The question nobody asks until afterward
Our breach case files walk three disposition failures — a global bank's decommissioning program that drew more than $160 million in combined penalties and settlements, a health insurer's missing drives, and hospital drives that surfaced on an auction site. Each one is a study in controls. None of them is a study in who paid, and that is the question that arrives at a risk manager's desk about a week after the incident, usually in the form of a coverage letter.
The reason it arrives late is structural. Organizations buy cyber insurance to cover breaches. Vendors carry insurance because contracts require it. Both parties reasonably assume that between the two policies, a breach caused by a retired device is covered by somebody. In practice, a disposition breach sits at an awkward intersection: the data was the customer's, the failure was the vendor's, the asset had left the customer's environment, and the harm was a third party's. Each policy in the chain was written with a narrower picture in mind. This brief describes that chain at the pattern level — how these policy types are generally structured — so the conversation with your broker and counsel happens before the coverage letter rather than after it.
Four policies, four different jobs
A disposition breach touches as many as four insurance instruments. Understanding what each was built to do explains why the gap exists.
Your cyber liability policy
A first-party cyber policy is generally built around the insured's own operating environment: incident response, forensics, notification costs, business interruption, and third-party liability arising from a breach of the insured's systems. Where disposition breaches get complicated is at the edges. Policies vary widely in how they treat data on assets that have left the organization's control, breaches attributable to a third-party vendor's conduct, and losses that follow from a failure to maintain the organization's own stated security procedures — the "did you exercise due care" question that insurers examine after a claim. Industry analysis of ITAD incidents has pointed to exclusions for improper asset disposal, vendor-caused breaches, and undisclosed prior incidents as recurring reasons claims are contested. Regulatory fines and penalties are treated differently from policy to policy and, in some jurisdictions, may not be insurable at all. None of that means your policy excludes disposition breaches; it means you cannot know without reading it against that scenario.
The vendor's commercial general liability policy
Commercial general liability is the policy every business carries, and it is the one most often produced when a customer asks for "proof of insurance." It responds to bodily injury and property damage: a pallet that falls on a loading dock, a truck that hits a car, a visitor injured at a facility. It is generally not designed to respond to the negligent performance of a professional service — a drive certified as sanitized that was not, a serial number that never matched, a pallet that went to the wrong downstream. A general liability certificate answers a question about physical accidents. It does not answer the question you are actually asking.
The vendor's technology errors & omissions policy
Professional liability — in the technology-services world, technology E&O — is the coverage built for the risk you are transferring: financial harm to a client arising from the negligent performance of the vendor's services. This is where a disposition failure lives. Institutional buyers know it, which is why university and public-sector technology-contract standards commonly require vendors to carry tech E&O and network-security coverage at meaningful limits, with the customer named on the policy. If a vendor's insurance program contains general liability and nothing else, the risk you thought you transferred is still yours.
The vendor's network security & privacy liability policy
Often bundled with tech E&O, this is the vendor's own cyber coverage — and it carries a trap that insurance brokers have written about directly. In the words of one wholesale broker's 2025 guidance on vendor agreements, cyber liability policies "are designed to cover a business's own expenses arising from a cyber event wherein the breach occurs on their system." A vendor's cyber policy is written for the vendor's losses. Whether it responds to your loss from their handling of your data depends on how the policy and the contract were built — which is what the next two sections are about.
What a certificate of insurance proves — and doesn't
The document that closes most vendor-insurance conversations is a certificate of insurance. It is worth being precise about what it is. A COI is a summary, typically on a standard industry form, evidencing that on the date it was issued the named insured carried the listed policy types, with the listed carriers, limits, and policy periods. That is useful. It is also all it is.
A certificate is not the policy. It does not show exclusions, and exclusions are where disposition claims are decided. It does not show endorsements — and whether your organization has been added as an additional insured is an endorsement question. Standard certificate forms state on their face that the certificate confers no rights upon the certificate holder. Coverage can be cancelled or changed after the certificate is issued, and notice-of-cancellation provisions vary. A COI showing general liability at a large limit and nothing under professional or cyber liability is not evidence of coverage for the risk you care about; it is evidence of coverage for a different one.
