Cyber Policy Draft
Cyber Policy Draft
Cyber Policy Draft
Policy No.4056/0000000000
Item 1 Policyholder :
Item 2 Address:
Item 3 Professional Services
Item 4 Policy Period: From:
To:
Item 5 Extended Reporting XX Days at Nil additional premium
Period:
1.2
Item 10 New Subsidiary XX%
Acquisition %
Item 11 Prior Acts Exclusion For Insuring Clause 1.1
Date: For Insuring Clause 1.2
a) Toll-freenumber:1800-2666
b) Postal Address:
ICICI Lombard General Insurance Company Limited
ICICI Lombard House,
414, Veer Savarkar Marg,
Near SiddhiVinayakTemple,
Prabhadevi, Mumbai 400025
c) E-mail:[email protected]
Policy Wording
Scope of Cover
In consideration of the receipt of premium, and in reliance of the statements made
and the information contained in the proposal form (which are a part of and form the
basis of this Policy) and subject to the terms and conditions of this Policy, the Insurer
and the Policyholder agree as follows.
1 Insuring Clauses:
The following insurance covers are solely for Claims which are first made against the
Insured, by a Third Party, during the Policy Period (or the Extended Reporting Period,
if applicable) and reported to the Insurer as required under this Policy
1.1 Security & The Insurer will pay the Loss arising out of a Security Breach
Privacy and/or Privacy Breach by the Insured that results in:
Liability (a) theft, loss, or Unauthorized Disclosure of Personal
Information;
(b) alteration, corruption, destruction, deletion, or damage
to Data stored in Computer System;
(c) denial of access to the authorised Third Party to the
Data stored in Computer System.
1.2 Multimedia The Insurer will pay the Loss arising out of Multimedia
Liability Activities of the Insured that results in:
(a) defamation including but not limited to libel, slander,
trade libel, infliction of emotional distress, outrage,
outrageous conduct or other tort related to
disparagement or harm to the reputation or character
of any person or organization;
(b) violation of the rights of privacy or publicity of an
individual, including false light and public disclosure of
private facts, commercial mis-appropriation of name,
persona, voice or likeness;
(c) infringement of copyright, domain name, title, or
slogan, trademark, service mark, service name, or
trade name
(d) plagiarism, misappropriation or theft of ideas or
IRDA Registration No. 115
Cyber Liability Insurance (Misc 139) Page 4 of 22
Attached to and forming part of
Policy No.4056/0000000000
2 Extensions:
2.1 Extended If this Policy is not:
Reporting (a) renewed by the Insurer or the Policyholder; nor
Period (b) replaced by the Insurer, nor
(c) cancelled by the Insurer for a breach of the terms of
this Policy by an Insured,
2.4 Business The Insurer will pay the Business Interruption Loss, incurred
Interruption Loss by the Company, upto the limit mentioned in Item 8a of the
Schedule.
3 Exclusions:
Insurer shall not be liable for Loss, based upon, arising out of, attributable to or in
any manner involving:
3.2 Bodily Injury/ any Bodily Injury or Property Damage, except that this
Property Damage exclusion shall not apply to wrongful infliction of
emotional distress or mental anguish arising out of
actual or alleged Multimedia Activities, Privacy Breach,
Security Breach as covered under Insuring Clauses 1.1
and 1.2
not apply:
3.6 Prior Acts any act, error, omission, Privacy Breach or Security
Breach that occurred prior to the Prior Acts exclusion
date specified at Item 11 of the Schedule
The Insurer shall not be liable for Business Interruption Loss arising out of, based
upon or attributable to:
3.17 Government Entity Any seizure, confiscation or destruction of a Computer
or Public Authority System by order of any government entity or public
authority.
3.18 Other Exclusions (i) any network or systems interruption
caused by loss of communications with
a Third Party computer system,
resulting in the inability of the Company
to communicate with those systems;
(ii) legal costs or legal expenses of any
type;
(iii) updating, upgrading, enhancing or
replacing any Computer System to a
level beyond that which existed prior to
sustaining Network Loss;
(iv) unfavorable business conditions; or
(v) the removal of software program errors
or vulnerabilities.
4 Definitions:
4.2 Breach means the laws and regulations for data protection and
Notice Law privacy in any country that requires notice to be given for an
actual or potential breach of laws and regulation relating to
Personal Information.
