THE CRUNCH · EPISODE 34 · 0:32 · RISK

The Coverage Gap

THE CRUNCH · EP 34
TAP TO PAUSE
PAUSED — TAP TO RESUME
Tap ♫ for music
Or keep scrolling — the full text is below
0:32 runtimeFully captioned · music optionalDrag the top bar to seekThe Crunch · :30 series

Prefer to read it?

A retired hard drive turns up with your data on it. Who pays? Often nobody you expected. Your cyber policy is typically written around your live systems, and policies vary in how they treat assets that have left your control or a vendor’s mistake.

The vendor’s general liability policy covers accidents — injuries and property damage, not a negligently performed service. The vendor’s own cyber policy is written for the vendor’s losses. And a certificate of insurance is not the policy: it does not show exclusions, and it gives you no rights.

What closes the gap is technology errors & omissions coverage, being named as an additional insured with a waiver of subrogation, and an indemnity with insurance behind it. An indemnity without insurance is decorative. Read your own policy against the disposition scenario, and put three insurance questions in every ITAD contract.

CYBERCRUNCH · NAID AAA · R2v3 · RIOS · PA DEP

Which policy pays when a retired drive causes a breach?

The brief walks the liability chain — cyber, general liability, tech E&O — what a certificate proves, and the three questions for every ITAD RFP.