Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. A software vendor is attacked, its service stops, and its clients claim for a badly performed service. Its professional liability policy names cyber nowhere. What happens?
It may well respond: it covers professional fault without distinguishing its cause, and the IT incident is only the cause. This is silent cyber in the full sense
The claim is contractual and bears on a service, not on an incident: that is this policy's triggering fact, whatever the cause. The answer treating silence as absence of cover inverts the very notion of silent cyber, which names unintended cover and not an implicit exclusion. The answer sending everything to the cyber policy confuses the cause with the triggering fact, and would empty every liability policy as soon as a computer is involved. The war exclusion answer imports reasoning from property policies, where the inherited clause is indeed the tipping point, into a line where the question does not arise that way.
Glossary entry · rc-pro2. A directors policy carries a cyber exclusion drafted in general terms. What does it exclude in practice, and why is that rarely the drafted intention?
It excludes a management fault because its subject was IT: in this line the triggering fact is not the intrusion but how it was handled, under investment, late notification, inaccurate disclosure to the market
What is particular to this line is that the claim bears on a decision and not on an incident, so a clause written about the subject catches the wrong object. The answer calling it ineffective starts from a correct observation, this policy does not answer for technical damage, and concludes the clause costs nothing, when it costs exactly what remains. The no gap answer assumes a join between two contracts drafted by two different insurers, which nothing guarantees: a cyber policy does not pick up a management fault. The third party answer names real claims that are not this policy's object, whose insured is the director.
Glossary entry · do-responsabilite-dirigeants3. A 480,000 euro transfer goes out on a convincing email, with no intrusion having taken place. Why do the crime policy and the cyber policy send the file back and forth?
Because each invokes what it lacks: the cyber policy, that no compromise of the system occurred; the crime policy, that the transfer was voluntarily ordered by an employee
The fact that produces the ping pong is that nothing technical happened: nobody got in, somebody wrote. The sub limit answer imagines a disagreement about amount where the disagreement is about characterization, and an amount never makes a cover cease to be concerned. The internal fraud answer states a restriction these policies do not all carry and misses the real objection, which is that the order was given voluntarily. The attribution answer transposes a question from property policies, where it decides a war exclusion, into a file where no state is involved.
Glossary entry · bec-fraude-virement4. Outside property policies, in what form does silent cyber almost always show up, and what does it cost the insured?
Rarely as a flat refusal and almost always as a discussion between two insurers of the same insured, each pointing at the other: the cost is delay, and eighteen months of it on fragile cash produces a harm of its own that nobody indemnifies
The real harm in these situations is temporal before it is financial, and that is what the lesson adds to the list of four lines. The flat refusal answer describes what would happen if the clauses were clear, which on these lines they are not, and so misses the ordinary case. The proportional reduction answer invents a split nobody agreed: two insurers disagreeing on characterization do not agree on shares. The answer keeping the insured out of it mistakes who waits: the insured waits, and waits without knowing for how long.
Glossary entry · silent-cyber5. A third party whose personal data leaked claims against the insured. The general liability policy says nothing about cyber. Onto which notions does the discussion move?
Onto notions written for something else: is there a damage, is it material, immaterial, consequential or non consequential, and is a third party's data a piece of property
A silent policy does not stop working, it works with its original vocabulary, and that vocabulary decides. The fault answer keeps a necessary condition and makes it the only question: established, it leaves entirely open which damage is answered for. The claims made answer names a real mechanism of this line, which decides which contract is seized and not what it covers. The answer pointing at the property policy assumes a program wide position where each contract carries its own, which is exactly the defect the policy inventory exists to expose.
Glossary entry · exfiltration-donnees