American Oil and Gas Reporter - December 2017 - 80

SpecialReport: Insurance Update
policies. For example, a 2011 cyber attack
stole confidential exploration and bidding
data from several major oil companies.
The coordinated attack, which had been
secretly targeting energy companies for
as many as four years, utilized both traditional methods of exploiting software vulnerabilities in computer operating systems
and "social engineering" techniques such
as spear-phishing. Security and privacy
losses tied to social engineering are particularly crucial components of cyber risk
mitigation, given that they may not be
covered by traditional insurance policies.
Third-Party Cyber Coverage
As its name suggests, third-party cyber
insurance protects policyholders from liabilities to third parties harmed by cyber
attacks, and may cover civil penalties
and other costs imposed by regulators or
government agencies. Covered costs under
such policies can include defense costs,
judgments, and settlement payments, as
well as certain fines and penalties. However, third-party cyber liability policies
do not automatically provide full coverage
for all possible claim scenarios involving
a cyber liability, such as situations where
a hacking incident causes bodily injury,
property damage, business interruption
or other physical losses.
Many businesses have redoubled efforts
to protect their most important digital
assets, intellectual property and critical
infrastructure in light of recent cyber attacks targeting so-called "crown jewels."
But more traditional consumer-facing aspects of many oil and gas operations still
are being targeted by hackers.
For example, an international oil company learned that an employee of a vendor
had utilized employees' personal information to facilitate an unemployment insurance claim scam in Texas, underscoring
the importance of protecting information
in all aspects of a company's operations,
however routine. In 2014, that same company reportedly had personal information
of approximately 7,000 customers in New
Zealand and Australia stolen by online
hackers. Loss arising from data breach
claims may result in both first-party (e.g.,
recovering stolen data) and third-party
(e.g., data privacy lawsuit) losses.
Crime Coverage
Crime insurance protects policyholders
from dishonest acts of third parties, including employee theft, forgery and alteration, computer fraud and funds transfer
80 THE AMERICAN OIL & GAS REPORTER

fraud, ransom and extortion, robbery, and
counterfeiting. While not a traditional
"cyber" coverage, crime insurance has
become critical to any comprehensive
cyber insurance program because it can
protect against financial loss caused by
social engineering threats.
As oil and gas companies continue to
increase the strength and resilience of
their computer systems, many hackers
simply choose to target the one entry
point that cannot be protected with software updates: employees. Last February,
the cause of an attempted spyware infection at a Middle Eastern company was
one employee opening an infected spreadsheet, which he had received from an
elaborate but fraudulent online "person"
with whom the employee had been communicating for more than a month. Using
this persona, criminals had cultivated
social media connections with numerous
mid-level technicians, software developers,
and administrators at oil and gas, technology, and consulting companies.
Traditional liability policies may present significant coverage gaps that do not
apply to cyber-related losses, in part because cyber threats are a relatively new
phenomenon from an insurance perspective. As a result, court rulings are inconsistent about whether cyber losses are
covered under general liability policies,
differing over whether traditional terms
such as "publication" and "tangible property" apply to electronic theft or compromise of digital information.
For that reason, policyholders should
not assume that their legacy insurance
policies are adequate to protect against
claims involving cyber attacks. Furthermore,
many traditional policies now contain express exclusions for cyber-related losses.
That said, legacy policies still can
play an important role in certain cyber
claim scenarios. The inherent risk of
physical loss resulting from a cyber event
underscores the importance of minimizing
coverage gaps between traditional and
cyber insurance policies, such as where
third-party cyber liability policies contain
bodily injury and property damage exclusions. For that reason, in the event of
a loss involving a cyber event, it is
essential that the policyholder examine
potential coverage under both traditional
and cyber insurance coverage.
Common Coverage Issues
Both legacy policies (general liability,
excess liability, pollution liability and

property) and cyber-specific insurance
products may not provide adequate coverage for all risks that arise from a cyber
event. There are some challenging exclusions and other limitations to evaluate
when assessing coverage for cyber risks.
The first is environmental liability.
Liability policies of all kinds may include
various forms of "pollution" exclusions,
which bar coverage for loss arising from
the discharge or release of pollutants.
Cyber attacks on oil and gas companies
frequently pose a risk of environmental
liability, but cyber insurance policies may
limit or bar coverage entirely for claims
involving the release of pollutants. Even
where companies purchase pollution-specific coverage, the definition of a pollutant
may not adequately cover liability arising
from cyber attack-related releases.
