Don’t Lose Sight of Security Among the Internet of Things

Did you know that there will be nearly 21 billion devices connected to the Internet by 2020?

According to Gartner, an information technology research company, 5.5 million new devices are connecting every day. This rapidly growing network of Internet-enabled physical devices capable connecting, communicating and identifying with other devices is commonly referred to as the Internet of Things. Not surprisingly, businesses are looking for ways to harness its power and potential. Unfortunately, hackers are too.

The Internet of Things adds a new security dimension that businesses must consider. A single insecure connection could expose not only sensitive information transmitted by a device, but everything else on a business’s network. Though there isn’t a one-size-fits-all approach, the Federal Trade Commission has identified various security measures that businesses can generally adopt to help minimize the risks created by the Internet of Things.

Encourage a culture of security. Designate senior executives who are responsible for security. Since most security breaches are avoidable, train staff to recognize and report vulnerabilities. Address security expectations and requirements in contracts with service providers.

Adopt a risk-based approach. Direct attention and allocate resources to protect network connections that are most vulnerable and sensitive information.

Consider (and reconsider) the need to collect or retain sensitive information. Steps must be taken to protect sensitive information that is collected and retained out of business necessity. Unnecessary sensitive information should not be collected or retained at all.

Manage passwords.Implement an effective way to manage passwords. Do not rely on default passwords.

Take advantage of readily available security tools.There’s a tool out there for a number of basic security testing tasks, such as scanning networks for open ports, reverse engineering of programming code or decompiling, checking password strength and scanning for known vulnerabilities. Many of these tools are free, and some of them work automatically.

Protect interfaces between devices and servers. Weaknesses are often found at the point where a device communicates with servers. The interface between a mobile device and the cloud, for example, could create an opening for hackers to access an entire network. There are a number of ways to test entry points for weaknesses. “Fuzzing” is a method that sends a device or system unexpected input data to detect possible defects. Businesses should use manual and automated tools to test interfaces.

Limit permissions. Access to sensitive information should be limited to only those who actually need it. Limiting access to the lowest level that will allow for normal functioning is known as the principle of least privilege. To maximize effectiveness, permission limits must strike a balance between utility and security.

Utilize encryption. Standard encryption techniques are available to protect sensitive data that is stored on devices and transmitted to networks. Not all encryption is created equal, so stronger encryption methods should be selected over weaker ones.

Emphasize authentication. Security starts by making sure people are who they say they are. The importance of proper authentication has magnified the Internet of Things. An authentication failure involving a single connected device could expose the entire network to which the device connected. Depending on the nature of a business or its sensitive information, additional authentication measures may be necessary. For example, a two-factor authentication process that requires a password and a secure token.

Finally, businesses must remember that data security is a dynamic process that requires constant attention and frequent adjustments. Since hackers are constantly adapting, so must security measures. Nevertheless, it’s impossible to protect against every cyber threat or prevent every data breach, so business should seriously consider Cyber Liability Insurance. Unlike traditional business insurance policies, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

Given the complexity of the risk and the absence of one-size-fits-all coverage, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Business Interrupted? Don’t Let a Property Loss Jeopardize Your Business

Did you know that nearly 40% of businesses do not reopen and another 25% fail within a year after a catastrophe or disaster? The actual loss or damage to buildings, facilities and property is often the reason for this frightening statistic, but it isn’t the only reason. Businesses are increasingly struggling to recover after a property loss because of the economic impact caused by the interruption of business operations during and after the event.

It’s common for business operations to be suspended temporarily after a property loss. Depending on the severity of the loss, a business may be forced to shut down for weeks, possibly months. Though revenue often stops, expenses continue. The inability to pay expenses (payroll, mortgage, suppliers, taxes, etc.) can turn a temporary suspension of business operations into a permanent shut down. Business interruption insurance can prevent this from happening.

Business Interruption, also known as Business Income, is a type of commercial insurance that protects against loss of income when a covered loss causes a business to reduce or suspend its operations. In the event of a covered loss, business interruption insurance will cover lost revenue and fixed expenses, like rent and utilities, during the suspension of operations. Extra expense coverage is also available to reimburse costs over and above normal operating expenses, like temporary relocation costs.

