Insuralex

  • The Group
    • About us
    • Current Management
    • Past Presidents
    • Membership inquiries
    • Regulatory Information
  • Experience and Vision
  • Services
  • Members
  • News + Articles
  • Reports
  • Events
  • Contact Us
  • FAQ´s
Join

A kind of digital vaccine: The importance of insurance coverage for cybercrime

by Insuralex / Monday, 19 April 2021 / Published in News + Articles

COVID-19, in and amongst all its other ramifications, has been a catalyst for digital evolution. In this context, it is important to note that the threats and vulnerabilities of the digital world are not new but have become more frequent. The Federal Bureau of Investigation (FBI) reported a 300% increase in cybercrimes in April 2020. In March 2020, ransomware attacks increased by 148%. Between February and April 2020, phishing was up 600% and, in April, Google blocked more than 18 million COVID-19-related phishing mails each day.

A number of high-profile data breaches affecting South Africans have reiterated the danger posed by the remote-working and digitalised environment we find ourselves in. Simply put, an increasing online world means heightened risk and liability for companies and organisations. The extent of the risk in the South African context may in fact have been underreported and the implementation of the Protection of Personal Information Act 4 of 2013 (the Act) will likely lead to further disclosure of cyber breaches, as the Act is embedded with a requirement to inform customers and regulators of any breach as soon as reasonably possible. The Act also makes provision for the imposition of penalties and potentially claims for damages in the event of breaches of its requirements, creating further potential liability for companies in relation to cyber breaches.

In the face of heightened risk and an increasingly regulatory legal environment, the use of standalone cyber insurance policies has become ever more important.

This is largely because traditional insurance policies do not necessarily provide cover for these cyber-related risks. Despite this, most South African organisations are not adequately prepared for the growing risks of cybercrime, particularly in the current pandemic and the associated remote working environments. According to a 2020 SHA Report, only 18% of South African businesses surveyed possessed specialist cyber cover.

In a recent foreign case, the importance of specialised cyber insurance was emphasised. The Ontario Court of Appeal, the Canadian province’s highest court, in a March 2021 ruling upheld an insurers refusal to defend based on policy exclusion clauses. In the case of Family and Children’s Services of Lanark, Leeds and Grenville v Co-operators General Insurance Company, 2021 ONCA 0159, Co-operators General Insurance Company (Co-operators) denied a claim for a duty to defend Family and Children’s Services of Lanark, Leeds and Grenville (FCS), a children’s aid society, and Laridae Communications Inc. (Laridae) against data-related claims.

In August 2015, Laridae was instructed by FCS to conduct communication and marketing services. Less than a year later, a hacker accessed FCS’ internal network and obtained a confidential report with case files and investigations of nearly 300 people. The document was subsequently shared on social media. As a result of the disclosure, a multi-million-dollar class action suit was filed against FCS.

FCS and Laridae were insured by Co-operators in terms of a Commercial General Liability policy and Laridae, in addition, also in terms of a Professional Liability Policy. Both parties claimed that Co-operators owed them a duty to defend against the class action in terms of the policies.

Both policies contained data exclusion clauses, which provided that, “There shall be no coverage under this policy in connection with any claim based on, attributable to or arising directly or indirectly from the distribution, or display of “data” by means of an Internet Website, the Internet, an Intranet, Extranet, or similar device or system designed or intended for electronic communication of “data””. The court accordingly upheld Cooperators refusal to defend based on the policy exclusions.

South African courts have yet to substantively delve into the matter of cyber insurance. Nonetheless, it is evident that traditional insurance policies do not necessarily adequately cover cyber risk. Commercial general liability insurance is more commonly offered to protect businesses against asset damage such as property destruction, employee injury and natural disasters.

It is therefore vital for companies to assess the current risks brought about by COVID-19, particularly those associated with remote working and the current regulatory environment and establish whether they are adequately covered against potential cyber threats.

 

 

Byron O’Connor                         Vaughn Rajah

   

  Print to PDF

 
               

Tagged under: Insuralex South Africa, insurance coverage cybercrime south Africa, Insurance Lawyers South Africa

Search

Categories

  • Allende & Brea
  • Andıç Partners
  • Arzinger
  • Barze Taylor Noles Lowther LLC
  • Belzuz Abogados Spain
  • Belzuz Portugal
  • BLP Costa Rica
  • BLP El Salvador
  • BLP Guatemala
  • BLP Honduras
  • BLP Nicaragua
  • Brigard Urrutia
  • Bullivant Houser Bailey PC
  • Carter Perry Bailey LLP
  • D’Empaire
  • Ens
  • Estudio Carvallo Abogados
  • Ferrere Abogados
  • Gallivan, White & Boyd, P.A
  • Gross, Orad, Schlimoff & Co.
  • HeplerBroom LLC
  • Heuking Kühn Lüer Wojtek
  • Jáuregui y Del Valle
  • Kellerhals Carrard
  • Larson ⋅ King
  • Law Firm Paul Muylaert
  • Marlow, Adler, Abrams & Rotunno
  • Mason Hayes & Curran
  • MehaffyWeber
  • Meridian Lawyers
  • Moreno Baldivieso
  • News + Articles
  • Olczak-Klimek van der Kroft Węgiełek
  • Osterling Abogados
  • PD Law Offices
  • Pereyra & Asociados
  • Pérez Bustamante & Ponce
  • Peroni Sosa Tellechea Burt & Narvaja
  • Pinheiro Neto Advogados
  • Popovici Nițu Stoica & Asociații
  • Rainey, Kizer, Reviere & Bell
  • Reports
  • Sajic
  • Saldaña Carvajal & Vélez-Rivé PSC
  • SCP Soulié & Coste-Floret
  • Streefkerk Advocaten
  • Studio Legale Giorgetti
  • Sucre Arias Reyes
  • Tramposch & Partner
  • Uncategorized
  • Zuber & Company LLC.

OUR SPONSORS

  • The Group
  • Experience and Vision
  • Services
  • Members
  • News + Articles
  • Reports
  • Events
  • Contact Us
  • FAQ´s

Insuralex is not a law firm, does not practice law and does not provide legal advice or legal opinions. Insuralex members are not a partnership of law firms or lawyers and are not affiliated or in a relationship for the joint practice of law. Insuralex member firms are strictly independent firms.

Insuralex 2025    Cookie Policy | Conditions of use | Privacy Policy | FAQ's | Contact

TOP
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}