The practical reading is simple: treat the certificate as the beginning of verification. Confirm the policy types match the risk (tech E&O and network security & privacy, not just general liability), confirm the limits are adequate for your data exposure rather than the vendor's convenience, and ask for the endorsement that names you.
Additional insured, waiver of subrogation, and why the words matter
Two contract mechanisms convert a vendor's insurance from something the vendor has into something available to you. Additional insured status — conferred by endorsement to the vendor's policy — gives your organization rights under that policy, rather than leaving you to sue the vendor and hope its carrier pays. A waiver of subrogation prevents the vendor's insurer from turning around and pursuing your organization to recover what it paid. Risk managers pair them for a reason, and institutional technology-contract standards commonly require both, along with an amendment permitting the additional insured to bring a claim directly.
The same broker guidance offers two further pieces of practical advice worth carrying into ITAD contracts: match limits across policies (if the vendor's E&O limit is set at a given level, its cyber limit should match it, so a claim doesn't fall into the smaller bucket), and require that coverage remain in force for as long as services are provided plus a tail — the guidance suggests five years — because disposition breaches are frequently discovered long after the service was performed. A drive sold on an auction site in 2026 may have been "destroyed" in 2023.
Indemnification without insurance is decorative
Most ITAD contracts contain an indemnification clause: the vendor agrees to hold the customer harmless for losses arising from the vendor's negligence. Customers often treat that clause as the answer to the coverage question. It is not. An indemnity is a promise to pay, and a promise to pay is exactly as reliable as the payer's ability to pay. A thinly capitalized vendor with a general liability policy and a well-drafted indemnity has given you a well-drafted document.
The clause does real work only when something stands behind it — a balance sheet large enough to absorb a seven-figure loss, or, far more commonly, insurance whose terms actually respond to the indemnified risk. That is why the two questions belong together in a contract: the indemnity defines what the vendor owes you, and the insurance requirements (types, limits, additional-insured status, tail) define how the vendor will be able to pay it. Broker guidance on vendor agreements makes the same pairing, recommending notification requirements and indemnification for first-party costs as the contractual backstop when insurance proves inadequate.
Liability follows the data owner
One more piece of the pattern explains why this matters so much. Under the frameworks that govern most regulated data — HIPAA for protected health information, GLBA for financial data, the state breach-notification laws that cover nearly everyone — the obligations generally attach to the organization that owns the data, not to the vendor that mishandled the device. The notification letters go out under your name. The regulator's inquiry is addressed to you. Your customers' claims name you. The bank in our case files paid its penalties itself; whatever it recovered from vendors came afterward, under contract.
The vendor relationship is how you recover, not how you avoid the obligation. Which is why the vendor's insurance is not a formality on a procurement checklist — it is the mechanism that determines whether "we'll recover from the vendor" is a plan or a hope. Our healthcare field guide and CMMC guide walk the data-owner obligations in their respective regimes.
The three insurance questions for every ITAD RFP
Everything above compresses into three questions that belong in every ITAD RFP and every renewal.
- Which policies, at what limits? Ask specifically for technology errors & omissions and network security & privacy liability, with limits sized to your data exposure, and for the general liability and, for recyclers handling e-waste, pollution liability that cover the physical side. A vendor that answers with a single general liability limit has told you something.
- Will you name us, and waive subrogation? Additional-insured status by endorsement, a waiver of subrogation, and a tail that outlasts the contract. Ask for the endorsement itself, not a line on a certificate.
- What stands behind the indemnity? Read the indemnification clause and the insurance schedule together. If the indemnity is broad and the insurance narrow, the clause is doing less than it looks like it is doing.
