Cyber liability
Everything BestInsurance Research holds on cyber liability: 40 cited checks, 1 answered questions, 1 worked examples and 16 source records carrying 124 recorded claims. Free to read, no account, nothing to fill in.
40 checks that bear on this line
These are the deterministic checks the worksheets run. Each one cites the source it rests on, so a check is readable as a published rule whether or not you ever open the worksheet. Nothing is submitted and no field you type leaves your browser.
Cyber Control Readiness
No published control baseline is recorded, so there is nothing to map your answers onto.
Two current public baselines cover everything this module asks about: NIST Cybersecurity Framework (CSF) 2.0, published 2024-02-26, which organizes outcomes under GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, and CISA Cross-Sector Cybersecurity Performance Goals Version 2.0, dated December 2025, which is aligned to those same CSF 2.0 functions and which the CISA program page describes as voluntary goals that strive to help small- and medium-sized organizations kickstart their cybersecurity efforts by prioritizing investment in a limited number of essential actions. Mapping to a named, dated edition means an answer you give today can be checked against a fixed public text later.
Multi-factor authentication is recorded as not in place on any account.
CISA CPG 3.F states that organizations require MFA to access assets using the strongest available method, and that all IT accounts leverage MFA with priority given to privileged administrative accounts. NIST CSF 2.0 carries the same outcome as PR.AA-03, users, services, and hardware are authenticated.
Multi-factor authentication is recorded as partial, and no answer here says which accounts are outside it.
A partial answer will be read differently by every reader unless the uncovered set is named. CPG 3.F asks that all IT accounts use MFA and that privileged administrative accounts for key systems be prioritized, so the question that matters is whether the uncovered accounts are administrative or remotely reachable, not how many there are.
Multi-factor authentication is in place but no dated written evidence of it is held.
This is a different open item from not having the control. Cyber underwriting has moved toward asking for control evidence rather than accepting a yes on its own, and CSF 2.0 GV.PO-01 treats policy as something established, communicated, and enforced, which implies it exists in writing. An enforced control with no artifact is hard to confirm and hard to re-confirm at the next renewal.
No offline or immutable backup copy is recorded.
CISA CPG 3.O directs organizations to securely store backups offsite and offline, and notes that adversaries delete data and disable recovery services to prevent system recovery. CSF 2.0 PR.DS-11 states that backups of data are created, protected, maintained, and tested. A backup that your own administrator credentials can reach is reachable by anyone who takes those credentials.
Offline or immutable backups are in place but no written backup inventory and retention schedule is held.
CPG 3.O asks organizations to develop a list of all maintained backups, including installation media, license keys, configuration information, and the retention period for the information. Without that list, nobody can say during an incident what exists, how far back it goes, or what is needed to stand a system up again.
No restore has ever been tested.
CPG 3.O directs that backups and recovery be tested on a recurring basis, no less than once per year, and that the integrity of backups be validated before restoration is started. CSF 2.0 adds RC.RP-03, the integrity of backups and other restoration assets is verified before using them for restoration.
Backups are recorded as in place while the restore test is recorded as never performed.
These two answers describe two different things, and taken together they say the recovery path is unproven. CSF 2.0 PR.DS-11 makes testing part of the outcome itself, backups of data are created, protected, maintained, and tested, and CPG 3.O pairs storing backups offline with testing backups and recovery at least annually.
Restores are tested but no dated written result for the most recent test is held.
CPG 3.O expects testing on a recurring basis with integrity validated before restoration, and CSF 2.0 ID.IM-02 treats improvements identified from tests and exercises as an outcome in its own right. A test that produced no record cannot show a date, a scope, or what was fixed afterwards.
The last recorded restore test is more than twelve months old.
CPG 3.O sets the cadence explicitly: test backups and recovery on a recurring basis, no less than once per year. The date you entered is more than twelve months old, so the stated annual cadence has lapsed.
No endpoint detection is recorded on laptops, desktops, or servers.
CPG 4.A directs organizations to implement both signature-based mechanisms and non-signature-based mechanisms focused on behavior, heuristics, or anomalies to detect and eradicate malicious code at system endpoints, organization-wide. CSF 2.0 DE.CM-01 covers the monitoring side, networks and network services are monitored to find potentially adverse events.
Endpoint detection is in place but no dated coverage report is held.
Coverage is the part of this control that drifts, because new devices arrive and old ones leave. CPG 4.A scopes malicious code detection organization-wide and asks that the software be updated, active, and configured to scan automatically, which is a claim about every device rather than about the tool. A dated coverage report is the artifact that supports the claim.
No defined patch cadence is recorded.
CPG 2.B directs organizations to implement a vulnerability management program to patch and mitigate misconfigured software in a timely manner across all organizational assets, including those that face the internet, and notes that adversaries frequently target unpatched and misconfigured systems. CSF 2.0 PR.PS-02 states that software is maintained, replaced, and removed commensurate with risk.
Patch cadence is recorded as partial, which leaves open which assets are outside the schedule and why.
CPG 2.B scopes patching to all organizational assets, to include those that face the internet, and in its operational technology note asks that where patching is not possible compensating controls such as segmentation or monitoring be applied and recorded. A partial answer becomes answerable once the exceptions are named and the reason for each is written down.
A patch cadence is followed but there is no written patching standard and no record of what was patched when.
CPG 2.B asks for a vulnerability management program and for progress to be monitored through artifacts such as a plan of action and milestones, a risk register, or risk detail reports, with responsibilities assigned and procedures followed. Those are all written things, so a cadence that leaves no record cannot demonstrate timeliness after the fact. CSF 2.0 PR.PS-02 is the underlying outcome.
The number of individuals whose personal information you hold is recorded as unknown.
CPG 2.A asks organizations to maintain a regularly updated inventory of all organizational assets, expressly including data, and CPG 3.K asks you to identify critical electronic file types and data to protect while in transit and at rest, which may include personally identifiable information. CSF 2.0 places asset management in the IDENTIFY function. An unknown here also means notification exposure cannot be scoped later, since deadlines run from discovery rather than from when you finish counting.
Payment card transactions are accepted and awareness training is not recorded as in place for all users.