Business interruption coverage is triggered when there is direct physical damage to property that was caused by a covered peril. For example, if wind damage is covered under a commercial property insurance policy, there would be business interruption coverage if operations were suspended due to a windstorm. On the other hand, if wind damage is not covered, there would be no business interruption coverage.

To calculate a business interruption loss, insurance companies need to determine how much the business would have earned if the loss had not occurred. They may review and consider various financial documents, such as tax returns, bank statements, profit and loss statements and balance sheets, to establish the amount of a business interruption loss.

According to the Insurance Information Institute, a recent report found that the economic impact from business interruption is often much higher than the cost of physical damage. Business interruption losses now make up a much larger part of overall property losses than they did just ten years ago. The increasing interdependence among businesses locally and globally also means that business interruption losses are expected to increase in frequency and severity.

Businesses should consider adding business interruption coverage to their existing insurance program. Though many aspects of this coverage are relatively standard, there are some variations among insurers and policy forms. For example, some policies may provide Civil Authority coverage. Given the relative complexity of business interruption coverage, an experienced and reputable insurance agent should be consulted to help identify needs and evaluate options.

Please contact us to learn how business interruption insurance can protect your business.

If you’d like to subscribe to our weekly newsletters, please click here.

Best Practices for Avoiding (Most) Data Security Breaches

Did you know that 93% of data breaches could have been avoided? Everyone should be interested in this somewhat shocking statistic because cyber threats and data security remain primary concerns among virtually every organization, regardless of size, industry or purpose. It’s true that some cyber threats simply cannot be avoided, which is why businesses should do everything in their power to avoid those that can.

The first step is recognizing and addressing some of the more common avoidable causes of security breaches and data loss. According to the Online Trust Alliance, these include:

  • Employee errors (lost data, files, drives or devices and improper disposal);
  • Accidental disclosures (via email and public postings);
  • Business Email Compromises (socially engineered exploits like phishing and whaling);
  • Unencrypted data and disclosed keys;
  • Improperly configured systems, networks and devices;
  • Failing to update or patch systems against known vulnerabilities; and
  • Using end of life devices, operating systems and applications.

The next step is implementing security processes and procedures. When it comes to defending against cyber threats and ensuring data security, business-specific circumstances and operations typically determine which essential preventative measures are most likely to be effective. Nevertheless, there are various baseline security best practices recommended by the Online Trust Alliance that most businesses can easily implement and manage, such as:

  • Encrypting data at rest, in storage and in transit. Without the corresponding cryptographic keys, encryption renders data useless to hackers. It may also exempt businesses from having to comply with various state data breach notification laws.
  • Managing passwords. Use password managers to generate and store passwords. Multi-factor authentication (smartcards and PINs in addition to passwords) can also be required to access sensitive information or accounts.
  • Adopting the least-privilege user account (LUA) strategy. User accounts should be given the least amount of privilege (access) required to perform their necessary functions.
  • Auditing security measures. Periodically conduct penetration tests and vulnerability scans to identify and mitigate vulnerabilities.
  • Monitoring emails. Require email authentication of all inbound and outbound mail servers to detect malicious and spoofed emails.
  • Managing mobile devices. Require authentication to unlock devices, lock out devices after numerous failed login attempts, encrypt communications and storage, and enable remote wiping of mobile devices that are lost or stolen.
  • Managing wireless networks. Only authorized wireless devices should be given network access. “Guest” network access should be kept on separate servers.
  • Implementing a data breach response plan. Conduct a post-mortem after every incident and make necessary adjustments. Practice by regularly testing response plans and personnel.

Since it’s impossible to protect against every cyber threat or prevent every data breach, the final step is obtaining Cyber Liability Insurance. According to PricewaterhouseCoopers’ 2016 Global State of Information Security Survey, 59% of businesses surveyed purchased cyber security insurance to mitigate the financial impact of data breaches and cyber incidents when they do occur. Businesses are increasingly realizing that what can’t be protected or prevented must be insured.

