Viewpoint: The Cyber Risk Pendulum
Article 0 Comments Privacy risk is so 2014, right? Ten years ago, numerous retail and healthcare companies were hit with data breaches related to the exposure of credit card or healthcare data. Given many data breach claims, which included fines by state attorney generals and the payment card Industry, the cyber insurance market focused on privacy risk. This focus remained until 2017, when ransomware claims developed into more substantial matters, triggering large business interruption losses for carriers. Underwriters accordingly focused on ransomware exposure to minimize the potential for business interruption claims. However, in 2024, with new state privacy laws and renewed interest from the plaintiffs’ bar, carriers are once again seeing privacy claims, based on biometric, pixel, or chat technology. While ransomware has not gone away, attacks have evolved from network encryption to the theft and ransom of consumer or confidential corporate information. The cyber pendulum has swung back to privacy risk. Stephanie Snyder Frenier While all 50 states have data breach notification laws, many states have passed comprehensive privacy bills following the model set by the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). According to the International Association of Privacy Professionals, and...