CPG 3.J names the specialized roles that warrant additional, role-based cybersecurity training, and finance personnel, senior leadership, and anyone with access to business-critical data are on that list alongside system administrators. Where money moves, the roles that move it are the ones the training is aimed at, and CPG 3.K asks separately that critical electronic file types and data be identified and protected while in transit and at rest.
Neither email filtering nor sender authentication is recorded as configured.
CPG 3.L states that on all corporate email infrastructure STARTTLS is enabled, SPF and DKIM are enabled, and DMARC is enabled and set to reject, in order to reduce risk from spoofing, phishing, and interception. CSF 2.0 PR.DS-01 and PR.DS-02 cover protecting data at rest and in transit.
Email filtering and sender authentication are in place but no dated record of the published configuration is held.
CPG 3.L is unusual among these controls because it is externally checkable, and it names a specific end state including DMARC set to reject. Recording what is published, and on what date, keeps a later answer honest if someone changes the policy value in the meantime.
Administrator rights are never re-reviewed.
CPG 3.G states that user accounts do not have administrator privileges, that administrators maintain separate user accounts for activities unrelated to their admin role such as business email and web browsing, and that privileges are re-evaluated on a recurring basis to validate continued need for a given set of permissions. CPG 3.H, a separate goal, asks that all user accounts, system roles, and processes operate with the minimum privileges necessary and that quarterly reviews of access permissions and role assignments be performed. CPG 3.D adds that user access should be reviewed and accounts disabled when inactive for a specified period, for example thirty days. CSF 2.0 PR.AA-05 requires access permissions to be defined in policy, managed, enforced, and reviewed with least privilege in mind.
Privileged access is reviewed but no dated review record or written offboarding checklist is held.
CPG 3.D asks for a defined and enforced administrative process to offboard staff, contractors, and vendors, including return of tokens or badges and revocation of all access. A review that leaves no record cannot show when it last happened or what changed, which is exactly what a later reviewer asks.
No incident response plan is recorded.
CPG 1.C directs organizations to develop, maintain, update, and regularly exercise incident response plans for common and organization-specific threat scenarios. CPG 4.B assumes the plan already exists, because it says that if an adverse event is suspected you follow the protocol outlined in the incident response plan to escalate. CSF 2.0 RS.MA-01 states that the incident response plan is executed in coordination with relevant third parties once an incident is declared.
An incident response plan exists in practice but is not written down.
This is the sharpest case of the difference between having a control and being able to evidence it. CPG 1.C asks that IR plans be developed, maintained, updated, and drilled, which are all acts performed on a document, and CSF 2.0 RS.MA-01 speaks of the plan being executed in coordination with third parties, which assumes third parties can be handed something. An unwritten plan also cannot be found during the outage that triggers it.
The incident response plan was last exercised more than twelve months ago.
CPG 1.C sets the cadence explicitly: IR plans should be reviewed and drilled, at a minimum, on an annual basis, and asks that drills be realistic and include all relevant stakeholders. The date you entered is more than twelve months old, so that stated cadence has lapsed. CSF 2.0 ID.IM-02 is the outcome the drill is for, improvements identified from security tests and exercises.
No security awareness training is recorded for people with accounts.
CPG 3.J directs that new employees receive initial cybersecurity training prior to accessing computer systems and that at least annual training be provided for all organizational users, covering recognizing social engineering attempts, reporting suspicious activity, and basic cyber hygiene. Its scope reaches employees, contractors, partners, suppliers, and other users of non-public resources. CSF 2.0 PR.AT-01 is the matching outcome.
Security awareness training happens but no dated completion record is held.
CPG 3.J is a coverage claim about all organizational users, not about whether a course exists, so the only thing that supports it is a record of who completed it and when. Underwriting review of cyber controls has moved toward asking for that kind of artifact rather than a yes.
The most recent training round closed more than twelve months ago.
CPG 3.J sets at least annual cybersecurity training for all organizational users. The date you entered is more than twelve months old, so the annual cadence has lapsed even though a programme exists.
The written evidence for these controls has not been assembled in one place.
Every control in this module resolves to an artifact somebody can read: a policy, a configuration export, a coverage report, a dated test result, a completion record, a backup inventory. Cyber underwriting increasingly turns on that evidence rather than on the answer alone, and assembling it once means the same pack serves renewal, a contract request, and an internal review.
A submission date is recorded while the control evidence is recorded as not assembled.
You have set yourself a date and have not yet gathered the artifacts the control answers rest on. The artifacts CPG 2.0 implies for these goals, including the backup inventory under 3.O, the drilled IR plan under 1.C, and the training records under 3.J, all take days to produce rather than minutes.
Nobody has been identified who can confirm the control answers in writing.
Applications are signed, and the control answers above are the part someone will be held to. CPG 1.A places cybersecurity roles, responsibilities, and authorities in writing as a governance outcome, asking that all roles and responsibilities involving cybersecurity be documented in an organization's cybersecurity policy, and CSF 2.0 GV.PO-01 treats policy as established, communicated, and enforced rather than assumed.
An outside provider runs IT and the security and notification terms of that agreement have not been read.
CPG 2.0 added net-new goals addressing managed service providers, least privilege, and incident communication procedures, and CPG 1.D covers notifying a customer of security incidents and vulnerabilities within a risk-informed time frame. Several answers above describe work the provider performs, so the agreement decides who must tell you, how fast, and what evidence you can obtain.
A hosted system holds customer or client records and its security and notification terms have not been read.
CPG 1.D concerns notifying a customer of security incidents and vulnerabilities within a risk-informed time frame, which is the same obligation running toward you from whoever holds your data. If a notification clock starts on discovery, the practical question is when the holder of the data tells you, because that is when your own clock can start.
A contract requires cyber or privacy liability coverage and no cyber coverage is recorded.
You have recorded a contractual requirement to carry this coverage and recorded none in force, which is a mismatch between an obligation you have accepted and what your programme shows. CSF 2.0 places supply chain and third-party commitments inside the GOVERN function as category GV.SC, Cybersecurity Supply Chain Risk Management, so this belongs with your governance records rather than being treated as a purchasing detail; the controls recorded above are a separate matter from the coverage question and neither substitutes for the other.