4.3 Business
Interruptionmeans the reduction in net profit that but for a Material
Loss Interruption, the Company would have earned (and which is
attributable to a loss of revenue) in the period from the
expiration of the Waiting Period until service is restored (but in
any event no later than 120 days after the commencement of
the Material Interruption) before payment of income taxes and
after accounting for savings and reasonable mitigation.
4.4 Claim means
(a) Any written demand for monetary or non-monetary
relief; or
4.10 Credit means reasonable fees, costs and expenses incurred, with the
Monitoring prior written consent of the Insurer, in respect of credit
Costs monitoring services for 12 months to affected individuals
following a Privacy Breach.
4.11 Crisis means reasonable fees, costs and expenses paid or incurred,
Management with the prior written consent of the Insurer, in respect of a
Costs public relations consultant to avert or mitigate material
damage to the Company’s reputation or goodwill arising from
a Crisis Management Event.
4.13 Cyber means reasonable fees, costs and expenses paid, with the
Extortion prior written consent of the Insurer, to security consultants
Costs retained by the Company and cash, marketable goods or
services paid by the Company to prevent or end a Cyber
Extortion Threat
4.14 Cyber means a credible threat or series of related threats directed at
Extortion the Insured to corrupt, damage, destruction, or introduce a
Threat Malicious Code, or a denial of service attack to Computer
System
4.15 Damages means
(a) Any monetary compensation the Insured is legally
4.18 Defence means reasonable fees, costs and expenses incurred with the
Costs
IRDA Registration No. 115
Cyber Liability Insurance (Misc 139) Page 11 of 22
Attached to and forming part of
Policy No.4056/0000000000
(a) Damages
4.25 Malicious means any software used to erase, corrupt or damage data or
Code network system or gain access to Computer Systems or
harmful software code, including but not limited to computer
viruses, Trojan horses, keystroke loggers, spyware, adware,
worms and logic bombs.
4.26 Material means any interruption in, or suspension of, the service
Interruption provided by the Computer System directly caused by a
Security Breach.
4.27 Multimedia means the publication or broadcast of any digital media
Activities content, other than computer software or the actual goods,
products or services described, illustrated or displayed.
4.33 Privacy means reasonable fees, costs and expenses incurred by the
Notification Insured, with the prior written consent of the Insurer, towards
Costs their legal obligation to comply with a Breach Notice Law to
provide notification to individuals who are required to be
notified.
For the purpose of this Policy Subsidiary shall also include any
incorporated entity or partnership, but only to the extent of the
Company’s financial interest in that entity.
For any Subsidiary or Insured thereof, cover under this Policy
shall only apply while such entity is a subsidiary of the
Policyholder
4.38 Third Party means any entity or natural person; except the following
(a) any Insured; or
(b) any entity which the Company manages or operates
(c) Any entity or natural person having more than 15%
stake in the Company
(d) Consultant
4.39 Unauthorized means disclosure that is not authorized by the Insured and is
Disclosure without knowledge or consent of the Control Group.
4.40 Waiting means the number of hours set forth in Item 8b of the
Period Schedule that must elapse once a Material Interruption has
begun before a Business Interruption Loss can begin to be
incurred.
The Insurer’s maximum aggregate liability under the Policy during the Policy Period
(or Extended Reporting Period, if applicable) is limited to the Limit of Liability, unless
expressly specified to the contrary in the Policy. The sub-limit for any cover or
Extension is a part of and not in addition to the Limit of Liability.
The Insurer will only pay for any amount of Loss which is in excess of Retention. The
Company will be liable for the Retention which will remain uninsured. A single
Retention shall apply to all Loss arising out of, based upon or attributable to
continuous, repeated or related Claim/Loss.
6 General Conditions:
6.1 Claim (a) The Insured shall give written notice to the Insurer of:
Reporting
(i) any circumstances that may reasonably be
expected to give rise to a Claim;
(ii) any Claim made against the Insured,
during the Policy Period (or Extended Reporting Period if
applicable).