Unlike traditional business insurance policies, Cyber Liability and Security Breach (Cyber Perils)Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws. Given the complexity of the risk and the absence of one-size-fits-all coverage, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

OSHA’s Revised Injury and Illness Record keeping and Reporting Requirements

Each year there are more than 3 million serious (requiring more than first aid) workplace injuries and illnesses. Given the Occupational Safety and Health Act’s requirement that employers provide safe and healthy workplaces, this number is unacceptably high. To address this problem, the Occupational Safety and Health Administration (OSHA) recently revised various workplace safety regulations.

The most notable revision adds an electronic submission requirement to OSHA’s current record keeping regulations, which require employers with more than ten employees to keep a record of serious work-related injuries and illnesses. Employers with ten or fewer employees and employers in certain lower-hazard industries are partially exempt from this requirement. This revision becomes effective January 1, 2017, and will be phased in over two years.

The revised regulations do not change an employer’s current obligation to complete and retain injury and illness records. Covered employers are (and have been) required to record information about recordable injuries and illnesses on three separate OSHA forms.

  • Form 300 (Log of Work-Related Injuries and Illnesses)
  • Form 300A (Summary of Work-Related Injuries and Illnesses)
  • Form 301 (Injury and Illness Incident Report)

Under the revised regulations, submission requirements depend on the number of employees working at a single physical location where business is conducted or where services and operations are performed (an Establishment).

Establishments with 250 or more employees must begin electronically submitting information from Form 300A to OSHA by July 1, 2017. Information from all three forms (300A, 300 and 301) must be submitted electronically by July 1, 2018. Beginning in 2019 and every year thereafter, the information must be submitted by March 2nd.

Establishments with 20 to 249 employees operating in certain high-risk industries must electronically submit information from Form 300A to OSHA by July 1st of 2017 and 2018. Beginning in 2019 and every year thereafter, the information must be submitted by March 2nd. Though some of the industries designated as high-risk are obvious (agriculture, utilities, construction, manufacturing), others are not (grocery and department stores, museums, boarding houses). If you’re not sure whether this new electronic submission requirement applies, contact OSHA.

Additional revisions were made to promote complete and accurate reporting of work-related injuries and illnesses. As of August 10, 2016, employers must establish a reasonable procedure for employees to promptly and accurately report work-related injuries and illnesses. A procedure is not reasonable if it would deter or discourage a reasonable employee from accurately reporting injuries or illnesses. Employees must be informed about the reporting procedure.

Employers must also inform each employee that:

  • they have the right to report work-related injuries and illnesses; and
  • employers are prohibited from discharging or in any manner discriminating against employees for reporting work-related injuries or illnesses.

OSHA will provide a secure website for electronic submissions, including web forms for direct data entry and instructions for other means of submission. OSHA also intends to provide an interface for entering data from mobile devices.

OSHA estimates that it will take a typical employer with less than 250 employees about 10 minutes to create an account and another 10 minutes to enter the required information from Form 300A. For larger employers, OSHA estimates an additional 12 minutes will be needed to enter the required information for each injury or illness recorded on their Forms 300 and 301.

The revised regulations should serve as a reminder for employers of their obligation to provide a safe and healthy workplace. In addition to protecting employees from work-related injuries, employers may benefit financially from lower workers’ compensation insurance premiums.

Please contact us if you would like more information about controlling workers’ compensation insurance costs .

Additional information is also available in our weekly Risk Management Newsletters.

 

Rental Applications and Servicemembers: New Rules for Condominium Associations

Why has July 1st become an important date for condominium associations? It’s the date legislative changes to Florida’s Condominium Act typically take effect. This year, no significant statutory amendments were passed, so instead of preparing for statutory changes, condominium associations can start planning Fourth of July celebrations. Well, not every condominium association.

If your association requires prospective tenants to complete rental applications, there is a new law that imposes specific processing requirements for applications submitted by servicemembers. These new requirements, which were added to Florida’s Residential Landlord and Tenant Act, become effective, wait for it…July 1, 2016.

Under the new law, if condominium associations require prospective tenants of condominium units to complete rental applications before being allowed to move in, the association:

  • MUST complete its processing of a servicemember’s rental application within 7 days after submission; and
  • MUST, within that 7-day period, notify the servicemember in writing whether the application was approved or denied, and, if denied, the reason for denial.