As noted, many cyber insurance policies
also exclude coverage for claims involving
bodily injury, property damage or other
physical loss, even where such loss is
caused by a cyber event. The industry
faces significant exposures for physical
loss following hacks of drilling platforms,
pipelines, storage tanks and other equipment. Policyholders should maintain coverage for physical losses through environmental and traditional general liability
insurance to minimize coverage gaps.
Liability policies also commonly include broadly worded exclusions barring
coverage for any loss arising from "war"
or "terrorism." Many cyber attacks may
have direct or indirect ties to terrorism.
This is particularly true in the oil and gas
sector, where certain industry participants
are state-sponsored and often targeted by
extremists. Companies should attempt to
exempt cyber terrorism from these exclusions through negotiations with their
insurers at the time of program renewal.
Another common exclusion is "liability
assumed by contract," which bars coverage
for fees, indemnification or other costs
that the policyholder is obligated to pay
due to a contract. One federal district
court case rejected a policyholder's attempt
to recover fees paid following a 2013
breach in which hackers obtained and
posted on the Internet 60,000 credit card
numbers belonging to the policyholder's
customers. The court held that the fees,
which were imposed by the bank under
its servicing agreement with the policyholder, were excludable under the policy's
contractual liability exclusion. The court
reached this conclusion notwithstanding
evidence that the policyholder had ex-



American Oil and Gas Reporter - December 2017

Table of Contents for the Digital Edition of American Oil and Gas Reporter - December 2017

Contents
American Oil and Gas Reporter - December 2017 - 1
American Oil and Gas Reporter - December 2017 - 2
American Oil and Gas Reporter - December 2017 - Contents
American Oil and Gas Reporter - December 2017 - 4
American Oil and Gas Reporter - December 2017 - 5
American Oil and Gas Reporter - December 2017 - 6
American Oil and Gas Reporter - December 2017 - 7
American Oil and Gas Reporter - December 2017 - 8
American Oil and Gas Reporter - December 2017 - 9
American Oil and Gas Reporter - December 2017 - 10
American Oil and Gas Reporter - December 2017 - 11
American Oil and Gas Reporter - December 2017 - 12
American Oil and Gas Reporter - December 2017 - 13
American Oil and Gas Reporter - December 2017 - 14
American Oil and Gas Reporter - December 2017 - 15
American Oil and Gas Reporter - December 2017 - 16
American Oil and Gas Reporter - December 2017 - 17
American Oil and Gas Reporter - December 2017 - 18
American Oil and Gas Reporter - December 2017 - 19
American Oil and Gas Reporter - December 2017 - 20
American Oil and Gas Reporter - December 2017 - 21
American Oil and Gas Reporter - December 2017 - 22
American Oil and Gas Reporter - December 2017 - 23
American Oil and Gas Reporter - December 2017 - 24
American Oil and Gas Reporter - December 2017 - 25
American Oil and Gas Reporter - December 2017 - 26
American Oil and Gas Reporter - December 2017 - 27
American Oil and Gas Reporter - December 2017 - 28
American Oil and Gas Reporter - December 2017 - 29
American Oil and Gas Reporter - December 2017 - 30
American Oil and Gas Reporter - December 2017 - 31
American Oil and Gas Reporter - December 2017 - 32
American Oil and Gas Reporter - December 2017 - 33
American Oil and Gas Reporter - December 2017 - 34
American Oil and Gas Reporter - December 2017 - 35
