Cyber-Related D&O Claims: Board Liability Underwriters Watch
On this page
- Why Underwriters Are Watching Board Exposure to Cyber-Related D&O Claims
- What exactly is a cyber-related D&O claim?
- Why has this exposure grown so quickly?
- Does cyber insurance cover claims against the board itself?
- Are these claims mostly a public company issue?
- What should a board actually document to manage this exposure?
- Are D&O underwriters pricing this exposure differently now?
- Sources
- Frequently Asked Questions
Why Underwriters Are Watching Board Exposure to Cyber-Related D&O Claims
For years, a data breach mostly meant a company-level problem: response costs, regulatory scrutiny, maybe a class action against the business itself. That's changed. Cyber-related D&O claims now regularly target the board and executive team personally, alleging they failed to oversee cybersecurity risk properly or mishandled disclosure after an incident, and underwriters have taken notice.
What exactly is a cyber-related D&O claim?
It's a claim against individual directors or officers, not the company itself, alleging a personal failure of oversight, disclosure, or response tied to a cybersecurity incident.
Shareholders or regulators bringing this kind of claim aren't arguing that the breach itself was preventable in some absolute sense. They're arguing that the board didn't ask the right questions beforehand, didn't disclose the incident properly afterward, or misrepresented the company's security posture to investors along the way. That framing matters because it shifts the claim from "the company was hacked" to "the people responsible for oversight failed at their job," which is a fundamentally different, and often harder to defend, allegation.
Why has this exposure grown so quickly?
Clearer disclosure requirements have given plaintiffs a more specific standard to measure board conduct against, which makes these claims easier to bring than they used to be.
The SEC's cybersecurity disclosure rule, adopted in 2023, requires public company boards to describe their role in overseeing cybersecurity risk in annual filings and to disclose material incidents on Form 8-K within four business days of determining materiality. Before this rule, plaintiffs had to argue a more abstract failure of general oversight duty. Now, there's a concrete, documented standard, did the board describe its oversight role accurately, did the company disclose within the required window, that a claim can point to directly.
Does cyber insurance cover claims against the board itself?
Generally no. Standalone cyber policies are built to cover the company's own breach response and liability costs, not personal claims against individual directors and officers.
This is one of the more consequential cyber insurance coverage gaps businesses run into, precisely because the two policies feel adjacent but respond to fundamentally different parties. A cyber policy paying for forensics and notification costs after a breach does nothing for a director facing a personal shareholder derivative suit over how the board handled that same breach. That claim needs to be picked up by the D&O policy, and specifically by whichever side of the D&O tower covers non-indemnifiable claims against individuals.
| Claim type | Who it targets | Which policy typically responds |
|---|---|---|
| Breach response costs (forensics, notification) | The company | Cyber insurance |
| Regulatory fine for inadequate security | The company | Cyber insurance, subject to jurisdiction and insurability |
| Shareholder derivative suit over oversight failure | Individual directors and officers | D&O insurance |
| Securities claim over disclosure timing or accuracy | The company and/or individual officers | D&O insurance |
| SEC enforcement action against an officer personally | The individual officer | D&O insurance |
Are these claims mostly a public company issue?
Public companies face the specific SEC disclosure requirements, but private company boards face a similar, if less formalized, version of the same scrutiny from investors and other stakeholders.
Private companies aren't subject to Form 8-K disclosure timelines, but their boards still face pressure from investors, particularly private equity and venture stakeholders, who increasingly ask pointed questions about cybersecurity oversight during diligence and after an incident. This scrutiny extends particularly to sectors already sensitive to governance failures. Financial services boards, for example, face this exposure on top of an already dense regulatory environment, which is covered in more depth in this look at cyber insurance for financial services firms.
What should a board actually document to manage this exposure?
Regular, recorded cybersecurity briefings and a clear, documented process for evaluating disclosure obligations after an incident are the two things underwriters and plaintiffs' attorneys both look for.
A board that can point to minutes showing regular cybersecurity updates, a named executive responsible for reporting to the board, and a documented escalation process for potential incidents is in a materially stronger position than one that discussed cybersecurity only in passing, if at all. This isn't about the board becoming technical experts. It's about demonstrating an active, structured oversight process rather than a passive one, which is precisely what both the SEC's rule and shareholder plaintiffs are now testing for directly.
Are D&O underwriters pricing this exposure differently now?
Yes, board-level cyber oversight has become a specific line of inquiry on many D&O renewal applications, not just a general governance question.
Underwriters increasingly ask how often the board receives cybersecurity briefings, who owns that reporting relationship, and whether the company has a documented incident disclosure evaluation process. A board that can answer these questions with specifics, rather than general assurances, tends to see this reflected favorably in D&O terms, in much the same way strong security controls earn favorable terms on the cyber side.
The line between a company's cyber risk and its board's personal liability has narrowed considerably. Boards that treat cybersecurity oversight as a standing governance item, documented and repeated, rather than a reactive conversation after an incident, are in a far stronger position when a cyber-related D&O claim eventually tests that record.
Sources
Frequently Asked Questions
What is a cyber-related D&O claim?
It's a claim against a company's directors or officers alleging they failed to properly oversee, disclose, or respond to a cybersecurity risk or incident.
Does cyber insurance cover claims against the board directly?
Usually not. Claims targeting directors and officers personally typically need to be picked up by D&O coverage, not the standalone cyber policy.
What triggered the recent rise in cyber-related D&O claims?
Stricter disclosure requirements, including the SEC's cybersecurity rule, have given plaintiffs clearer grounds to challenge how boards handled disclosure.
What does the SEC's cybersecurity disclosure rule require of boards?
Boards must describe their role overseeing cybersecurity risk and ensure material incidents are disclosed on Form 8-K within four business days of determination.
Can a board be held liable even if the company had cyber insurance?
Yes. Cyber insurance addresses the company's breach response costs, not personal liability claims against individual directors and officers.
Do underwriters ask about board-level cyber oversight now?
Increasingly yes, particularly for D&O renewals, where documented board involvement in cybersecurity oversight is becoming a rating factor.
What should a board document to reduce this exposure?
Regular cybersecurity briefings, clear escalation procedures, and a documented process for evaluating disclosure obligations after an incident.
Is this exposure limited to public companies?
No. Private company boards face similar scrutiny from investors and stakeholders, though the disclosure rules themselves apply specifically to public companies.

Hitul Mistry
CEO, Insurnest
An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.
View LinkedIn profile →