis on informed decision-making and documentation. “The whole point is the distinction between an informed and an uninformed decision, and documenting it,” Borsani said.
The challenge is widening as companies become more dependent on external technology and service providers. Köberich said clients are examining where providers store data, assessing the resilience of key suppliers and considering alternatives where disruption to one provider could affect operations.
Borsani also pointed to specific regulations, such as NIS2, being introduced for certain industries, and the growing scrutiny around cyber controls and supply-chain risk as another reason for management to understand and document its exposures.
As businesses automate more processes and rely on increasingly interconnected ecosystems, boards also need to understand where critical dependencies sit and how disruption could spread through the organisation.
“Once an incident happens, it is not just about restoring operations and resolving the incident,” Borsani said. “What is the full tail of effects it could trigger? How could a cyber incident affect an entire industry?”
For companies, that means moving away from viewing cyber, crime and D&O as completely separate conversations. The protections may remain distinct, but the risks increasingly need to be understood together.
Aldo Borsani is head of financial lines & cyber, Europe, at Gallagher. He can be contacted at aldo_borsani@ajg.com.
Harald Köberich is managing director of Köberich Financial Lines and head of carrier management for Gallagher in Europe. He can be contacted at harald_koeberich@koeberich-fl.com.
For more news from FERMA Forum Today, click here.
Did you get value from this story? Sign up to our free daily newsletters and get stories like this sent straight to your inbox.
Editor's picks
Editor's picks
More articles
Copyright © intelligentinsurer.com 2024 | Headless Content Management with Blaze