American Oil and Gas Reporter - December 2017 - 36
American Oil and Gas Reporter - December 2017 - 37
American Oil and Gas Reporter - December 2017 - 38
American Oil and Gas Reporter - December 2017 - 39
American Oil and Gas Reporter - December 2017 - 40
American Oil and Gas Reporter - December 2017 - 41
American Oil and Gas Reporter - December 2017 - 42
American Oil and Gas Reporter - December 2017 - 43
American Oil and Gas Reporter - December 2017 - 44
American Oil and Gas Reporter - December 2017 - 45
American Oil and Gas Reporter - December 2017 - 46
American Oil and Gas Reporter - December 2017 - 47
American Oil and Gas Reporter - December 2017 - 48
American Oil and Gas Reporter - December 2017 - 49
American Oil and Gas Reporter - December 2017 - 50
American Oil and Gas Reporter - December 2017 - 51
American Oil and Gas Reporter - December 2017 - 52
American Oil and Gas Reporter - December 2017 - 53
American Oil and Gas Reporter - December 2017 - 54
American Oil and Gas Reporter - December 2017 - 55
American Oil and Gas Reporter - December 2017 - 56
American Oil and Gas Reporter - December 2017 - 57
American Oil and Gas Reporter - December 2017 - 58
American Oil and Gas Reporter - December 2017 - 59
American Oil and Gas Reporter - December 2017 - 60
American Oil and Gas Reporter - December 2017 - 61
American Oil and Gas Reporter - December 2017 - 62
American Oil and Gas Reporter - December 2017 - 63
American Oil and Gas Reporter - December 2017 - 64
American Oil and Gas Reporter - December 2017 - 65
American Oil and Gas Reporter - December 2017 - 66
American Oil and Gas Reporter - December 2017 - 67
American Oil and Gas Reporter - December 2017 - 68
American Oil and Gas Reporter - December 2017 - 69
American Oil and Gas Reporter - December 2017 - 70
American Oil and Gas Reporter - December 2017 - 71
American Oil and Gas Reporter - December 2017 - 72
American Oil and Gas Reporter - December 2017 - 73
American Oil and Gas Reporter - December 2017 - 74
American Oil and Gas Reporter - December 2017 - 75
American Oil and Gas Reporter - December 2017 - 76
American Oil and Gas Reporter - December 2017 - 77
American Oil and Gas Reporter - December 2017 - 78
American Oil and Gas Reporter - December 2017 - 79
American Oil and Gas Reporter - December 2017 - 80
American Oil and Gas Reporter - December 2017 - 81
American Oil and Gas Reporter - December 2017 - 82
American Oil and Gas Reporter - December 2017 - 83
American Oil and Gas Reporter - December 2017 - 84
American Oil and Gas Reporter - December 2017 - 85
American Oil and Gas Reporter - December 2017 - 86
American Oil and Gas Reporter - December 2017 - 87
American Oil and Gas Reporter - December 2017 - 88
American Oil and Gas Reporter - December 2017 - 89
American Oil and Gas Reporter - December 2017 - 90
American Oil and Gas Reporter - December 2017 - 91
American Oil and Gas Reporter - December 2017 - 92
American Oil and Gas Reporter - December 2017 - 93
American Oil and Gas Reporter - December 2017 - 94
American Oil and Gas Reporter - December 2017 - 95
American Oil and Gas Reporter - December 2017 - 96
American Oil and Gas Reporter - December 2017 - 97
American Oil and Gas Reporter - December 2017 - 98
American Oil and Gas Reporter - December 2017 - 99
American Oil and Gas Reporter - December 2017 - 100
American Oil and Gas Reporter - December 2017 - 101
American Oil and Gas Reporter - December 2017 - 102
American Oil and Gas Reporter - December 2017 - 103
American Oil and Gas Reporter - December 2017 - 104
American Oil and Gas Reporter - December 2017 - 105