The recorded cyber limit is lower than the limit the strictest contract requires.
This is arithmetic on the two numbers you entered: the limit recorded on your coverage is less than the limit the contract demands. A shortfall against a contractual figure is a contract compliance question first, and it sits inside the same third-party governance work that CSF 2.0 collects under GV.SC, Cybersecurity Supply Chain Risk Management; matching numbers still does not mean two policies respond to the same thing.
A contract requires cyber coverage and the limit it demands is not recorded.
You recorded a contractual requirement to carry this coverage without recording the limit the clause names. Until that figure is written down there is nothing to compare a policy against, so the requirement cannot be checked at all. CSF 2.0 places third-party commitments inside the GOVERN function as category GV.SC, Cybersecurity Supply Chain Risk Management, which is where an obligation of this kind belongs on the record.
The limit a contract requires is recorded, and the limit actually carried is not.
You recorded what the clause demands but not what your own coverage carries, so the comparison this module would otherwise run cannot be run. The figure is on your declarations page rather than a matter of recollection. CSF 2.0 collects third-party commitments under GV.SC, Cybersecurity Supply Chain Risk Management.
Protected health information is handled, an incident is recorded as discovered more than sixty calendar days ago, and notification is recorded as not sent.
45 CFR 164.404(b) provides that a covered entity shall provide the required notification without unreasonable delay and in no case later than sixty calendar days after discovery of a breach. The discovery date you entered is more than sixty calendar days ago, so on the dates recorded that outer limit has already passed. Whether the event is a breach requiring notification at all is a legal determination, not something this module can decide.
Protected health information is handled, an incident was discovered within the last sixty calendar days, and notification is recorded as not sent.
45 CFR 164.404(b) requires notification without unreasonable delay and in no case later than sixty calendar days after discovery. The discovery date you entered is within the last sixty calendar days, so the outer limit has not yet passed; note that the without unreasonable delay wording means the sixty days is a ceiling and not a permitted waiting period.
The sector recorded is healthcare, and CISA publishes Healthcare Sector-Specific Goals beyond the cross-sector set.
CISA lists Sector-Specific Goals as available now for the Healthcare sector, described as voluntary practices that go beyond the Cross-Sector CPGs. Those goals are a published text you can map to by name, in the same way as the cross-sector goals in CPG 2.0, Version 2.0, December 2025.
A prior cyber incident is recorded while no written incident response plan is recorded.
The business has already been through the event the plan exists for, and the plan is still recorded as absent. CPG 1.C treats plan development, maintenance, and drilling as the mechanism for identifying improvements, and CSF 2.0 ID.IM-02 makes improvements identified from tests and exercises an explicit outcome.
Examples touching this line
Lines that share a worksheet with this one
A worksheet that covers this line also covers these, which usually means the same decision touches all of them.
Source ledger
16 sources. Every citation number above resolves to a record below. Nothing here sits behind an account.
- [1]The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29)(opens the original record on National Institute of Standards and Technology, U.S. Department of Commerce)National Institute of Standards and Technology, U.S. Department of CommerceSecondaryPrimaryJurisdiction USPublished February 26, 2024Effective February 26, 2024Last checked August 31, 2026Updates: major-revisionID
nist-csf-2-0What this source supports (15)
- The current edition is CSF 2.0, published February 26, 2024, available free of charge at https://doi.org/10.6028/NIST.CSWP.29.
- CSF 2.0 organizes outcomes under six Functions: GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS), RECOVER (RC).
- PR.AA-03: Users, services, and hardware are authenticated.
- PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
- PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.
- PR.DS-11: Backups of data are created, protected, maintained, and tested.
- PR.PS-02: Software is maintained, replaced, and removed commensurate with risk.
- DE.CM-01: Networks and network services are monitored to find potentially adverse events.
- RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared.
- RC.RP-03: The integrity of backups and other restoration assets is verified before using them for restoration.
- GV.PO-01: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities, and is communicated and enforced.
- ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties.
- The CSF does not prescribe how outcomes should be achieved; it offers a taxonomy of high-level cybersecurity outcomes usable by any organization regardless of size, sector, or maturity.
- PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected. PR.DS-02: The confidentiality, integrity, and availability of data-in-transit are protected.
- Cybersecurity Supply Chain Risk Management (GV.SC) is a category within the GOVERN function, covering cyber supply chain risk management processes identified, established, managed, monitored, and improved by organizational stakeholders.
Active - [2]Cross-Sector Cybersecurity Performance Goals, Version 2.0(opens the original record on Cybersecurity and Infrastructure Security Agency, U.S. Department of Homeland Security)Cybersecurity and Infrastructure Security Agency, U.S. Department of Homeland SecuritySecondaryPrimaryJurisdiction USPublished December 1, 2025Effective December 1, 2025Last checked August 31, 2026Updates: major-revisionID
cisa-cpg-2-0What this source supports (23)
- Cover page reads Cross-Sector Cybersecurity Performance Goals, Version 2.0, December 2025, Cybersecurity and Infrastructure Security Agency; marked TLP:CLEAR.
- Contents are organized as 1. GOVERN, 2. IDENTIFY, 3. PROTECT, 4. DETECT, 5. RESPOND, 6. RECOVER, aligning to NIST Cybersecurity Framework version 2.0.
- Goal 1.C MAINTAIN INCIDENT RESPONSE PLANS: organizations develop, maintain, update, and regularly exercise IR plans; IR plans should be reviewed and drilled, at a minimum, on an annual basis.
- Goal 1.D SUPPLY CHAIN INCIDENT REPORTING AND VULNERABILITY DISCLOSURE addresses notifying a customer of security incidents and vulnerabilities within a risk-informed time frame.
- Goal 2.C MITIGATE KNOWN VULNERABILITIES: implement a vulnerability management program to patch and mitigate misconfigured software in a timely manner, covering all organizational assets including those that face the internet.
- Goal 3.D REVOKE CREDENTIALS FOR DEPARTING STAFF: a defined and enforced administrative process to offboard staff including revocation of all access; review user access and disable accounts when inactive for a specified period, for example 30 days.