(c) The Insured shall give written notice to the Insurer with
respect to Privacy Breach , Security Breach, Crisis
management Event , Cyber Extortion Threat , and share
the following details
6.4 Consent The Insured shall not admit or assume any liability, enter into any
settlement agreement, make any settlement offer, stipulate to
any judgment, or incur any costs without the prior written
consent of the Insurer. Only those settlements, stipulated
judgments and costs which have been consented to by the
Insurer and arising from Claims defended in accordance with this
Policy shall be recoverable as Loss under the terms of this Policy.
However, the Insurer's consent shall not be unreasonably
withheld.
In the event that the Insurer and the Insured cannot agree within
fifteen (15) days as to the amount of costs to be advanced under
the Policy, then the Insurer shall advance Defence Costs which
the Insurer believes to be covered under this Policy until a
different amount shall be agreed upon or determined pursuant
to the provisions of this Policy and applicable law.
6.6 Payment of The Insurer will pay all covered Costs in excess of the Retention ,
Costs covered by this Policy promptly after sufficiently detailed
invoices for those costs are received by the Insurer.
In the event that the Insurer advances any costs and it is finally
established that the Insurer has no liability for all or any portion
of these costs hereunder, the Insured, shall repay to the Insurer,
all monies advanced and so determined to be reimbursable.
The Crisis Management Costs can only be incurred from the date
of notification to the Insurer in accordance with clause 6.1 to the
date falling 185 days after such notification.
6.7 Other If other valid insurance with any other Insurer is already available
Insurance to the Insured covering a Loss also covered by this Policy, this
Policy shall apply in excess of such other insurance and shall not
contribute with such other insurance.
6.8 Subrogation The Insured shall do everything necessary for the purpose of
enforcing any rights, remedies, obtaining relief or indemnity
from other parties to which the Insurer is become entitled upon
the Insurer paying for any Loss under this Policy, whether before
or after indemnification.
6.9 Maintenance The Insured will take all reasonable steps to maintain data and
of Security information security procedures to no lesser standard than
disclosed in the proposal form.
6.13 Assignment Assignment of interest under this Policy shall not bind the Insurer
unless its consent is specifically provided for.
6.14 Observance The due observance and fulfillment of the terms, conditions and
of Terms and endorsements of this Policy in so far as they relate to anything to
Conditions be done or complied with by the Insured, shall be a condition
precedent to any liability on the Insurer’s part to make any
payment under this Policy.
6.16 Cancellation The Policyholder may cancel the Policy by giving 15 days notice
in writing to the Insurer and the Insurer shall refund premium for
the unexpired Policy Period at the short period scales specified
below. The Insurer may cancel the Policy on grounds of mis-
representation, fraud, non-disclosure of material facts or non-co-
operation of the insured by giving 30 days notice in writing to
the Insured and the Insurer shall refund a pro-rata premium for
the unexpired Policy Period. The Insured will not get any
cancellation refund in case there is a Loss /circumstance
reported under the Policy.
6.18 Title & The titles and headings used in this Policy, including any
Headings Endorsements, are for the purposes of reference only and shall
not otherwise affect the meaning of this Policy. Singular includes
the plural, and vice versa. Words in bold typeface(except
headings) have special meaning and are defined In Section 4.
6.19 Grievance In case the Insured is aggrieved in any way, the Insured should
Redressal call the Insurers at toll free number: 1800 2666 or email the
Insurer at [email protected].
If the Insured is not satisfied with the resolution, then the Insured
may successively write to the manager- service quality, corporate
manager- service quality, national manager- operations & finally
director-services and business development at the following
address:
[email protected] [email protected]
n n
Office of the Insurance
Ombudsman,
1st Floor, Kalpana Arcade
Building,
Bazar Samiti Road, Bahadurpur,
PATNA – 800006
Tel No: 0612-2680952
Email id :
[email protected].
6.20 Maintenance The Insured will take all reasonable steps to maintain data and
of Security information security procedures to no lesser standard than
disclosed in the proposal form.
The Insured will ensure that back-up systems and processes are
maintained to no lesser standard than disclosed in the proposal
form and that the ability to restore such data is regularly tested
(at least every six (6) months).
6.21 Sanctions The Insurer shall not be deemed to provide cover under this
Clause Policy or be liable to pay any claim under the Policy to the extent
that the provision of such cover or payment of such claim would
expose the Insurer to any sanction, prohibition or restriction
under United Nations resolutions or the trade or economic
sanctions, laws or regulations of the European Union, United
Kingdom or United States of America.