Professional Liability Insurance and Cyber Coverage
May 25, 2016
Did you know that your Lawyers’ Professional Liability Insurance Group Policy with the Canadian Lawyers Insurance Association (CLIA) has what is generally referred to as a “cyber coverage” exclusion.
Condition 3.9.1 of your Insurance Policy excludes “claims arising out of or from damage to or loss of use of tangible or intangible property, loss of data, disclosure of confidential information, or any other loss which is directly or indirectly connected with the receipt or transmission of a computer virus or other damaging program via the internet or in any other electronic manner, or through unauthorized interference with an internet connection, network, computer or telecommunication device.”
CLIA has recently clarified what this policy exclusion means. Essentially there is no coverage for most cyber claims, including claims where the law firm itself suffers damage as a result of unauthorized interference from things like cyber-attack, computer melt-down due to viruses, theft, or hacking of electronic equipment or data. Further, there is no coverage where a client suffers damage as a result of the theft, cyber-attack or hacking of your firm’s computers.
What does this mean for you? If you lose your cell phone, your laptop is stolen from your vehicle or computers or servers are taken from your office in a break-in, your professional liability coverage will not respond. Likewise, if you are a victim of “hacking” – like the recent well-publicized cyber-attack on Bay Street firms involved in the unsuccessful Potash Corp sale – damage suffered by the firm or its clients would not be covered.
So, what should you do to protect yourself from exposure to claims arising from lost equipment or compromised data? You may find some coverage for theft or cyber-attacks in your existing general office liability policy. Read that policy carefully and check on your coverage limits for lost or stolen devices and data interruption at the same time. There are also some commercially available cyber policies specifically designed to cover “hacker” and “cyber-attacks”. Check those out with your insurance broker.
More importantly, do what you can to prevent cyber-attacks, and consult with a computer security expert about firewalls, encryption, anti-virus software, secure passwords, intrusion detection systems and other ways to protect your equipment and your clients’ information. Protect your portable devices with secure passwords, and keep them locked and stored in a safe place when you are not using them. And ensure all your electronic data is backed up.