- Goal 3.F IMPLEMENT MULTIFACTOR AUTHENTICATION (MFA): organizations require MFA to access assets using the strongest available method; options sorted high to low are phishing-resistant MFA, then mobile app-based soft tokens, then SMS or voice only when no other options are possible; all IT accounts leverage MFA, prioritizing privileged administrative accounts.
- Goal 3.H IMPLEMENT THE PRINCIPLES OF LEAST PRIVILEGE: user accounts do not have administrator privileges, administrators maintain separate user accounts for non-admin activity, and privileges are re-evaluated on a recurring basis to validate continued need.
- Goal 3.J IMPLEMENT CYBERSECURITY TRAINING: new employees receive initial cybersecurity training prior to accessing computer systems, and at least annual cybersecurity training is provided for all organizational users covering recognizing social engineering, reporting suspicious activity, and basic cyber hygiene.
- Goal 3.M ENABLE EMAIL SECURITY: on all corporate email infrastructure STARTTLS is enabled, SPF and DKIM are enabled, and DMARC is enabled and set to reject.
- Goal 3.O MAINTAIN SYSTEM BACKUPS AND RESTORATION ABILITY: develop a list of all maintained backups including installation media, license keys, configuration information, and retention period; securely store backups offsite and offline; test backups and recovery on a recurring basis, no less than once per year; validate the integrity of backups before initiating restoration.
- Goal 4.A ESTABLISH MALICIOUS CODE DETECTION: implement signature-based and non-signature-based mechanisms to detect and eradicate malicious code at system endpoints, organization-wide.
- Goal 4.B IDENTIFY ADVERSE EVENTS: define clear criteria and processes for adverse events, and if an adverse event is suspected follow the protocol outlined in the incident response plan to escalate.
- The CPGs are voluntary and strive to help small- and medium-sized organizations kickstart cybersecurity efforts by prioritizing a limited number of essential actions.
- Goal 1.A ESTABLISH CYBERSECURITY RESPONSIBILITIES: roles, responsibilities, and authorities related to the organization's cybersecurity program are established, communicated, enforced, and aligned within the organization and external partners, and all roles and responsibilities involving cybersecurity should be documented in an organization's cybersecurity policy; scope reaches C-suite personnel, critical section leadership, physical and cybersecurity personnel, third-party contractors, vendors, and suppliers; NIST CSF 2.0 reference GV.RR-02.
- Goal 1.B MANAGE CYBERSECURITY OVERSIGHT is a separate goal: policies for managing the cybersecurity program are reviewed at least annually, updated when changes are applied, communicated, and enforced; NIST CSF 2.0 reference GV.OV-03.
- Goal 2.A MANAGE ORGANIZATIONAL ASSETS: maintain a regularly updated inventory of all organizational assets, meaning data, hardware, software, systems, facilities, and personnel, with IT and OT assets determined to be critical for business or operational functions updated on a more frequent basis.
- Goal 3.K UTILIZE STRONG ENCRYPTION: use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of network communications, and identify critical electronic file types and data to protect while in transit and at rest, which may include personally identifiable information and sensitive, proprietary or trade secret information.
- Goal 2.B MITIGATE KNOWN VULNERABILITIES: implement a vulnerability management program to patch and mitigate misconfigured software in a timely manner, with a scope of all organizational assets, to include those that face the internet; monitor risk response progress through tools such as plan of action and milestones, risk registers, and risk detail reports; assign responsibilities and ensure procedures are followed. Goal 2.C is a different goal, OBTAIN INDEPENDENT VALIDATION OF CYBERSECURITY CONTROLS.
- Goal 3.G ADMINISTRATORS MAINTAIN SEPARATE USER AND PRIVILEGED ACCOUNTS: user accounts do not have administrator privileges, administrators maintain separate user accounts for activities unrelated to their admin role, such as business email and web browsing, and privileges are re-evaluated on a recurring basis to validate continued need for a given set of permissions.
- Goal 3.H IMPLEMENT THE PRINCIPLES OF LEAST PRIVILEGE: all user accounts, system roles, and processes operate with the minimum privileges necessary to perform their tasks, and quarterly reviews of access permissions and role assignments are performed to verify compliance with established policies.
- Goal 3.L ENABLE EMAIL SECURITY: on all corporate email infrastructure (1) STARTTLS is enabled, (2) Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) are enabled, and (3) Domain-based Message Authentication, Reporting, and Conformance (DMARC) is enabled and set to reject; the stated outcome is reduced risk from spoofing, phishing, and interception. Goal 3.M is a different goal, DISABLE AUTORUN AND MACROS BY DEFAULT.
- On small organizations the PDF says only that each organization faces unique cybersecurity challenges and that small- and medium-sized organizations may have limited budgets, staffing, and expertise; one of the stated criteria for a goal is that it be reasonably straightforward and not cost-prohibitive for small- and medium-sized entities to successfully implement. The voluntary and kickstart framing quoted in this module comes from the CISA program page, not from this PDF.
Active - [3]Cross-Sector Cybersecurity Performance Goals (program page)(opens the original record on Cybersecurity and Infrastructure Security Agency, U.S. Department of Homeland Security)Cybersecurity and Infrastructure Security Agency, U.S. Department of Homeland SecuritySecondaryPrimaryJurisdiction USPublished December 1, 2025Effective December 1, 2025Last checked August 31, 2026Updates: as-neededID
cisa-cpg-program-pageWhat this source supports (7)
- CISA's Cross-Sector Cybersecurity Performance Goals 2.0 are a subset of cybersecurity practices aimed at meaningfully reducing risks to critical infrastructure operations and the American people.
- Cross-Sector CPGs 2.0 have been updated to align to the NIST Cybersecurity Framework (CSF) 2.0 functions and build upon the foundation established in version 1.0.1, with the addition of the GOVERN function.
- Net-new goals address managed service providers (MSPs), the principle of least privileges, and incident communication procedures.
- The CPGs are intended as a baseline set of practices broadly applicable across critical infrastructure and a benchmark for operators to measure and improve.
- Sector-Specific Goals are available now for the Chemical, Energy (Distribution and Distributed Energy Resources), Healthcare, and Information Technology sectors, with Financial Services SSGs listed as coming.
