The recent ShinyHunters cyberattack, which impacted hundreds of organizations through a PeopleSoft software vulnerability, highlights the growing importance—and complexity—of cyber insurance coverage. As businesses grapple with ransomware demands, operational disruptions, and potential data exposure, policyholders should understand not only what their cyber policies cover, but also how insurers may evaluate claims arising from large-scale incidents.
In a recent Law360 article examining the insurance implications of the attack, Sherilyn Pastornotes that cyber policies can provide broad first-party coverage, including ransomware payments, business interruption losses, system restoration costs, and, in some cases, reputational harm and customer goodwill expenses.
Sheri also emphasizes that many policies require detailed proof of loss to support claims for reasonable expenses, interruption costs and beyond, and that insurers, who are focused on their bottoms line in the wake of a mass incident, will scrutinize them and want to discuss the event when discussing limits and premiums on renewals.