Then do two things on your own side. Read your cyber policy against the disposition scenario with your broker — assets outside your control, vendor-caused loss, procedure-failure conditions, fines and penalties — and put the answers in your program file. And keep the disposition records that demonstrate due care: serialized certificates, reconciled inventories, downstream disclosures. In the case files, the organizations that struggled most were the ones that could not show what happened to the hardware. When a carrier asks whether you exercised reasonable care, the chain-of-custody file is your answer.
The vendor due-diligence guide covers how to verify credentials generally, and the scorecard scores insurance alongside the other evidence. The point of this brief is narrower: insurance is the one line on the scorecard that determines whether all the others have consequences.
Insurance & disposition-breach FAQ
Does cyber insurance cover a breach caused by a retired hard drive?
Sometimes, and the answer lives in your specific policy. Cyber liability policies are typically written around an organization's operating systems and networks, and they vary widely in how they treat data on assets that have left the organization's control, breaches attributable to a third-party vendor, and failures to follow the organization's own stated procedures. Some policies exclude or limit these scenarios; some do not. Regulatory fines and penalties are treated differently from policy to policy and jurisdiction to jurisdiction. The only reliable answer comes from reading the policy with your broker before an incident, not after.
What is the difference between general liability and errors and omissions insurance for an ITAD vendor?
Commercial general liability responds to bodily injury and property damage — a dropped pallet, a truck accident, an injury on site. It is generally not designed to respond to the negligent performance of a professional service, such as a drive that was certified sanitized but was not. That risk belongs to technology errors and omissions (professional liability) coverage, and to network security and privacy liability coverage for data-related third-party claims. A vendor that shows you only a general liability certificate has shown you the wrong policy for the risk you are transferring.
What does a certificate of insurance actually prove?
A certificate of insurance is a summary document evidencing that, on the date it was issued, the named insured carried the listed policy types with the listed carriers, limits, and policy periods. It is not the policy, it does not show exclusions or endorsements, it does not by itself give the certificate holder any rights under the policy, and coverage can be cancelled after the certificate is issued. It is a starting point for verification, not the end of it.
What is additional insured status and why does it matter in an ITAD contract?
Being named as an additional insured on a vendor's policy, typically by endorsement, gives your organization certain rights under that policy rather than leaving you to sue the vendor and hope its insurer pays. Paired with a waiver of subrogation, it is the mechanism risk managers use to make a vendor's insurance actually available to the customer's loss. Institutional buyers commonly require it in technology contracts, along with minimum limits for technology errors and omissions and cyber coverage.
If my vendor causes the breach, isn't the vendor liable instead of us?
Regulatory liability generally follows the data owner. Under frameworks like HIPAA, GLBA, and state breach-notification laws, the organization that collected the data typically owes the notification, regulatory, and customer obligations regardless of which vendor mishandled a device; it may then seek recovery from the vendor under the contract. That is why indemnification clauses matter, and why they are only as reliable as the insurance or balance sheet behind them. A contractual promise from a thinly capitalized, thinly insured vendor is a promise, not a recovery.
THE INSURANCE LAYER, IN WRITING
See the coverage behind the certificates
The CyberCrunch Compliance & Credentials Packet reproduces the certifications, the permit, the insurance program, and the chain-of-custody process in one audit-ready PDF — so your risk team can read the insurance layer alongside the credentials instead of taking a certificate's word for it.
This article is general information about how common commercial insurance policy types are typically structured, drawing on published broker guidance on vendor agreements, publicly available institutional technology-contract insurance standards, and industry analysis of IT asset disposition incidents, as of August 2026. It is not legal advice, insurance advice, or a description of any particular policy; policy terms, exclusions, endorsements, and the insurability of fines and penalties vary by carrier, form, and jurisdiction. Consult your insurance broker and qualified counsel about your own coverage and contracts before relying on any general pattern described here. References to CyberCrunch's insurance program describe documents available in its credentials packet and are not a representation of coverage for any particular customer or loss.