- A new CSET assessment module for CPG 2.0 and an updated CPG 2.0 Checklist are noted as becoming available in Q1 2026.
- These voluntary Cross-Sector CPGs strive to help small- and medium-sized organizations kickstart their cybersecurity efforts by prioritizing investment in a limited number of essential actions with high-impact security outcomes.
Active - [4]Cyber COPE (R) Transforming Cyber Underwriting (by Patrick Thielen)(opens the original record on Chubb)ChubbCarrier officialSecondaryJurisdiction USLast checked August 31, 2026Updates: Standalone whitepaper; no published revision schedule.ID
chubb-cyber-cope-whitepaperWhat this source supports (4)
- The paper defines COPE as Construction, Occupancy, Protection, and Exposures, and calls it a straightforward and effective method of examining diverse measurements to help underwriters make better decisions about property risk.
- The paper refers to COPE as a time-tested property underwriting model.
- The paper opens with four sample questions it says insurance companies ask so they can properly and thoroughly underwrite risks presented for coverage: how tall is your office building, how close is the nearest fire hydrant, does the building have an alarm system, and are you in a flood zone.
- The paper states that in the 1700s the risk of fire made it difficult for many commercial property owners to secure the insurance coverage they needed, and that over time the industry adopted the COPE concept.
Fetched today. WebFetch returned PDF binary, so the text was extracted locally with pdftotext -layout and read directly. The title page reads Cyber COPE (registered mark) Transforming Cyber Underwriting, with no colon, and credits Patrick Thielen; the registered-trademark symbol is transliterated as (R) here to keep the record ASCII. No publication date appears in the extracted text, so publishedDate is left unknown. This is a cyber underwriting paper that describes the property COPE model it is adapting; it is cited only for its description of COPE, not as a commercial property underwriting guide. It says nothing about whether carriers must use COPE or about how application forms were designed.
Active - [5]45 CFR 164.404 - Notification to individuals (HIPAA Breach Notification Rule)(opens the original record on Cornell Legal Information Institute, reproducing the Code of Federal Regulations)Cornell Legal Information Institute, reproducing the Code of Federal RegulationsSecondarySecondaryJurisdiction USThird-party reproductionPublished January 25, 2013Effective March 26, 2013Last checked August 31, 2026Updates: on-amendmentID
cfr-45-164-404-liiWhat this source supports (2)
- Paragraph (b), Implementation specification: Timeliness of notification, provides that a covered entity shall provide the notification required by paragraph (a) without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.
- The 60 calendar day period runs from discovery of the breach, and is an outer limit rather than a safe harbor, because notification must also be without unreasonable delay.
ActiveReproduction - [6]11 NYCRR 73.1 - Definitions (Regulation 121, claims-made policies)(opens the original record on Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations))Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations)SecondarySecondaryJurisdiction NYThird-party reproductionLast checked August 31, 2026Updates: changes when the New York Department of Financial Services amends Regulation 121; the mirror is republished on Cornell's own scheduleID
ny-11-nycrr-73-1What this source supports (5)
- Defines a claims-made policy as an insurance policy that covers liability for injury or damage the insured is legally obligated to pay, including injury or damage occurring prior to the effective date of the policy but subsequent to the retroactive date, if any, arising out of incidents, acts or omissions, as long as the claim is first made during the policy period or any extended reporting period.
- Defines an occurrence policy as one that covers liability for injury or damage arising out of incidents, acts or omissions that occurred during the policy period, and where a claim may be made during or subsequent to the policy period.
- Defines a retroactive date as a date concurrent with the effective date of the policy, or a particular date prior to the effective date of the policy, upon which the insurer and insured agree in the policy that policy coverage will be applicable.
- Defines extended reporting period coverage (tail coverage) as coverage for that period of time specified in the policy wherein claims first made after termination of coverage under the policy, for injury or damage that occurs during the policy term or that occurs on or after the retroactive date, if any, will be considered made during the policy term.
- Defines the claims-made relationship as the period between the effective date of the first claims-made policy between the insurer and the insured and the cancellation or nonrenewal of the last consecutive claims-made policy between such parties, where there has been no gap in coverage, and states that it does not include any period covered by extended reporting period coverage.
Fetched 2026-08-31 and all five definitions read verbatim off the page. This is Cornell LII's unofficial republication, not the state's own publication, so it is recorded as a secondary mirror of primary law; the official citation is 11 NYCRR 73.1. The page does not state an adoption or amendment date, so publishedDate and effectiveDate are left unknown rather than guessed.
ActiveReproduction - [7]11 NYCRR 73.2 - Applicability (Regulation 121, claims-made policies)(opens the original record on Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations))Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations)SecondarySecondaryJurisdiction NYThird-party reproductionLast checked August 31, 2026Updates: changes when the New York Department of Financial Services amends Regulation 121; the mirror is republished on Cornell's own scheduleID
ny-11-nycrr-73-2What this source supports (2)
- Enumerates the coverages for which claims-made policies may be written in New York, which include completed operations liability, directors and officers liability, employee benefits liability, errors and omissions liability, excess liability, fiduciary liability, pollution and environmental impairment liability, public entity liability, products liability, professional liability including medical malpractice liability, ski resort liability, employment practices liability, and risks specified in paragraph (d)(1).
- Provides that claims-made coverage shall not be permitted for motor vehicle liability, or for any liability risk or coverage subject to section 3425 of the Insurance Law.
Fetched 2026-08-31. The enumerated list and the prohibition were read off the page. Unofficial Cornell LII mirror; official citation is 11 NYCRR 73.2. The section also contains premium and limit thresholds for large commercial insureds that this bundle does not rely on and therefore does not list here.
ActiveReproduction - [8]11 NYCRR 73.3 - Terms and conditions of claims-made policies(opens the original record on Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations))Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations)SecondarySecondaryJurisdiction NYThird-party reproductionLast checked August 31, 2026Updates: changes when the New York Department of Financial Services amends Regulation 121; the mirror is republished on Cornell's own scheduleID
ny-11-nycrr-73-3What this source supports (8)
- Provides in subdivision (b) that a retroactive date may not be changed during the term of the claims-made relationship and any extended reporting period.