American Oil and Gas Reporter - December 2017 - 106
American Oil and Gas Reporter - December 2017 - 107
American Oil and Gas Reporter - December 2017 - 108
https://www.nxtbook.com/nxtbooks/aogr/202404
https://www.nxtbook.com/nxtbooks/aogr/202403
https://www.nxtbook.com/nxtbooks/aogr/202402
https://www.nxtbook.com/nxtbooks/aogr/202401
https://www.nxtbook.com/nxtbooks/aogr/202312
https://www.nxtbook.com/nxtbooks/aogr/202311
https://www.nxtbook.com/nxtbooks/aogr/pbios_202310
https://www.nxtbook.com/nxtbooks/aogr/202309
https://www.nxtbook.com/nxtbooks/aogr/202308
https://www.nxtbook.com/nxtbooks/aogr/202307
https://www.nxtbook.com/nxtbooks/aogr/202306
https://www.nxtbook.com/nxtbooks/aogr/202305
https://www.nxtbook.com/nxtbooks/aogr/202304
https://www.nxtbook.com/nxtbooks/aogr/202303
https://www.nxtbook.com/nxtbooks/aogr/202302
https://www.nxtbook.com/nxtbooks/aogr/202301
https://www.nxtbook.com/nxtbooks/aogr/202212
https://www.nxtbook.com/nxtbooks/aogr/202211
https://www.nxtbook.com/nxtbooks/aogr/202210
https://www.nxtbook.com/nxtbooks/aogr/202209
https://www.nxtbook.com/nxtbooks/aogr/202208
https://www.nxtbook.com/nxtbooks/aogr/202207
https://www.nxtbook.com/nxtbooks/aogr/202206
https://www.nxtbook.com/nxtbooks/aogr/202205
https://www.nxtbook.com/nxtbooks/aogr/202204
https://www.nxtbook.com/nxtbooks/aogr/202203
https://www.nxtbook.com/nxtbooks/aogr/202202
https://www.nxtbook.com/nxtbooks/aogr/202201
https://www.nxtbook.com/nxtbooks/aogr/202112
https://www.nxtbook.com/nxtbooks/aogr/202111
https://www.nxtbook.com/nxtbooks/aogr/pbios_202110
https://www.nxtbook.com/nxtbooks/aogr/202109
https://www.nxtbook.com/nxtbooks/aogr/202108
https://www.nxtbook.com/nxtbooks/aogr/202107
https://www.nxtbook.com/nxtbooks/aogr/202106
https://www.nxtbook.com/nxtbooks/aogr/202105
https://www.nxtbook.com/nxtbooks/aogr/202104
https://www.nxtbook.com/nxtbooks/aogr/202103
https://www.nxtbook.com/nxtbooks/aogr/202102
https://www.nxtbook.com/nxtbooks/aogr/202101
https://www.nxtbook.com/nxtbooks/aogr/202012
https://www.nxtbook.com/nxtbooks/aogr/202011
https://www.nxtbook.com/nxtbooks/aogr/202010
https://www.nxtbook.com/nxtbooks/aogr/202009
https://www.nxtbook.com/nxtbooks/aogr/202008
https://www.nxtbook.com/nxtbooks/aogr/202007
https://www.nxtbook.com/nxtbooks/aogr/202006
https://www.nxtbook.com/nxtbooks/aogr/202005
https://www.nxtbook.com/nxtbooks/aogr/202004
https://www.nxtbook.com/nxtbooks/aogr/202003
https://www.nxtbook.com/nxtbooks/aogr/202002
https://www.nxtbook.com/nxtbooks/aogr/202001
https://www.nxtbook.com/nxtbooks/aogr/201912
https://www.nxtbook.com/nxtbooks/aogr/201911
https://www.nxtbook.com/nxtbooks/aogr/201910
https://www.nxtbook.com/nxtbooks/aogr/201909
https://www.nxtbook.com/nxtbooks/aogr/201908
https://www.nxtbook.com/nxtbooks/aogr/201907
https://www.nxtbook.com/nxtbooks/aogr/201906
https://www.nxtbook.com/nxtbooks/aogr/201905
https://www.nxtbook.com/nxtbooks/aogr/201904
https://www.nxtbook.com/nxtbooks/aogr/201903
https://www.nxtbook.com/nxtbooks/aogr/201902
https://www.nxtbook.com/nxtbooks/aogr/201901
https://www.nxtbook.com/nxtbooks/aogr/201812
https://www.nxtbook.com/nxtbooks/aogr/201811
https://www.nxtbook.com/nxtbooks/aogr/201810
https://www.nxtbook.com/nxtbooks/aogr/pbios_201810
https://www.nxtbook.com/nxtbooks/aogr/201809
https://www.nxtbook.com/nxtbooks/aogr/201808
https://www.nxtbook.com/nxtbooks/aogr/201807
https://www.nxtbook.com/nxtbooks/aogr/201806
https://www.nxtbook.com/nxtbooks/aogr/201805
https://www.nxtbook.com/nxtbooks/aogr/201804
https://www.nxtbook.com/nxtbooks/aogr/201803
https://www.nxtbook.com/nxtbooks/aogr/201802
