© Copyright 2026 by Anderson Kill P.C. ClickySoft - WordPress Development Company

Risk Management Magazine
The ransomware attack against United Healthcare subsidiary Change Healthcare, which froze medical claims and payments throughout the United States for weeks, should serve as a wake-up call to all companies and organizations not only to maximize cyber defenses, but also to ensure that their insurance policies will respond to losses and liabilities stemming from a cyberattack. Policyholders should know that the “human factor” does not preclude cyber coverage, despite insurance companies routinely arguing that claims are barred or limited in coverage when employees, managers or other human beings factored into the losses suffered from a cyber incident.
For example, an early 2024 case involving a “layered” cyber insurance program sold to Southwest Airlines did not involve a hacker. Instead, it involved a computer system failure that excess cyber insurance company Liberty Insurance argued were partly due to the airline’s management decisions. Specifically, after a three-day outage in 2016, Southwest submitted a cyber coverage claim for $77 million in losses from massive delays and disruptions to its operations.
The primary insurance company and three excess insurers paid the claim, but Liberty Insurance, the last layer in the tower, demurred. Southwest sought coverage for costs incurred through various programs and initiatives aimed at assisting the nearly half-million customers affected by system failure, including:
...
To read this full article, click here.


© Copyright 2026 by Anderson Kill P.C. ClickySoft - WordPress Development Company