- Requires in subdivision (d) that upon termination of coverage a 60-day automatic extended reporting period, or 90 days in the case of public entity liability insurance policies, must be provided by the insurer.
- Provides in subdivision (f) that, except as provided in subdivision (g) of the section and sections 73.4 and 73.5 of the Part, upon termination of coverage an insurer must offer the insured a three-year extended reporting period.
- Lists in subdivision (g) eight coverages for which the offer is a one-year extended reporting period rather than three years: (1) directors and officers liability, except not-for-profit organizations; (2) employee benefits liability; (3) fiduciary liability; (4) public entity liability; (5) pollution and environmental impairment liability; (6) ski resort liability subject to section 73.2(f); (7) employment practices liability; and (8) policies issued or renewed pursuant to section 73.2(d).
- Requires in subdivision (e)(1) that within 30 days after termination of coverage the insurer advise the insured in writing of the automatic extended reporting period coverage and of the availability of, the premium for, and the importance of purchasing additional extended reporting period coverage.
- Provides in subdivision (e)(2) that upon cancellation due to nonpayment of premium or fraud on the part of the insured, an insurer shall not be required to provide a premium quotation for extended reporting period coverage unless requested by the insured.
- Provides in subdivision (e)(3) that the insured shall have the greater of 60 days from the effective date of termination of coverage or 30 days from the date of mailing or delivery of the advice required by paragraph (1) in which to submit written acceptance of extended reporting period coverage.
- Provides in subdivision (k) that where a claims-made relationship has continued for less than one year, subdivisions (e) through (h) and (j) of the section shall not apply upon termination of coverage for nonpayment of premium or fraud.
Fetched twice on 2026-08-31, the second time to read subdivisions (e), (g) and (k) in full. The earlier draft of this bundle omitted the 'except not-for-profit organizations' carve-out in (g)(1), omitted item (8) of the (g) list, and stated the three-year offer without the (f) opening qualifier; all three are corrected here. Unofficial Cornell LII mirror; official citation is 11 NYCRR 73.3.
ActiveReproduction - [9]11 NYCRR 73.7 - Disclosure and notice requirements(opens the original record on Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations))Legal Information Institute, Cornell Law School (unofficial republication of the New York Codes, Rules and Regulations)SecondarySecondaryJurisdiction NYThird-party reproductionLast checked August 31, 2026Updates: changes when the New York Department of Financial Services amends Regulation 121; the mirror is republished on Cornell's own scheduleID
ny-11-nycrr-73-7What this source supports (5)
- Requires disclosure that the policy is, or identification of those portions of the policy that are, written on a claims-made basis.
- Requires disclosure that the policy provides no coverage for claims arising out of incidents, occurrences or alleged wrongful acts which took place prior to the retroactive date stated in the policy.
- Requires disclosure of the length of any automatic or additional extended reporting period coverage and, unless that coverage is for an unlimited time period, a statement advising the insured specifically of potential coverage gaps that may arise upon expiration of the extended reporting period coverage.
- Requires the declarations page, or an addendum to it, to state the premium that will be charged for each extended reporting period coverage option if the policy is terminated on the next anniversary date.
- Requires these disclosures to appear in the policy application and the declaration page, or addenda to them, and to be conspicuously displayed.
Fetched 2026-08-31 and the quoted disclosure language read off the page. This section imposes disclosure duties on insurers writing in New York. It is not itself a coverage grant or an exclusion, and it is cited in this bundle only for what insurers must tell the insured. Unofficial Cornell LII mirror; official citation is 11 NYCRR 73.7.
ActiveReproduction - [10]OGC Opinion No. 03-07-35: Claims Made and Reported Policies(opens the original record on New York State Department of Financial Services, Office of General Counsel (issued by the then New York State Insurance Department))New York State Department of Financial Services, Office of General Counsel (issued by the then New York State Insurance Department)RegulatorSecondaryJurisdiction NYLast checked August 31, 2026Updates: one-time opinion letter; the Department does not routinely revisit or annotate archived OGC opinionsID
ny-dfs-ogc-03-07-35What this source supports (3)
- States that a claims-made and reported policy requires that the claim and the reporting of the claim to the insurer both take place during the same policy term.
- States that authorized insurers are not permitted to write such policies chiefly because of the risk of gaps in coverage inherent in such policies.
- Concludes that a claims-made and reported policy may not be issued in New York except by an unauthorized insurer through an excess line broker.
Fetched twice on 2026-08-31; opinion number, July 31, 2003 date, and the quoted language confirmed on the page. This is an informal Office of General Counsel opinion letter, not a regulation, and it is 23 years old. The page carries no currency or supersession disclaimer, which means its continued accuracy is not affirmed by the page itself. Cited in this bundle as a 2003 regulator opinion, not as a standing legal rule. Published: 2003-07-31
Active - [11]OGC Opinion No. 02-10-24: Tail Coverage for Medical Malpractice Insurance(opens the original record on New York State Department of Financial Services, Office of General Counsel (issued by the then New York State Insurance Department))New York State Department of Financial Services, Office of General Counsel (issued by the then New York State Insurance Department)RegulatorSecondaryJurisdiction NYLast checked August 31, 2026Updates: one-time opinion letter; the Department does not routinely revisit or annotate archived OGC opinionsID
ny-dfs-ogc-02-10-24What this source supports (3)
- States that section 73.3(c)(1) of Regulation 121 requires that the extended reporting period coverage required by that Part be made available upon termination of claims-made coverage.
- States that N.Y. Insurance Law section 3436(b)(1) provides tail coverage at no charge only where the insured retires permanently and totally from the practice of medicine and meets specified age and duration requirements.
- Concludes that a physician who retired from private practice but continued in full-time hospital practice had not retired permanently and totally from the practice of medicine and was therefore required to pay for tail coverage.
