Insurance

Cyber-Related D&O Claims: Board Liability Underwriters Watch

On this page

For years, a data breach mostly meant a company-level problem: response costs, regulatory scrutiny, maybe a class action against the business itself. That's changed. Cyber-related D&O claims now regularly target the board and executive team personally, alleging they failed to oversee cybersecurity risk properly or mishandled disclosure after an incident, and underwriters have taken notice.

It's a claim against individual directors or officers, not the company itself, alleging a personal failure of oversight, disclosure, or response tied to a cybersecurity incident.

Shareholders or regulators bringing this kind of claim aren't arguing that the breach itself was preventable in some absolute sense. They're arguing that the board didn't ask the right questions beforehand, didn't disclose the incident properly afterward, or misrepresented the company's security posture to investors along the way. That framing matters because it shifts the claim from "the company was hacked" to "the people responsible for oversight failed at their job," which is a fundamentally different, and often harder to defend, allegation.

Why has this exposure grown so quickly?

Clearer disclosure requirements have given plaintiffs a more specific standard to measure board conduct against, which makes these claims easier to bring than they used to be.

The SEC's cybersecurity disclosure rule, adopted in 2023, requires public company boards to describe their role in overseeing cybersecurity risk in annual filings and to disclose material incidents on Form 8-K within four business days of determining materiality. Before this rule, plaintiffs had to argue a more abstract failure of general oversight duty. Now, there's a concrete, documented standard, did the board describe its oversight role accurately, did the company disclose within the required window, that a claim can point to directly.

Does cyber insurance cover claims against the board itself?

Generally no. Standalone cyber policies are built to cover the company's own breach response and liability costs, not personal claims against individual directors and officers.

This is one of the more consequential cyber insurance coverage gaps businesses run into, precisely because the two policies feel adjacent but respond to fundamentally different parties. A cyber policy paying for forensics and notification costs after a breach does nothing for a director facing a personal shareholder derivative suit over how the board handled that same breach. That claim needs to be picked up by the D&O policy, and specifically by whichever side of the D&O tower covers non-indemnifiable claims against individuals.

Claim typeWho it targetsWhich policy typically responds
Breach response costs (forensics, notification)The companyCyber insurance
Regulatory fine for inadequate securityThe companyCyber insurance, subject to jurisdiction and insurability
Shareholder derivative suit over oversight failureIndividual directors and officersD&O insurance
Securities claim over disclosure timing or accuracyThe company and/or individual officersD&O insurance
SEC enforcement action against an officer personallyThe individual officerD&O insurance

Are these claims mostly a public company issue?

Public companies face the specific SEC disclosure requirements, but private company boards face a similar, if less formalized, version of the same scrutiny from investors and other stakeholders.

Private companies aren't subject to Form 8-K disclosure timelines, but their boards still face pressure from investors, particularly private equity and venture stakeholders, who increasingly ask pointed questions about cybersecurity oversight during diligence and after an incident. This scrutiny extends particularly to sectors already sensitive to governance failures. Financial services boards, for example, face this exposure on top of an already dense regulatory environment, which is covered in more depth in this look at cyber insurance for financial services firms.

What should a board actually document to manage this exposure?

Regular, recorded cybersecurity briefings and a clear, documented process for evaluating disclosure obligations after an incident are the two things underwriters and plaintiffs' attorneys both look for.

A board that can point to minutes showing regular cybersecurity updates, a named executive responsible for reporting to the board, and a documented escalation process for potential incidents is in a materially stronger position than one that discussed cybersecurity only in passing, if at all. This isn't about the board becoming technical experts. It's about demonstrating an active, structured oversight process rather than a passive one, which is precisely what both the SEC's rule and shareholder plaintiffs are now testing for directly.

Are D&O underwriters pricing this exposure differently now?

Yes, board-level cyber oversight has become a specific line of inquiry on many D&O renewal applications, not just a general governance question.

Underwriters increasingly ask how often the board receives cybersecurity briefings, who owns that reporting relationship, and whether the company has a documented incident disclosure evaluation process. A board that can answer these questions with specifics, rather than general assurances, tends to see this reflected favorably in D&O terms, in much the same way strong security controls earn favorable terms on the cyber side.

The line between a company's cyber risk and its board's personal liability has narrowed considerably. Boards that treat cybersecurity oversight as a standing governance item, documented and repeated, rather than a reactive conversation after an incident, are in a far stronger position when a cyber-related D&O claim eventually tests that record.

Sources

Frequently Asked Questions

What is a cyber-related D&O claim?

It's a claim against a company's directors or officers alleging they failed to properly oversee, disclose, or respond to a cybersecurity risk or incident.

Does cyber insurance cover claims against the board directly?

Usually not. Claims targeting directors and officers personally typically need to be picked up by D&O coverage, not the standalone cyber policy.

What triggered the recent rise in cyber-related D&O claims?

Stricter disclosure requirements, including the SEC's cybersecurity rule, have given plaintiffs clearer grounds to challenge how boards handled disclosure.

What does the SEC's cybersecurity disclosure rule require of boards?

Boards must describe their role overseeing cybersecurity risk and ensure material incidents are disclosed on Form 8-K within four business days of determination.

Can a board be held liable even if the company had cyber insurance?

Yes. Cyber insurance addresses the company's breach response costs, not personal liability claims against individual directors and officers.

Do underwriters ask about board-level cyber oversight now?

Increasingly yes, particularly for D&O renewals, where documented board involvement in cybersecurity oversight is becoming a rating factor.

What should a board document to reduce this exposure?

Regular cybersecurity briefings, clear escalation procedures, and a documented process for evaluating disclosure obligations after an incident.

Is this exposure limited to public companies?

No. Private company boards face similar scrutiny from investors and stakeholders, though the disclosure rules themselves apply specifically to public companies.

Hitul Mistry

Hitul Mistry

CEO, Insurnest

An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.

View LinkedIn profile →
ShareLinkedInX

Read our latest blogs and research

Featured Resources

Insurance

Cyber Insurance Coverage Gaps Most Policies Still Miss

Common cyber insurance coverage gaps leave real losses unpaid even on well-priced policies. Here's what standard wording still tends to skip.

Read more
Insurance

Cyber Insurance for Financial Firms: Layering Cover Beyond Bonds

Cyber insurance for financial services firms has to layer on top of bank bonds and crime coverage, since those instruments were never built for modern cyber risk.

Read more
Reinsurance

D&O Reinsurance in the Age of Activism and ESG Litigation

How D&O reinsurance responds to shareholder activism, ESG and climate litigation, event-driven claims, and aggregation across Side A/B/C towers.

Read more

Meet Our Innovators:

We aim to revolutionize how businesses operate through digital technology driving industry growth and positioning ourselves as global leaders.

circle basecircle base
Pioneering Digital Solutions in Insurance

Insurnest

Empowering insurers, re-insurers, and brokers to excel with innovative technology.

Insurnest specializes in digital solutions for the insurance sector, helping insurers, re-insurers, and brokers enhance operations and customer experiences with cutting-edge technology. Our deep industry expertise enables us to address unique challenges and drive competitiveness in a dynamic market.

Get in Touch with us

Ready to transform your business? Contact us now!