If a servicemember’s rental application is not denied within the 7-day period, the condominium association must allow the unit owner to lease and the landlord must lease the rental unit to the servicemember if all other terms of the application and lease are complied with. These new requirements cannot be waived or modified under any circumstances, so condominium associations must comply.

Compliance means knowing when an applicant is a servicemember. A servicemember is any person serving in the United States Army, Navy, Air Force, Marine Corps or Coast Guard who is on active duty or state active duty. Members of the Florida National Guard and United States Reserve Forces are also servicemembers.

Active duty means full-time duty in active military service of the United States, including federal duty such as full-time and annual training. Active military personnel who are absent from duty as a result of illness, being wounded, being on leave or other lawful cause are also considered to be on active duty. Full-time duty in the National Guard is not considered active duty.

State active duty means full-time duty in active military service of the State of Florida when ordered by the Governor or Adjutant General for various reasons, such as preserving the public peace, enhancing security, responding to terrorist threats, enforcing the law and responding to emergencies. State active duty includes the duties of officers or enlisted personnel who are ordered by the Governor to perform various functions, such as recruiting, inspecting troops and sitting on general or special courts-martial.

If your association always processesevery rental application within 7 days, the new law shouldn’t pose any problems. But, associations that always or even sometimes need more than 7 days (you know who you are) must implement processes to ensure compliance with the new law. For example:

  • Every rental application must be reviewed immediately upon submission to determine whether the applicant is a servicemember. Non-servicemember applications can be processed like before, but servicemember applications must be placed on top of the pile and made a priority.
  • Strict processing standards must replace relaxed or informal procedures. Applications cannot wait until the next board meeting or be casually left in someone’s inbox.
  • Rental applications should specifically and conspicuously ask whether the applicant is a servicemember—yes or no. Resolve any uncertainties or ambiguities.
  • Those who physically provide or receive rental applications on behalf of the association should confirm the applicant’s servicemember status and notify the board.
  • If rental applications can be submitted online, there must be a way to immediately review every application to identify those submitted by servicemembers.

Complying with the new law may be inconvenient, but it requires far less than commitment and sacrifice made by those serving in the U.S. Armed Forces. Making things a bit easier for servicemembers isn’t just the right thing to do, it’s the law.

Setnor Byer Insurance & Risk is available to discuss ways to identify, manage and insure the risks facing condominium associations and their board members.

Clients of Setnor Byer’s Condominium Program also enjoy access to various risk management services, such as Setnor Byer’s Risk Management Group and Unit Owners’ Report Line, as well as our affiliate’s Condominium Board Member Education Certification, which has been approved by the Division of Florida Condominiums, Timeshares, and Mobile Homes.

You can also receive additional information by subscribing to our weekly Risk Management Newsletters.

Is Your Business Ready for New FLSA White-Collar Overtime Rules?

Over two years ago, the possibility of new overtime rules for white-collar employees under the Fair Labor Standard Act (FLSA) first appeared on the horizon. Last year, the Department of Labor (DOL) released proposed revisions to overtime exemption regulations, including those for executive, administrative and professional employees. Today, that once looming possibility is looking more like a fast approaching reality. Fast, as in possibly by mid-July, fast.

On March 14, 2016, the DOL submitted its final version of the revised overtime exemption regulations to the White House’s Office of Management and Budget (OMB) for review. Once the OMB completes its review, the final regulations will be published. After that, it’s just a matter of time. Unfortunately, there are some details we still don’t know about the final regulations. Minor details, really, like what they are or when they will go into effect.

What will be different under the final regulations?

No one really knows. The final regulations will not be made public until the OMB completes its review, and few details have leaked or been disclosed. Many expect the final regulations to be identical or very similar to the proposed regulations issued in July 2015, including the DOL’s proposal to:

  • Increase the minimum salary requirement for white collar exemptions from $455 per week ($23,660/year) to $921 per week ($47,892/year);
  • Increase the minimum compensation requirement for the Highly Compensated Employee exemption from $100,000 to $122,148 per year; and
  • Automatically update the new minimum salary and compensation levels annually.

