Cyber Insurance Blog

Why D&O Insurance Should Be Part of the Boardroom Discussion

Why D&O Insurance Should Be Part of the Boardroom Discussion

When CrowdStrike’s faulty software update triggered widespread disruptions in July 2024, businesses worldwide experienced system outages, with airlines canceling thousands of flights and hospitals delaying procedures. The fallout soon reached the boardroom, as shareholders questioned whether company leadership had adequately overseen technology-related risks.

Similar questions have followed other high-profile cyber incidents. The Ticketmaster breach highlighted the risks associated with third-party vendors, while the SolarWinds supply chain attack put cyber security governance and disclosure practices under the microscope. Although the circumstances differed, each event raised questions about executive oversight.

Those questions often extend beyond Cyber Insurance and into D&O Insurance, particularly when shareholders and regulators challenge leadership decisions following a major incident.

Vendor Risk Is Expanding Board Exposure

Airport departures board showing widespread flight cancellations following a major technology outage or cyber disruption. Many organizations depend on a relatively small number of technology providers to support critical business functions. That reliance creates a challenge for leadership because a cyber event can originate outside the organization’s own network and still disrupt operations.

Boards are increasingly expected to understand:

  • Which vendors support critical business functions
  • How a disruption at a key provider could affect the organization
  • What the backup plan is if an essential service shuts down
  • How third-party cyber risks are monitored and reviewed

For many organizations, vendor risk is no longer viewed solely as a technology issue. It has become part of the broader governance responsibilities that boards are expected to oversee.

When Cyber Events Lead to Executive Scrutiny

Recent cyber incidents have placed executive oversight under greater scrutiny. In some cases, shareholders and regulators have questioned whether leadership adequately addressed cyber risks before the incident occurred.

Following CrowdStrike’s 2024 outage, Delta Air Lines publicly blamed the company for hundreds of millions of dollars in losses and pursued legal action. The outage also contributed to a sharp decline in CrowdStrike’s share price, drawing investor scrutiny and prompting shareholder attorneys to examine the company’s oversight of third-party software providers.

SolarWinds faced a different type of fallout. After attackers compromised the company’s software platform and used it to reach thousands of customers, including U.S. government agencies, the SEC sued both the company and its chief information security officer. Regulators alleged that SolarWinds presented a stronger picture of its cyber security practices than internal communications suggested.

These are not the types of allegations typically addressed by a Cyber policy. Claims involving executive oversight and fiduciary responsibilities often fall within the realm of D&O Insurance.

What Is D&O Insurance, and Why Should Brokers Be Talking About It?

These examples highlight a risk that Cyber Insurance alone may not address: allegations involving executive oversight and decision-making.

Cyber Insurance and D&O Insurance Address Different Risks

Judge's gavel symbolizing litigation, regulatory scrutiny, and executive liability following a major cyber incident. Many organizations purchase Cyber Insurance to help address the direct costs associated with a cyber event. Depending on the policy, that may include:

  • Forensic investigations
  • Breach response services
  • Legal expenses
  • Notification costs
  • Business interruption losses

While Cyber Insurance is designed to address many of the immediate consequences of an incident, it does not answer every question that may emerge afterward.

D&O Liability Insurance serves a different purpose. It helps protect directors and officers when claims allege wrongful acts committed while managing an organization.

That distinction becomes important after a major cyber incident. A ransomware attack, software failure, or vendor-related outage may trigger a Cyber Insurance claim. If shareholders later challenge the way leadership handled cyber risk before the incident occurred, the focus shifts from the event itself to executive decision-making.

The same event can create two separate exposures: one tied to the operational impact of the incident and another tied to allegations against directors and officers. That is where D&O Insurance coverage may become relevant.

Why This Can Create a Coverage Gap

Many organizations regularly review their Cyber Insurance because they can clearly see how a cyber incident could affect the business.

D&O Insurance often receives less attention.

As companies grow, acquire other businesses, enter new markets, adopt new technologies, or become increasingly dependent on third-party providers, their risk profile changes. Cyber Insurance limits are often revisited as those exposures evolve. D&O Insurance limits may not receive the same level of review.

That can create a disconnect between a company’s current risk environment and the protections in place for its directors and officers.

That does not mean every organization needs additional coverage. It does mean executive liability exposures deserve careful consideration as cyber risks continue to evolve.

Potential coverage gaps are easier to address before a cyber incident leads to shareholder claims or regulatory action.

Help Clients Prepare for More Than the Breach

ProWriters broker sits at laptop computer with dual monitors in cubicle, reviewing Tech E&O coverage policy options for client.The technical side of a cyber incident is often only the beginning. As CrowdStrike and SolarWinds demonstrated, the questions that follow can reach executive leadership.

ProWriters helps brokers evaluate both Cyber and D&O Insurance exposures so clients are prepared for the operational and liability consequences that can emerge from the same event. Whether the concern is a vendor-related outage, shareholder scrutiny, or executive liability, our team can help identify coverage solutions that address the full scope of the risk.

If your clients are reviewing their Cyber Insurance program, now is the time to review their D&O Insurance strategy as well.

Contact ProWriters to explore coverage solutions that help protect directors, officers, and organizations when cyber incidents lead to boardroom scrutiny.

Subscribe to Our Monthly Newsletter!

    Retail vs. Wholesale Brokerage

    Experts Weigh In

    Get the eBook