Fetched 2026-08-31; opinion number, October 23, 2002 date, question, conclusion, and the Regulation 121 and Insurance Law section 3436(b)(1) references confirmed on the page. Informal OGC opinion letter, not a regulation, and 24 years old with no currency disclaimer on the page. Its scope is medical malpractice coverage under Insurance Law section 3436; it says nothing about tail pricing in other lines and is not cited here for anything broader. Published: 2002-10-23
Active - [12]14VAC5-335-20 - Definitions (Rules Governing Claims-Made Liability Insurance Policies)(opens the original record on Virginia Administrative Code, Virginia General Assembly Legislative Information System)Virginia Administrative Code, Virginia General Assembly Legislative Information SystemPrimary lawPrimaryJurisdiction VALast checked August 31, 2026Updates: changes when the Virginia State Corporation Commission amends 14VAC5-335ID
va-14vac5-335-20What this source supports (4)
- Defines claims-made liability insurance as an insurance policy providing coverage for the insured's liability for injury, damage, or wrongful act or omission occurring prior to the termination of coverage but subsequent to any applicable retroactive date, provided the claim is first made during the policy period or any extended reporting period.
- Defines a retroactive date as the date on or after which injury, damage, or wrongful act or omission may occur and be covered under a claims-made liability insurance policy.
- Defines an extended reporting period as an extension of the time allowed for reporting claims, after termination of a claims-made liability policy, for injury, damage, or a wrongful act or omission that occurred prior to termination of the policy and that, except for the requirement to report claims during the policy period, was otherwise covered by the policy.
- Defines a basic extended reporting period as an automatic extended reporting period provided at no additional premium charge, and a supplemental extended reporting period as an extended reporting period that is available for the insured to purchase.
Fetched 2026-08-31 from the official Virginia Administrative Code site; all four definitional claims read verbatim off the page. History note on the page: derived from Virginia Register Volume 20, Issue 21, effective January 1, 2005; amended by Virginia Register Volume 34, Issue 16, effective October 1, 2018. This definition of extended reporting period says nothing about the retroactive date, so it is not cited for that point anywhere in this bundle. Published: 2018-10-01 Effective: 2018-10-01
Active - [13]14VAC5-335-30 - Requirement to offer supplemental extended reporting period(opens the original record on Virginia Administrative Code, Virginia General Assembly Legislative Information System)Virginia Administrative Code, Virginia General Assembly Legislative Information SystemPrimary lawPrimaryJurisdiction VALast checked August 31, 2026Updates: changes when the Virginia State Corporation Commission amends 14VAC5-335ID
va-14vac5-335-30What this source supports (4)
- Requires every claims-made liability insurance policy to include a provision that the named insured may purchase a supplemental extended reporting period upon policy termination, where termination includes cancellation or nonrenewal, advancement of any applicable retroactive date, and renewal on other than a claims-made basis.
- Provides that no offer of a supplemental extended reporting period is required if the cancellation or nonrenewal is due to nonpayment of premium, failure to comply with terms or conditions of the policy, or fraud.
- Requires each claims-made liability insurance policy to contain provisions that clearly state when the supplemental extended reporting period will and will not be offered.
- Requires the offer to be made in writing no earlier than the date of notification of termination of the policy and not later than 15 days after the termination, and requires that the insured have a minimum of 30 days from policy termination to purchase the supplemental extended reporting period.
Fetched 2026-08-31 from the official Virginia Administrative Code site; subsections A through D read off the page. The earlier draft of this bundle carried the subsection B exceptions in the source record but never surfaced them in the prose; they now appear in the answer itself. Published: 2018-10-01 Effective: 2018-10-01
Active - [14]Colorado Revised Statutes section 10-4-419 - Claims-made policy forms(opens the original record on FindLaw (Thomson Reuters), a commercial republication of the Colorado Revised Statutes)FindLaw (Thomson Reuters), a commercial republication of the Colorado Revised StatutesSecondarySecondaryJurisdiction COThird-party reproductionLast checked August 31, 2026Updates: changes when the Colorado General Assembly amends the section; FindLaw states the page is current as of January 01, 2025ID
co-crs-10-4-419What this source supports (5)
- Subsection (2)(c) conditions delivery on the policy clearly defining the events and conditions which trigger coverage and defining when and how a claim is deemed to be made.
- Subsection (2)(d) conditions delivery on the policy offering, at the insured's option, the purchase of an extended reporting period of at least one year for claims not filed during the policy period, and provides that the premium may not exceed two hundred percent of the expiring policy premium unless the adjusted premium is determined by the commissioner to be inadequate based upon section 10-4-403 and upon an opinion of a qualified actuary submitted on behalf of the insurer.
- Subsection (3) provides that the commissioner may prohibit the use of a claims-made liability policy if the policy does not contain one or more of the listed policy provisions, which include a provision guaranteeing the insured a sixty-day period to purchase extended reporting period coverage in the event of cancellation or nonrenewal for any reason, and a provision allowing the insured, at the insured's option, to purchase an extended reporting period of at least the length of time of exposure under the applicable statute of limitation.
- Subsection (5) defines a claims-made policy as a policy of liability insurance that provides coverage for those claims that are made or reported to the insurance carrier during the term of the policy or for an extended reporting term for which coverage has been purchased.
- Subsections (7) and (8) require insurers writing on a claims-made basis in Colorado to submit an annual listing of policy forms, endorsements and disclosure forms to the commissioner by July 1 of each year, and to submit any new form at least thirty-one days before using it.
Fetched twice on 2026-08-31 and the quoted subsections read off the page, which states 'Current as of January 01, 2025'. This is a commercial mirror, not primary law, and it is recorded as secondary for that reason. Attempts to corroborate against Justia returned HTTP 403 and the Colorado legislature's Title 10 PDF could not be parsed, so the text has not been checked against the official Colorado publication and should be before any reliance. Note that the mirror shows a broken internal cross-reference inside subsection (3), which suggests renumbering artifacts. The earlier draft of this bundle treated the sixty-day purchase right and the statute-of-limitations-length option as mandates and as alternatives to the (2)(d) one-year option; both characterizations were wrong and are corrected here.