It’s possible that the final regulations may include additional changes, particularly the duties test used to determine eligibility under the current white-collar exemptions . In the proposed regulations, the DOL asked for comments about whether changes need to be made to the duties tests. Though the DOL specifically stated that it’s not proposing any specific regulatory changes to the duties test, we don’t know for sure.

When will the final regulations become effective?

This is also uncertain, but it may be sooner than initially expected. The Solicitor of Labor has indicated that the effective date of the final regulations will be 60 days after publication. But, before they can be published, they must be reviewed. The OMB generally has 90 days to review regulations, which would put the deadline near the middle of June. However, because of the upcoming election, the middle of May is probably the OMB’s real deadline. Here’s why.

Under the Congressional Review Act (CRA), Congress is generally given 60 days to review and disapprove a major rule, like the DOL’s new overtime exemption regulations. However, the CRA makes an exception for “midnight rules” that are issued toward the end of an administration. If a rule is issued too late, the 60-day review period essentially resets to give the next session of Congress an opportunity to review and disapprove the rule.

The current administration does not want this to happen, so the OMB must complete its review before the date on which the CRA’s reset provision is triggered. Otherwise, the new overtime exemption regulations would be at the mercy of the next Congress and a new president.

According to calculations by the Congressional Research Service, this date is estimated to be May 16, 2016.

This date was estimated using projected congressional schedules, so it may change. Nevertheless, if we assume the final regulations are published by May 16, 2016, and add 60 days, the new regulations could become effective around July 15, 2016, maybe even sooner!

Or, maybe later. On March 17, 2016, the Protecting Workplace Advancement and Opportunity Act was introduced as a bill. If passed, this law would essentially void any changes made to the white-collar overtime exemptions. Before proposing any new changes, the law would also require the DOL to undertake a comprehensive analysis of how changing overtime regulations would impact employers, including small businesses.

In the meantime, potentially significant changes to overtime pay requirements for white-collar employees may soon be here. How can employers prepare? Unfortunately, plans cannot be finalized until the final regulations are released, but employers can use the July 2015 proposed regulations as a guide to begin developing preliminary plans. In case there are any surprises, these plans should be flexible and capable of adapting to possible contingencies.

The risk of employment-related lawsuits, particularly those involving overtime under the FLSA, is nothing new for employers. But, the prospect of new rules, and their uncertainty, is expected to increase that risk significantly. Employment Practices Liability Insurance can protect against various employment-related claims, and limited coverage for wage and hour claims may also be available.

Please contact us if you would like to learn more about protecting your business with employment practices liability insurance.

To receive regular updates about developments which may affect your business, subscribe to Setnor Byer Insurance & Risk’s weekly risk management news brief.

Did You Get the Text About Distracted Driving Awareness Month?

Did you know that April is National Distracted Driving Awareness Month? If not, it’s time to take notice. According to the National Highway Traffic Safety Administration, approximately 10% of crash fatalities and 18% of crash injuries involve distracted drivers. The consequences of distracted driving can be severe, and the problem only seems to be getting worse.

Distracted driving is any activity that could divert a person’s attention away from the primary task of driving. There are three general categories of driver distraction, all of which can endanger the safety of drivers, passengers and pedestrians:

  • Visual: Taking your eyes off the road.
  • Manual: Taking your hands off the steering wheel.
  • Cognitive: Thinking about anything other than driving.

Common driving distractions include:

  • Texting;
  • Using a smartphone;
  • Eating or drinking;
  • Talking to passengers;
  • Grooming;
  • Reading (maps, emails, etc.);
  • Using a navigation system;
  • Watching a video; and
  • Adjusting radios and CD/MP3 players.

Though all distractions can be dangerous, texting is by far the most alarming because it requires a driver’s visual, manual and cognitive attention. Unfortunately, the number of drivers engaging in this behavior has been steadily increasing, even though nearly every state has made it illegal.