https://www.nxtbook.com/nxtbooks/aogr/201801
https://www.nxtbook.com/nxtbooks/aogr/201712
https://www.nxtbook.com/nxtbooks/aogr/201711
https://www.nxtbook.com/nxtbooks/aogr/201710
https://www.nxtbook.com/nxtbooks/aogr/201709
https://www.nxtbook.com/nxtbooks/aogr/201708
https://www.nxtbook.com/nxtbooks/aogr/201707
https://www.nxtbook.com/nxtbooks/aogr/201706
https://www.nxtbook.com/nxtbooks/aogr/201705
https://www.nxtbook.com/nxtbooks/aogr/201704
https://www.nxtbook.com/nxtbooks/aogr/201703
https://www.nxtbook.com/nxtbooks/aogr/201702
https://www.nxtbook.com/nxtbooks/aogr/201701
https://www.nxtbook.com/nxtbooks/aogr/201612
https://www.nxtbook.com/nxtbooks/aogr/201611
https://www.nxtbook.com/nxtbooks/aogr/201610
https://www.nxtbook.com/nxtbooks/aogr/pbios2016_programguide
https://www.nxtbook.com/nxtbooks/aogr/201609
https://www.nxtbook.com/nxtbooks/aogr/201608
https://www.nxtbook.com/nxtbooks/aogr/201607
https://www.nxtbook.com/nxtbooks/aogr/201606
https://www.nxtbook.com/nxtbooks/aogr/201605
https://www.nxtbook.com/nxtbooks/aogr/201604
https://www.nxtbook.com/nxtbooks/aogr/201603
https://www.nxtbook.com/nxtbooks/aogr/201602
https://www.nxtbook.com/nxtbooks/aogr/201601
https://www.nxtbook.com/nxtbooks/aogr/201512
https://www.nxtbook.com/nxtbooks/aogr/201511
https://www.nxtbook.com/nxtbooks/aogr/201510
https://www.nxtbook.com/nxtbooks/aogr/201509
https://www.nxtbook.com/nxtbooks/aogr/201508
https://www.nxtbook.com/nxtbooks/aogr/201507
https://www.nxtbook.com/nxtbooks/aogr/201506
https://www.nxtbook.com/nxtbooks/aogr/201505
https://www.nxtbook.com/nxtbooks/aogr/201504
https://www.nxtbook.com/nxtbooks/aogr/201503
https://www.nxtbook.com/nxtbooks/aogr/201502
https://www.nxtbook.com/nxtbooks/aogr/201501
https://www.nxtbook.com/nxtbooks/aogr/201412
https://www.nxtbook.com/nxtbooks/aogr/201411
https://www.nxtbook.com/nxtbooks/aogr/201410
https://www.nxtbook.com/nxtbooks/aogr/201409
https://www.nxtbook.com/nxtbooks/aogr/pbios2014_programguide
https://www.nxtbook.com/nxtbooks/aogr/201408
https://www.nxtbook.com/nxtbooks/aogr/201407
https://www.nxtbook.com/nxtbooks/aogr/201406
https://www.nxtbook.com/nxtbooks/aogr/201405
https://www.nxtbook.com/nxtbooks/aogr/201404
https://www.nxtbook.com/nxtbooks/aogr/201403
https://www.nxtbook.com/nxtbooks/aogr/201402
https://www.nxtbook.com/nxtbooks/aogr/201401
https://www.nxtbook.com/nxtbooks/aogr/201312
https://www.nxtbook.com/nxtbooks/aogr/201311
https://www.nxtbook.com/nxtbooks/aogr/201310
https://www.nxtbook.com/nxtbooks/aogr/201309
https://www.nxtbook.com/nxtbooks/aogr/201308
https://www.nxtbook.com/nxtbooks/aogr/201307
https://www.nxtbook.com/nxtbooks/aogr/201306
https://www.nxtbook.com/nxtbooks/aogr/201305
https://www.nxtbook.com/nxtbooks/aogr/201304
https://www.nxtbook.com/nxtbooks/aogr/201303
https://www.nxtbook.com/nxtbooks/aogr/201302
https://www.nxtbook.com/nxtbooks/aogr/201301
https://www.nxtbook.com/nxtbooks/aogr/201212
https://www.nxtbook.com/nxtbooks/aogr/201211
https://www.nxtbook.com/nxtbooks/aogr/201210
https://www.nxtbook.com/nxtbooks/aogr/201209
https://www.nxtbook.com/nxtbooks/aogr/2012_pbios
https://www.nxtbook.com/nxtbooks/aogr/201208
https://www.nxtbook.com/nxtbooks/aogr/201207
https://www.nxtbook.com/nxtbooks/aogr/201206
https://www.nxtbook.com/nxtbooks/aogr/201205
https://www.nxtbook.com/nxtbooks/aogr/201204
https://www.nxtbook.com/nxtbooks/aogr/201203
https://www.nxtbook.com/nxtbooks/aogr/201202
https://www.nxtbook.com/nxtbooks/aogr/201201
https://www.nxtbook.com/nxtbooks/demo/aogr_clone
https://www.nxtbook.com/nxtbooks/aogr/201112
https://www.nxtbookmedia.com