ActiveReproduction - [15]Commercial Insurance Guide (CDI Form 700)(opens the original record on California Department of Insurance)California Department of InsuranceRegulatorPrimaryJurisdiction CALast checked August 31, 2026Updates: revised by the California Department of Insurance without a fixed schedule; the page carries the marker Form 700 Revised June 14, 2024ID
ca-cdi-commercial-insurance-guideWhat this source supports (33)
- The guide's glossary entry headed 'Claims Made' reads: a liability insurance policy where coverage applies to claims filed during the policy period no matter when the loss occurred subject to a retroactive inception date.
- The guide's glossary entry headed 'Occurrence' reads: a liability insurance policy that covers claims arising out of occurrences that take place during the policy period, regardless of when the claim is filed.
- CDI states that there are three primary coverage sections that make up a CGL policy: premises liability, products liability and completed operations.
- CDI describes CGL coverage as comprehensive in nature, covering all hazards within the scope of the insuring agreement that are not otherwise excluded.
- CDI states that the major exclusions under a CGL policy include intentional injury; insured contracts; liquor liability; workers compensation and employers liability; pollution; aircraft; automobile; watercraft; mobile equipment; war; care, custody, and control; damage to your work; impaired property; sistership liability; and failure to perform.
- CDI describes specified perils as consisting of a list of each peril to be insured against, such as fire, explosion, windstorm and vandalism, and describes open perils coverage as covering all losses unless they are specifically excluded.
- CDI states that earth movement (including earthquake) and flood are two common perils that are excluded under open perils coverage.
- CDI describes three commercial property valuation approaches: actual cash value, agreed value, which it says waives any coinsurance penalty and pays 100 percent of the stated amount, and replacement cost, which it describes as the amount it takes to replace property with new property of like kind and quality up to the limits of insurance.
- CDI describes coinsurance as an insurance clause that defines the amount of each loss the company pays according to the amount of insurance carried divided by the amount of insurance required, and states that a policyholder can be subject to a monetary penalty at the time of a loss where a building is not insured to value.
- CDI states that business interruption coverage replaces lost business income after a covered loss.
- CDI describes a Business Owners Policy (BOP) as a combination commercial policy that covers property, general liability and business interruption.
- CDI states that when a business has had three applications turned down from a licensed commercial insurance carrier, with written documentation of the declination, it can proceed to obtain insurance from the surplus line market.
- CDI states that a surplus line company can only be accessed through a specially licensed broker who holds a surplus line license issued by the CDI.
- CDI states that although surplus line insurers must follow the Fair Claims Settlement Practices Regulations, the CDI has limited jurisdiction over the operation of surplus line insurers.
- CDI states that the California Insurance Guarantee Association (CIGA), which protects claims with admitted insurers, does not apply to surplus line insurers.
- There are three primary coverage sections that make up a CGL policy: premises liability, products liability and completed operations.
- Premises liability covers liability for accidental injury or property damage that results from either a condition on your premises or your operations in progress, whether on or away from your premises.
- A products liability hazard exists for any business that manufactures, sells, handles, or distributes goods or products.
- Completed operations covers your potential liability for bodily injury or property damage that arises out of your completed work.
- The CGL policy has separate limits of insurance for general liability, fire legal liability, products and completed operations liability, advertising and personal liability, and medical payments.
- The page carries the line Form 700 Revised June 14, 2024.
- The guide states that inland marine is a specialized type of property insurance that primarily covers damage to or destruction of your business property while in transport.
- The guide states that inland marine insurance can cover a variety of transportation exposures, however it does not cover boating transportation, which is covered under ocean marine insurance.
- The guide states that some of the most common types of coverage offered are accounts receivable insurance, consignment insurance, equipment floaters (i.e., contractors equipment), installation floaters, motor truck cargo insurance, trip transit insurance, and valuable papers (records) insurance.
- The guide states that standard perils in inland marine may include fire, lightning, windstorm, flood, earthquake, landslide, theft, collision, derailment, overturn of the transporting vehicle, and bridge collapse.
- The guide states that commercial property insurance can protect a business owner from some of the most common losses experienced by business owners, such as property damage, business interruption, theft, liability, and worker injury.
- The guide states that an aggregate limit of liability is in force for the general liability, fire legal liability, advertising and personal liability, and medical payments claims.
- The guide states that when total claims for all these areas exceed a stated annual aggregate limit of liability, the policy limits are exhausted and no more claims will be paid from the policy for the duration of the policy period.
- The guide states that there is also a separate aggregate limit of liability in force for products and completed operations liability claims.
- The guide defines split limits as the technique for expressing limits of liability coverage under a particular insurance policy by stating separate limits for different types of claims growing out of a single event or combination of events.
- The guide states that if a building is not insured to value the insured can be subject to a monetary penalty at the time of a loss, commonly referred to as coinsurance, and defines coinsurance as an insurance clause that defines the amount of each loss that the company pays according to the amount of insurance carried, divided by the amount of insurance required.
- The guide states that the California Insurance Guarantee Association (CIGA), which protects claims with admitted insurers, does not apply to surplus line insurers.
- The guide states that while surplus line companies are not licensed by the CDI, they do have to go through an approval process that includes providing evidence of minimum capital and surplus requirements.
Fetched 2026-08-31 and both glossary entries read off the page. The '?page=3' query parameter used in the earlier draft is inert and has been dropped from the URL. publishedDate is taken from the page's own 'Form 700 Revised June 14, 2024' marker. This is a consumer guide glossary and the weakest authority in the bundle; it is cited only for the two trigger definitions. It does not address retroactive dates, extended reporting periods, or which lines are written on which trigger. Published: 2024-06-14 Effective: 2024-06-14
Active - [16]Prior acts coverage (glossary of insurance and risk management terms)(opens the original record on International Risk Management Institute, Inc. (IRMI))International Risk Management Institute, Inc. (IRMI)SecondarySecondaryJurisdiction USLast checked August 31, 2026Updates: glossary entries are revised by the publisher without a fixed scheduleID
irmi-prior-acts-coverageWhat this source supports (1)
- Defines prior acts coverage as a feature of claims-made policies that have either no retroactive date or a retroactive date earlier than the inception date of the policy.
Fetched 2026-08-31; the definition was read off the page. IRMI is a commercial insurance reference publisher, not a regulator, so this is cited only to attribute an industry term of art and never for a legal requirement or a coverage outcome. The page shows no publication or revision date.
Active