  • 14 states have primary enforcement laws prohibiting the use of hand-held cell phones while driving, which allow an officer to cite a driver for using a hand-held phone without any other traffic offense taking place.
  • 46 states ban text messaging for all drivers, most through primary enforcement laws. A few states, like Florida, have secondary enforcement laws, so drivers cannot be stopped for texting unless another infraction, such as weaving or speeding, is also observed.
  • 38 states ban cell phone use by novice drivers.
  • We’re past the point of denying the consequences of distracted driving, particularly texting while driving. We know too much. Then why are we seeing more and more drivers focusing on their phones instead of the road?
  • Maybe it’s not enough to simply know the consequences of distracted driving. We must also truly understand them. If you don’t think there is a difference between the two, talk to someone who survived a crash caused by a distracted driver or the survivors of someone who didn’t.
  • It’s time for us to change our distracted driving ways. National Distracted Driving Awareness Month makes it the perfect time to start a new habit of avoiding (or at least reducing) driving distractions. It’s particularly important for parents to be vigilant with their driving-aged children. Young drivers and their young passengers need to hear about the dangers of distracted driving early and often.

Please contact us if you would like more information about protecting against the damage caused by distracted drivers.

For more tips and information about safe driving, subscribe to Setnor Byer Insurance & Risk’s weekly risk management news brief.

Did I Just Expose Your Password?

Virtually every aspect of our personal and professional lives is password protected. Forgetting your password is like forgetting where you parked. You’re stuck. With so many passwords to remember, we try to make passwords easier to remember by taking shortcuts. Though some are clever, many are not. Either way, shortcuts can undermine the sole purpose of a password—security.

To hackers and identity thieves, accounts protected by weak passwords aren’t really password protected at all. Using a weak password may provide a sense of security, but it doesn’t provide any real security. It’s like hanging your spare key from the door knob. What’s the point of even having a lock?

If you think this is a bit extreme, judge for yourself. Look at SplashData’s Top 10 list of the most common passwords of 2015, which were identified by analyzing 2 million leaked passwords:

 

  • 123456
  • password
  • 12345678
  • qwerty
  • 12345
  • 123456789
  • football
  • 1234
  • 1234567
  • baseball

[Editor’s Note: We apologize to those who just had their passwords exposed. You know who you are. Since everyone has just seen your password, you should probably change it now.]

This list makes it easy to understand how passwords can be rendered virtually worthless by being weak. It’s absurd to think anyone is actually using these passwords. Unfortunately, it doesn’t look like people are changing their approach to passwords. The 2015 list is nearly identical to the 2014 list, though there were a few new additions, like welcome, login and starwars. Not exactly Fort Knox.

But wait, it gets even worse. People are actually using these passwords to protect information they would never want exposed. Not so much to the world, but to their spouse. That’s right, information about infidelity. After the Ashley Madison breach, millions of passwords were leaked. Here are the top 5 passwords people used to protect perhaps their most intimate secret:

  • 123456
  • 12345
  • password
  • DEFAULT
  • 123456789

Passwords are the first line of defense against unauthorized access to our personal and professional lives. The thing that makes passwords more memorable can also make them weak. Passwords must be strong to be effective. According to Microsoft, a strong password:

  • Is at least eight characters long.
  • Doesn’t contain your user name, real name or company name.
  • Doesn’t contain a complete word.
  • Is significantly different from previous passwords.
  • Contains uppercase and lowercase characters, numbers and symbols.

Cyber threats and data security remain a primary concern for individuals and businesses alike. Even the most sophisticated security measures are vulnerable to attack. Steps can be taken to reduce the risk of being victimized by hackers and identity thieves. The first one can be using strong passwords.

Please contact us if you would like to discuss ways to protect against data breaches and cyber security liability.

Additional information is also available in our weekly Risk Management Newsletters.

Using the Benefits of Representations and Warranties Insurance When Buying or Selling a Business

Deals to buy or sell a business typically include statements of fact by the seller about the business. These representations and warranties are then combined with indemnification provisions to allocate risks and liabilities between the parties. Negotiating representations and warranties can be challenging, and deals often fall apart because the parties cannot reach an agreement. Representations and Warranties Insurance (RWI) can simplify negotiations and possibly save the deal.

RWI protects against unintentional and unknown breaches of a seller’s contractual representations and warranties. Though RWI is not a new insurance product, it’s increasingly being used by both buyers and sellers to shift liability to insurers for a fixed cost.

