A cyber insurance policy is a young contract sold into an old dispute system. When Andrew Nadolna and I surveyed this market in 2016, gross written premiums had just set a record of $2.75 billion on annual increases of 25 to 50 percent — growth so rapid that not every exposure had been identified, turned into policy language, and priced. Terms and conditions were negotiable, and the forms were being revised constantly. A decade on, the market is far larger, but the underlying condition persists: this is a line of insurance whose language has never hardened into standard forms.
That matters because unsettled language is where coverage disputes come from — and because it breaks the tool courts normally use to resolve them. A cyber policy is generally an amalgamated form of several older coverages — errors & omissions, network security, privacy — combined with protections for loss or corruption of data, business interruption, crisis management, and cyber terrorism. When a claim lands in the gap between what the insured believed it bought and what the form actually says, the parties reach for precedent. In cyber, there is very little worth reaching for. Court decisions construe wordings the market has already amended; the next dispute arrives on a form no court has ever read.
§ 01 · The lesson of P.F. Chang’s
Consider the case that taught the market this. In P.F. Chang’s China Bistro, Inc. v. Federal Insurance Co., No. CV-15-01322, 2016 WL 3055111 (D. Ariz. May 31, 2016), the restaurant chain discovered a 2014 data breach involving 33 restaurants and the credit card data of roughly 60,000 customers. It reported the breach to its carrier immediately and sought coverage for its payments to the credit card companies arising from the resulting fraudulent charges. The policy covered “direct loss, legal liability, and consequential loss resulting from cyber security breaches” — and the court still held that the loss fell outside coverage. Relying on case law developed under commercial general liability policies, it reasoned that coverage is generally excluded for the assumption of another’s liability, and P.F. Chang’s was seeking coverage for exactly that.
The lesson: the words were broad, the loss was real, and the coverage was not there. Most cyber forms were subsequently amended to cover the exposures at issue in the case — which is precisely the point. Every litigated wording becomes an amended wording. Litigation in this market does not build a stable body of interpretation; it documents, expensively and publicly, one generation of drafting mistakes at a time.
§ 02 · What mediation and arbitration actually buy
Against that backdrop, the case for resolving cyber coverage disputes through mediation or arbitration is not ideological. It rests on three practical advantages. First, speed: depending on the dispute, ADR can save anywhere from a handful of months to several years, largely because the parties set their own discovery procedures — almost always faster, easier, and more direct than discovery in traditional litigation. Second, fluency: cyber coverage disputes braid complex technical questions into complex insurance questions, and a judge will often need significant time and resources to come up to speed on both. The parties, by contrast, can select a neutral who already has technical cyber experience, relevant insurance experience, or both.
The technical questions in particular reward a neutral who can read the record directly. The technical elements of a dispute are not grounded in law, advocacy, and persuasion; they are grounded in the ones and zeroes of the relevant computer systems. A technically competent neutral can surface those truths efficiently, without the parties funding lengthy rounds of briefing and dueling expert opinions to establish facts that were never genuinely in dispute.
Every litigated wording becomes an amended wording. The next dispute arrives on a form no court has ever read.
Third, confidentiality — and in cyber, this cuts deeper than reputation management. A coverage fight after a breach can require discovery into the policyholder’s cyber defenses and their weaknesses, its diligence in selecting systems, the adequacy of its security funding, and the quality of its internal decision-making. Breaches also tend to arrive with company: class actions and regulatory proceedings whose lawyers follow any public coverage litigation with interest, looking for material they could not obtain in their own discovery. Few policyholders want a published judicial ruling that their defenses were inadequate or misrepresented. Arbitration produces neither the public record nor the precedent.
§ 03 · Negotiate the clause before the breach
None of this happens by accident; it happens by clause, and the clause must be drafted with care. A mandatory arbitration provision in an insurance policy is both unpopular and, in many places, unenforceable — nearly half the states forbid mandatory arbitration clauses in some or all insurance contracts, and the Washington Supreme Court has held them unenforceable even in the excess and surplus lines market. State of Washington Department of Transportation v. James River Insurance Co., 176 Wash. 2d 390 (2013). Parties have already litigated over the ADR clauses in cyber policies themselves — see Columbia Casualty Co. v. Cottage Health System, 2015 U.S. Dist. LEXIS 93456 (C.D. Cal. July 17, 2015) — and litigation over the dispute-resolution method defeats every purpose the method was meant to serve.
The workable answer is an optional, negotiated clause rather than an imposed one. Policyholder counsel should treat the ADR provision as part of the placement negotiation and press on five points: (1) the trigger — mutual consent, or better for the insured, a one-way option letting the policyholder elect arbitration that the insurer cannot refuse; (2) the panel — qualification requirements ensuring at least one arbitrator fluent in both policy language and technical cyber issues; (3) choice of law and rules of interpretation, so that the common-law rule construing ambiguity in the policyholder’s favor is not quietly bargained away; (4) fees and remedies, including whether attorneys’ fees and bad-faith damages remain available, subject to caps if the insurer insists; and (5) the tower — pressing every carrier on the program toward a clause that permits consolidation of common issues, so coverage is not relitigated layer by layer.
Consider the position of a company that has just been hacked. Regulators are on the way, a class action may be filed at any moment, the breach-response teams are on high alert — and then the reservation-of-rights letter arrives, with counsel advising that a declaratory judgment action in federal court may follow. If the policy has no dispute-resolution clause, would you want to try negotiating one at that moment? Better to have the option in place before the crisis. The worst time to design the forum is the moment you need it.
Draws on Daniel's cyber-insurance and ADR writing co-authored with Andrew Nadolna and Michael Mann (Law360 and Law.com, 2016–2017).