These policies cover many of a seller’s standard representations and warranties, such as statements about:

  • Capitalization and debt;
  • Accuracy of financial statements;
  • Title to real, personal and intellectual property;
  • Tax matters;
  • Accounts receivable/payable and inventory;
  • Employee benefits and compensation; and
  • Compliance with laws and regulations.

 

In the past, RWI was typically reserved for buyers, but today RWI is used by both buyers and sellers. A ‘buy-side’ policy covers a buyer’s losses, including defense costs, due to the seller’s breach of a representation or warranty. A ‘sell-side’ policy covers the seller for defense costs and losses resulting from claims made by the buyer that the seller breached a representation or warranty.

Sellers can use RWI to:

  • Reduce potential liability for future representation and warranty claims;
  • Lock in their return on investment;
  • Cleanly exit a business or industry;
  • Eliminate the need for purchase price escrows or holdbacks;
  • Retain, use or distribute all or most of the sale proceeds;
  • Protect passive sellers; or
  • Expedite a sale.

 

Buyers can use RWI to:

  • Ensure a source of recovery for the seller’s breach of representations and warranties;
  • Ease concerns created by a sellers’ poor financial condition or other practical considerations that can make it difficult to collect from the seller in the event of a breach, such as sellers that are numerous, geographically dispersed or difficult to locate;
  • Distinguish its bid and appear more attractive to a seller;
  • Provide additional time to detect and report problems by extending the duration of a seller’s representations and warranties; or
  • Protect relationships with sellers who may continue working with buyer after the sale as a key employee or business partner.

 

Unlike standard general liability and property insurance policies, RWI coverages and exclusions can be relatively complex and can also vary depending on the specific policy form and insurance company. You should consult a reputable insurance agent with experience handling RWI applications and policies.

Please contact us if you would like more information about obtaining Representations and Warranties Insurance coverage.

Additional information is also available in our weekly Risk Management Newsletters.

Should You Be Concerned About Products Liability?

Products liability cases typically make the headlines when a manufacturer is hit with a massive jury award for injuries caused by its defective product. As a result, many believe only large manufacturers need to worry about products liability. However, products liability extends well beyond manufacturers.

If someone is injured by a defective product, everyone involved with that product may have a liability exposure. Products liability generally applies to those engaged in the business of selling or otherwise distributing a product, so those in the distribution chain who sell or distribute a defective product may be held liable. Links in this chain may include a product’s designer, manufacturer, distributor, wholesaler or retailer.

A product is generally considered defective when, at the time of sale or distribution, it contains a manufacturing defect, a design defective, or because of inadequate instructions or warnings.

Manufacturing Defect. The product contains a manufacturing defect that departs from its intended design, despite exercising all possible care when preparing and marketing the product.

Design Defect. A product is defective in design when foreseeable risks of harm could have been reduced or avoided by the adoption of a reasonable alternative design and the omission of the alternative design renders the product not reasonably safe.

Inadequate Instructions or Warnings. A product is defective because of inadequate instructions or warnings when foreseeable risks of harm posed by the product could have been reduced or avoided with reasonable instructions or warnings and the lack of instructions or warnings renders the product not reasonably safe.

One justification for the broad scope of potential liability is the belief that those who profit from the sale or distribution of a product should bear the financial burden of damage caused by a defective product. Needless to say, this financial burden can be immense.

According to the Insurance Information Institute, the average products liability jury award in 2013 was nearly $6.4 million. Moreover, the costs of defending products liability cases are often higher than other types of litigation. For example, in addition to $1.6 billion in products liability losses, insurers spent another $1.2 billion in settlement expenses in 2013, or 75 percent of the losses.

Most businesses would not survive the financial burden created by a defective product without insurance. Products liability insurance protects against financial loss arising out of liability that is incurred when a defective product causes injury or damage. This coverage may be available under a standard commercial general liability insurance policy (often referred to as products-completed operations coverage) or a under a separate policy.

Though sufficient coverage can often be obtained under a standard general liability policy, the amount and availability of products liability coverage depends on various factors, such as the nature of the product. An experienced insurance agent can help you find coverage that best suits your needs.

If you would like more information about obtaining products liability insurance coverage, please contact us.